Merge ledger-close-23 a9d53a44 into master (gate: green on a9d53a44, recorded by tools/ci/pre-push.sh; landed on the box mirror)

This commit is contained in:
igneum-labs 2026-10-07 21:55:35 +00:00
commit 8f967351be
6 changed files with 97 additions and 23 deletions

View file

@ -8,7 +8,7 @@ Every serious criticism or attack we expect against Igneum, written the way it w
The ledger exists because the only way a design survives public scrutiny is for every pick to have been answered in public before anyone else makes it. It is written against litepaper v0.1 and the design document as of 3 October 2026. Entries are never deleted. When the status of an entry changes, the old status stays in the history of this file.
Statuses used:
Statuses used (the rule since 7 October 2026, night: an entry's current status is the first sentence of its last `Status:` paragraph, the previous one follows "Was:", and the paragraph starts with one of the six statuses' words, never with a date; `tools/ledger/export-public.mjs --check` fails any entry that does not, and `tools/ledger/README.md` carries the rule):
| Status | Meaning |
|---|---|
@ -185,7 +185,7 @@ Evidence: `docs/analysis/horizon/algorithm.md` section 5.1 (the ceiling table: m
### M34. The shadow size N is a constant of the binary, so the one lever against the dataset-storing chip needs a fork to move
"Your own Horizon lane says the reserve and the era draw buy nothing against a chip that stores the dataset, and that the only lever is the latency-shadow size N. N is 27 passes of a 256-instruction block, hard-coded in `V4_CLASS`. So when HBM4 doubles a chip's rate per stack in 2028, your answer is a hard fork, and a fork that retires the M5 Max at the first doubling. And now there is a shipping RandomX ASIC."
Status: Relabelled (7 October 2026, morning, X36): the X9 in this row and in the litepaper paragraph is the chip Bitmain announced and withdrew before launch, its core claimed and never measured; the ladder's arithmetic against that core is unchanged.
Status: Conceded, implemented, stated; relabelled (7 October 2026, morning, X36): the X9 in this row and in the litepaper paragraph is the chip Bitmain announced and withdrew before launch, its core claimed and never measured; the ladder's arithmetic against that core is unchanged.
Status: Conceded, implemented (6 October 2026, night; `docs/design/latency-ladder.md`, branch `ladder`, fork branch `ladder-node`, the 0.3.17 feature tree, behind `latency_ladder_activation_daa`, never until set, 0 on the testnet when the founder says): N is a genesis ladder of six rungs (27, 35, 53, 88, 173, 267 passes; about 102,100 to 1,001,600 counted ops) with a measured admissibility flag per rung (cold verify under 10 ms on the reference core with its SMT sibling loaded, igneum-build-1, 6 October 2026: rungs 0 to 2 pass at 8.77, 8.87 and 9.23 ms, rung 3 misses by 0.08 ms under a box load of 25 and is out until a quiet re-run, rungs 4 and 5 are out at 12.38 and 14.96), and the step is consensus state derived from two bits of the header version: up one rung when 90 percent of blue blocks in each of seven consecutive windows ask for it and the rung above is admissible, down one rung symmetrically, never two rungs inside seven windows (the oldest window must begin after the last step took effect), never unconditionally. Tests, the known-failed case first: a changed N today hashes another program under the same program id (a hard fork no pack line told apart); after, rung 0 is class v4 byte for byte, a rung above carries its pass count in the id, 8,999 bps in one window of seven does not move the step, a two-step jump is impossible, down never passes rung 0, an inadmissible rung is never entered. Stated in `site/litepaper.html`, Mining section ("The work that waits can grow").
@ -193,6 +193,8 @@ Answer: Correct on both counts, and the second was the sharper one. The X9 (Bitm
Evidence: `docs/design/latency-ladder.md` (the rule, the hostile review, the measured verifier table, the X9 arithmetic); `igneum-pow/src/generator.rs` test `latency_ladder_known_failed_a_changed_n_was_a_hard_fork_and_rungs_are_class_v4`; the fork's `consensus/core/src/igneum.rs` test `latency_ladder_rule`, `consensus/pow/src/igneum.rs` test `latency_ladder_rungs_are_programs_of_their_own_over_one_day_cache`; `infra/fast-time/latency-ladder.mjs` (the step, no-step and known-failed cases).
Status: Conceded, implemented, stated (7 October 2026, night, the ledger close): the public text carries the ladder (`site/litepaper.html`, Mining: the six-rung genesis ladder of the latency shadow with a measured admissibility flag per rung, moved by miner signalling, never by a fork; and the X9 relabelled as announced, withdrawn and unbenchmarked), and the rule is implemented behind `latency_ladder_activation_daa` as the paragraph below records. Was: Conceded, implemented.
## 2. Finality and attacks
### F1. Finality is attackable for the first month
@ -371,6 +373,8 @@ Evidence: not yet. Fix: overclaims list, item 25.
Round 2 (5 October 2026, night): status made terminal-explicit. Blocker: the wrapper (design 5.6 `wrap`, R4) does not exist in the repository; the light verifier of the pinned compressed proof is a 58 MB native binary (bench-log 5 October, "the program id split"). Next date: the phase 2 benchmark. Nothing else in the entry changes.
Status: Answered by design (7 October 2026, night, the ledger close): the design rule covers the claim (design 5.6 `wrap`, R4: the aggregated block proof wrapped once into a small curve-based proof by the aggregator) and the public text says what is and is not measured (`site/litepaper.html`, Proving: "Wrapped for light clients, a phone checks it in milliseconds; the wrapping cost is a phase two measurement", with the certificate half's 139 to 155 ms cold and 58 to 68 ms warm on a laptop core). The measurement that closes it: a wrapped segment proof timed on a 12 GB and a 24 GB card and verified on a phone, by the proving lane, in the phase 2 benchmark (November 2026 to January 2027 on the roadmap). Was: Open, blocked on phase 2.
### P4. Trustless light clients need a consensus proof you do not have
"Checking 'one proof and one locked checkpoint' means verifying a BLS certificate against two thirds of active 30-day weight. Computing that weight needs 30 days of headers. Your own review scoped the consensus proof as phase two. The litepaper sells it at launch."
@ -702,7 +706,7 @@ Evidence: litepaper "For miners", hardware paragraph. Wording: overclaims list,
### C2. vs Monero: "no chip in seven years" is not proof
"Absence of a public RandomX ASIC is not evidence one cannot exist. Monero is also a small prize."
Status: Reopened as conceded (7 October 2026, morning, X36): the X9 never shipped, so Monero's record is again seven years without a shipped chip, and the concession stands as first written; the litepaper says so in the same sentences.
Status: Conceded, stated; reopened as conceded (7 October 2026, morning, X36): the X9 never shipped, so Monero's record is again seven years without a shipped chip, and the concession stands as first written; the litepaper says so in the same sentences.
Status: Conceded, stated (7 October 2026, morning): the one-screen home page is back on the owner's word, so this row is stated on `site/litepaper.html` only; the sentence there is unchanged and the text check lists it under the litepaper.
@ -839,6 +843,8 @@ Answer: There is no sale, no premine, no allocation and no promise of return, an
Evidence: design doc "Legal" paragraph. Fix: overclaims list, items 75 and 76.
Status: Open (7 October 2026, night, the ledger close): only the founder's decision with counsel settles it; counsel engaged since 6 October 2026 (decisions item 6). The question for the founder: has counsel's Howey review of the founder-business paragraph, the launch grants and the pool returned, and on that opinion does the litepaper keep or drop the founder-business paragraph before v0.2? The listing sentence is already gone (overclaims 75 and 76).
### L2. Financial promotion rules
"Several jurisdictions now treat a cryptoasset promotion to their consumers as regulated: the UK since October 2023 needs an authorised approver, the EU under MiCA has its own marketing rules, the US has the Howey test. 'The people who show up early get the most' on a domain you own is a promotion wherever the reader sits."
@ -850,6 +856,8 @@ Answer: A litepaper describing how to mine a coin that does not exist is arguabl
Evidence: none. Fix: overclaims list, item 77.
Status: Open (7 October 2026, night, the ledger close): only the founder's decision with counsel settles it; the text half is stated (the schedule facts above). The question for the founder: does counsel confirm that the litepaper's schedule facts are information and not a financial promotion for UK and EU readers, or does the site need an authorised approver before the public testnet opens?
### L3. GoDaddy domains are a seizure risk
"Fifteen domains at a US registrar on US nameservers behind a US host. One court order and igneum.network is a parking page."
@ -872,6 +880,8 @@ Answer: Correct that it needs an entity, terms and tax treatment before it happe
Evidence: design doc "The first six months".
Status: Open (7 October 2026, night, the ledger close): only the founder's decision with counsel settles it. The question for the founder: which entity signs the testnet payment terms with the customer rollup, and does counsel's payments and tax opinion arrive before phase 5, so that paid testnet proving can be announced or the sentence comes out of the roadmap?
### L5. Trademark
"Igneum. Have you checked EUIPO, USPTO and the UK IPO? There is no evidence you did."
@ -883,6 +893,8 @@ Answer: No clearance search is recorded in the repository. One is required befor
Evidence: none.
Status: Answered with evidence (7 October 2026, night, the ledger close): the clearance search is recorded in the repository as the entry asked, `docs/legal/trademark-search-2026-10-03.md` (3 October 2026, one verdict per register: EUIPO RISK, IGNIUM EUTM 018212492 live in classes 36 and 42; UK IPO RISK, IGNIUM UK00918212492 live; USPTO MODERATE RISK, IGNIUM pending in 9 and 42; WIPO partial, no IGNEUM; UAE unsearched; an identical IGNEUM registered in Australia in 37 and 42; preliminary, automated, no attorney review). The name stays provisional in the public text until counsel's filing plan for the IGNIUM mark; the one decision left for the founder: file in classes 9, 36 and 42 on counsel's plan before the public testnet, or keep the name provisional through launch. Was: Open, counsel engaged.
### L6. A permissionless job market paid in dollars is money transmission
"Rollups pay dollars for proofs through your contract and your client picks the winner."
@ -1721,6 +1733,8 @@ Evidence: `site/litepaper.html` Governance; spec 10.6, 4.5; G7, E2. Experiment:
Round 2 (5 October 2026, night): status made terminal-explicit. Blocker: the test needs a network the project does not run alone, which exists from the public testnet (phase 5, Aug to Oct 2027 on the litepaper roadmap). Next date: a published time in that window, before mainnet. The devnet cannot stand in: its nodes are all the project's (developer-adoption section 5, RPC providers row).
Status: Answered by design (7 October 2026, night, the ledger close): the design rules the sentence rests on are in force (every node ships a VDF evaluator, spec 4.5; the seed list ships in the client, spec 10.6; no project-run service sits in consensus, no stake, no fee to any team, spec 5.5 and 5.6), and the public text claims no more than that (`site/litepaper.html`, Governance). The measurement that proves it: O-X.2 as written in the Answer above (every project-run node, miner, prover, aggregator and seed stopped at a published time, the observer and live page down, 24 hours of blocks per second, proof lag, certificates per hour and a fresh sync from the shipped seed list), by the testnet lane, on the public testnet once it opens on the go word (the three seed nodes and the public RPC are up, 7 October 2026), inside that testnet's first month and before mainnet. Was: Open, blocked on the public testnet.
### X16. An evidence page with four labels
"Every claim needs a status, a software version, the test that produced it, the result and whether anyone outside reproduced it. 'Implemented', 'tested by the team', 'reproduced externally' and 'reviewed independently' are four different things, and your bench-log uses one voice for all of them."
@ -1802,6 +1816,8 @@ Answer: Correct, and already true of the rewards since devnet v4 (`BlockFixture.
Round 2 (5 October 2026, night): status made terminal-explicit. Blocker: until the consensus proof of design 7 exists, the rewards and payouts stay data inputs to the shard statement (spec 7.7 item 6) and the node's own derivation is the check. Next date: phase 2. The D6 review of this round names the same class for job outputs, where no consensus derivation exists to check against (`docs/review/d6-forged-job-result-2026-10-05.md`, section 1).
Status: Answered by design (7 October 2026, night, the ledger close): the design rule that contains it is in force, spec 7.7 item 6 and design 5.5: the rewards and payouts a shard statement carries are checked against every node's own consensus derivation, so a proof over any other list matches no node's statement and pays nothing (the native veto); the consensus-proof switch exists dormant (`proving_consensus_verify_daa`, exec-sync-0313, 0.3.20). The work that makes them outputs: the consensus proof of design 7 (the aggregator derives the rewards and payouts from consensus data it verifies), by the proving lane, in phase 2 (November 2026 to January 2027); the same class holds for job outputs (D6). Was: Open, blocked on the phase 2 consensus proof.
## Status updates, 4 October 2026 (branch fin-fixes, commit da1eb889)
- **F17** (keys are free, the draw is per key). Status: Fixed in the node (4 October 2026). `is_aggregator` draws the 8 aggregators by weight, `output x total < 8 x weight x 2^64`, so a splitter holds the tickets its weight buys and no more; spec 3.10 S1 row; unit test `sortition_is_by_weight_not_key_count` (200 dust keys plus 6 real ones); attack harness scenario 2 re-run: honest keys drew 1.61 seats per crowded checkpoint against 1.55 expected by weight, where master drew 0.32 against 0.33 per key (`docs/bench-log.md`, "finality fixes F17 and F1"). Still open from this entry: the client's one-key default, S2 (O-3.5), the bitmap size (O-3.12). Was: Rule fixed (spec 7.2 and W6), node per key.
@ -1860,6 +1876,8 @@ Answer: Correct that the cost exists and that nothing in the design measures it.
Evidence: none possible; `site/litepaper.html` "Questions builders ask".
Status: Conceded, stated (7 October 2026, night, the ledger close): `site/litepaper.html`, What Igneum does not claim, "A label that costs nothing. No. Some investors and exchanges read 'GPU-mined' as 2021 whatever the proofs do, and nothing here measures that cost." Was: Conceded, no experiment possible.
### D4. No dollar, no DeFi
"No stablecoin and no bridge at genesis. 'Native USDC is requested from Circle' is a request. There is no DeFi without a dollar, and your consumer apps cannot exist until phase two."
@ -1880,6 +1898,8 @@ Evidence: `docs/design/execution-layer.md` 10.1 (RPC table, "Missing"), 10.3; de
Round 2 (5 October 2026, night): the order in `docs/design/developer-adoption.md` section 5 is confirmed and the paragraph "Owner and gate" added below its table: step 1 the docs and the Hardhat and Foundry templates; step 2 `debug_traceTransaction`, `trace_block`, `eth_subscribe` and `eth_getProof` with the four-state tags; step 3 a public devnet RPC, the chain-id listing, the wallet tests of R11 and a faucet; step 4 the Blockscout fork. Owner: the execution engineer for every step, the docs site also waiting on the public-repository decision G11. Gate: no outside team is invited to build on the devnet before step 2 is done, with done meaning the methods answer on the devnet nodes under Foundry's debugger and the Blockscout fork, not on a branch.
Status: Conceded, scheduled, stated (7 October 2026, night, the ledger close): `site/litepaper.html`, What Igneum does not claim, "A chain you can debug today. Not yet." with the four steps and the gate (no outside team invited before the second step). The schedule stands as above. Was: Conceded, scheduled.
### D6. A forged job result reaches my contract and nobody vetoes it
"Segments have the native-execution veto. Jobs do not: full nodes cannot re-run an arbitrary program, so for a precompile job the proof is the only check. A soundness bug in SP1 writes whatever the attacker wants into my callback."
@ -1891,6 +1911,8 @@ Evidence: `docs/design/execution-layer.md` 6, 5.6, 9.1 R12; spec 5.7; ledger P7;
Round 2 (5 October 2026, night): reviewed by the cryptographer agent, `docs/review/d6-forged-job-result-2026-10-05.md`. The attack as reviewed: a soundness bug in the proof system version in force lets a prover sign a job statement with a chosen output; the native-execution veto cannot catch it because every full node consumes the output as an input to `onProof` and computes the same root (design 6, 5.5), so the chain is consistent and wrong in one place. What the rules guarantee: no IGN is minted (emission and the pool are state transitions from consensus data, design 1.1 and 4.4; the only IGN moved is the job's escrow, 90% to the forger and 10% burned, design 6); no system contract is written except the job's own result slot in `Prover` (design 4.5, 6), so R12's "touch system contracts" wording needs that narrower sentence; the version gate (design 5.6, steps 1 to 5) and the emergency bump (design 5.5, spec 5.7) close a bug for good. What they do not: the callback's own state and everything downstream of it; the window between disclosure and activation, in which nothing pauses jobs and the 3-month overlap keeps a known-broken verifier reaching callbacks unless job records of the old version are cut at activation (the review's recommendations 2 and 3); the forger's payout; light clients, which agree with full nodes here. The rule for an app (review section 4): a job output is one party's word, and anything irreversible it drives keeps a fallback the app controls (a delay longer than the emergency activation time, a value cap, a second check, or a human veto). Design changes asked: the containment as a normative rule with the precise boundary; job records of version N invalid from the activation of N+1; the emergency release may cut jobs at activation while keeping the segment overlap; the prover is paid when the callback reverts. Devnet checks named (review section 6, phase 4): a job forged against a deliberately broken verifier, with the IGN total, the registry and `Prover` storage compared before and after; the swap procedure in fast time with version-N job records at each stage, the exposure window counted in blocks; four callbacks at the boundary (re-entrant request, past the stipend, reverting, and the app rule with a delay and a second check).
Status: Conceded, contained by rule, stated (7 October 2026, night, the ledger close): `site/litepaper.html`, What Igneum does not claim, "A veto on job results. No." with the containment (a job output mints nothing and touches no system contract; an app that acts irreversibly on a job result keeps its own fallback). The three devnet checks of the review's section 6 stand as the next step. Was: Conceded, contained by rule, reviewed.
## Round 4 entries (4 October 2026, afternoon): what is live
Review: `docs/review/round-4-2026-10-04.md`. Scope: devnet v4 through `a21ff239` (HEAD `3bfe346f`), the prebuilt workers, the Igneum Miner app 0.3.1 to 0.3.3, the relay, the Windows CI, the downloads host, the live site and the economics after the day's measurements. No secret value appears in any entry; comparisons were count-only.
@ -2276,7 +2298,7 @@ Evidence: `site/litepaper.html`; `docs/plans/testnet-go.md`; X31, X32.
### X34. RandomX described as chip-free
"The home page said the random program 'has kept chips off Monero since 2019', the litepaper said Monero ran on RandomX 'with no chip publicly shipped' and spoke of 'Monero's seven years without a public chip'. Bitmain's Antminer X9, a RandomX chip, ships from July 2026 (1 MH/s at 2,472 W, about USD 5,600; monero-project/monero issue 10270), and RandomX 2.0 shipped on 25 March 2026. Every sentence that said or implied RandomX is chip-free, or that Monero's approach has held, was wrong."
Status: Corrected (7 October 2026, morning, X36): the X9 never shipped. Bitmain opened pre-orders on 26 December 2025 and withdrew the product in mid-May 2026 before any unit was delivered; every sentence below that had it shipping now states that, and RandomX stands as a technique no chip has yet shipped against. The sentences in this row are the history.
Status: Fixed, stated; corrected (7 October 2026, morning, X36): the X9 never shipped. Bitmain opened pre-orders on 26 December 2025 and withdrew the product in mid-May 2026 before any unit was delivered; every sentence below that had it shipping now states that, and RandomX stands as a technique no chip has yet shipped against. The sentences in this row are the history.
Status: Fixed, stated (7 October 2026, morning): the one-screen home page carries no RandomX sentence, so the corrected wording stands on `site/litepaper.html` (four sentences and the table row); the text check lists them there.
@ -2298,7 +2320,7 @@ Evidence: `site/index.html`; `site/litepaper.html`; `tools/ci/ledger-text-check.
### X35. The class v4 chip headline stated as one number, 2.1x
"The home page said the strongest chip reaches 'about 2x once the lever now in its gates ships' and the litepaper said the latency-shadow work 'brings the chip to about 2x' and that its edge 'falls from 5.6x to 2.1x ... at a chip core equal to the GPU's'. That 2.1x assumes the chip's core costs what the GPU's does per operation (k = 1). Bitmain's Antminer X9 reached about a third of its honest device's energy on a latency-bound random program, so k about 0.33 is a shipped product class, and at that k the same model gives 3.9x."
Status: Kept, relabelled (7 October 2026, morning, X36): the range stands, with k about 0.33 labelled as the X9's claimed, unmeasured core, since no unit shipped or was benchmarked.
Status: Fixed, stated; kept and relabelled (7 October 2026, morning, X36): the range stands, with k about 0.33 labelled as the X9's claimed, unmeasured core, since no unit shipped or was benchmarked.
Status: Fixed, stated (7 October 2026, 00:0x UK, from the ladder lane's recalibration against the X9): every public sentence that stated 2.1x alone now states the range with k named. The 5.7x class v3 memory-only figure has no core work in it and is unmoved; the litepaper's 5.6x is the Counter ASIC 3.0 item 8 figure and stays as cited.
- `site/index.html`, chip model card. Was: "In our public model the strongest chip reaches 5x to 9x per joule against an RTX 5090 today, about 2x once the lever now in its gates ships." Now: "In our public model the strongest chip reaches 5x to 9x per joule against an RTX 5090 today. With the class v4 shadow work it is 2.1x to 3.9x, the range running from a chip core as costly per operation as the GPU's (k = 1) to one as efficient as Bitmain's RandomX chip (k about 0.33); the ladder's second rung takes that 3.9x to about 2.8x."
@ -2311,6 +2333,8 @@ Answer: One number was the model's k = 1 column; the X9 made the k = 0.33 column
Evidence: `docs/design/latency-ladder.md` (the k column, the rung table at k = 0.33, the verifier table); M34; X34.
Status: Fixed, stated; restated (7 October 2026, evening, by order of the coordinator; the chip-text rewrite e57da45a, on master at 25f38035): the served texts give the floor and the premium at the 5090's measured knee: 2.1x per joule with a core as good as a GPU lane (k = 1), 3.4x with one three times better (k about 0.33), no core below about 1.8 pJ per op in the model's range, the premium 81.8 W at the best points, Ember Tune named as how a user gets there; the ledger pin for X35 moved to the new sentence; `site/litepaper.html#chip-model` and the home line.
### X36. The X9 described as a shipping chip
"X34 and X35 said Bitmain's Antminer X9 'ships from July 2026' and called it 'the shipping RandomX chip'. It never shipped: Bitmain opened pre-orders on 26 December 2025 for July 2026 delivery, resellers told buyers in mid-May 2026 that Bitmain had discontinued it and refunded them, no unit was delivered and none was independently benchmarked."
@ -2329,6 +2353,17 @@ Sources: bitmain.com news post dated 1 January 2026 (pre-orders opened 26 Decemb
Evidence: `site/index.html`; `site/litepaper.html`; `tools/ci/ledger-text-check.mjs`; X34, X35, M34.
Status: Fixed, stated; restated further (7 October 2026, evening, from the counter-asic-4 research file d7721ebe; on master at 25f38035): the X9's claimed ratio is against a CPU core, not a GPU lane, so the texts no longer use it as a pessimistic chip core; every served sentence says so; the pin for X36 moved.
### X37. The class v4 energy premium is a cost the user pays, not a line in a model
"Your chip model counts joules per hash for the attacker. What does class v4 cost the miner at the wall, and can any hash-side change bring that premium to zero?"
Status: Answered with evidence (7 October 2026, the Counter ASIC lane's measurement; levers in flight): measured on the RTX 5090, 145 W of premium unlocked and 82 W at the knee; the RTX 5080 at stock 84 W, its grid running; the research lane's identity says the premium needed for 2x at k = 1 is 103 W at the lock and a premium of zero is impossible by any hash-side lever; the chip model's section 5.10 (`docs/analysis/chip-model-v3.md`, aa829826) shows class v5 with the shadow at zero leaves the stored-dataset chip at 5.1x to 9.1x, so the shadow stays the only lever. The levers: the core-clock knob into Ember Tune for 0.3.24, the SM-sparse kernel and the L2 hot-table reads on PC 1's queue.
Answer: Correct that it is a cost at the wall, and it is measured, not modelled: 82 W at the knee on a 5090 is the price of the latency shadow, and Ember Tune is how a user reaches the knee. What no hash-side change can do is remove it: without the shadow the stored-dataset chip's edge returns (5.1x to 9.1x in the model), so the premium is the chip defence, priced per card.
Evidence: `docs/plans/counter-asic-3-status.md` (the knee record, a657de73, 88a97f6c); `docs/analysis/chip-model-v3.md` section 5.10; `docs/bench-log.md`.
## Status updates, 4 October 2026 (round 4)
- **F21** (the long-partition fork). Extended: a side locks alone when its own share of its own table reaches two thirds, at `t = W (2/3 - s) / (1 - s)`: 50/50 at 2,400 DAA s on the devnet (about 40 minutes), 10 days on mainnet; the 60 side of 60/40 at 1,200 DAA s (20 minutes), 5 days; the ledger's measured `W/(3R)` = 200 s is this formula at s = 1/2. At HEAD a second certificate at an index is kept, logged and ignored (`processes/finality.rs:650-655, 661-666`) and `fork_choice_lock` (`:886-901`) pins the node. Public text: `site/litepaper.html:511` says a third of the blocks is needed to split finality in a partition; the partition alone does it. Replacement sentence in `docs/review/round-4-2026-10-04.md` section 1 (b). Review id R4.1.5.
@ -2464,6 +2499,8 @@ F8's 64-seed gate on 017e7037 (the attack-pass lane, box 2, last seed 16:00:20 U
Owed (recorded, not run, by the founder's word): G2 (the CPU verifier on 1,024 hashes per card) on the amended stream; G3 (the Metal fuzz, edge, stats and determinism runs) on the amended stream; the hash-rate ladder re-measure on the M5 Max and the RTX 5090 (the amendment changes the base program's source draws, not the op mix or the load count, so the latency-bound rows of `docs/analysis/latency-shadow-2026-10-06.md` are expected to hold within their spread; unmeasured); AMD (the RX 9070 XT, PC 1); the 2019-class verifier core (O-1.14); F8's phase E (the 64-seed dynamic census) on the amended stream, which is the attack-pass lane's and the test of the per-op table. The row reads FIXED-AND-PASSED only after phase E passes against the amended class.
Status: Fixed in part, finding bounded, stated (7 October 2026, night, the Counter ASIC lane's words): class v4 sub-version 3 (igneum-pow 017e7037, the audit-freeze tag) is frozen with the dataflow rule, the shared-operand rule, the 0.98 ratio and the total draw; the in-house pass's F8 re-gate reads 60 of 64 seeds under 1.2x with the four-seed tail accepted by the coordinator as the window model's unattributed residue (no chip consequence); the pass then attributed the class by value (eight live hot sets at 1.54x to 2.24x in the lowest 30 of 29,032 accepted programs, each about 1 MB of items at 0.3 percent of reads, 1.002x to a chip); class v5 (1c420786, frozen 21:53 UK) carries the fix as rule (c'''), the per-site distinct-index floor at 0.995 on the state flag (its census refuses 2.435 percent of accepted programs; seven of seven live hot sets refused at 0.9821 to 0.9919; the eighth's ratio owed tonight), with a named residual (three mild shadow-block-written concentrations at 0.9992 to 0.9997, about 1.0004x, a value-level test in the next class); the record is `docs/plans/counter-asic-3-status.md` section 7c and the class v5 design's section 14. The eighth live hot set (seed 122960, id 4be7393ab6c84802, the deepest found: X_f +0.111 percent, 1.54x the window model, its hottest item at 475,616 reads from an all-ones source) reads minimum site 12 at 0.9824 at the acceptance's own 2^20 sample (live 0.9822), refused by class v5's (c''') floor at 0.995; so the floor refuses eight of eight live hot sets by X_f at or above f found in the tail of 88,051 accepted programs (minimum sites 0.9821 to 0.9919) against 0 hot sets in 20 random programs; what it misses stays the three mild shadow-block-written concentrations at 0.9992 to 0.9997 (Devnet 3's first program among them), about 1.0004x to a chip, the value-level test in the next class (22:41 BST; the logs under `docs/analysis/cryptanalysis/logs/adv-accept/` on branch adv-accept; the v5 design's section 14). The RTX 5080 grid's knee is not in tonight; X37 keeps the 5080's stock premium only.
## Genesis forward-compatibility entries (7 October 2026, mission item 8, branch `genesis-forward`)
The three genesis fields of `docs/analysis/mission/mission.md` section 2.8, built on the node fork branch `genesis-forward` (from release-0.3.19-node dc141409) and the repo branch `genesis-forward`; the design and the gates in `docs/design/genesis-forward.md`. Every switch is never on the devnet (its digest c562d70e... does not move); the testnet genesis sets all three (the testnet lane re-pins and re-digests).
@ -2495,3 +2532,6 @@ Answer: Consumer LLC is 96 to 128 MB today and datacentre 256 MB (`chip-model-v3
Status: Conceded, flagged in spec 04 section 4.8 (7 October 2026); not sized. The fallback is a hash-chain delay behind the same version byte that moves the signature scheme; designed when the scheme flip is scheduled.
Answer: A grindable hourly seed is a liveness nuisance against the lottery, not a safety break: finality rests on the vote keys (GF1), the seed on the VDF. The two flip together by one class change.
Status: Conceded, stated (7 October 2026, night, the ledger close): `site/litepaper.html`, What Igneum does not claim, "A delay function that outlives a quantum computer. No." with the fallback (a hash-chain delay behind the version byte that moves the signature scheme, one class change) and the reading (a liveness nuisance, not a break of finality). Still not sized. Was: Conceded, flagged in spec 04 section 4.8.

View file

@ -2,7 +2,7 @@
Generated by `tools/ledger/export-public.mjs` from `docs/fud-ledger.md`; a gate check fails when the two drift. One row per item: the claim or criticism, its status, what was done, and the evidence. Internal identifiers, times of day and team-member names are left out on purpose; the full ledger is published with the repository.
190 items. By status: Conceded, stated 50; Fixed 30; Decided 22; Fixed on a branch, pending merge 14; Answered by design 6; Fixed, stated 6; Open, counsel engaged 4; Answered with evidence 4; Closed by rule 3; Answered by design, with a correction to our own text 1; Answered with evidence, stated 1; Answered by design for finality, Conceded for the lottery 1; Conceded, implemented 1; Rule implemented and measured; launch month simulated 1; Answered by design, with the concession stated 1; Conceded, stated in the litepaper and the design doc 1; Answered with evidence at 1 block/s 1; Conceded, stated in the simulation report 1; Answered by design, with the dependency conceded. Update 7… 1; Conceded, stated in the litepaper, with the dial explained 1; Open, blocked on phase 2 1; Closed by spec 1; Conceded by decision, stated in the design doc 1; Answered by design, with the founder's edge conceded 1; Answered by design, with a metrics caveat 1; Closed by removal, 3 October 2026 1; Conceded, stated in the litepaper 1; Conceded, stated in the design doc 1; Measured on the live node line, and the overlay does NOT… 1; Conceded, stated in the simulation 1; Conceded in part, labelled, stated 1; Fixed in the node 1; Answered with evidence for the largest body the rules allow 1; Spec fixed 1; Fixed in the proving code 1; Fixed in the spec 1; Rule fixed 1; Rule written 1; Fixed, logged 1; Answered with evidence for the test half 1; Fixed in the node and shipped, rule not yet activated on… 1; Simulation half run 1; Answered with evidence for all four 1; Open, blocked on the public testnet 1; Written 1; Designed 1; Fixed and confirmed 1; Open, blocked on the phase 2 consensus proof 1; Rolled out 1; Conceded, no experiment possible 1; Conceded by decision 1; Conceded, scheduled 1; Conceded, contained by rule, reviewed 1; Fixed on a branch and verified locally 1; Answered with evidence and stated 1; Answered with evidence for PC 2 1; Answered by design and with evidence 1; Fixed on a branch, pending the 0.3.20 node ship 1; Fixed as a genesis lever, measurement owed 1; Conceded, flagged in spec 04 section 4.8 1.
191 items. By status: Conceded, stated 52; Fixed 30; Decided 22; Fixed on a branch, pending merge 14; Answered by design 9; Answered with evidence 6; Fixed, stated 4; Closed by rule 3; Open 3; Answered by design, with a correction to our own text 1; Answered with evidence, stated 1; Answered by design for finality, Conceded for the lottery 1; Conceded, implemented, stated 1; Rule implemented and measured; launch month simulated 1; Answered by design, with the concession stated 1; Conceded, stated in the litepaper and the design doc 1; Answered with evidence at 1 block/s 1; Conceded, stated in the simulation report 1; Answered by design, with the dependency conceded. Update 7… 1; Conceded, stated in the litepaper, with the dial explained 1; Closed by spec 1; Conceded by decision, stated in the design doc 1; Answered by design, with the founder's edge conceded 1; Answered by design, with a metrics caveat 1; Closed by removal, 3 October 2026 1; Conceded, stated in the litepaper 1; Conceded, stated in the design doc 1; Measured on the live node line, and the overlay does NOT… 1; Conceded, stated in the simulation 1; Conceded in part, labelled, stated 1; Fixed in the node 1; Answered with evidence for the largest body the rules allow 1; Spec fixed 1; Fixed in the proving code 1; Fixed in the spec 1; Rule fixed 1; Rule written 1; Fixed, logged 1; Answered with evidence for the test half 1; Fixed in the node and shipped, rule not yet activated on… 1; Simulation half run 1; Answered with evidence for all four 1; Written 1; Designed 1; Fixed and confirmed 1; Rolled out 1; Conceded by decision 1; Conceded, scheduled, stated 1; Conceded, contained by rule, stated 1; Fixed on a branch and verified locally 1; Answered with evidence and stated 1; Answered with evidence for PC 2 1; Answered by design and with evidence 1; Fixed, stated; restated 1; Fixed, stated; restated further 1; Fixed in part, finding bounded, stated 1; Fixed as a genesis lever, measurement owed 1.
| Id | Claim or criticism | Status | What was done | Evidence |
|---|---|---|---|---|
@ -21,7 +21,7 @@ Generated by `tools/ledger/export-public.mjs` from `docs/fud-ledger.md`; a gate
| M13 | Macs mine too is marketing | Conceded, stated | `Site/litepaper.html`, For miners, Hardware, "Macs mine too, at about a fifth of a flagship card: Measured, 26.7 against 123 million hashes a second" (confirmed by grep tonight; the projected-earnings half is not… | [docs/bench-log.md](../docs/bench-log.md) |
| M32 | "Automatic anti-ASIC escalators" overstates what the era draw and the instruction reserve do | Conceded, stated | The era draw and the instruction reserve are automatic schedule changes against fixed datapaths and against human forks; against the stored-dataset chip every drawn parameter is firmware, and the defence against that… | [docs/analysis/horizon/algorithm.md](../docs/analysis/horizon/algorithm.md) |
| M33 | The FPGA ceiling rests on a tFAW the JEDEC HBM2 table does not give | Conceded, stated | The public FPGA line carries only the measured row, 2.4 G reads/s per card and 0.30x to 0.39x of the RTX 5090 per watt (Shuhai, FCCM 2020 Fig 7; the tFAW arithmetic from ICCAD 2021 Table I), and the 11.4 G bank-bound… | [docs/analysis/horizon/algorithm.md](../docs/analysis/horizon/algorithm.md) |
| M34 | The shadow size N is a constant of the binary, so the one lever against the dataset-storing chip needs a fork to move | Conceded, implemented | N is a genesis ladder of six rungs (27, 35, 53, 88, 173, 267 passes; about 102,100 to 1,001,600 counted ops) with a measured admissibility flag per rung (cold verify under 10 ms on the reference core with its SMT… | [docs/design/latency-ladder.md](../docs/design/latency-ladder.md) |
| M34 | The shadow size N is a constant of the binary, so the one lever against the dataset-storing chip needs a fork to move | Conceded, implemented, stated | The public text carries the ladder (`site/litepaper.html`, Mining: the six-rung genesis ladder of the latency shadow with a measured admissibility flag per rung, moved by miner signalling, never by a fork; and the X9… | [docs/design/latency-ladder.md](../docs/design/latency-ladder.md) |
| F1 | Finality is attackable for the first month | Rule implemented and measured; launch month simulated | The harness text only: `tools/finality-attacks/run.mjs` names the 2/3-of-total floor in the s6 comments and criterion and in the s5 result line, where it still said 56.7%; the scenario logic is untouched. | [sim/](../sim/) |
| F2 | The two-hour presence window is an eclipse vector | Closed by rule | Correct that the presence window trades safety for liveness. | [sim/results.md](../sim/results.md) |
| F3 | Participation grinding through the bitmap | Decided | The per-block vote bound and the bitmap wire bound of spec 3.4.2 items 2 and 3 are adopted for gate 3; the spec moves them from Proposed to Decided at the next spec edit. | design doc Finality v2, Quorum item 2 and Checkpoints item 3. |
@ -38,7 +38,7 @@ Generated by `tools/ledger/export-public.mjs` from `docs/fud-ledger.md`; a gate
| F26 | "No stake" needs its one sentence: what is at stake, and what strips it | Conceded, stated | `Site/litepaper.html`, the finality section's "What is not here" paragraph and the "Igneum at a glance" Finality row carry the sentence verbatim: "No coin is staked. | [docs/analysis/horizon/frontier.md](../docs/analysis/horizon/frontier.md) |
| P1 | The 20-second shard is a number you made up | Conceded, stated | `Site/litepaper.html`, Proving, The proving budget, "Target: shard size will be set so a 12 GB card proves one shard in about 20 seconds. | [site/journey.json](../site/journey.json) |
| P2 | Real-time proving needs a hundred GPUs per block | Conceded, stated in the litepaper, with the dial explained | True, and the litepaper says a full block needs a cluster of 100 to 200 consumer GPUs, approximate. | design doc "Unit economics of a proof"; litepaper "What Igneum does not claim" item 1. |
| P3 | A phone verifies in milliseconds is a SNARK-wrapper claim | Open, blocked on phase 2 | Next measurement the phase 2 benchmark, design R4 (Nov 2026 to Jan 2027 per the litepaper roadmap), a wrapped segment proof timed on a 12 GB and a 24 GB card and verified on a phone. | not yet. |
| P3 | A phone verifies in milliseconds is a SNARK-wrapper claim | Answered by design | The design rule covers the claim (design 5.6 `wrap`, R4: the aggregated block proof wrapped once into a small curve-based proof by the aggregator) and the public text says what is and is not measured… | not yet. |
| P4 | Trustless light clients need a consensus proof you do not have | Conceded, stated | `Site/litepaper.html`, precedents table row 6, "The consensus proof that makes the checkpoint self-verifying is phase two"; Building item 2, "Light clients". | design doc, hostile review table rows "Slashing an external prover" and "One-proof light clients". |
| P5 | EVM "unchanged" on a DAG is false | Closed by spec | Correct. | design doc, hostile review table row "EVM semantics on a DAG". |
| P6 | The proving market is tiny | Conceded, stated | `Site/litepaper.html`, The problem, "a supplier whose marginal cost is close to power"; "cheapest supplier" and "lowest cost" absent from the page (grep, tonight). | design doc "Market size, honestly" and "Existing prover networks" table (labelled from memory). |
@ -80,11 +80,11 @@ Generated by `tools/ledger/export-public.mjs` from `docs/fud-ledger.md`; a gate
| C10 | vs Boundless and Succinct: you cannot bid there without their tokens | Conceded, stated | `Site/litepaper.html`, Proving for everyone else, "Boundless provers post ZKC and Succinct provers stake PROVE (approximate, from their documentation)". | design doc "Existing prover networks" table, labelled approximate. |
| C11 | vs everyone: "firsts" that are not | Conceded, stated | `Site/litepaper.html`, precedents table, "We know of no chain that combines them"; Building, "that we know no other EVM chain offers". | this ledger. |
| C12 | vs Monero: you borrowed the hash idea and left out the point | Answered by design | Transactions on Igneum are public, as on Ethereum. | CLAUDE.md rules (privacy rejected). |
| L1 | It is a security under Howey | Open, counsel engaged | There is no sale, no premine, no allocation and no promise of return, and nothing in consensus is controlled by the team and no protocol fee reaches it (the development fund was removed on 3 October 2026), which is the… | design doc "Legal" paragraph. |
| L2 | Financial promotion rules | Open, counsel engaged | ; the text half is stated below. | none. |
| L1 | It is a security under Howey | Open | Only the founder's decision with counsel settles it; counsel engaged since 6 October 2026 (decisions item 6). | design doc "Legal" paragraph. |
| L2 | Financial promotion rules | Open | Only the founder's decision with counsel settles it; the text half is stated (the schedule facts above). | none. |
| L3 | GoDaddy domains are a seizure risk | Decided | The nameserver move to deSEC in one sitting with every domain's Vercel verification checked afterwards; a non-US registrar in December 2026 when the transfer lock ends. | CLAUDE.md "Domains". |
| L4 | Paying testnet miners real money is a payment before launch | Open, counsel engaged | Correct that it needs an entity, terms and tax treatment before it happens. | design doc "The first six months". |
| L5 | Trademark | Open, counsel engaged | The clearance search is recorded in the repository as a dated one-line result per register when it returns. | none. |
| L4 | Paying testnet miners real money is a payment before launch | Open | Only the founder's decision with counsel settles it. | design doc "The first six months". |
| L5 | Trademark | Answered with evidence | The clearance search is recorded in the repository as the entry asked, `docs/legal/trademark-search-2026-10-03.md` (3 October 2026, one verdict per register: EUIPO RISK, IGNIUM EUTM 018212492 live in classes 36 and 42;… | none. |
| L6 | A permissionless job market paid in dollars is money transmission | Answered by design | At launch jobs are paid on the customer's chain, in the customer's asset, by the customer's contract, to the prover's address; Igneum operates no custody and takes no cut off-chain. | design doc "The first six months". |
| X1 | "Reproducible from the repository" and the repository is private | Conceded, stated | `Site/litepaper.html`, vs RandomX "Track record" row, "The specification, reference hash, test vectors and simulators are public now (git.igneum.network/igneum-network/spec). | [site/index.html](../site/index.html) |
| X2 | "Get the miner" with no miner | Conceded, stated | `Site/index.html`, hero button "See the miner"; the Mine section's download buttons carry the shipped devnet build's version and size (v0.3.9) beside "Public testnet: not yet open; the devnet build is here for people… | [site/index.html](../site/index.html) |
@ -136,7 +136,7 @@ Generated by `tools/ledger/export-public.mjs` from `docs/fud-ledger.md`; a gate
| G11 | Publish the inspectable components now, labelled experimental | Decided | The specification subset is public as `igneum-network/spec` (`docs/plans/public-repo.md`), labelled; the node fork, the proving code and the harnesses stay private until the benchmark. | [docs/fud-fixes.md](../docs/fud-fixes.md) |
| X13 | One paying customer for a stated reason | Decided | The paid pilot stays in phase 5, the phase 4 gate stays the signature, nothing moves earlier before counsel answers L4. | [site/journey.json](../site/journey.json) |
| X14 | Concentration is unmeasured in four places | Answered with evidence for all four | , ledger close round 2: X14 signing concentration from block payloads"); the independence definition stays the founder's (X5). | X5, F10, P12, spec 9.4.2. |
| X15 | Remove the founders from a test network and show what continues | Open, blocked on the public testnet | Next step O-X.2 run at a published time on that testnet, with the protocol already in the Answer below (every project-run node, miner, prover, aggregator and seed stopped, the observer and live page down, 24 hours of… | [site/litepaper.html](../site/litepaper.html) |
| X15 | Remove the founders from a test network and show what continues | Answered by design | The design rules the sentence rests on are in force (every node ships a VDF evaluator, spec 4.5; the seed list ships in the client, spec 10.6; no project-run service sits in consensus, no stake, no fee to any team,… | [site/litepaper.html](../site/litepaper.html) |
| X16 | An evidence page with four labels | Written | `Docs/evidence.md`, one row per public claim with five labels (tonight, counting the label column of the claims table: designed 9, implemented 8, tested by the team 26, reproduced externally 3, reviewed independently 2). | [docs/bench-log.md](../docs/bench-log.md) |
| X17 | The miner app must show net earnings and keep jobs away from keys | Designed | Spec 8.8 and phone-app 4.1; measurement O-8.2 and the escape test O-8.3 scheduled for the phase 4 devnet. | [site/litepaper.html](../site/litepaper.html) |
| P18 | The mempool queues transactions no block can carry | Fixed | Correct, and low: the queue slot was reserved against the sender's funds, so it was self-limited. | [docs/bench-log.md](../docs/bench-log.md) |
@ -144,14 +144,14 @@ Generated by `tools/ledger/export-public.mjs` from `docs/fud-ledger.md`; a gate
| P20 | The SP1 GPU client panics on shutdown and the compressed stage waited ten minutes | Fixed and confirmed | The buffered save closed the gap, the core proof finished at and the compressed stage started at; shard timings repeated within 0.3 s (core 9.1 s, compressed 10.5 s); a guest that returned 0 bytes on the second run was… | [docs/bench-log.md](../docs/bench-log.md) |
| M23 | Forge timestamps inside the rules and the controller mines you a 10x difficulty for free | Fixed | Correct on every point, and measured first by our own attack run (`sim/difficulty/attacks/README.md`, scenarios 3 and 7): in the simulator a 50% forger took the block rate to 0.12 (earliest stamp) and 0.56 (latest) of… | [docs/bench-log.md](../docs/bench-log.md) |
| P21 | The SP1 proof is not what consensus checks in proving v0 | Decided | Proving v0 (every producer verifies off the consensus path) through the public testnet; the in-consensus verifier is the execution engineer's plan item for after it; the litepaper sentence labelled Open stands. | none named |
| P22 | The rewards and payouts are inputs to the shard proof, not outputs | Open, blocked on the phase 2 consensus proof | Next step that consensus-proof work, in phase 2 (Nov 2026 to Jan 2027 per the litepaper roadmap), no earlier date. | none named |
| P22 | The rewards and payouts are inputs to the shard proof, not outputs | Answered by design | The design rule that contains it is in force, spec 7.7 item 6 and design 5.5: the rewards and payouts a shard statement carries are checked against every node's own consensus derivation, so a proof over any other list… | none named |
| M24 | Your two-lane controller oscillates for an hour when a second miner joins mid-epoch | Rolled out | Rule v2 activated on the live devnet at DAA 33,000 by the height switch after a 12-node cloud rehearsal (settle 157 to 272 s, no swing); node 1, the seed, the observer and the three app machines crossed the height on… | [sim/difficulty/records/live-2026-10-04.csv](../sim/difficulty/records/live-2026-10-04.csv) |
| D1 | Your users are a gate, not a fact | Conceded, stated | Correct on the count and on the definition. | [docs/bench-log.md](../docs/bench-log.md) |
| D2 | The app share pays nothing | Conceded, stated | `Site/litepaper.html`, Building, Why build here, "a million 100,000-gas calls a day at a 1 gwei tip pays about 7,300 IGN a year"; Canto and Blast absent from the page (grep, tonight). | [docs/design/developer-adoption.md](../docs/design/developer-adoption.md) |
| D3 | Proof of work in 2027 is a perception cost you cannot measure | Conceded, no experiment possible | Correct that the cost exists and that nothing in the design measures it. | [site/litepaper.html](../site/litepaper.html) |
| D3 | Proof of work in 2027 is a perception cost you cannot measure | Conceded, stated | `Site/litepaper.html`, What Igneum does not claim, "A label that costs nothing. | [site/litepaper.html](../site/litepaper.html) |
| D4 | No dollar, no DeFi | Conceded by decision | , restated here for builders. | [docs/review/round-3-2026-10-03.md](../docs/review/round-3-2026-10-03.md) |
| D5 | I cannot debug a revert | Conceded, scheduled | `Docs/design/developer-adoption.md` section 5, owner and gate named (the execution engineer; no outside team is invited before step 2 is done). | [docs/design/execution-layer.md](../docs/design/execution-layer.md) |
| D6 | A forged job result reaches my contract and nobody vetoes it | Conceded, contained by rule, reviewed | `Docs/review/d6-forged-job-result-2026-10-05.md`. | [docs/design/execution-layer.md](../docs/design/execution-layer.md) |
| D5 | I cannot debug a revert | Conceded, scheduled, stated | `Site/litepaper.html`, What Igneum does not claim, "A chain you can debug today. | [docs/design/execution-layer.md](../docs/design/execution-layer.md) |
| D6 | A forged job result reaches my contract and nobody vetoes it | Conceded, contained by rule, stated | `Site/litepaper.html`, What Igneum does not claim, "A veto on job results. | [docs/design/execution-layer.md](../docs/design/execution-layer.md) |
| X23 | One shipped key is an administrator channel to the founder's PCs | Fixed on a branch, pending merge | Three tiers in `relay/lib/guard.mjs` (`authVia`): the console token (header or the phone page's path), the relay's own key (`RELAY_KEY`: reads and reports, never `task`, `run`, `name`, `role`, `secret`, `delete`), and… | [docs/review/round-4-2026-10-04.md](../docs/review/round-4-2026-10-04.md) |
| X24 | The relay token rides in the URL on every request | Fixed on a branch, pending merge | Every client and Mac tool calls `/api/relay?fn=<fn>` with `x-relay-token` (and `x-igneum-key`) as headers: `igneum-agent.ps1` and `send.ps1` (`Api-Url`), `agent.sh` and `send.sh` (through a 0600 curl config file, `-K`,… | [tools/relay.mjs](../tools/relay.mjs) |
| X25 | The PC agent installs itself at every logon, at highest privilege, on every start | Fixed on a branch, pending merge | `Igneum-agent.ps1` calls `Arm-Restart` only on the two paths that end in `shutdown.exe /r` (a task that printed `RELAY-REBOOT` on its own line AND was queued with `--reboot` or `--reboot-continue`), sets… | [relay/clients/igneum-agent.ps1](../relay/clients/igneum-agent.ps1) |
@ -186,13 +186,14 @@ Generated by `tools/ledger/export-public.mjs` from `docs/fud-ledger.md`; a gate
| X32 | The roadmap carried calendar months beside a testnet that is weeks away | Fixed, stated | Every calendar month is out of the roadmap. | [site/litepaper.html](../site/litepaper.html) |
| X33 | The public benchmark dated "January 2027" | Fixed, stated | Both sentences read "The public benchmark with a leaderboard ships with the public testnet." (`site/litepaper.html`, For miners and Questions miners ask). | [site/litepaper.html](../site/litepaper.html) |
| X34 | RandomX described as chip-free | Fixed, stated | Four sentences corrected, each with the X9 as the stated fact and its date; every sentence that only names the technique stands. | [site/index.html](../site/index.html) |
| X35 | The class v4 chip headline stated as one number, 2.1x | Fixed, stated | Every public sentence that stated 2.1x alone now states the range with k named. | [docs/design/latency-ladder.md](../docs/design/latency-ladder.md) |
| X36 | The X9 described as a shipping chip | Fixed, stated | Every public sentence that had the X9 shipping now states the pre-order, the withdrawal and the unbenchmarked core. | [site/index.html](../site/index.html) |
| X35 | The class v4 chip headline stated as one number, 2.1x | Fixed, stated; restated | The served texts give the floor and the premium at the 5090's measured knee: 2.1x per joule with a core as good as a the team (k = 1), 3.4x with one three times better (k about 0.33), no core below about 1.8 pJ per op… | [docs/design/latency-ladder.md](../docs/design/latency-ladder.md) |
| X36 | The X9 described as a shipping chip | Fixed, stated; restated further | The X9's claimed ratio is against a CPU core, not a the team, so the texts no longer use it as a pessimistic chip core; every served sentence says so; the pin for X36 moved. | [site/index.html](../site/index.html) |
| X37 | The class v4 energy premium is a cost the user pays, not a line in a model | Answered with evidence | Measured on the RTX 5090, 145 W of premium unlocked and 82 W at the knee; the RTX 5080 at stock 84 W, its grid running; the team identity says the premium needed for 2x at k = 1 is 103 W at the lock and a premium of… | [docs/plans/counter-asic-3-status.md](../docs/plans/counter-asic-3-status.md) |
| N1 | A 0.3.15 node on the live file wrote blocks every 0.3.14 node rejected | Fixed | The class v4 signal (PROPOSED, `docs/plans/counter-asic-3-node.md` section 6) is the producer's object version in the high byte of the header version; the first 0.3.15 build stamped it from the binary alone, so on the… | [infra/fast-time/node-compat.mjs](../infra/fast-time/node-compat.mjs) |
| N2 | Any peer could crash any pruned node with a sync request below its retention | Fixed | `SyncManager::antipast_hashes_between` (the IBD headers path, `RequestHeaders`) unwrapped the GHOSTDAG reads of the requested low block and of every chain block of the walk; a pruned node holds no GHOSTDAG data below… | unit test `a_sync_request_below_retention_is_an_error_not_a_panic` (a chain of six headers, the genesis's GHOSTDAG… |
| P23 | An unwound transaction leaves the node's view until its sender resends it | Fixed on a branch, pending merge | a fork a commit (the P23 commit, on the merge of `ledger-fixes` and `ledger-fixes-2` onto the 0.3.11 fork tip a commit); `EvmPool::on_chain_removed` (igneum/exec/src/pool.rs) and `ExecService::requeue_unwound`… | [igneum/exec/src/pool.rs](../igneum/exec/src/pool.rs) |
| AP-F8-1 | A load whose source was last written by `or`, `mul` or `mulhi` makes a cross-hash hot set | Fixed on a branch, pending the 0.3.20 node ship | `Ca3-v4-amend` a commit (the generator and the packs) and a commit (the PC 2 playbook), on origin/master a commit plus `ca3-v4-uniform` a commit (the analysis). | [docs/analysis/ca3-v4-uniform.md](../docs/analysis/ca3-v4-uniform.md) |
| AP-F8-1 | A load whose source was last written by `or`, `mul` or `mulhi` makes a cross-hash hot set | Fixed in part, finding bounded, stated | Class v4 sub-version 3 (igneum-pow a commit, the audit-freeze tag) is frozen with the dataflow rule, the shared-operand rule, the 0.98 ratio and the total draw; the in-house pass's F8 re-gate reads 60 of 64 seeds under… | [docs/analysis/ca3-v4-uniform.md](../docs/analysis/ca3-v4-uniform.md) |
| GF1 | A post-quantum signature scheme would need a hard fork, and every vote key is a public BLS12-381 point | Fixed | The byte costs nothing now and a fork later. | none named |
| GF2 | A vote key cannot move: a miner who changes keys re-earns 30 days of weight, and so does the post-quantum migration | Fixed | The successor inherits the window, not a fresh one, so a key rotation costs no weight and the migration of GF1 is one item per key. | none named |
| GF3 | A 256 MB on-chip cache makes the lottery hash 2 to 3x cheaper for the card that has it, and the cache size is a constant | Fixed as a genesis lever, measurement owed | Consumer LLC is 96 to 128 MB today and datacentre 256 MB (`chip-model-v3`, approximate), so the shortcut is a datacentre card's today and a consumer card's in a generation or two. | none named |
| GF4 | The class-group VDF falls to the same quantum computer | Conceded, flagged in spec 04 section 4.8 | ; not sized. | none named |
| GF4 | The class-group VDF falls to the same quantum computer | Conceded, stated | `Site/litepaper.html`, What Igneum does not claim, "A delay function that outlives a quantum computer. | none named |

View file

@ -813,6 +813,10 @@ body.all .pager{display:none}
<li><strong>A cryptography team.</strong> Not yet. One founder working with AI systems wrote the design and the code; external reviewers are named and paid before gate 3, and every security claim here is a design claim until then.</li>
<li><strong>Finality that no amount of hardware can break.</strong> No. A miner holding a third of the last 30 days of blocks can split finality during a network partition, and two thirds can lock a bad checkpoint for a double-spend bounded by the 12-hour finality depth. Reaching a third takes at least ten days of producing every block on the chain, in public; an attacker matching the honest network needs twenty days for a third and never reaches two thirds. That is harder than attacking Bitcoin, where a majority can reorganise at once, and it is the limit of proof of work without stake or an outside chain. Igneum chose those limits on purpose. The floor is also bounded in time: an honest partition that lasts long enough for each side's own new blocks to reach two thirds of its window locks on both sides, about ten days of a 30-day window at an even split, and an operator must then resolve it (measured on a test network, 4 October 2026).</li>
<li><strong>Finality that never pauses.</strong> No. A lock needs two thirds of all 30-day mining weight. Whenever less than two thirds of that weight is connected and signing, finality pauses until it returns or ages out of the window, up to 30 days. The chain keeps running on proof of work and the node reports the pause.</li>
<li><strong>A label that costs nothing.</strong> No. Some investors and exchanges read "GPU-mined" as 2021 whatever the proofs do, and nothing here measures that cost. The only evidence will be whether the first miner apps and verifiable-compute apps sign despite the label.</li>
<li><strong>A chain you can debug today.</strong> Not yet. The node does not serve debug_traceTransaction, eth_subscribe or eth_getProof, and there is no public RPC, faucet or explorer for the devnet. They come in a fixed order (docs and templates, then the tracing and subscription RPCs, then a public RPC, listing and faucet, then the explorer) and no outside team is invited to build before the second step is done.</li>
<li><strong>A veto on job results.</strong> No. A segment proof is checked against every node's own execution; a proving job for another chain is not, because no full node can re-run an arbitrary program, so a soundness bug in the proof system in force reaches the requesting contract. A job output can mint nothing and touch no system contract, and an app that acts irreversibly on a job result keeps its own fallback.</li>
<li><strong>A delay function that outlives a quantum computer.</strong> No. The class-group delay between a locked checkpoint and the next program seed falls to the same machine that would forge the vote keys; it is flagged in the specification, not yet sized, and the fallback is a hash-chain delay behind the same version byte that moves the signature scheme, so both flip in one class change. A grindable hourly seed is a liveness nuisance against the lottery, not a break of finality.</li>
<li><strong>A finished protocol.</strong> The sustained-mining finality rule is the newest piece and the one that external review will try hardest to break. The specification, the review and the benchmarks are published as they happen.</li>
</ul>
<p>Everything in this document is subject to the gates on the roadmap. Nothing in it is an offer to sell anything. Found an error, or a criticism this document does not answer? Email <a href="mailto:hello@igneum.network">hello@igneum.network</a>, or open an issue on the public specification repository: <a href="https://git.igneum.network/igneum-network/spec/issues" rel="noopener">git.igneum.network/igneum-network/spec/issues</a>. Post reaches Igneum Labs LTD, Unit IH-00-01-01-OF-01, Level 01, Innovation One, Dubai International Financial Centre.</p>

View file

@ -54,7 +54,7 @@ for (const l of lines) {
if (!cur) continue;
const s = l.trim();
if (!cur.quote && s.startsWith('"')) cur.quote = s.replace(/^"|"$/g, '');
else if (!cur.status && s.startsWith('Status:')) cur.status = s.slice(7).trim();
else if (s.startsWith('Status:')) cur.status = s.slice(7).trim(); // the LAST status line wins, as tools/ledger/export-public.mjs reads it (7 October 2026: the page read the first and counted four entries as Other that the export did not)
else if (!cur.answer && s.startsWith('Answer:')) cur.answer = s.slice(7).trim();
}

11
tools/ledger/README.md Normal file
View file

@ -0,0 +1,11 @@
# The criticism ledger's tools
`export-public.mjs` writes `docs/ledger-public.md` from `docs/fud-ledger.md` (one row per item; no commit ids, times of day, lane or agent names) and `--check` is the pre-push gate for it; `tools/ledger-page.mjs` renders the same file to `/ledger` at the site build.
## The status rule (7 October 2026, night)
- An entry's **current status is the first sentence of its last `Status:` paragraph**. The export, the page and the counts read that paragraph and nothing earlier in the entry.
- The **previous status follows `Was:`** inside the same paragraph, so the history stays readable in one place.
- A `Status:` paragraph **starts with one of the six statuses' words**: Open; Conceded; Fixed (also Rolled out, Rule fixed, Spec fixed, Rule implemented, Rule written, Written, Designed); Closed or Decided; Answered with evidence (also Measured, Simulation half); Answered by design. Never with a date, a lane's word or a verb outside them (Relabelled, Reopened, Corrected and Kept were the four the page could not place).
- `export-public.mjs --check` fails any entry that breaks the third rule and names it; its self-test plants a date-led and a word-led status first (known-failed), then the clean fixture.
- A "not yet stated" concession becomes "stated" only by writing the sentence into the public text it belongs to (the litepaper, the miner page's Before you start, the claims section) and naming the page in the status.

View file

@ -6,7 +6,8 @@
// every tracked file.
//
// node tools/ledger/export-public.mjs # rewrite docs/ledger-public.md from docs/fud-ledger.md
// node tools/ledger/export-public.mjs --check # exit 1 when docs/ledger-public.md differs from what the ledger generates (the gate)
// node tools/ledger/export-public.mjs --check # exit 1 when docs/ledger-public.md differs from what the ledger generates, or when an entry's
// # last Status paragraph starts with a date or a word outside the six statuses (the gate)
// node tools/ledger/export-public.mjs --self-test # a fixture ledger with a commit id, a time, a lane name and a Fix line gives rows
// # with none of them and the right fields; --check fails on a drifted output
// Node 22, standard library only.
@ -61,6 +62,16 @@ export function scrub(s) {
.replace(/,\s*;/g, ';').replace(/\(\s*[;,]\s*/g, '(').replace(/\(\s*\)/g, '').replace(/,\s*\)/g, ')').replace(/\s+([,.;:)])/g, '$1').replace(/\s{2,}/g, ' ').trim();
}
const cell = (s, max) => { s = s.replace(/\|/g, '\\|'); return s.length > max ? s.slice(0, max - 1).replace(/\s+\S*$/, '') + '…' : s; };
// The status-word rule (main, 7 October 2026, night, from the site audit's finding that an appended update can miss the public
// row): an entry's current status is the FIRST SENTENCE of its last Status paragraph, the previous one follows "Was:", and the
// paragraph must START with one of the six statuses' words (Open; Conceded; Fixed, Rolled out, Rule fixed, Spec fixed, Rule
// implemented, Rule written, Written, Designed; Closed, Decided; Answered with evidence, Measured, Simulation half; Answered by
// design), never with a date or a word outside them (Relabelled, Reopened, Corrected, Kept were the four the /ledger page could
// not place on 7 October 2026). --check fails on any such entry and names it; the self-test plants both shapes first.
export const STATUS_WORD = /^(open|conceded|fixed|rolled out|rule fixed|spec fixed|rule implemented|rule written|written|designed|closed|decided|answered with evidence|measured|simulation half|answered by design)\b/i;
export function badStatuses(text) {
return parseItems(text).map((it) => [it.id, field(it.body, 'Status:').replace(/^Status:\s*/, '')]).filter(([, st]) => !STATUS_WORD.test(st)).map(([id, st]) => `${id}: "${st.slice(0, 60)}"`);
}
export function rowOf(item) {
const status = field(item.body, 'Status:').replace(/^Status:\s*/, '');
let statusShort = status.split(/[(:]/)[0].replace(/[.,;\s]+$/, '').trim() || 'unstated';
@ -114,6 +125,11 @@ function selfTest() {
for (const bad of [/0e2d6b1c/, /fbb0082a/, /da1eb889/, /\d\d:\d\d/, /hash lane/, /attack-pass lane/, /main's/, /, night/, /fin-fixes/, /ledger-fixes-0311/]) if (bad.test(text)) fails.push(`scrub: ${bad} survived: ${text.match(bad)?.input?.slice(0, 0)}${(text.split('\n').find((l) => bad.test(l)) || '').slice(0, 160)}`);
if (!/\| AP-F8-1 \| A load whose source was last written by `or` makes a hot set \| Fixed \|/.test(text)) fails.push('AP-F8-1 row missing or wrong');
if (!/^3 items\. By status: /m.test(text)) fails.push('count line');
// the status-word rule, known-failed first: a date-led and a word-led status both fail; the fixture's three pass
const bad = `# ledger\n\n### Z1. A date-led status\n"x"\n\nStatus: 7 October 2026, morning: relabelled.\n\n### Z2. A word outside the six\n"y"\n\nStatus: Relabelled (7 October 2026): the range stands.\n\n### Z3. A fine one\n"z"\n\nStatus: Conceded, stated (7 October 2026). Was: Conceded.\n`;
const b = badStatuses(bad);
if (b.length !== 2 || !b[0].startsWith('Z1:') || !b[1].startsWith('Z2:')) fails.push(`status-word rule: known-failed shapes not caught: ${JSON.stringify(b)}`);
if (badStatuses(fx).length) fails.push(`status-word rule: the fixture's statuses were refused: ${JSON.stringify(badStatuses(fx))}`);
// --check: a drifted output fails, the generated one passes
const dir = fs.mkdtempSync(path.join(os.tmpdir(), 'ledger-public-')); const o = path.join(dir, 'out.md');
fs.writeFileSync(o, render(fx)); if (!check(fx, o)) fails.push('check: a fresh output was reported as drifted');
@ -127,6 +143,8 @@ export function check(text, outFile) { return fs.existsSync(outFile) && fs.readF
const arg = process.argv[2];
if (arg === '--self-test') selfTest();
else if (arg === '--check') {
const bad = badStatuses(fs.readFileSync(LEDGER, 'utf8'));
if (bad.length) { console.error(`ledger-public: ${bad.length} entr${bad.length === 1 ? 'y' : 'ies'} whose last Status paragraph does not start with one of the six statuses' words (the current status is its first sentence; the previous follows "Was:"): ${bad.join('; ')}`); process.exit(1); }
const ok = check(fs.readFileSync(LEDGER, 'utf8'), OUT);
console.log(ok ? `ledger-public: docs/ledger-public.md matches docs/fud-ledger.md (${parseItems(fs.readFileSync(LEDGER, 'utf8')).length} items)` : 'ledger-public: docs/ledger-public.md differs from what docs/fud-ledger.md generates; run node tools/ledger/export-public.mjs and commit');
process.exit(ok ? 0 : 1);