Counter ASIC 3.0 status: 0.3.17 is the node-only fresh-join hotfix (main's decision)

This commit is contained in:
igneum-labs 2026-10-07 03:37:00 +00:00
parent de42083b08
commit ca16dde4e9

View file

@ -301,7 +301,7 @@ A script never switches the installed app's cards: a POST of enabled false to /a
| The fork's final tree for 0.3.15 (ca3-v4-order-fix, four commits) | 791ff22c the order-test race (tests only); 713ef876 the digest once-set rule; 17c60367 the signal stamp and read gated on both v4 fields (header version 2 on the live file, 1026 only with publish 2's object); 7961c5f1 a sync request below a pruned node's retention answered as SyncManagerError::BlockBelowRetention to the peer, never an unwrap (the hub's 19:57Z panic: a remote crash vector against every pruned node since the first one). The shipper built 0.3.15 from 7961c5f1 on all three platforms, the digests unchanged, the six-crate suite green. The node-compat gate (ca3-v4-node 4d7e677, `infra/fast-time/node-compat.mjs`, 20:19Z): a mining new node beside a 0.3.14 node on the live object PASS (one digest on five nodes, the new miner's 75 blocks accepted by the old hub, header versions 2 only, 195 blocks on every node including the clean join through the old hub, the old node served from genesis by the new one, the new node restarted and re-synced); the canary binary 713ef876 on the same gate FAILS with the fleet's exact reject lines (the known-failed case). Ledger rows N1 and N2 (security, conceded, dated, with the fixes) in docs/fud-ledger.md. The audit pass landed (fork ca3-v4-deps f8f0f1df from 7961c5f1, Cargo.lock only, the shipper's 0.3.15.1 node change): h2 0.4.20, quinn-proto 0.11.19, rustls 0.23.45, crossbeam-epoch 0.9.21, ruint 1.20.1; cargo audit on the box 6 vulnerabilities and 16 warnings before, 1 and 16 after (the one left tracing-subscriber 0.2.25 pinned through ark-groth16, a major bump, named and not taken); the six-crate suite green on the new lock (99 / 111 + 7 / 20 / 15 / 18 / 33); row P5 on ca3-v4-node 536e084. The receive-side fix f1ea7a38 (fork ca3-v4-order-fix on 7961c5f1, 21:39 UK, to the shipper 21:46 UK; the box line kaspa-consensus 99, consensus-core 111 + 7, rc 0): with the window or the floor absent, a header's version must be exactly 2 (0.3.14's rule), so a 1026 header is refused before the engine with WrongBlockVersion(1026, 2) and never relayed; with publish 2's object both bytes are read as designed; the test inside cheap_checks_run_before_the_pow_engine; the gate re-run with a poisoned peer in the topology (a 713ef876 node mining 1026 blocks into the new node, 20:42 to 20:45Z) PASS: 12 refusals with 0.3.14's exact line, none relayed, the old hub's chain holding version-2 headers only, every clean node at 180; stale blocks on the live devnet: a 0.3.14 node holding them is disconnected by its 0.3.14 peers by their own rule, new nodes are immune, the fleet wipes the poisoned datadirs; ledger N1 extended; the shipper rebuilds once on f1ea7a38. The node lane's further queue (the peer-driven unwrap class with a sync-request fuzz gate, the 7-window signalling rule, the Horizon items, the stale-block nuisance-peer case) reports to main: it is the cut's and the ledger's, not this file's | | The fork's final tree for 0.3.15 (ca3-v4-order-fix, four commits) | 791ff22c the order-test race (tests only); 713ef876 the digest once-set rule; 17c60367 the signal stamp and read gated on both v4 fields (header version 2 on the live file, 1026 only with publish 2's object); 7961c5f1 a sync request below a pruned node's retention answered as SyncManagerError::BlockBelowRetention to the peer, never an unwrap (the hub's 19:57Z panic: a remote crash vector against every pruned node since the first one). The shipper built 0.3.15 from 7961c5f1 on all three platforms, the digests unchanged, the six-crate suite green. The node-compat gate (ca3-v4-node 4d7e677, `infra/fast-time/node-compat.mjs`, 20:19Z): a mining new node beside a 0.3.14 node on the live object PASS (one digest on five nodes, the new miner's 75 blocks accepted by the old hub, header versions 2 only, 195 blocks on every node including the clean join through the old hub, the old node served from genesis by the new one, the new node restarted and re-synced); the canary binary 713ef876 on the same gate FAILS with the fleet's exact reject lines (the known-failed case). Ledger rows N1 and N2 (security, conceded, dated, with the fixes) in docs/fud-ledger.md. The audit pass landed (fork ca3-v4-deps f8f0f1df from 7961c5f1, Cargo.lock only, the shipper's 0.3.15.1 node change): h2 0.4.20, quinn-proto 0.11.19, rustls 0.23.45, crossbeam-epoch 0.9.21, ruint 1.20.1; cargo audit on the box 6 vulnerabilities and 16 warnings before, 1 and 16 after (the one left tracing-subscriber 0.2.25 pinned through ark-groth16, a major bump, named and not taken); the six-crate suite green on the new lock (99 / 111 + 7 / 20 / 15 / 18 / 33); row P5 on ca3-v4-node 536e084. The receive-side fix f1ea7a38 (fork ca3-v4-order-fix on 7961c5f1, 21:39 UK, to the shipper 21:46 UK; the box line kaspa-consensus 99, consensus-core 111 + 7, rc 0): with the window or the floor absent, a header's version must be exactly 2 (0.3.14's rule), so a 1026 header is refused before the engine with WrongBlockVersion(1026, 2) and never relayed; with publish 2's object both bytes are read as designed; the test inside cheap_checks_run_before_the_pow_engine; the gate re-run with a poisoned peer in the topology (a 713ef876 node mining 1026 blocks into the new node, 20:42 to 20:45Z) PASS: 12 refusals with 0.3.14's exact line, none relayed, the old hub's chain holding version-2 headers only, every clean node at 180; stale blocks on the live devnet: a 0.3.14 node holding them is disconnected by its 0.3.14 peers by their own rule, new nodes are immune, the fleet wipes the poisoned datadirs; ledger N1 extended; the shipper rebuilds once on f1ea7a38. The node lane's further queue (the peer-driven unwrap class with a sync-request fuzz gate, the 7-window signalling rule, the Horizon items, the stale-block nuisance-peer case) reports to main: it is the cut's and the ledger's, not this file's |
| the project lead's go | given in advance for tonight; publish 1 on the 0.3.15 canary line, publish 2 once every online node and worker reads 0.3.15 | | the project lead's go | given in advance for tonight; publish 1 on the 0.3.15 canary line, publish 2 once every online node and worker reads 0.3.15 |
| PUBLISH 2 LIVE AND READ BACK (22:43Z, the shipper) | the sixteen-field object (the live thirteen, the exec pin, program_class_v4_activation_daa 831,600, program_class_v4_signal_window_daa 86,400), digest eada4bda8aa8368c2b2c3d17744bc7a70a0ff0e996dad681884d3ac5de1207eb on igneumd/2.1.0-f1ea7a38, on the fleet's 14 standing boxes, both PCs, the hands and the seed; every node prints "active from epoch 231" and the 86,400 window at 9500 bps; THE VOTE OPENED at DAA 223,667. Two facts from the way there: 0.3.15's node gained two gates beyond the signalling fork (the stamp AND the header-version rule both gated on publish 2's object: 17c60367, f1ea7a38) after the live canary found a 0.3.15 node writing version 1026 on the thirteen-field file and then accepting one from a poisoned peer; and the floor sits a week past the publish (831,600) because the floor flips unconditionally on this node (the 0.3.17 P2 rule applied early). The rehearsal chain igneum-devnet-400 ends on this line (the fleet agent told) | | PUBLISH 2 LIVE AND READ BACK (22:43Z, the shipper) | the sixteen-field object (the live thirteen, the exec pin, program_class_v4_activation_daa 831,600, program_class_v4_signal_window_daa 86,400), digest eada4bda8aa8368c2b2c3d17744bc7a70a0ff0e996dad681884d3ac5de1207eb on igneumd/2.1.0-f1ea7a38, on the fleet's 14 standing boxes, both PCs, the hands and the seed; every node prints "active from epoch 231" and the 86,400 window at 9500 bps; THE VOTE OPENED at DAA 223,667. Two facts from the way there: 0.3.15's node gained two gates beyond the signalling fork (the stamp AND the header-version rule both gated on publish 2's object: 17c60367, f1ea7a38) after the live canary found a 0.3.15 node writing version 1026 on the thirteen-field file and then accepting one from a poisoned peer; and the floor sits a week past the publish (831,600) because the floor flips unconditionally on this node (the 0.3.17 P2 rule applied early). The rehearsal chain igneum-devnet-400 ends on this line (the fleet agent told) |
| A FAULT SINCE PUBLISH 2, fixed (the node lane, 03:03 UK, fork ca3-v4-0317-fix 90aaf38e on 02d15a87, with the shipper) | protocol/flows/src/ibd/flow.rs sync_and_validate_pruning_proof compared the syncer's relay block's WHOLE header version with the block version (upstream's guard) while the consensus rule reads the low byte when the signals are active, so a fresh node on the headers-proof IBD path with the window object refused every legal 1026 relay block; the live f1ea7a38 has the same line, so no fresh node joined through that path since the window opened at 22:43Z (nodes syncing without a proof, under 419 headers, were unaffected, which is why the hands moved). The fix: one shared reading, igneum::header_version_acceptable, at both sites; the known-failed unit test first (1026 against 2 legal with the signals, refused without); consensus-core 123, the header tests, p2p-flows 34 green on the box. Owed: the two-daemon integration test with the window object over relay and IBD (next on the 0318 tree). It alters no consensus outcome and the digest is untouched, so a 0.3.16.1 interoperates; main decides | | A FAULT SINCE PUBLISH 2, fixed (the node lane, 03:03 UK, fork ca3-v4-0317-fix 90aaf38e on 02d15a87, with the shipper) | protocol/flows/src/ibd/flow.rs sync_and_validate_pruning_proof compared the syncer's relay block's WHOLE header version with the block version (upstream's guard) while the consensus rule reads the low byte when the signals are active, so a fresh node on the headers-proof IBD path with the window object refused every legal 1026 relay block; the live f1ea7a38 has the same line, so no fresh node joined through that path since the window opened at 22:43Z (nodes syncing without a proof, under 419 headers, were unaffected, which is why the hands moved). The fix: one shared reading, igneum::header_version_acceptable, at both sites; the known-failed unit test first (1026 against 2 legal with the signals, refused without); consensus-core 123, the header tests, p2p-flows 34 green on the box. Owed: the two-daemon integration test with the window object over relay and IBD (next on the 0318 tree). It alters no consensus outcome and the digest is untouched. MAIN'S DECISION: 0.3.17 is a node-only hotfix on the 0.3.16 app tree (the fresh-join fix, node b3c228fa), taken by the canary, then the Mac, PC 1 and PC 2 by update-now on the shipper's line; the feature tree becomes 0.3.18 and decimals 0.3.19 |
## 7a. The two fast-forwards to master (decision 5) ## 7a. The two fast-forwards to master (decision 5)