diff --git a/docs/fud-ledger.md b/docs/fud-ledger.md index 6953b9d97..1636f88f8 100644 --- a/docs/fud-ledger.md +++ b/docs/fud-ledger.md @@ -2085,11 +2085,11 @@ Fix (the node side, ca3-v4-0318; the shard guest's port of the executor is the p ### N8. The execution layer credits every block of a segment at the merging chain block's DAA; the UTXO coinbase pays each merged block the subsidy of its own DAA (found by the bridge-identity harness's known-failed run, 7 October 2026, 09:16 UK) -The first disagreement of that run was on an A row (a signing key, so not N7's bonus): the UTXO coinbase paid the parent 253,783,734 sompi and the EVM record credited it 253,784,614, one second of launch ramp apart. `igneum/exec/src/service.rs` computes `block_subsidy(header.daa_score)` once per chain block and credits every block of the segment with it; `utxo_validation.rs` pays each merged block `coinbase_data.subsidy`, the figure its own coinbase carries at its own DAA. So on every chain, the devnet included, the two ledgers differ by the ramp's slope on every merged block for the first 30 days and by the whole step for the blocks on the far side of every subsidy period boundary; between, they agree. +The first disagreement of that run was on an A row (a signing key, so not N7's bonus): the UTXO coinbase paid the parent 253,783,734 sompi and the EVM record credited it 253,784,614, one second of launch ramp apart. `igneum/exec/src/service.rs` computes `block_subsidy(header.daa_score)` once per chain block and credits every block of the segment with it; `utxo_validation.rs` pays each merged block `coinbase_data.subsidy`, the figure its own coinbase carries at its own DAA. Corrected after a live read of a chain block's record (09:5x UK): the execution layer credits a chain block in its own record (the segment of chain block N holds N and its non-chain blues, not its selected parent), while the UTXO coinbase of N pays N's selected parent, so for every chain block both ledgers price it at its own DAA and agree exactly; the 880-sompi gap the harness first showed was its pairing (a parent's UTXO payment against the child's own EVM credit, one DAA apart). The gap is real only for the non-chain blues a chain block merges (side blocks priced at the chain block's DAA on the EVM side, at their own on the UTXO side): the ramp's slope times the DAA difference during the first 30 days, the whole step at a period boundary, on every chain with wide mergesets (the devnet's mergeset reads 1.00 at 1 bps, so rarely there; a 10-bps network merges 3 to 4 blues per chain block). Per tier: no balance anyone can see is wrong (0.0003 percent of a share on the ramp), but the bridge identity the base-unit gate asserts is false by that slope on the devnet today and on the testnet from its first block, and a strict reconciler reports it. -Fix (switched, since it changes the EVM state transition): `Params::subsidy_per_block_activation_daa`, a new object field in the subsidy family, never on every network as compiled, in the digest once set; from that chain-block DAA the service fills `SegmentBlock::subsidy` with the block's own `block_subsidy(daa)` and the executor splits it. Known failed first in the executor's test: two blocks a second apart on the ramp and two straddling the first halving boundary, the chain block's subsidy without the rule and their own with it. The harness reports the exact per-row identity beside the N7 bonus ratio and fails on it under `--subsidy-per-block`. Fixed in d840537b on ca3-v4-0318 (09:21 UK; igneum-exec 26, consensus-core 113, consensus 109 plus the two moved targets, kaspad check clean on igneum-build-1). the project lead's ruling (09:5x UK): the testnet active from genesis (the field at 0 in the re-cut object; the digest and the genesis hash move with it), the devnet at an upgrade height carried by 0.3.19 under the fleet's one-box-at-a-time rollout, the height named at that cut. The testnet lane's re-cut gains the one field. +Fix (switched, since it changes the EVM state transition): `Params::subsidy_per_block_activation_daa`, a new object field in the subsidy family, never on every network as compiled, in the digest once set; from that chain-block DAA the service fills `SegmentBlock::subsidy` with the block's own `block_subsidy(daa)` and the executor splits it. Known failed first in the executor's test: two blocks a second apart on the ramp and two straddling the first halving boundary, the chain block's subsidy without the rule and their own with it. The harness checks the exact per-row identity on the selected chain in both rule states (a parent's UTXO payment against the parent's own EVM record); the N8 case itself needs wide mergesets (the 10-bps profile) and is owed there. Fixed in d840537b on ca3-v4-0318 (09:21 UK; igneum-exec 26, consensus-core 113, consensus 109 plus the two moved targets, kaspad check clean on igneum-build-1). the project lead's ruling (09:5x UK): the testnet active from genesis (the field at 0 in the re-cut object; the digest and the genesis hash move with it), the devnet at an upgrade height carried by 0.3.19 under the fleet's one-box-at-a-time rollout, the height named at that cut. The testnet lane's re-cut gains the one field. ### N9. The proof oracle is installed whatever the verification switch, so a fresh 0.3.18 node demands the proof bytes of every record-carrying block of the live chain and no peer can serve them (the 0.3.18 canary on c18-1, 7 October 2026, 08:00Z) diff --git a/docs/plans/counter-asic-3-node.md b/docs/plans/counter-asic-3-node.md index c913d2631..3d114a2c7 100644 --- a/docs/plans/counter-asic-3-node.md +++ b/docs/plans/counter-asic-3-node.md @@ -272,6 +272,7 @@ Harness `infra/fast-time/vote-or-burn.mjs`: node A's miner votes, node B's runs | 09:18 to 09:23 | 27d1b520 | the same, the EVM bonus ratio as the failing check | EVM medians null (the mergeset-position pairing found no rows) | FAIL as it must (`evm_bonus_ratio_matches`) | | 09:31 to 09:37 | e5e6c2bf (d840537b: N7 in, N8's switch at never) | `--rule bonus --expect bonus` | EVM credit medians A 253,736,201 B 228,375,257 sompi, ratio 0.9000 (want 0.9): a silent key's credit is the bonus share on the EVM side too; exact identity 0 of 66 rows (N8's slope, the switch off) | PASS (N7 closed) | | 09:37 to 09:42 | e5e6c2bf | `--subsidy-per-block` (N8's switch at 0) | ratio 0.9000; exact identity 0 of 59, the entry compared was the chain block's own (the pairing took the last entry for the address; the segment lists the parent first) | FAIL on `bridge_identity_exact`, the harness's fault; re-run with the pairing corrected recorded below | +| 09:46 to 09:52 | e5e6c2bf | the same, the smaller of the two entries | still 880 sompi apart: the live read of a chain block's record (09:5x UK) shows the segment holds the chain block itself, not its parent; the execution layer credits a chain block in its own record and the UTXO coinbase pays it in the child's, both at its own DAA, so the harness paired a parent's payment with the child's credit. N8 is real for non-chain blues only (wide mergesets, the 10-bps profile, owed); the pairing corrected to the parent's own record and the exact identity a failing check in both rule states, the two runs recorded below | FAIL on `bridge_identity_exact`, the harness's fault | The testnet lane compiles the switches into TESTNET_PARAMS on testnet-genesis-2-node (the testnet refuses an override file): signing bonus 0 and 1,000; finality_leave_activation_daa 0 with finality.leave_delay 3,600; finality_v3_activation_daa 0; finality_daa_rule_activation_daa 0; difficulty_v3_activation_daa 0; latency_ladder_activation_daa 0 with latency_ladder_window_daa 86,400 and the six rungs (27, 35, 53 admissible; 88, 173 and 267 not); proving_consensus_verify_daa 0 with the manifest's program ids. Rung 3 re-measured on the project lead's word (08:46 UK, igneum-build-1 under the measure hold, both build slots held, load 6.1, core 40 at 3.66 GHz, the ladder worktree's igneum-pow 59ae70cf): reps 88 cold alone 9.04 ms, cold with the SMT sibling loaded 10.85 ms (averages of 50: 5.95 and 10.11), over the 10 ms gate by 0.85, so it stays inadmissible; the control rung 2 (reps 53) read 9.25 cold loaded, admissible as before. Raw lines in `counter-asic-3-gate/ladder-bench/20261007T074547Z`. ### 7.7 The miner's stall guard and the node's idle-peer drop (ledger N4)