From 9e256a4bc00ebbe9de173cf9fcd352c8fb86ca45 Mon Sep 17 00:00:00 2001 From: igneum-josh <337424239+igneum-josh@users.noreply.github.com> Date: Wed, 7 Oct 2026 11:03:37 +0100 Subject: [PATCH] Genesis forward-compatibility (mission item 8): design doc, spec text (W1 scheme byte, W5 succession, the cache rung, the VDF fallback flagged), ledger rows GF1 to GF4, the fast-time harness, override-60x.json docs/design/genesis-forward.md names the three fields, their defaults, the digest change and the gates; spec 03 W1 and W5 amended and the W5 implementation row filled; spec 01 the cache rung beside the schedule; spec 04 the class-group VDF's quantum fallback flagged, not sized; infra/fast-time/key-succession.mjs (3 nodes, one CPU miner each: the window fills, a succession carried once on every node, refused twice, scheme 1 refused by every node; the known-failed case --expect no-succession first); override-60x.json carries the four new keys at never. Co-Authored-By: Claude Fable 5.1 --- docs/design/genesis-forward.md | 69 +++++++++ docs/fud-ledger.md | 32 ++++ docs/spec/01-lottery-hash.md | 2 +- docs/spec/03-finality.md | 9 +- docs/spec/04-seeds-and-vdf.md | 2 + infra/fast-time/key-succession.mjs | 228 +++++++++++++++++++++++++++++ infra/fast-time/override-60x.json | 4 + 7 files changed, 341 insertions(+), 5 deletions(-) create mode 100644 docs/design/genesis-forward.md create mode 100644 infra/fast-time/key-succession.mjs diff --git a/docs/design/genesis-forward.md b/docs/design/genesis-forward.md new file mode 100644 index 000000000..5a4f5fd84 --- /dev/null +++ b/docs/design/genesis-forward.md @@ -0,0 +1,69 @@ +# Genesis forward-compatibility: the scheme byte, key succession, the cache rung + +7 October 2026, 10:1x UK, Josh's order to build mission item 8 now (`docs/analysis/mission/mission.md` section 2.8; the research in `docs/analysis/mission/future.md` sections 1.3, 7 and 10 and `docs/design/finality-in-proof.md` section 7). Branch `genesis-forward` on the node fork (from release-0.3.19-node dc141409, the merged line that carries the ladder and the W7 leave item, which ca3-v4-0318 alone does not) and `genesis-forward` on the repo. Three genesis fields, every switch never on the devnet (its digest does not move), all three set at the testnet genesis by the testnet lane, which holds the cut and re-pins. The class-group VDF's quantum fallback is flagged in spec 04 section 4.8, not built. + +## 1. The scheme byte + +| Item | Place | Value | +|---|---|---| +| The byte | `finality::Vote::sig_scheme`, `finality::KeyReveal::sig_scheme`, `finality::Succession::successor_scheme` | `SIG_SCHEME_BLS12_381` = 0 everywhere today | +| The genesis value | `Params::sig_scheme` (override key `sig_scheme`) | 0 on every network | +| The switch | `Params::sig_scheme_activation_daa` (override key `sig_scheme_activation_daa`; `u64::MAX` = never) | never on devnet, simnet, mainnet; 0 at the testnet genesis | +| The digest | both fields enter once the switch is set (the 0.3.15 rule) | the devnet's digest unchanged; the testnet's moves at the cut | +| The wire, plain | vote item tag 1 (`Vote::LEN` = 280 bytes), evidence tag 3, reveal `IGNK` + 288 hex: scheme 0 implied | byte for byte what every live network carries | +| The wire, explicit | vote item tag 5 = `scheme \|\| vote`, evidence tag 6 = `scheme \|\| first \|\| second`, reveal `IGNS` + 2 hex of the scheme + 288 hex | written by every template once the switch is active (`encode_section_explicit_within`); a vote of any other scheme is always explicit, so a scheme the node does not run is never mistaken for one it does | +| The active scheme | `igneum::active_sig_scheme(genesis, class)` = the scheme the program class at the sink names (`SIG_SCHEME_OF_CLASS`, a genesis table with no row today), else the genesis byte; the finality manager re-reads it at every virtual change | 0 | +| The refusal | `FinalityManager::scheme_refusal`: a reveal is not registered, a vote is not recorded, carried or gossiped, a successor is refused; the RPC answers `refused: vote carries signature scheme 1; the active scheme is 0 (BLS12-381); another scheme is named only by a program class the 95 percent signal moves to, and none names one` | every node, whatever its switch | + +Why a class change names the scheme: the flip is the P2 mechanism (95 percent of mining weight over a window with a floor height, the one path a consensus change takes on this chain), and the aggregated-vote format must ship first (naive ML-DSA-44 votes at 8,192 voters cost 19.4 MB a checkpoint and 57 GB a day, `future.md` 7.3; with 250x SNARK aggregation about 223 MB a day). Adding a row to the table is a code change under the class path; the byte is in every item from genesis so the row costs no fork. + +## 2. Key succession, W5 + +| Item | Place | Value | +|---|---|---| +| The item | `finality::Succession` (tag 7, 297 bytes): `daa`, old key, successor key, successor scheme, the old key's signature, the successor's signature, both over `"igneum-succeed-v1/" \|\| chain_id \|\| 0 \|\| daa \|\| old \|\| new \|\| scheme` under `IGNEUM_SUCCEED_V1_BLS12381G2_XMD:SHA-256_SSWU_RO_NUL_` | the successor's signature is its consent and its proof of possession in one | +| The switch | `Params::finality_succession_activation_daa` (override key of the same name) | never everywhere; 0 at the testnet genesis; in the digest once set | +| Submission | `submitFinalitySuccession` (RPC op 158, gRPC 1131/1132, wRPC, `igneum-miner succeed `) | carried after the leaves in the templates of the node that holds it; no p2p gossip kind (the successor's own node mines it) | +| The fold | `successions_at` (deterministic like `leaves_at`: the lowest-DAA carrier in C's past dates it) and `fold_successions` inside `voters_at`: the old key's window blocks are credited to the successor as they stand (count and oldest block), the old key leaves the table, a ban or a leave on the old key lands on the successor; the successor's presence counts the old key's carried votes | from the first checkpoint whose past holds the carrier; the window inherited, not a fresh one | +| Once | one record per old key: a second succession from a key that handed over is refused (`already handed its weight to`), a successor that has itself handed over is refused (`has itself handed`), which also refuses every cycle; a chain old to new to newer is legal | a record outlives the weight it moved by one window, then is trimmed | +| After | the old key's votes are refused (`handed its weight to`), never counted, never carried | the old key is dead | +| The report | `getFinalityWeights`: `succeededFrom` on the successor's row, a weightless row for the old key with `succeededTo` | both nodes of the unit test agree on every voter list | + +Not in this round: a p2p gossip kind for successions (the leave's shape, protocol version bump); the app's "rotate key" button, which signs the item from the old key's label and restarts the miner under the new label (the `succeed` subcommand is the primitive); the aggregated-vote format. + +## 3. The cache rung beside N + +| Item | Place | Value | +|---|---|---| +| The rung | `igneum::CacheRung { mib, admissible }` as `LatencyLadder::cache_rung` (override key `latency_ladder_cache_rung`) | `{512, false}` at genesis; a power of two above the 256 MiB genesis cache | +| The signal | `LadderSignal::Cache` = both ladder bits set (header version 0xc000; until today both set was "no signal" and no node ever stamped it, so no block written so far changes meaning); `IGNEUM_LADDER_SIGNAL=cache` | code 3 in `PowEpochInfo::latency_ladder_signal` | +| The rule | `latency_ladder_step_signalled_with_cache`: the cache step moves 0 to 1 when every one of the newest seven windows reaches 90 percent for the cache rung, the rung is admissible and the cool-down holds (the oldest window begins after the last decision, shared with N); never back; never in the same decision as N (one signal per block, exclusive shares) | `LadderState::cache_step` | +| The digest | the rung's size and flag enter with the ladder, once `latency_ladder_activation_daa` is set | the testnet's digest moves at the cut | +| The RPC | `powEpoch.latencyLadderCacheStep`, `nextLatencyLadderCacheStep`, `latencyLadderCacheMib`, `nextLatencyLadderCacheMib`, `latencyLadderCacheBps`, `latencyLadderCacheWeakestBps`, `latencyLadderCacheAdmissible` (proto fields 37 to 43); the daemon's ladder line (`cache [512 MiB]`) | the rung visible on every node | +| The gate | `admissible` in the genesis list, false until measured: the cold verify of one warp with the 512 MiB cache on the reference core with its SMT sibling loaded under 10 ms (the verifier reads the cache, so this is the bound), the day-cache build on a 2019-class core under twice today's, and the 8 GB tier still holding dataset, cache and the prover footprint | the rule never enters an inadmissible rung (tested) | + +Why beside N and not a seventh N rung: the six approved rungs and their indices stand (Josh, 7 October 2026, 09:3x UK); a rung inserted in the list would either sit behind the three inadmissible rungs (unreachable) or shift the approved indices. A second lever on the same signal carrier keeps the list as approved and the cool-down shared. + +Owed with the measurement: the engine's consumption of `cache_mib` (`EpochSeeds` carries `shadow_reps` today and no cache size; the pack and the three hosts build a 256 MiB cache), so the flag stays false until the path exists and is measured. Per tier what the rung means: every tier from 8 GB holds a 512 MiB cache; the day-cache build doubles (about 0.7 s on the reference core today, approximate, from the class v4 fill line); the Apple tier's unified memory holds it; a pool user does nothing. + +## 4. The class-group VDF under a quantum computer + +Flagged in spec 04 section 4.8, not sized: Shor computes the class-group order, which removes the sequentiality assumption of the Wesolowski VDF, so an attacker with a cryptographically relevant quantum computer grinds the hourly seed (a liveness nuisance against the lottery, not a safety break; finality rests on the vote keys of section 1). The fallback is a hash-chain delay behind the same version byte, designed when the scheme flip is scheduled. + +## 5. Gates + +| Gate | Where | Result | +|---|---|---| +| The digest test | `consensus_digest_covers_every_consensus_field_and_nothing_else` (30 edits; the scheme byte and the cache rung alone move nothing), `override_params_carry_the_genesis_forward_fields_and_the_digest_moves_only_when_set` | section 6 | +| Scheme 1 refused by every node until the signal | unit: `a_vote_reveal_or_successor_of_another_signature_scheme_is_refused_until_a_class_names_it` (RPC, in a block, a reveal, a successor; the explicit template form); fast-time: `probe-scheme` on three nodes | section 6 | +| A succession carried once and refused twice | unit: `a_key_hands_its_window_to_a_successor_once_and_a_second_succession_is_refused` (two nodes); fast-time: `infra/fast-time/key-succession.mjs` (the known-failed case `--expect no-succession` first) | section 6 | +| The ladder rung visible in the RPC | `powEpoch.latencyLadderCache*` on `getBlockTemplate`, the daemon line; unit: `latency_ladder_rule` (an inadmissible cache rung never entered; with the flag, 90 percent in seven windows enters it, N still steps after it, one rung, never back) | section 6 | +| The codec | `scheme_byte_and_succession_items_round_trip_and_an_older_decoder_stops_at_them` | section 6 | + +## 6. Results + +Filled in when the box runs are green (build and test lines, the harness summaries copied to `docs/design/genesis-forward-harness/`). + +## 7. For the testnet lane + +Override keys and testnet values: `sig_scheme: 0`, `sig_scheme_activation_daa: 0`, `finality_succession_activation_daa: 0`, `latency_ladder_cache_rung: {"mib": 512, "admissible": false}` (the six N rungs unchanged). Digest: with the ladder already active from genesis the cache rung's two fields enter after the six rungs' fields; the scheme switch adds two fields, the succession switch one. `print_testnet_object` prints the four keys. diff --git a/docs/fud-ledger.md b/docs/fud-ledger.md index d5bcdc76a..f06e53f2f 100644 --- a/docs/fud-ledger.md +++ b/docs/fud-ledger.md @@ -2410,3 +2410,35 @@ Same rule as the counts above. 167 entries. The bucket "Decided or closed by rule" counts each entry once: M8, M11 and P16 move there from Answered, so Answered is 28 less those three plus M16 and E17, as the table states; the sum of the rows is 167 with M8, M11, P16 and F3, F17 counted in Decided only. + +## Genesis forward-compatibility entries (7 October 2026, mission item 8, branch `genesis-forward`) + +The three genesis fields of `docs/analysis/mission/mission.md` section 2.8, built on the node fork branch `genesis-forward` (from release-0.3.19-node dc141409) and the repo branch `genesis-forward`; the design and the gates in `docs/design/genesis-forward.md`. Every switch is never on the devnet (its digest c562d70e... does not move); the testnet genesis sets all three (the testnet lane re-pins and re-digests). + +### GF1. A post-quantum signature scheme would need a hard fork, and every vote key is a public BLS12-381 point +"When a quantum computer comes, every BLS vote key is forged and the chain has no way to change the scheme without a fork of the kind you say you never need." + +Status: Fixed (7 October 2026). `sig_scheme` byte in every vote item and key reveal (`finality::SIG_SCHEME_BLS12_381` = 0), `Params::sig_scheme` and `Params::sig_scheme_activation_daa` in the digest once set; any other byte refused by every node (`scheme_refusal`) until a program class the 95 percent signal moves to names it (`igneum::sig_scheme_of_class`, empty today). Gate: the digest test `override_params_carry_the_genesis_forward_fields_and_the_digest_moves_only_when_set` and `consensus_digest_covers_every_consensus_field_and_nothing_else` (30 edits); a scheme-1 vote refused over RPC, in a block, and as a successor's scheme (`a_vote_reveal_or_successor_of_another_signature_scheme_is_refused_until_a_class_names_it`); the fast-time probe on three nodes (`infra/fast-time/key-succession.mjs`, `probe-scheme`). + +Answer: The byte costs nothing now and a fork later. The flip is a class change (spec 03 W1 as amended): the aggregated-vote format ships first (naive ML-DSA-44 votes at 8,192 voters cost 57 GB a day, `future.md` 7.3), the scheme second, both by the 95 percent signal with a floor height. Per tier at migration: a home miner on any card runs the updater and signs one succession item (GF2); nothing hardware-specific, the signature runs on the CPU. + +### GF2. A vote key cannot move: a miner who changes keys re-earns 30 days of weight, and so does the post-quantum migration +"Your weight is bound to a key. Rotate it, lose a month. So nobody rotates, and the one day everyone must rotate, finality pauses for a month." + +Status: Fixed (7 October 2026). W5 key succession implemented (spec 03 W5 as amended): a succession item signed by both keys, carried in blocks after the leaves, folds the old key's window blocks and forfeit term into the successor from the first checkpoint whose past holds the carrier (`successions_at`, `fold_successions`); once per key, a second succession refused, a successor that has itself handed over refused. Behind `finality_succession_activation_daa`. Gate: carried once and refused twice in the unit test on two nodes and in the fast-time harness. + +Answer: The successor inherits the window, not a fresh one, so a key rotation costs no weight and the migration of GF1 is one item per key. The old key signs nothing after; a buyer of a key gets the clean transfer (spec 3.11.5) and the seller's copy is worthless. + +### GF3. A 256 MB on-chip cache makes the lottery hash 2 to 3x cheaper for the card that has it, and the cache size is a constant +"The dataset is built from a 256 MiB cache. A datacentre part with a 256 MB last-level cache keeps the whole cache on die and skips the memory. Consumer cards cannot." + +Status: Fixed as a genesis lever, measurement owed (7 October 2026). The latency ladder carries one cache rung beside N (`LatencyLadder::cache_rung`, 512 MiB, `LadderSignal::Cache` = both ladder bits, the same 90 percent in seven windows, one rung, never back, in the digest with the ladder); inadmissible at genesis until the verifier bound and the 8 GB tier are measured (design doc section 3); visible in `getBlockTemplate`'s `powEpoch` (`latencyLadderCacheStep`, `latencyLadderCacheMib`, `latencyLadderCacheBps`, `latencyLadderCacheAdmissible`) and in the daemon's ladder line. + +Answer: Consumer LLC is 96 to 128 MB today and datacentre 256 MB (`chip-model-v3`, approximate), so the shortcut is a datacentre card's today and a consumer card's in a generation or two. The rung lets the miners double the cache by signal the day the shortcut shows on the hash-rate charts, without a fork; the measurement that admits it is the same verifier bound as every N rung. Per tier: a 512 MiB cache is held by every tier from 8 GB up; the day-cache build doubles (about 0.7 s on the reference core today, approximate); the verifier reads the cache, not the dataset, so the 10 ms bound decides. + +### GF4. The class-group VDF falls to the same quantum computer +"Shor computes the class-group order; your epoch seed is then grindable." + +Status: Conceded, flagged in spec 04 section 4.8 (7 October 2026); not sized. The fallback is a hash-chain delay behind the same version byte that moves the signature scheme; designed when the scheme flip is scheduled. + +Answer: A grindable hourly seed is a liveness nuisance against the lottery, not a safety break: finality rests on the vote keys (GF1), the seed on the VDF. The two flip together by one class change. diff --git a/docs/spec/01-lottery-hash.md b/docs/spec/01-lottery-hash.md index f43b4bc55..56ef9ddce 100644 --- a/docs/spec/01-lottery-hash.md +++ b/docs/spec/01-lottery-hash.md @@ -207,7 +207,7 @@ Implemented for the prototype size; Designed for genesis. A load reads one 4-byte word at `src AND MASK`. Every load in every emitted kernel has exactly this form; the static check in `TESTS.md` section 5 is part of conformance (section 1.15). Because item values do not depend on the dataset size (section 1.8.5), the 1 GiB vectors remain valid for words below 2^28 at any larger size. -Growth beyond genesis is in section 1.13; under program class v3 the cache follows the dataset's doublings (1.13.3) and the verifier holds 256 MiB, then 512 MiB from year 4 and 1 GiB from year 12. +Growth beyond genesis is in section 1.13; under program class v3 the cache follows the dataset's doublings (1.13.3) and the verifier holds 256 MiB, then 512 MiB from year 4 and 1 GiB from year 12. Beside the schedule the latency ladder (`docs/design/latency-ladder.md`) carries one cache rung (genesis forward-compatibility, 7 October 2026, `docs/design/genesis-forward.md` section 3): `LatencyLadder::cache_rung`, 512 MiB, entered by the same rule as a shadow rung (90 percent of blue blocks with both ladder bits set in each of seven consecutive windows, one decision per seven windows, one rung, never back), because a consumer last-level cache at the cache size gives that card's owners a 2 to 3x shortcut (`chip-model-v3`; consumer LLC 96 to 128 MB today, datacentre 256 MB). Its gate is the rung's `admissible` flag in the genesis list, false until the cold verify with the larger cache on the reference core with its sibling loaded is measured under 10 ms, the day-cache build on a 2019-class core under twice today's, and the 8 GB tier still holds dataset, cache and the prover footprint; the engine's consumption of the larger cache is owed with that measurement, and the rule never enters the rung before the flag is set. ## 1.6 Register initialisation diff --git a/docs/spec/03-finality.md b/docs/spec/03-finality.md index f361eac41..8dcb7e837 100644 --- a/docs/spec/03-finality.md +++ b/docs/spec/03-finality.md @@ -8,11 +8,11 @@ Two statements frame everything below. Finality is miner-only and self-contained ## 3.1 Weight -- **W1.** Every block header names a vote key by `vote_key_hash` (section 2.4): the hash of a BLS12-381 G1 compressed public key. The first block that uses a key reveals the key in its coinbase payload. A header whose `vote_key_hash` has never been revealed is valid; the key simply cannot vote until it is revealed. +- **W1.** Every block header names a vote key by `vote_key_hash` (section 2.4): the hash of a BLS12-381 G1 compressed public key. The first block that uses a key reveals the key in its coinbase payload. A header whose `vote_key_hash` has never been revealed is valid; the key simply cannot vote until it is revealed. Every key reveal and every vote item carries a signature scheme byte, `sig_scheme` (genesis forward-compatibility, 7 October 2026, `docs/design/genesis-forward.md`): the genesis value is 0, BLS12-381 in the minimal-public-key setting, and a node refuses any reveal, vote or successor whose byte is not the active scheme. The active scheme is the genesis byte until a program class that the 95 percent class signal moves to names another (`igneum::sig_scheme_of_class`, a genesis table with no row today), so a post-quantum scheme arrives by signal, never by a fork; the aggregated-vote format (`docs/analysis/mission/future.md` 7.3) ships before the flip. - **W2.** Weight is counted in blocks and denominated in past-median time (rule of 3 October 2026, ledger M14 and F14, round 3; the simulated form is kept below). Cut the trailing 30 days of past-median time before C, `(mt(C) - 2,592,000 s, mt(C)]`, into 43,200 buckets of 60 s; a blue block in C's past falls in the bucket that holds its own past-median time. The weight of key k at C is the sum over buckets of k's share of the blue blocks in that bucket (an empty bucket contributes 0 to everyone). A bucket is worth 1 whatever it holds, so 50x the blocks in one minute is one minute of weight, and a retarget lag can neither inflate a key's count nor age the window. No damping, no cap, no floor. Blocks are the only thing in proof of work that cannot be forged, so weight is counted in blocks; time is the denominator because blocks per unit of DAA time is exactly what a lagging controller lets a renter buy (section 2.3; `docs/review/round-3-2026-10-03.md`, "Tonight's devnet"). As simulated (`sim/results_v2.md`, every run): the number of blue blocks in C's past whose header names k and whose DAA score is in `(daa(C) - 2,592,000, daa(C)]`. The two forms agree whenever the controller holds the target; O-3.14 runs the simulation under both with the DAA in the loop and confirms or reverts this rule at gate 3. The damped rule of version 1 was removed because its 2x cap was defeated by splitting into free keys (`sim/results.md` table C; `docs/bench-log.md` finality_sim entry). - **W3.** Dust: a key with fewer than 100 blue blocks in the window (a block count, not bucket weight) is not a voter and is in no denominator. Measured consequence (`sim/results_v2.md` A and G): every honest key in a 1,000-key Pareto network clears 100 blocks by day 20 from zero history and the smallest new keys need up to 25 days after a doubling; a 9x renter's victims lose about one point to dust (B). - **W4.** Steady state: weight equals hashrate. Simulated correlation 1.00000 at day 60, Gini equal to three figures, weight-to-hash ratio within 0.82 to 1.12 for every key (`sim/results_v2.md` A). -- **W5.** Key succession: a message signed by the old key naming a new key, included in any block, moves the old key's weight history to the new key once. The old key is dead thereafter: its later blocks earn nothing and its votes are invalid. +- **W5.** Key succession: a succession item signed by both keys (the old key hands over, the successor consents and proves possession in one signature) over `(chain_id, daa, old key, successor key, successor scheme)`, carried in any block, moves the old key's weight to the successor once. The fold is a function of the chain, as the equivocation ban (3.6) and the leave (W7) are: at checkpoint C the old key's blue blocks in the window are credited to the successor exactly when some block in C's past carries the succession and the rule is active at C, the successor inherits the window as it stands (the count and its oldest block, never a fresh window), and a ban or a leave on the old key lands on the successor (the forfeit term inherited). The old key is dead thereafter: its votes are refused and never carried, and no node records a second succession from it, nor one naming as successor a key that has itself handed over (which also refuses every cycle). A chain old to new to newer is legal, each key handing over once. Implemented 7 October 2026 (`docs/design/genesis-forward.md` section 2; behind `finality_succession_activation_daa`, 0 on the testnet). - **W6.** Keys are free. Nothing in the protocol prices a vote key and the devnet launcher mints one per worker process (ledger F17, round 3). Weight is the only Sybil-resistant quantity in this specification, so every rule that draws from the voter population draws by weight and never per key: W2 (no damping, no per-key cap), the shard sortition of section 7.2 (drawn by weight since 3 October 2026) and the sub-user sortition of S2. A rule that counts keys is a rule a splitter wins. The headline arithmetic (W2 with constant hashrate): an attacker with share a of hashrate for t days holds weight share `(t/30) x a/(1+a)`, verified by simulation to 0.04 points for a = 1 and 2 (`sim/results_v2.md` B). @@ -166,9 +166,10 @@ Status of this section: Implemented in `vendor/igneum-node` (reading guide in `d | Clause | Implementation | Departure or gap | |---|---|---| -| W1 | `vote_key_hash` = BLAKE2b (domain `IgneumVoteKeyHash`) of the 48-byte compressed G1 key. The key is revealed with a proof of possession in the miner's coinbase extra data (`IGNK` plus 288 hex characters) and a node registers it only when the hash matches the header. A vote carries the public key too, so a key that votes is revealed by its vote | The reveal is hex, not binary, because the template RPC carries extra data as a UTF-8 string. Mainnet should carry the reveal in a dedicated field or transaction | +| W1 | `vote_key_hash` = BLAKE2b (domain `IgneumVoteKeyHash`) of the 48-byte compressed G1 key. The key is revealed with a proof of possession in the miner's coinbase extra data (`IGNK` plus 288 hex characters, scheme 0 implied; or `IGNS` plus two hex characters of the scheme byte plus the 288, the explicit form) and a node registers it only when the hash matches the header and the scheme byte is the active one. A vote carries the public key too, so a key that votes is revealed by its vote. The vote item carries its scheme byte as item tag 5 (`scheme \|\| vote`; tag 1 is the plain scheme-0 form every live network carries), evidence as tag 6; under `sig_scheme_activation_daa` every template writes the explicit forms (7 October 2026) | The reveal is hex, not binary, because the template RPC carries extra data as a UTF-8 string. Mainnet should carry the reveal in a dedicated field or transaction | | W2 | Blue blocks per key in `(daa(C) - window, daa(C)]`, counted along C's selected chain through every chain block's mergeset blues, C included | O(window) per checkpoint: fine at the devnet window of 7,200 DAA seconds, not at 2,592,000. Mainnet needs an incremental window kept per chain block | -| W3, W5 | Dust excludes a key from the voter list and from both denominators | Key succession (W5) is not implemented | +| W3 | Dust excludes a key from the voter list and from both denominators | | +| W5 | `Succession` item (tag 7, 297 bytes: daa, old key, successor key, successor scheme byte, both signatures under `IGNEUM_SUCCEED_V1_...`), submitted over `submitFinalitySuccession` by the successor's miner, carried after the leaves in the templates of every node that holds it, one record per old key; `successions_at` dates it from the lowest-DAA carrier in C's past and `voters_at` folds the old key into the successor (`fold_successions`), bans and leaves with it; the successor's presence counts the old key's carried votes; `getFinalityWeights` shows `succeededFrom` on the successor and a weightless `succeededTo` row for the old key. Behind `finality_succession_activation_daa` (never on the devnet, 0 on the testnet). Tests: the unit test `a_key_hands_its_window_to_a_successor_once_and_a_second_succession_is_refused` (two nodes agree on every voter list, the successor locks on the inherited weight, A to D and C to A refused) and the fast-time harness `infra/fast-time/key-succession.mjs` | Successions travel in blocks only (no p2p gossip kind; the successor's own node carries it); a record outlives the weight it moved by one window and is then trimmed, so a key that handed over could hand over again two windows later with nothing left to hand | | C1 | Checkpoint i is the lowest selected-chain block with blue score at least 30 i (blue scores along the chain can skip values), determined when the sink's blue score reaches 30 i + d, d = 20 on devnet. Re-determination (branch `fud-consensus`, 4 October 2026 night, ledger F24): after every virtual change, every unlocked record whose block is no longer a chain ancestor of the sink is determined again on the new chain (`on_virtual_changed`, "re-determined" log line); the certificate held over the old block is dropped, the fold clock restarts, and the certificates kept pending over the new block (`pending_certificates`, at most 4 per index, indices up to 64 ahead of the next determination) are verified. A locked record is never revisited. Unit test `reorg_past_an_unlocked_checkpoint_re_determines_it_and_verifies_the_pending_certificate` (a 6-block side chain's certificate is pending with no conflict, the 15-block side chain overtakes, index 13 is re-determined and locks from it; a block with the wrong blue score is refused) and `a_locked_checkpoint_pins_the_chain_and_a_certificate_against_it_conflicts` (a side chain twice as long does not become the sink past a lock, the certificate against the lock is the one conflict) | d = 20 is below the placeholder 60; the devnet reorg-depth distribution that sets d has not been recorded. Measured in `docs/bench-log.md`, "round-4 consensus items" (reorg run) | | C2 | BLS signature over `"igneum-vote-v1/" \|\| chain_id \|\| 0 \|\| index \|\| hash(C_i)` under `IGNEUM_VOTE_V1_BLS12381G2_XMD:SHA-256_SSWU_RO_NUL_`; the chain id is the prefixed network name (`igneum-devnet`, `igneum-devnet-7`); votes are p2p message 70 and ride in the coinbase extra data of every block | | | C3 | Certificate = index, checkpoint, voter count, signer bitmap over the canonical voter list (keys above dust and not stripped, sorted by key hash), aggregate signature, aggregator key hash and sortition proof. Every template carries the certificates not yet in its past | The validity rule (a block whose selected chain misses a certified checkpoint is invalid) is NOT enforced; only fork choice (F1, F2) is | diff --git a/docs/spec/04-seeds-and-vdf.md b/docs/spec/04-seeds-and-vdf.md index b62d9c92c..0a08fa5df 100644 --- a/docs/spec/04-seeds-and-vdf.md +++ b/docs/spec/04-seeds-and-vdf.md @@ -103,4 +103,6 @@ Decision at gate 3 with the devnet, where the time to first block after an epoch ## 4.8 Open items from the prototype +Flagged, not sized (genesis forward-compatibility, 7 October 2026, `docs/analysis/mission/future.md` 7.2 and `docs/design/genesis-forward.md` section 4): a cryptographically relevant quantum computer computes the class-group order by Shor, which removes the sequentiality assumption of the Wesolowski VDF, so an attacker with one grinds the hourly program seed; the fallback is a hash-chain delay behind the same version byte that moves the signature scheme (a class change by the 95 percent signal), designed and sized when the scheme flip is scheduled, not before. Nothing in the pipeline of 4.3 and 4.4 changes today. + Carried into section 6: external review of `classgroup.rs` against chiavdf (O-4.1); reference core choice (O-4.2); whether `C(e)` must be certified and the header field (O-4.3); the fallback (O-4.4); HashPrime layout, carrying D in the proof, compact form encoding (O-4.5); reduction only when `a` exceeds 8 limbs as chiavdf does, a further speedup to port (O-4.6); no fuzzing of `deserialize` on hostile bytes beyond validity checks, no measurement on NVIDIA or AMD hosts' CPUs (O-4.7). diff --git a/infra/fast-time/key-succession.mjs b/infra/fast-time/key-succession.mjs new file mode 100644 index 000000000..2b1f1b3d4 --- /dev/null +++ b/infra/fast-time/key-succession.mjs @@ -0,0 +1,228 @@ +#!/usr/bin/env node +// Genesis forward-compatibility (mission item 8, docs/analysis/mission/mission.md 2.8; docs/design/genesis-forward.md): +// the fast-time gate for the W5 key succession and the sig_scheme byte, on a 3-node network with one real CPU miner +// per node, the class-v4-signal.mjs shape. Ports 29720 and up, network igneum-devnet-972, data /tmp/igneum-fast-time-w5; +// override-60x.json with CPU genesis bits, finality v3, the leave item, the key succession and the explicit scheme +// forms all active from DAA 0. +// +// The gate, in order (every check is a chain-side fact read from the nodes, never a rate or a process name): +// 1. the window fills: the old key (node 2's miner, label w5-old) holds blocks on every node's weight table; +// 2. carried once: node 2's miner stops (no leave), `igneum-miner succeed` hands w5-old to w5-new, a miner starts +// under w5-new; every node logs the succession carried by a block, every node's getFinalityWeights shows w5-new +// inheriting (succeededFrom = the old key's hash, blocks above what w5-new mined alone) and w5-old with no weight +// (succeededTo = the new key's hash); finality keeps locking with the new key signing; +// 3. refused twice: w5-old to w5-third is refused on node 2 AND on node 0 (A has handed over); w5-new to w5-old is +// refused (the successor named has handed over); +// 4. the scheme byte: a vote stamped with scheme 1 is refused by every node with the reason (probe-scheme). +// The known-failed case is run first: `--expect no-succession` with the succession never submitted must report FAIL +// on the carried-once checks (the harness is trusted only after it fires on a failure). +// +// node infra/fast-time/key-succession.mjs [--expect succession|no-succession] [--secs 720] [--succeed-at-daa 260] +// IGNEUMD, IGNEUM_MINER name the binaries (defaults: the genesis-forward fork worktree's target-remote/release on the +// box, target/release on the Mac). + +import { spawn, spawnSync } from 'node:child_process'; +import { mkdirSync, rmSync, writeFileSync, readFileSync, openSync, existsSync } from 'node:fs'; +import { Rpc } from '../../tools/finality-attacks/lib/rpc.mjs'; + +const ROOT = new URL('../../', import.meta.url).pathname; +const FILE = `${ROOT}infra/fast-time/override-60x.json`; +const BIN = process.env.IGNEUM_GF_BIN || (existsSync(`${ROOT}vendor/igneum-node-gf/target/release/igneumd`) ? `${ROOT}vendor/igneum-node-gf/target/release` : `${ROOT}vendor/igneum-node-gf/target-remote/release`); +const IGNEUMD = process.env.IGNEUMD || `${BIN}/igneumd`; +const CPU_MINER = process.env.IGNEUM_MINER || `${BIN}/igneum-miner`; +const TMP = process.env.IGNEUM_FAST_TIME_DIR || '/tmp/igneum-fast-time-w5'; +const BASE = 29720, SUFFIX = 972; +const NEVER = '18446744073709551615'; +const args = process.argv.slice(2); +const flag = (name, dflt) => { const i = args.indexOf(`--${name}`); return i >= 0 ? +args[i + 1] : dflt; }; +const sflag = (name) => { const i = args.indexOf(`--${name}`); return i >= 0 ? args[i + 1] : null; }; +const GENESIS_BITS = flag('genesis-bits', 0x1f010000); +const SECS = flag('secs', 720); +const SUCCEED_AT = flag('succeed-at-daa', 260); +const EXPECT = sflag('expect') || 'succession'; +if (!['succession', 'no-succession'].includes(EXPECT)) { console.error('usage: --expect succession|no-succession'); process.exit(2); } +const started = []; +const log = (...a) => console.log(new Date().toISOString().slice(11, 23), ...a); +const sleep = (ms) => new Promise(r => setTimeout(r, ms)); +for (const b of [IGNEUMD, CPU_MINER]) if (!existsSync(b)) { console.error(`missing ${b}`); process.exit(2); } + +rmSync(TMP, { recursive: true, force: true }); mkdirSync(TMP, { recursive: true }); +const baseText = readFileSync(FILE, 'utf8'); +const field = (name) => { const m = new RegExp(`"${name}":\\s*([0-9]+)`).exec(baseText); return m ? +m[1] : undefined; }; +const DAY_MS = field('pow_day_ms'); +const WINDOW = (() => { const m = /"weight_window":\s*([0-9]+)/.exec(baseText); return m ? +m[1] : 120; })(); +export function mergeOverrideText(text, fields) { + let out = text; + for (const k of Object.keys(fields)) out = out.replace(new RegExp(`\\s*"${k}":\\s*[^,}\\n]+,?`), ''); + const extra = Object.entries(fields).map(([k, v]) => `"${k}": ${typeof v === 'string' && !/^\d+$/.test(v) ? JSON.stringify(v) : v}`).join(', '); + return out.replace(/,?\s*}\s*$/, `,\n ${extra}\n}\n`); +} +const override = `${TMP}/override.json`; +writeFileSync(override, mergeOverrideText(baseText, { + genesis_bits: GENESIS_BITS, skip_proof_of_work: false, finality_v3_activation_daa: '0', finality_leave_activation_daa: '0', + finality_succession_activation_daa: '0', sig_scheme_activation_daa: '0', sig_scheme: '0', latency_ladder_activation_daa: NEVER, +})); +log(`expect ${EXPECT}; weight window ${WINDOW} DAA; the succession at DAA ${SUCCEED_AT}; run ${SECS} s`); + +class Node { + constructor(i, connect = []) { + this.i = i; this.grpcPort = BASE + i * 10; this.p2pPort = BASE + i * 10 + 1; this.jsonPort = BASE + i * 10 + 2; + this.connect = connect; this.dir = `${TMP}/n${i}`; this.logFile = `${this.dir}/node.log`; + } + get grpc() { return `grpc://127.0.0.1:${this.grpcPort}`; } + async start() { + mkdirSync(this.dir, { recursive: true }); + const a = ['--devnet', `--devnet-suffix=${SUFFIX}`, '--nodnsseed', '--disable-upnp', '--nologfiles', '--enable-unsynced-mining', '--utxoindex', + `--appdir=${this.dir}`, `--rpclisten=127.0.0.1:${this.grpcPort}`, `--rpclisten-json=127.0.0.1:${this.jsonPort}`, + `--listen=127.0.0.1:${this.p2pPort}`, `--override-params-file=${override}`, '--loglevel=info', '--yes']; + if (this.connect.length) a.push(`--connect=${this.connect.join(',')}`); else a.push('--outpeers=0'); + const out = openSync(this.logFile, 'a'); + this.proc = spawn(IGNEUMD, a, { stdio: ['ignore', out, out] }); + started.push(this.proc); + await sleep(1500); + this.rpc = new Rpc(`ws://127.0.0.1:${this.jsonPort}`); + if (!(await this.rpc.connect())) throw new Error(`n${this.i}: rpc did not open`); + log(`n${this.i} up pid ${this.proc.pid} json ${this.jsonPort} p2p ${this.p2pPort}`); + return this; + } + grepLog(re) { try { return readFileSync(this.logFile, 'utf8').split('\n').filter(l => re.test(l)); } catch { return []; } } + async weights() { try { return await this.rpc.call('getFinalityWeights'); } catch (e) { return null; } } + async daa() { try { return +(await this.rpc.call('getBlockDagInfo')).virtualDaaScore; } catch { return null; } } +} +function miner(argv, name, env = {}) { + const out = openSync(`${TMP}/${name}.log`, 'a'); + const p = spawn(CPU_MINER, argv, { stdio: ['ignore', out, out], env: { ...process.env, IGNEUM_POW_DAY_MS: String(DAY_MS), ...env } }); + started.push(p); + return p; +} +function minerArgs(node, label, noLeave) { + const a = ['mine', node.grpc, '1', String(SECS), label, '--engine', 'igneum-pow', '--payout-label', label, '--status-secs', '30']; + if (noLeave) a.push('--no-leave'); + return a; +} +async function stopAll() { + for (const p of started.reverse()) { try { p.kill('SIGINT'); } catch { } } + await sleep(1500); + for (const p of started) { try { p.kill('SIGKILL'); } catch { } } +} +process.on('SIGINT', async () => { await stopAll(); process.exit(130); }); +process.on('unhandledRejection', async (e) => { log(`FAILED: ${e?.stack || e}`); await stopAll(); process.exit(3); }); +const minerLog = (name) => { try { return readFileSync(`${TMP}/${name}.log`, 'utf8').split('\n'); } catch { return []; } }; +const keyHash = (label) => (spawnSync(CPU_MINER, ['key-hash', label], { encoding: 'utf8' }).stdout || '').trim(); +const CARRIED_LINE = /hands its weight and its forfeit term to .* carried by/; +const LOCK_LINE = /Finality: checkpoint (\d+) LOCKED/; + +const t0 = Date.now(); +const since = () => ((Date.now() - t0) / 1000).toFixed(1); +const n0 = await new Node(0).start(); +const n1 = await new Node(1, [`127.0.0.1:${n0.p2pPort}`]).start(); +const n2 = await new Node(2, [`127.0.0.1:${n0.p2pPort}`]).start(); +const nodes = [n0, n1, n2]; +for (const n of nodes) log(`n${n.i}: ${n.grepLog(/Key succession \(W5\) from the override file/).map(l => l.replace(/^.*?(Key succession)/, '$1'))[0] || '(no W5 line)'} | ${n.grepLog(/Signature scheme byte from the override file/).map(l => l.replace(/^.*?(Signature scheme)/, '$1'))[0] || '(no scheme line)'}`); +log(`n0 digest: ${n0.grepLog(/Consensus params digest/).map(l => l.replace(/^.*?digest: /, '').slice(0, 16)).join(' ')}`); +const OLD = 'w5-old', NEW = 'w5-new', THIRD = 'w5-third', PROBE = 'w5-probe'; +const oldHash = keyHash(OLD), newHash = keyHash(NEW); +log(`old key ${oldHash.slice(0, 16)} (${OLD}), successor ${newHash.slice(0, 16)} (${NEW})`); +miner(minerArgs(n0, 'w5-a0', false), 'cpu0'); +miner(minerArgs(n1, 'w5-b1', false), 'cpu1'); +let cpu2 = miner(minerArgs(n2, OLD, true), 'cpu2'); + +const samples = []; +let phase = 'fill', oldBlocksBefore = null, succeedOutcome = null, succeededAtDaa = null, newStartedAt = null, carriedSeenAt = null; +let refusals = [], probes = [], locksBefore = null, locksAfter = null, lastReport = 0; +const run = (argv) => { const r = spawnSync(CPU_MINER, argv, { encoding: 'utf8' }); return { code: r.status, out: (r.stdout || '') + (r.stderr || '') }; }; +while (Date.now() - t0 < SECS * 1000) { + await sleep(1000); + const daa = await n0.daa(); + if (daa == null) continue; + if (Date.now() - lastReport > 15000) { + lastReport = Date.now(); + const w = await Promise.all(nodes.map(n => n.weights())); + const rows = w.map(r => r ? `${r.totalWeight}/${r.voters}` : '?'); + const locks = nodes.map(n => n.grepLog(LOCK_LINE).length); + log(`t=${since()} s daa ${daa} phase ${phase} total/voters per node ${rows.join(' ')} locks ${locks.join(' ')}`); + samples.push({ t: +since(), daa, phase, weights: rows, locks }); + } + if (phase === 'fill' && daa >= SUCCEED_AT) { + const w = await n0.weights(); + const row = w?.keys?.find(k => k.keyHash === oldHash); + oldBlocksBefore = row ? +row.blocks : 0; + locksBefore = n0.grepLog(LOCK_LINE).length; + log(`window filled: ${OLD} holds ${oldBlocksBefore} blocks on n0 at daa ${daa}; ${locksBefore} locks on n0`); + try { cpu2.kill('SIGINT'); } catch { } + await sleep(2500); + if (EXPECT === 'succession') { + succeedOutcome = run(['succeed', n2.grpc, OLD, NEW]); + log(`succeed ${OLD} -> ${NEW} on n2: exit ${succeedOutcome.code}: ${succeedOutcome.out.trim().split('\n').pop()}`); + } else { + log(`known-failed case: no succession submitted`); + } + succeededAtDaa = daa; + newStartedAt = daa; + cpu2 = miner(minerArgs(n2, NEW, false), 'cpu2b'); + phase = 'carry'; + continue; + } + if (phase === 'carry') { + const carried = nodes.map(n => n.grepLog(CARRIED_LINE).length > 0); + if (carried.every(Boolean) && carriedSeenAt == null) { carriedSeenAt = daa; log(`carried: every node logs the succession carried by a block at daa ${daa}`); } + // the fold: every node's report shows the successor inheriting and the old key handed over + const w = await Promise.all(nodes.map(n => n.weights())); + const folded = w.every(r => r && r.keys.some(k => k.keyHash === newHash && k.succeededFrom === oldHash) && r.keys.some(k => k.keyHash === oldHash && k.succeededTo === newHash)); + if (folded || (EXPECT === 'no-succession' && daa >= succeededAtDaa + 2 * WINDOW)) { + const minedAlone = minerLog('cpu2b').filter(l => /ACCEPTED block/.test(l)).length; + const rows = w.map(r => ({ new: r?.keys?.find(k => k.keyHash === newHash) || null, old: r?.keys?.find(k => k.keyHash === oldHash) || null })); + log(`fold at daa ${daa}: ${NEW} mined ${minedAlone} blocks alone; per node new/old blocks ${rows.map(r => `${r.new?.blocks ?? '-'}/${r.old?.blocks ?? '-'}`).join(' ')}`); + // refused twice, on n2 and on n0 (every node); and the successor named has handed over + refusals = [ + { what: `${OLD} -> ${THIRD} on n2`, ...run(['succeed', n2.grpc, OLD, THIRD]) }, + { what: `${OLD} -> ${THIRD} on n0`, ...run(['succeed', n0.grpc, OLD, THIRD]) }, + { what: `${NEW} -> ${OLD} on n1`, ...run(['succeed', n1.grpc, NEW, OLD]) }, + ]; + for (const r of refusals) log(`${r.what}: exit ${r.code}: ${r.out.trim().split('\n').pop()}`); + probes = nodes.map(n => ({ node: n.i, ...run(['probe-scheme', n.grpc, PROBE, '1']) })); + for (const p of probes) log(`probe scheme 1 on n${p.node}: exit ${p.code}: ${p.out.trim().split('\n').pop()}`); + phase = 'after'; + locksAfter = n0.grepLog(LOCK_LINE).length; + continue; + } + } + if (phase === 'after') { + // locks keep coming with the new key signing: two windows after the fold is enough to see it + const locksNow = n0.grepLog(LOCK_LINE).length; + if (locksNow > locksAfter + 2) { log(`locks after the fold: ${locksNow} on n0 (${locksAfter} at the fold)`); break; } + } +} +await sleep(1500); +const w = await Promise.all(nodes.map(n => n.weights())); +const dag = await Promise.all(nodes.map(async n => { try { return await n.rpc.call('getBlockDagInfo'); } catch (e) { return { error: e.message }; } })); +const minedAlone = minerLog('cpu2b').filter(l => /ACCEPTED block/.test(l)).length; +const rows = w.map(r => ({ new: r?.keys?.find(k => k.keyHash === newHash) || null, old: r?.keys?.find(k => k.keyHash === oldHash) || null })); +const locks = nodes.map(n => n.grepLog(LOCK_LINE).length); +const rejectedNode = nodes.map(n => n.grepLog(/PoW rejected|Rejected block|rejected block/i).length); +const checks = { + window_filled_before_the_succession: oldBlocksBefore != null && oldBlocksBefore >= 5, + succession_accepted_on_submit: EXPECT === 'succession' ? succeedOutcome?.code === 0 && /SUCCEED old=/.test(succeedOutcome.out) : succeedOutcome == null, + carried_once_on_every_node: nodes.every(n => n.grepLog(CARRIED_LINE).length >= 1), + successor_inherits_on_every_node: rows.every(r => r.new && r.new.succeededFrom === oldHash && +r.new.blocks > minedAlone), + old_key_handed_over_on_every_node: rows.every(r => r.old && r.old.succeededTo === newHash && +r.old.blocks === 0 && r.old.voter === false), + nodes_agree_on_the_successor_weight: new Set(rows.map(r => String(r.new?.blocks))).size === 1, + refused_old_again_on_n2: refusals[0]?.code === 3 && /already handed/.test(refusals[0].out), + refused_old_again_on_n0: refusals[1]?.code === 3 && /already handed/.test(refusals[1].out), + refused_successor_that_handed_over: refusals[2]?.code === 3 && /has itself handed/.test(refusals[2].out), + scheme_1_refused_by_every_node: probes.length === 3 && probes.every(p => p.code === 0 && /SCHEME 1 REFUSED/.test(p.out) && /active scheme is 0/.test(p.out)), + locks_continue_after_the_fold: locksAfter != null && locks[0] > locksAfter + 2, + zero_rejected_by_nodes: rejectedNode.every(c => c === 0), + sinks_agree: new Set(dag.map(d => String(d.sink))).size === 1, +}; +const pass = Object.values(checks).every(Boolean); +const summary = { + expect: EXPECT, pass, checks, old_key: oldHash, new_key: newHash, old_blocks_before: oldBlocksBefore, succeeded_at_daa: succeededAtDaa, + carried_seen_at_daa: carriedSeenAt, new_mined_alone: minedAlone, rows, locks, locks_at_fold: locksAfter, refusals: refusals.map(r => ({ what: r.what, code: r.code, line: r.out.trim().split('\n').pop() })), + probes: probes.map(p => ({ node: p.node, code: p.code, line: p.out.trim().split('\n').pop() })), samples, wall_s: +since(), + binaries: { igneumd: IGNEUMD, miner: CPU_MINER }, +}; +writeFileSync(`${TMP}/summary.json`, JSON.stringify(summary, null, 2)); +log(`SUMMARY ${pass ? 'PASS' : 'FAIL'} (${EXPECT}): ${Object.entries(checks).filter(([, v]) => !v).map(([k]) => `FAILED CHECK ${k}`).join('; ') || 'every check holds'}; ${TMP}/summary.json`); +await stopAll(); +process.exit(pass ? 0 : 1); diff --git a/infra/fast-time/override-60x.json b/infra/fast-time/override-60x.json index f232111df..aed3b8f02 100644 --- a/infra/fast-time/override-60x.json +++ b/infra/fast-time/override-60x.json @@ -67,5 +67,9 @@ "proving_v1_unproven_daa": 10, "proving_v1_aggregator_share_bps": 1000, "fees_v1_activation_daa": 0, + "sig_scheme": 0, + "sig_scheme_activation_daa": 18446744073709551615, + "finality_succession_activation_daa": 18446744073709551615, + "latency_ladder_cache_rung": {"mib": 512, "admissible": false}, "fees": {"pgas": {"version": 1, "cycles_per_pgas": 1000, "intrinsic_pgas_per_tx": 300, "modexp_base": 10, "modexp_per_byte_numer": 1, "modexp_per_byte_denom": 10}, "block_proving_gas_limit": 120000, "shard_proving_gas_budget": 30000, "min_execution_base_fee_wei": 100000000000, "min_proving_base_fee_wei": 10000000000000, "initial_execution_base_fee_wei": 100000000000, "initial_proving_base_fee_wei": 10000000000000, "base_fee_change_denominator": 8} }