From d037347bbf1c0cddad09bd729b0d1fe60b51fd7b Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Wed, 7 Oct 2026 13:36:33 +0000 Subject: [PATCH] fud ledger N14: a node started without the verifier host built zero-id segment statements (the fleet's 12 GB line); the embedded keys' ids on 55768f88; plan 6.7 rows Co-Authored-By: Claude Fable 5.1 --- docs/fud-ledger.md | 8 ++++++++ docs/plans/counter-asic-3-node.md | 5 ++++- 2 files changed, 12 insertions(+), 1 deletion(-) diff --git a/docs/fud-ledger.md b/docs/fud-ledger.md index 0a9cdeac3..5772dbbae 100644 --- a/docs/fud-ledger.md +++ b/docs/fud-ledger.md @@ -2453,6 +2453,14 @@ Per tier: a one-box roll keeps datadirs, so the roll would have killed every sta Fix on release-0.3.20-node (the fourth commit): the virtual-state store reads the live row in the current layout first (a datadir already on the line keeps reading first-try) and on a deserialization error decodes it as a mirror of the v1 layout (`IgneumV1VirtualState`, rewards of three fields), converts with `silent: false` (no block of that row was judged silent; the next virtual update recomputes it) and rewrites it under the same key in the current layout, with one info line; the version suffix is unchanged. Gate: `a_virtual_state_row_from_before_the_silence_field_is_read_and_rewritten` (a v1 row on a temp DB; the current layout reads it short first, the known-failed shape; the store reads, converts and rewrites; a second open reads first-try), and the fleet's kept-datadir start on p12-vast's second datadir on the fixed binary. The rule this adds for every node cut from now: a kept-datadir restart gate on a standing box's datadir copy beside the wiped canary, and no persisted struct gains a field under `#[serde(default)]` without a versioned read (bincode does not default). +### N14. A node started without the verifier host on a file without the id fields builds its segment statements with zero program ids and refuses every proof (p12-vast on c4459193, 7 October 2026, 13:25Z) + +The fleet's 12 GB line: the prover claimed behind the settled floor as the rule wants (segment 164198..164205, 31 blocks behind the settled number), proved it on a 3060 (8 of 8 shards, 136 s, 8.5 GB) and was refused at the submit: "statement differs from the node's at hex offset 472: ours ...2b1a81cb... node ...0000". The node's start lines read "proving v1: ... shard program id unknown, aggregator id unknown" and then "verifying keys embedded: shard program id 0x2b1a81cb... aggregator id 0x474678f3...". On every build, 5899f603 included, the statement's ids came from the override object's two fields, else `IGNEUM_PROOF_PROGRAM_IDS`, else the verifier host's `--mode id` when `IGNEUM_PROOF_VERIFIER` is set; the live sixteen-field file carries no id fields, hub-1 runs with the host (its process environment) and reads the ids from it, and the pod's node was started bare, so `program_ids` answered None and the statement carried zeros. No commit on the line lost them: a bare 5899f603 reads "unknown" too (Devnet 2's nodes compared statements against zero ids on 6 October for the same reason, the 0.3.17 note in the daemon). What made it the line's to fix: the binary embeds the verifying keys it verifies carried proofs with, so it knows the ids it expects whatever the start environment. + +Per tier: a home node or a hand started without the host refused every proof submitted to it and paid nothing, silently to the prover ("statement differs"); the swept fleet as rolled by the script with the host set was never at risk; nothing on chain affected. + +Fix on release-0.3.20-node, 55768f88 (c4459193's child): `resolve_program_ids`, the override object's fields first, then the env or the host, then the embedded keys; a bare node reports the ids in its proving v1 line and builds the statement with them. Gate: `a_bare_node_resolves_its_program_ids_from_the_embedded_keys` (known failed first: the bare node's None and the zero-id statement differing from the one with the ids at the id bytes; then the resolver's embedded ids, the override's fields still winning), and the fleet's 12 GB line on the 55768f88 binary. Owed: the proving v1 line names where its ids came from (file, env, host or embedded). + ## Status updates, 5 October 2026 (ledger sweep, night of 4 to 5 October) `docs/review/ledger-sweep-2026-10-05.md` holds the runs, the commands and the running table. Every Open, Proposed, Unmeasured or pending entry was read against its experiment line; the status lines above carry the evidence inline, marked "Sweep (5 October 2026)" where a note was added and "Was:" where the status changed. Items owned by the other two night branches (F23, F24, G12, X18, the flood memory growth; the base-fee floor, testnet parameters, G13, G14, public text) were left to them. diff --git a/docs/plans/counter-asic-3-node.md b/docs/plans/counter-asic-3-node.md index 2749907e9..9c1dbb313 100644 --- a/docs/plans/counter-asic-3-node.md +++ b/docs/plans/counter-asic-3-node.md @@ -156,7 +156,7 @@ the project lead's word (15:2x UK, through the coordinator): option A, the load- ### 6.7 The 0.3.20 node line's gates (7 October 2026, UTC; the box runs CEST and earlier stamps in this section's messages read an hour fast) -The line on the mirror, branch release-0.3.20-node, pairing igneum-pow 8c728ca3 (object bytes settled by main: 0.3.20 ships class v4 sub-version 1 at byte 5, class v5 takes 6, class v4 sub-version 2 takes 7 after 0.3.20): 8097d600 (object 5, isSynced, the weight-table cache, the lazy snapshot, the submit path, the 100 ms template wait, the finality reports with signers), 6b94c823 (test-only: the stale PC 1 test), 6a3432a3 (the key methods, the claims, the settled claim floor, the listener watchdog), 09124180 (N12: a held exec port is a retry), b7cc37e7 (N13: a kept 0.3.17 datadir's virtual-state row read through a v1 mirror and rewritten), c4459193 (the watchdog's poll returns on shutdown). The candidate pin is c4459193 (b7cc37e7 plus the watchdog's shutdown fix); no earlier build is a pin for the one-box roll: every build since 10db4b61 dies at start on a kept datadir until b7cc37e7, and b7cc37e7 stops up to 10 s late. +The line on the mirror, branch release-0.3.20-node, pairing igneum-pow 8c728ca3 (object bytes settled by main: 0.3.20 ships class v4 sub-version 1 at byte 5, class v5 takes 6, class v4 sub-version 2 takes 7 after 0.3.20): 8097d600 (object 5, isSynced, the weight-table cache, the lazy snapshot, the submit path, the 100 ms template wait, the finality reports with signers), 6b94c823 (test-only: the stale PC 1 test), 6a3432a3 (the key methods, the claims, the settled claim floor, the listener watchdog), 09124180 (N12: a held exec port is a retry), b7cc37e7 (N13: a kept 0.3.17 datadir's virtual-state row read through a v1 mirror and rewritten), c4459193 (the watchdog's poll returns on shutdown), 55768f88 (N14: a bare node's program ids from the embedded verifying keys). The candidate pin is 55768f88 (c4459193 plus the program ids from the embedded keys, N14); no earlier build is a pin for the one-box roll: every build since 10db4b61 dies at start on a kept datadir until b7cc37e7, and b7cc37e7 stops up to 10 s late. | Gate | Binary | Run (UTC) | Line | |---|---|---|---| @@ -167,6 +167,9 @@ The line on the mirror, branch release-0.3.20-node, pairing igneum-pow 8c728ca3 | Mixed-version, ten minutes beside the 5899f603 pair | c4459193 | 12:35:26 to 12:45:39 | PASS: one digest b0afb2ee on all five, 215 new and 314 old blocks accepted, 0 rejected, plain header version 2, counts equal at 312, 441 and 529 through both clean joins and the restart step (the new node restarted on its own datadir and resynced), no panic in any log, every check green | | Kept-datadir start | c4459193 (carried from b7cc37e7: the store code is identical; the fleet's canary re-reads it on this binary) | | the b7cc37e7 lines above | | Shutdown within a second | c4459193 | 12:29 (build-2) | `a_shutdown_returns_within_a_second_whatever_the_poll` green in the exec suite's 31, beside the two other watchdog tests | +| The 12 GB settled-claim line (the fleet, p12-vast) | c4459193 | 13:23 to 13:27 | the claim 31 blocks behind the settled number, 8 of 8 shards proved in 136 s at 8.5 GB on a 3060, the submit refused: the node was started bare and built a zero-id statement (N14); not the binary's change but fixed on it | +| Exec suite with the bare-node ids test | 55768f88 (c4459193's child, sha256 279b1b690e854fc9, the string read back) | 13:29 | 32 passed, `a_bare_node_resolves_its_program_ids_from_the_embedded_keys` (known failed first) | +| Digest, mixed-version, the fleet's set | 55768f88 | from 13:37 | (the lines follow, each as it lands) | | Digest | 6b94c823 (the fallback, sha256 b1b7d47b) | 11:56:45 to 11:57:52 | compat and refusal digests right; the one failed check read n3's peers at 1 with its refusal line present (the refused connection's reconnect in flight; the read is now the minimum of five, 36d3efdc) | | Mixed-version | 6b94c823 | 11:57:53 to 12:08:05 | one digest b0afb2ee on all five, 146 new and 246 old blocks accepted, 0 rejected, counts equal through both joins and the restart; the one failed check: six "Address already in use" panics in the two OLD nodes' server threads, the gate started the second the digest gate's nodes got SIGTERM on the same ports (a 20 s gap now) | | Mixed-version on the live sixteen-field file (void: the binary at the path was replaced mid-run) | 8097d600 | 11:42:55 to 11:53:07 | the interop fact: one digest on all five, the 5899f603 hub accepted 235 byte-5 blocks from the new node with 0 rejected, old headers 1026 (byte 4), new 1282 (byte 5), counts equal on all five at 472 before the restart step |