diff --git a/docs/plans/counter-asic-3-status.md b/docs/plans/counter-asic-3-status.md index b39f24b59..6ea5e164a 100644 --- a/docs/plans/counter-asic-3-status.md +++ b/docs/plans/counter-asic-3-status.md @@ -338,7 +338,7 @@ the project lead gave the go in advance for tonight: the shipper runs publish 1 | THE ANALYSIS (the hash lane, ca3-v4-uniform 095f84a7, `docs/analysis/ca3-v4-uniform.md`, the tool on igneum-build-1) | the window model moves the null from 0.115 to 0.160 percent (1.39x, not 4.05x); the rest is a FAULT beyond it: site 15 reads a register last written by `or r6, r4`, so all-ones recurs at (3/4)^32 per read and the era map sends it to F8's hottest item exactly (the popcount model predicts 77,348 all-ones reads against 78,479; the top-0.1-percent share 0.58 against 0.52); it passes the acceptance rule because part (a) takes any write as a fresh source and part (c) counts saturation on final values only. The census of 1,024 chain-shaped v4 programs: 96.6 percent carry a lossy-sourced load (or, mul, mulhi as the last writer), 48.5 percent an or-sourced one (0.30 percent of all reads per site), 4.9 percent an or-of-or chain (4.6 percent of all reads on 0.1 percent of items); F8's 1.2x gate fails 96.6 percent of today's programs. Worth to a chip: 1.07 MB of SRAM ($0.25) serving 0.52 percent of a typical program's reads and 4.6 percent of the worst class's, at most 1.005x and 1.048x in rate; the ceiling under rule (c)'s 120-of-128 floor one site repeating its item in all 8 iterations, 6.25 percent of reads, 1.067x in 64 bytes; the 2x margin stands; the public line says "bounded at 1.067x", not "uniform" (the public text corrected) | | The two options, priced, STOPPED at the coordinator for the project lead's word | A: a 0.3.19 class amendment before the flip (the generator draws a load's source from the registers whose last writer injects): a new program stream, new vectors, the seven gate packs re-exported, the six gates again (G1 to G3 and the verifier about an hour on the Mac and PC 2; G4 to G6 the node lane), every node before the flip under the one-box-at-a-time rule; the risk a node that misses the build splits the chain at the flip. B: hold the flip at the floor with v4 as it is; the bound documented; the source rule to class v5: a hot set worth up to 1.005x on about half the hours and 1.05x on 5 percent, 1.067x at the ceiling; no chain risk. The number: 1.067x at the ceiling against the 2x margin. The lane recommends B | | The v5 bound (sent to the v5 lane) | H = W_0.1 (the window term, 0.115 to 0.251 percent) + the sum over load sites of h(last writer) (or 0.30 percent, an or chain 4.5, mul 0.067, mulhi 0.049, an injecting op or a rotate 0), H at or under 1.2 x W_0.1, which is the static rule "every load's source was last written by an injecting op or a rotate"; as a rejection it costs 96.6 percent of candidates (about 30 attempts per seed), as a generator draw nothing; gate F8's 64-seed census with the saturated-source count | -| [user]'S WORD (15:2x UK, 7 October): OPTION A, "do this but limit the testing, get it pushed" | the class v4 amendment: a load's source drawn only from registers whose last writer injects or is a rotate (the v5 rule applied now), a new program stream and vectors, the seven gate packs re-exported, the amended class with its own generator stamp; rides 0.3.20, the feature node (release-0.3.20-node = dc141409; 0.3.19 is an app-only cut with nothing of ours), on the shipper's line. The rollout arithmetic for the flip clock (the shipper): the standing fleet's one-box-at-a-time rollout took 32 minutes for 14 boxes (04:56 to 05:28Z, 7 October), the hands and the seed about 3 minutes after the miners, the Mac and the PCs within minutes of the publish; every 0.3.20 worker must accept the amended stamp before any flip. Owners: the hash lane (ca3-v4-amend: the generator, the vectors, the packs, the pairing on the box, one G1 run on PC 2, the ledger row), the node lane (release-0.3.20-node: the stamp agreed with the hash lane, the split-protection mechanism and the earliest flip time, the digest test, the mixed-version Devnet 2 gate), the attack-pass lane (the F8 census at 2^24 on the new stream, the gate 1.2x of the window model over 64 seeds), the shipper (the cut, the rollout order that sets the earliest flip). Testing limited to what prevents a split and proves the fix; G2, G3, the ladder re-measure and the rest of G4 to G6 OWED. THE STAMP agreed (the node and hash lanes, 7 October afternoon): generator 4 with sub-version 1 inside igneum-pow's id function, so the amended v4's program id for a seed differs from the old v4's (the old devnet epoch-0 id c120d7963abdcd96 pinned as the must-differ vector in kaspa-pow's test). SPLIT PROTECTION SETTLED (the node lane, plan section 6.6, ca3-v4-node fa5bc9e6; the node side on release-0.3.20-node): a fresh object byte. CLASS_SIGNAL_V4 is 5; the amended binary stamps 5 and the tally counts a block only at byte 5 or above; object 4 was stamped only by the unpublished dc141409 canary, so no published block carries it and a byte-4 block never counts; a node of the 6 October stream that sees byte 5 counts it as v4 (its rule is at least 4), flips to its own stream at the same epoch and forks ALONE (its blocks fail the amended id check, generator 4 sub-version 1 inside every id; the amended blocks fail its own), ours to upgrade in the sweep; object 6 is class v5's; the two holds already in the rule keep the window shut until every node is on 0.3.20 (a node stamps and tallies only with both v4 fields in its file; the fields publish only after the one-sweep rollout); a lagging worker refuses the amended pack at packcheck and mines nothing after the flip, costing that box, never the chain; no extra window hold: seven full day-windows are the hold. THE EARLIEST FLIP (approximate, measured 09:40Z: DAA 270,659, 1.095 DAA/s over 25 hours, 1.165 over 4; epoch 3,600, lead 600; seven windows 604,800 DAA wholly after the sweep's end D_s = T + about 40 minutes; the flip epoch the first e with 3600 e - 600 >= D_s + 604,800): T + 6 days 10 hours to T + 6 days 11 hours UK; for a publish at 12:00 UK on 7 October, 13 October between 22:20 and 23:10 UK (about 13:00 UK if the 4-hour rate holds). The floor as it stands (831,600, about 13 October 09:00 UK) would fire before any seven-window signal from a publish today completes, so it moves by the 0.3.16 rule to the publish DAA + 604,800 rounded up to the epoch boundary (882,000 for a 12:00 UK publish), firing about 30 minutes before the earliest signal flip: either way about 6 days 10 hours after the publish, never before every node has had the sweep plus a week. THE CLOCK (the node lane, 11:3x UK, after a Mac reboot moved its runs to the box): the 0.3.20 node line (dc141409 plus the proof archive aea0ca5c plus the amended v4 at object byte 5, igneum-pow at the hash lane's a0aaca92 beside the fork on the box) tested on the box, committed on release-0.3.20-node, pushed to the mirror and origin, igneumd and igneum-miner built, the tip to the shipper: about 12:00 UK; the mixed-version Devnet 2 gate (node-compat.mjs on the box, the amended node beside the 5899f603 pair for ten minutes) and the digest test (digest-compat.mjs): about 12:45 UK; the object-byte pin 5 unless the v5 lane answers both lanes with another assignment (v5 at 6 proposed). The gates: the digest test and the kaspa-pow vector test (the amended devnet epoch-0 id 1a4230699a6b9c60 must equal, c120d7963abdcd96 must differ, the v3 control unchanged) on the box; the mixed-version Devnet 2 gate (the amended 0.3.20 node beside a 5899f603 node for ten minutes on the live file without the v4 fields) after the Mac build; the fresh-join canary the 0.3.20 cut's | +| [user]'S WORD (15:2x UK, 7 October): OPTION A, "do this but limit the testing, get it pushed" | the class v4 amendment: a load's source drawn only from registers whose last writer injects or is a rotate (the v5 rule applied now), a new program stream and vectors, the seven gate packs re-exported, the amended class with its own generator stamp; rides 0.3.20, the feature node (release-0.3.20-node = dc141409; 0.3.19 is an app-only cut with nothing of ours), on the shipper's line. The rollout arithmetic for the flip clock (the shipper): the standing fleet's one-box-at-a-time rollout took 32 minutes for 14 boxes (04:56 to 05:28Z, 7 October), the hands and the seed about 3 minutes after the miners, the Mac and the PCs within minutes of the publish; every 0.3.20 worker must accept the amended stamp before any flip. Owners: the hash lane (ca3-v4-amend: the generator, the vectors, the packs, the pairing on the box, one G1 run on PC 2, the ledger row), the node lane (release-0.3.20-node: the stamp agreed with the hash lane, the split-protection mechanism and the earliest flip time, the digest test, the mixed-version Devnet 2 gate), the attack-pass lane (the F8 census at 2^24 on the new stream, the gate 1.2x of the window model over 64 seeds), the shipper (the cut, the rollout order that sets the earliest flip). Testing limited to what prevents a split and proves the fix; G2, G3, the ladder re-measure and the rest of G4 to G6 OWED. THE STAMP agreed (the node and hash lanes, 7 October afternoon): generator 4 with sub-version 1 inside igneum-pow's id function, so the amended v4's program id for a seed differs from the old v4's (the old devnet epoch-0 id c120d7963abdcd96 pinned as the must-differ vector in kaspa-pow's test). SPLIT PROTECTION SETTLED (the node lane, plan section 6.6, ca3-v4-node fa5bc9e6; the node side on release-0.3.20-node): a fresh object byte. CLASS_SIGNAL_V4 is 5; the amended binary stamps 5 and the tally counts a block only at byte 5 or above; object 4 was stamped only by the unpublished dc141409 canary, so no published block carries it and a byte-4 block never counts; a node of the 6 October stream that sees byte 5 counts it as v4 (its rule is at least 4), flips to its own stream at the same epoch and forks ALONE (its blocks fail the amended id check, generator 4 sub-version 1 inside every id; the amended blocks fail its own), ours to upgrade in the sweep; object 6 is class v5's; the two holds already in the rule keep the window shut until every node is on 0.3.20 (a node stamps and tallies only with both v4 fields in its file; the fields publish only after the one-sweep rollout); a lagging worker refuses the amended pack at packcheck and mines nothing after the flip, costing that box, never the chain; no extra window hold: seven full day-windows are the hold. THE EARLIEST FLIP (approximate, measured 09:40Z: DAA 270,659, 1.095 DAA/s over 25 hours, 1.165 over 4; epoch 3,600, lead 600; seven windows 604,800 DAA wholly after the sweep's end D_s = T + about 40 minutes; the flip epoch the first e with 3600 e - 600 >= D_s + 604,800): T + 6 days 10 hours to T + 6 days 11 hours UK; for a publish at 12:00 UK on 7 October, 13 October between 22:20 and 23:10 UK (about 13:00 UK if the 4-hour rate holds). The floor as it stands (831,600, about 13 October 09:00 UK) would fire before any seven-window signal from a publish today completes, so it moves by the 0.3.16 rule to the publish DAA + 604,800 rounded up to the epoch boundary (882,000 for a 12:00 UK publish), firing about 30 minutes before the earliest signal flip: either way about 6 days 10 hours after the publish, never before every node has had the sweep plus a week. THE CLOCK (the node lane, 11:3x UK, after a Mac reboot moved its runs to the box): the 0.3.20 node line (dc141409 plus the proof archive aea0ca5c plus the amended v4 at object byte 5, igneum-pow at the hash lane's a0aaca92 beside the fork on the box) tested on the box, committed on release-0.3.20-node, pushed to the mirror and origin, igneumd and igneum-miner built, the tip to the shipper: about 12:00 UK; the mixed-version Devnet 2 gate (node-compat.mjs on the box, the amended node beside the 5899f603 pair for ten minutes) and the digest test (digest-compat.mjs): about 12:45 UK; the object-byte pin 5 unless the v5 lane answers both lanes with another assignment (v5 at 6 proposed). THE FIRST GREEN (11:31 UK, the box): the kaspa-pow suite on release-0.3.20-node (dc141409 plus the proof archive aea0ca5c plus the object-5 change) against the hash lane's igneum-pow 8c728ca3: 17 passed, 0 failed; the amended devnet epoch-0 id 1a4230699a6b9c60 pinned equal and c120d7963abdcd96 differing, the ladder's rung test green under the rekeyed rule, the v3 control unchanged; the consensus-core and exec RPC suites follow, then the node line (commit, push, box build, the tip to the shipper), then the digest and mixed-version gates. The gates: the digest test and the kaspa-pow vector test (the amended devnet epoch-0 id 1a4230699a6b9c60 must equal, c120d7963abdcd96 must differ, the v3 control unchanged) on the box; the mixed-version Devnet 2 gate (the amended 0.3.20 node beside a 5899f603 node for ten minutes on the live file without the v4 fields) after the Mac build; the fresh-join canary the 0.3.20 cut's | | Main's rulings (7 October, morning) | no generator change to v4 on the live devnet; the record's null is the window model with numbers, sent by the hash lane to the attack-pass lane so AP-F8-1 re-gates against it; a fault beyond the model (a low-entropy source at site 15) stops at the coordinator with the two options priced (a 0.3.19 class amendment before the flip, or the flip held at the floor), nothing shipping without the project lead's word; the tighter tail, an acceptance bound on the hot-set share, is a CLASS V5 item (sent to the v5 lane a6410f3b8abefb762 with the 64-seed census as its gate; the bound's number follows from the model) | ### AP-F4-1, the weak-day MUL draw (the attack-pass lane, 7 October, morning): PASS against v4, a class v5 rule