Merge pool-int-rows 4f5c76ca into master (gate: green on 02d96fce, recorded by tools/ci/pre-push.sh; landed on the box mirror)

This commit is contained in:
igneum-labs 2026-10-08 23:47:51 +00:00
commit dd52dccb3e
4 changed files with 210 additions and 113 deletions

View file

@ -266,6 +266,9 @@ Rule: a case maps to a cell only where the cell's tests visibly answer it; cover
- Cases:
- UX-05 Keep voting keys with the miner through pooling: partial: the vote-key commitment on the wire (verify::tests::a_share_under_another_key_is_refused_before_the_hash: known-pass the member's key, known-fail another key on the share and a job naming another key, refused with code vote_key before the hash), the open pool's sidechain::check_key (the claimed key, the header's key and the reveal are one key), the same-nonce-other-template wrong_hash test, the TLS binding test; the malicious-pool run and the leave-and-retain run on the devnet-4 pair are the UX-05 batch's other evidence; review B INT-15 (8 October 2026): server::authorise_tests::a_replayed_proof_of_possession_is_not_an_authorisation (a public PoP replayed into another session, payout, pool or chain, or under another key, refused; only the challenge-bound binding v2 admits on a public network) and the_binding_policy_follows_the_network
- UX-04 Pay small operators without hidden custody: partial: PPLNS distribution tests (fee first, never overpays, late joiner), the payout key file round trip, the signed transfer decode; the live payout path on the devnet-4 pair is the UX-04 batch's evidence; review B F12 and INT-03/INT-04 (8 October 2026): payout::intent_tests (a restart from the pre-broadcast snapshot, a lost send response, a crash on either side of the broadcast, a stuck transaction replaced under the same intent, a reorged receipt and a finality pause, a failed transaction, a ledger that cannot be written: never a duplicate or a lost obligation, finalised only under the chain's final lock) and state::ledger_tests (an unreadable ledger is refused or restored, never emptied); F13/INT-16: frame, admission and pool::share_tests (the frame bound while reading, the bounded outgoing queue, one membership per session, the nonce and in-flight bounds, the share and connection budgets); the devnet-4 pair's class (8 October 2026 21:24 UK): state_provider::tests::an_unsynced_node_hands_the_pool_no_state_and_no_job (no job on a node whose igneum_getExecStatus reads synced false, blocked or re-executing; known-failed first against the 8ff7a0f4 provider; pool-synced-guard-202 f3e99e9c on release-2.0.2, 986252e7 on pool-2.0, 52 of 52 on build-6)
- INT-03 Durable payout outbox survives every crash/RPC boundary without duplicate or lost liabilities.: partial: the pool suite's durable payment intent tests (payout::intent_tests: a restart from the pre-broadcast snapshot, a lost send response, a crash on either side of the broadcast, a stuck transaction replaced under the same intent, a reorged receipt and a finality pause, a failed transaction, a ledger that cannot be written: never a duplicate or a lost liability) on every 2.0.2 node sha named 8 to 9 October 2026 (7cfa422a 53, f775c347 53, a284380b 54, d657e490 54, 94e4c6ba 54, 490ebcfe 54, cf32be79 54, all rc 0 at gate priority on build-6); the live-network half (a real payout across a crash on the roll) is the roll's
- INT-04 Corrupt existing pool state, disk-full and reorg cause safe recovery, not silent empty balances.: partial: the pool suite's ledger tests (state::ledger_tests: a corrupt, truncated or digest-failing state.json restores the previous snapshot or refuses to start, never an empty ledger; the migration of pre-intent payments) and the disk-full test (payout::intent_tests::a_ledger_that_cannot_be_written_broadcasts_nothing) on the same seven shas; the live-network half (corruption and a reorg on the roll) is the roll's
- INT-15 Public PoP replay is not session authorization; payout/server/network binding enforced.: partial: the pool suite's binding v2 and session tests (server::authorise_tests: a public PoP replayed into another session, payout, pool or chain, or under another key, refused; the policy follows the network; protocol::tests::the_session_binding_digest_is_the_nodes against consensus-core's session_binding_v2 since node ab489403) on the same seven shas; the live-network half (a 2.0.2 miner's authorize against the rolled pool) is the roll's
### harness:economics-model
@ -391,6 +394,7 @@ Rule: a case maps to a cell only where the cell's tests visibly answer it; cover
- Cases:
- R2-F03-R02 Same job context produces identical accepted work in node, CPU reference, CUDA, Metal, OpenCL and pool.: partial until every reader has run: bit-for-bit agreement per nonce across node, CPU reference, CUDA, OpenCL, Metal and pool on one job context
- R2-F03-R03 Cross every scheduled transition with old/new client behavior documented and identical rule identities.: partial: the day-boundary transition in phase 2 (the one transition every live network crosses hourly at 60x); a class rotation is the same test on a research object until a v6 floor is set
- INT-16 Pool parsing/queues/connection and crypto budgets remain bounded under controlled adversarial traffic.: partial: the member-side re-check over the job context (igneum-pool recheck, the pool's own share verifier per nonce against the CPU reference): the d1-pairing row PASS x3 on the class v6 object (context 02, 3,145,728 of 3,145,728, 256 of 256 shares accepted, the boundary switched), the kit row PASS x3 on the class v5 chain-seed object (context 03, the kit as pinned, the same counts), the kit row on 02 BLOCKED by the kit's V5 pins (the reason in each file); the bounded-input half (slow readers, oversized frames, floods under controlled traffic) is the pool suite's frame, admission and share tests, not a network run
### canary:fresh-install
@ -517,8 +521,6 @@ Rule: a case maps to a cell only where the cell's tests visibly answer it; cover
- REV-F14-3 : F14 (P1, the external review): the regression's harness is the owner lane's (app lane, relay lane); not yet named in the map
- INT-01 Real proof H cannot authenticate a different statement under a warm cache.: INT-01 (R1 integration gate): the gate's harness is the owner lane's (proving lane (a6e8f84588b809d62)); not yet named in the map
- INT-02 Warm/cold/relay/restart/concurrent cache order does not change block or payout decisions; negative cache isolated.: INT-02 (R1 integration gate): the gate's harness is the owner lane's (proving lane (a6e8f84588b809d62)); not yet named in the map
- INT-03 Durable payout outbox survives every crash/RPC boundary without duplicate or lost liabilities.: INT-03 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map
- INT-04 Corrupt existing pool state, disk-full and reorg cause safe recovery, not silent empty balances.: INT-04 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map
- INT-05 The supplied finality implementation matches the approved anchor rule after >window healing.: INT-05 (R1 integration gate): the gate's harness is the owner lane's (node lane (a283f5f0d364ceef0)); not yet named in the map
- INT-06 Recovery tests state and preserve their weaker fault bound; interfaces never label it as a stronger guarantee.: INT-06 (R1 integration gate): the gate's harness is the owner lane's (node lane (a283f5f0d364ceef0)); not yet named in the map
- INT-08 Census, production acceptance, schedule counters and live-dataset tests use the identical frozen contract.: INT-08 (R1 integration gate): the gate's harness is the owner lane's (CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)); not yet named in the map
@ -528,8 +530,6 @@ Rule: a case maps to a cell only where the cell's tests visibly answer it; cover
- INT-12 Transient shard errors can retry safely; expiration, loss and paid work remain distinct durable outcomes.: INT-12 (R1 integration gate): the gate's harness is the owner lane's (proving lane (a6e8f84588b809d62) and fleet lane (ac055d60427caab99)); not yet named in the map
- INT-13 Ember cannot retain a rate-ineligible prior; material workload changes invalidate incompatible profiles.: INT-13 (R1 integration gate): the gate's harness is the owner lane's (Ember lane (a04fe3451877e2ff0) with the app lane); not yet named in the map
- INT-14 Protected helper and per-device leases restore owned settings on normal/abnormal exit; real ACL/security tests.: INT-14 (R1 integration gate): the gate's harness is the owner lane's (Ember lane (a04fe3451877e2ff0) with the app lane); not yet named in the map
- INT-15 Public PoP replay is not session authorization; payout/server/network binding enforced.: INT-15 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map
- INT-16 Pool parsing/queues/connection and crypto budgets remain bounded under controlled adversarial traffic.: INT-16 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map
- INT-17 Missing oracle/keys/mandatory real-proof fixture blocks the applicable production acceptance gate.: INT-17 (R1 integration gate): the gate's harness is the owner lane's (proving lane (a6e8f84588b809d62)); not yet named in the map
- INT-18 Whole-system economics pass the strongest feasible adversary, including sunk development and multi-epoch survival.: INT-18 (R1 integration gate): the gate's harness is the owner lane's (research lane (ad6a2bd47d4a46105)); not yet named in the map
- R2-F01-R01 Valid proof A, warm cache, carried statement B: refuse exactly as a cold node does.: R2-F01 (P0, the external review): the regression's harness is the owner lane's (proving lane, node lane); not yet named in the map
@ -576,4 +576,4 @@ Rule: a case maps to a cell only where the cell's tests visibly answer it; cover
## Count
171 automated cases: 84 mapped to a cell, 145 NOT RUN with a reason.
171 automated cases: 88 mapped to a cell, 141 NOT RUN with a reason.

View file

@ -15078,42 +15078,51 @@
"owner_lane": "pool lane (a1c484c48a62948c2)",
"run_status": "NOT RUN",
"master_status": "PROPOSED / NOT RUN",
"updated": "2026-10-08T20:10:24.556Z",
"updated": "2026-10-08T23:47:51.313Z",
"evidence_record": {
"reason": "INT-03 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map",
"at": "2026-10-08T20:10:24.556Z",
"method": "static",
"requirement_id": "INT-03",
"decision": "NOT RUN",
"reviewer": "",
"claim_impact": "",
"method": "native",
"cell": "suite:pool",
"manifest_sha": "490ebcfe",
"run_id": "pool-int-20261009-01",
"evidence": "build-1:/srv/artefacts/tas/pool-review-b-20261008-01/pool-suite-build-6.log; build-6:/srv/builds/_log/builds.jsonl",
"in_progress": false,
"coverage": "partial: the pool suite's durable payment intent tests (payout::intent_tests: a restart from the pre-broadcast snapshot, a lost send response, a crash on either side of the broadcast, a stuck transaction replaced under the same intent, a reorged receipt and a finality pause, a failed transaction, a ledger that cannot be written: never a duplicate or a lost liability) on every 2.0.2 node sha named 8 to 9 October 2026 (7cfa422a 53, f775c347 53, a284380b 54, d657e490 54, 94e4c6ba 54, 490ebcfe 54, cf32be79 54, all rc 0 at gate priority on build-6); the live-network half (a real payout across a crash on the roll) is the roll's",
"release_identity": {
"commit": "",
"lockfile": "",
"binary": "",
"network_object": "",
"activation": "",
"commit": "release-2.0.2 5db25637 (pool tree = pool-recheck-202 909ae65b + the INT-15 switch ef98ba93); pool-2.0 587cb565 the same tree",
"lockfile": "pool/Cargo.lock at 5db25637",
"binary": "igneum-pool on build-6: 2f6378e4e0023ba0 (the kit row on 02, 00c7e1db's tree), 46e4c44080d87db3 (the kit row on 03, 909ae65b's tree); on build-4 10425cc9e216a66f (the d1-pairing row: igneum-pow 1a938abe + vendored class-v6-node-review e8773ff5)",
"network_object": "the suites: none (a crate suite); the same-work rows: context 02 the chain-seed class v6 object 0x2a1d6caab4c24564 over node1-state.igsd1 (abb58003), context 03 devnet-4's class v5 object at epoch 2, 0x81fbfa3aa413173f, over state-epoch2.igsd1 (f36e6bba)",
"activation": "none",
"profile_hashes": ""
}
},
"claim_impact": "INT-03/04/15: the pool's payment integrity, ledger recovery and session authorisation hold by construction in the crate on every 2.0.2 node sha named tonight; the live-network halves ride the roll. INT-16: the pool's share verdict equals the CPU reference per nonce on two live objects across a day rotation; the bounded-input half is the suite's, not a network run",
"reviewer": "",
"at": "2026-10-08T23:47:51.313Z"
},
"evidence_records": {
"record": {
"reason": "INT-03 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map",
"at": "2026-10-08T20:10:24.556Z",
"method": "static",
"suite:pool": {
"requirement_id": "INT-03",
"decision": "NOT RUN",
"reviewer": "",
"claim_impact": "",
"method": "native",
"cell": "suite:pool",
"manifest_sha": "490ebcfe",
"run_id": "pool-int-20261009-01",
"evidence": "build-1:/srv/artefacts/tas/pool-review-b-20261008-01/pool-suite-build-6.log; build-6:/srv/builds/_log/builds.jsonl",
"in_progress": false,
"coverage": "partial: the pool suite's durable payment intent tests (payout::intent_tests: a restart from the pre-broadcast snapshot, a lost send response, a crash on either side of the broadcast, a stuck transaction replaced under the same intent, a reorged receipt and a finality pause, a failed transaction, a ledger that cannot be written: never a duplicate or a lost liability) on every 2.0.2 node sha named 8 to 9 October 2026 (7cfa422a 53, f775c347 53, a284380b 54, d657e490 54, 94e4c6ba 54, 490ebcfe 54, cf32be79 54, all rc 0 at gate priority on build-6); the live-network half (a real payout across a crash on the roll) is the roll's",
"release_identity": {
"commit": "",
"lockfile": "",
"binary": "",
"network_object": "",
"activation": "",
"commit": "release-2.0.2 5db25637 (pool tree = pool-recheck-202 909ae65b + the INT-15 switch ef98ba93); pool-2.0 587cb565 the same tree",
"lockfile": "pool/Cargo.lock at 5db25637",
"binary": "igneum-pool on build-6: 2f6378e4e0023ba0 (the kit row on 02, 00c7e1db's tree), 46e4c44080d87db3 (the kit row on 03, 909ae65b's tree); on build-4 10425cc9e216a66f (the d1-pairing row: igneum-pow 1a938abe + vendored class-v6-node-review e8773ff5)",
"network_object": "the suites: none (a crate suite); the same-work rows: context 02 the chain-seed class v6 object 0x2a1d6caab4c24564 over node1-state.igsd1 (abb58003), context 03 devnet-4's class v5 object at epoch 2, 0x81fbfa3aa413173f, over state-epoch2.igsd1 (f36e6bba)",
"activation": "none",
"profile_hashes": ""
},
"in_progress": false
"claim_impact": "INT-03/04/15: the pool's payment integrity, ledger recovery and session authorisation hold by construction in the crate on every 2.0.2 node sha named tonight; the live-network halves ride the roll. INT-16: the pool's share verdict equals the CPU reference per nonce on two live objects across a day rotation; the bounded-input half is the suite's, not a network run",
"reviewer": "",
"at": "2026-10-08T23:47:51.313Z"
}
},
"approvals": {
@ -15121,7 +15130,9 @@
"implementation_complete": null,
"evidence_reproduced": null,
"claim_authorised": null
}
},
"run_id": "pool-int-20261009-01",
"evidence_path": "build-1:/srv/artefacts/tas/pool-review-b-20261008-01/pool-suite-build-6.log; build-6:/srv/builds/_log/builds.jsonl"
},
{
"id": "INT-04",
@ -15146,42 +15157,51 @@
"owner_lane": "pool lane (a1c484c48a62948c2)",
"run_status": "NOT RUN",
"master_status": "PROPOSED / NOT RUN",
"updated": "2026-10-08T20:10:24.556Z",
"updated": "2026-10-08T23:47:51.313Z",
"evidence_record": {
"reason": "INT-04 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map",
"at": "2026-10-08T20:10:24.556Z",
"method": "static",
"requirement_id": "INT-04",
"decision": "NOT RUN",
"reviewer": "",
"claim_impact": "",
"method": "native",
"cell": "suite:pool",
"manifest_sha": "490ebcfe",
"run_id": "pool-int-20261009-01",
"evidence": "build-1:/srv/artefacts/tas/pool-review-b-20261008-01/pool-suite-build-6.log; build-6:/srv/builds/_log/builds.jsonl",
"in_progress": false,
"coverage": "partial: the pool suite's ledger tests (state::ledger_tests: a corrupt, truncated or digest-failing state.json restores the previous snapshot or refuses to start, never an empty ledger; the migration of pre-intent payments) and the disk-full test (payout::intent_tests::a_ledger_that_cannot_be_written_broadcasts_nothing) on the same seven shas; the live-network half (corruption and a reorg on the roll) is the roll's",
"release_identity": {
"commit": "",
"lockfile": "",
"binary": "",
"network_object": "",
"activation": "",
"commit": "release-2.0.2 5db25637 (pool tree = pool-recheck-202 909ae65b + the INT-15 switch ef98ba93); pool-2.0 587cb565 the same tree",
"lockfile": "pool/Cargo.lock at 5db25637",
"binary": "igneum-pool on build-6: 2f6378e4e0023ba0 (the kit row on 02, 00c7e1db's tree), 46e4c44080d87db3 (the kit row on 03, 909ae65b's tree); on build-4 10425cc9e216a66f (the d1-pairing row: igneum-pow 1a938abe + vendored class-v6-node-review e8773ff5)",
"network_object": "the suites: none (a crate suite); the same-work rows: context 02 the chain-seed class v6 object 0x2a1d6caab4c24564 over node1-state.igsd1 (abb58003), context 03 devnet-4's class v5 object at epoch 2, 0x81fbfa3aa413173f, over state-epoch2.igsd1 (f36e6bba)",
"activation": "none",
"profile_hashes": ""
}
},
"claim_impact": "INT-03/04/15: the pool's payment integrity, ledger recovery and session authorisation hold by construction in the crate on every 2.0.2 node sha named tonight; the live-network halves ride the roll. INT-16: the pool's share verdict equals the CPU reference per nonce on two live objects across a day rotation; the bounded-input half is the suite's, not a network run",
"reviewer": "",
"at": "2026-10-08T23:47:51.313Z"
},
"evidence_records": {
"record": {
"reason": "INT-04 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map",
"at": "2026-10-08T20:10:24.556Z",
"method": "static",
"suite:pool": {
"requirement_id": "INT-04",
"decision": "NOT RUN",
"reviewer": "",
"claim_impact": "",
"method": "native",
"cell": "suite:pool",
"manifest_sha": "490ebcfe",
"run_id": "pool-int-20261009-01",
"evidence": "build-1:/srv/artefacts/tas/pool-review-b-20261008-01/pool-suite-build-6.log; build-6:/srv/builds/_log/builds.jsonl",
"in_progress": false,
"coverage": "partial: the pool suite's ledger tests (state::ledger_tests: a corrupt, truncated or digest-failing state.json restores the previous snapshot or refuses to start, never an empty ledger; the migration of pre-intent payments) and the disk-full test (payout::intent_tests::a_ledger_that_cannot_be_written_broadcasts_nothing) on the same seven shas; the live-network half (corruption and a reorg on the roll) is the roll's",
"release_identity": {
"commit": "",
"lockfile": "",
"binary": "",
"network_object": "",
"activation": "",
"commit": "release-2.0.2 5db25637 (pool tree = pool-recheck-202 909ae65b + the INT-15 switch ef98ba93); pool-2.0 587cb565 the same tree",
"lockfile": "pool/Cargo.lock at 5db25637",
"binary": "igneum-pool on build-6: 2f6378e4e0023ba0 (the kit row on 02, 00c7e1db's tree), 46e4c44080d87db3 (the kit row on 03, 909ae65b's tree); on build-4 10425cc9e216a66f (the d1-pairing row: igneum-pow 1a938abe + vendored class-v6-node-review e8773ff5)",
"network_object": "the suites: none (a crate suite); the same-work rows: context 02 the chain-seed class v6 object 0x2a1d6caab4c24564 over node1-state.igsd1 (abb58003), context 03 devnet-4's class v5 object at epoch 2, 0x81fbfa3aa413173f, over state-epoch2.igsd1 (f36e6bba)",
"activation": "none",
"profile_hashes": ""
},
"in_progress": false
"claim_impact": "INT-03/04/15: the pool's payment integrity, ledger recovery and session authorisation hold by construction in the crate on every 2.0.2 node sha named tonight; the live-network halves ride the roll. INT-16: the pool's share verdict equals the CPU reference per nonce on two live objects across a day rotation; the bounded-input half is the suite's, not a network run",
"reviewer": "",
"at": "2026-10-08T23:47:51.313Z"
}
},
"approvals": {
@ -15189,7 +15209,9 @@
"implementation_complete": null,
"evidence_reproduced": null,
"claim_authorised": null
}
},
"run_id": "pool-int-20261009-01",
"evidence_path": "build-1:/srv/artefacts/tas/pool-review-b-20261008-01/pool-suite-build-6.log; build-6:/srv/builds/_log/builds.jsonl"
},
{
"id": "INT-05",
@ -15908,42 +15930,51 @@
"owner_lane": "pool lane (a1c484c48a62948c2)",
"run_status": "NOT RUN",
"master_status": "PROPOSED / NOT RUN",
"updated": "2026-10-08T20:10:24.556Z",
"updated": "2026-10-08T23:47:51.313Z",
"evidence_record": {
"reason": "INT-15 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map",
"at": "2026-10-08T20:10:24.556Z",
"method": "static",
"requirement_id": "INT-15",
"decision": "NOT RUN",
"reviewer": "",
"claim_impact": "",
"method": "native",
"cell": "suite:pool",
"manifest_sha": "490ebcfe",
"run_id": "pool-int-20261009-01",
"evidence": "build-1:/srv/artefacts/tas/pool-review-b-20261008-01/pool-suite-build-6.log; build-6:/srv/builds/_log/builds.jsonl",
"in_progress": false,
"coverage": "partial: the pool suite's binding v2 and session tests (server::authorise_tests: a public PoP replayed into another session, payout, pool or chain, or under another key, refused; the policy follows the network; protocol::tests::the_session_binding_digest_is_the_nodes against consensus-core's session_binding_v2 since node ab489403) on the same seven shas; the live-network half (a 2.0.2 miner's authorize against the rolled pool) is the roll's",
"release_identity": {
"commit": "",
"lockfile": "",
"binary": "",
"network_object": "",
"activation": "",
"commit": "release-2.0.2 5db25637 (pool tree = pool-recheck-202 909ae65b + the INT-15 switch ef98ba93); pool-2.0 587cb565 the same tree",
"lockfile": "pool/Cargo.lock at 5db25637",
"binary": "igneum-pool on build-6: 2f6378e4e0023ba0 (the kit row on 02, 00c7e1db's tree), 46e4c44080d87db3 (the kit row on 03, 909ae65b's tree); on build-4 10425cc9e216a66f (the d1-pairing row: igneum-pow 1a938abe + vendored class-v6-node-review e8773ff5)",
"network_object": "the suites: none (a crate suite); the same-work rows: context 02 the chain-seed class v6 object 0x2a1d6caab4c24564 over node1-state.igsd1 (abb58003), context 03 devnet-4's class v5 object at epoch 2, 0x81fbfa3aa413173f, over state-epoch2.igsd1 (f36e6bba)",
"activation": "none",
"profile_hashes": ""
}
},
"claim_impact": "INT-03/04/15: the pool's payment integrity, ledger recovery and session authorisation hold by construction in the crate on every 2.0.2 node sha named tonight; the live-network halves ride the roll. INT-16: the pool's share verdict equals the CPU reference per nonce on two live objects across a day rotation; the bounded-input half is the suite's, not a network run",
"reviewer": "",
"at": "2026-10-08T23:47:51.313Z"
},
"evidence_records": {
"record": {
"reason": "INT-15 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map",
"at": "2026-10-08T20:10:24.556Z",
"method": "static",
"suite:pool": {
"requirement_id": "INT-15",
"decision": "NOT RUN",
"reviewer": "",
"claim_impact": "",
"method": "native",
"cell": "suite:pool",
"manifest_sha": "490ebcfe",
"run_id": "pool-int-20261009-01",
"evidence": "build-1:/srv/artefacts/tas/pool-review-b-20261008-01/pool-suite-build-6.log; build-6:/srv/builds/_log/builds.jsonl",
"in_progress": false,
"coverage": "partial: the pool suite's binding v2 and session tests (server::authorise_tests: a public PoP replayed into another session, payout, pool or chain, or under another key, refused; the policy follows the network; protocol::tests::the_session_binding_digest_is_the_nodes against consensus-core's session_binding_v2 since node ab489403) on the same seven shas; the live-network half (a 2.0.2 miner's authorize against the rolled pool) is the roll's",
"release_identity": {
"commit": "",
"lockfile": "",
"binary": "",
"network_object": "",
"activation": "",
"commit": "release-2.0.2 5db25637 (pool tree = pool-recheck-202 909ae65b + the INT-15 switch ef98ba93); pool-2.0 587cb565 the same tree",
"lockfile": "pool/Cargo.lock at 5db25637",
"binary": "igneum-pool on build-6: 2f6378e4e0023ba0 (the kit row on 02, 00c7e1db's tree), 46e4c44080d87db3 (the kit row on 03, 909ae65b's tree); on build-4 10425cc9e216a66f (the d1-pairing row: igneum-pow 1a938abe + vendored class-v6-node-review e8773ff5)",
"network_object": "the suites: none (a crate suite); the same-work rows: context 02 the chain-seed class v6 object 0x2a1d6caab4c24564 over node1-state.igsd1 (abb58003), context 03 devnet-4's class v5 object at epoch 2, 0x81fbfa3aa413173f, over state-epoch2.igsd1 (f36e6bba)",
"activation": "none",
"profile_hashes": ""
},
"in_progress": false
"claim_impact": "INT-03/04/15: the pool's payment integrity, ledger recovery and session authorisation hold by construction in the crate on every 2.0.2 node sha named tonight; the live-network halves ride the roll. INT-16: the pool's share verdict equals the CPU reference per nonce on two live objects across a day rotation; the bounded-input half is the suite's, not a network run",
"reviewer": "",
"at": "2026-10-08T23:47:51.313Z"
}
},
"approvals": {
@ -15951,7 +15982,9 @@
"implementation_complete": null,
"evidence_reproduced": null,
"claim_authorised": null
}
},
"run_id": "pool-int-20261009-01",
"evidence_path": "build-1:/srv/artefacts/tas/pool-review-b-20261008-01/pool-suite-build-6.log; build-6:/srv/builds/_log/builds.jsonl"
},
{
"id": "INT-16",
@ -15976,42 +16009,53 @@
"owner_lane": "pool lane (a1c484c48a62948c2)",
"run_status": "NOT RUN",
"master_status": "PROPOSED / NOT RUN",
"updated": "2026-10-08T20:10:24.556Z",
"updated": "2026-10-08T23:47:51.313Z",
"evidence_record": {
"reason": "INT-16 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map",
"at": "2026-10-08T20:10:24.556Z",
"method": "static",
"requirement_id": "INT-16",
"decision": "NOT RUN",
"reviewer": "",
"claim_impact": "",
"method": "native",
"cell": "harness:same-work",
"manifest_sha": "490ebcfe",
"run_id": "pool-int-20261009-01",
"evidence": "build-1:/srv/artefacts/tas/same-work-20261008-02/pool/kit-row/README.json; build-1:/srv/artefacts/tas/same-work-20261008-02/pool/d1-pairing/README.json; build-1:/srv/artefacts/tas/same-work-20261008-03/pool/kit-row/README.json",
"in_progress": false,
"coverage": "partial: the member-side re-check over the job context (igneum-pool recheck, the pool's own share verifier per nonce against the CPU reference): the d1-pairing row PASS x3 on the class v6 object (context 02, 3,145,728 of 3,145,728, 256 of 256 shares accepted, the boundary switched), the kit row PASS x3 on the class v5 chain-seed object (context 03, the kit as pinned, the same counts), the kit row on 02 BLOCKED by the kit's V5 pins (the reason in each file); the bounded-input half (slow readers, oversized frames, floods under controlled traffic) is the pool suite's frame, admission and share tests, not a network run",
"release_identity": {
"commit": "",
"lockfile": "",
"binary": "",
"network_object": "",
"activation": "",
"commit": "release-2.0.2 5db25637 (pool tree = pool-recheck-202 909ae65b + the INT-15 switch ef98ba93); pool-2.0 587cb565 the same tree",
"lockfile": "pool/Cargo.lock at 5db25637",
"binary": "igneum-pool on build-6: 2f6378e4e0023ba0 (the kit row on 02, 00c7e1db's tree), 46e4c44080d87db3 (the kit row on 03, 909ae65b's tree); on build-4 10425cc9e216a66f (the d1-pairing row: igneum-pow 1a938abe + vendored class-v6-node-review e8773ff5)",
"network_object": "the suites: none (a crate suite); the same-work rows: context 02 the chain-seed class v6 object 0x2a1d6caab4c24564 over node1-state.igsd1 (abb58003), context 03 devnet-4's class v5 object at epoch 2, 0x81fbfa3aa413173f, over state-epoch2.igsd1 (f36e6bba)",
"activation": "none",
"profile_hashes": ""
}
},
"claim_impact": "INT-03/04/15: the pool's payment integrity, ledger recovery and session authorisation hold by construction in the crate on every 2.0.2 node sha named tonight; the live-network halves ride the roll. INT-16: the pool's share verdict equals the CPU reference per nonce on two live objects across a day rotation; the bounded-input half is the suite's, not a network run",
"reviewer": "",
"at": "2026-10-08T23:47:51.313Z",
"network_label": "on an island, not a network"
},
"evidence_records": {
"record": {
"reason": "INT-16 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map",
"at": "2026-10-08T20:10:24.556Z",
"method": "static",
"harness:same-work": {
"requirement_id": "INT-16",
"decision": "NOT RUN",
"reviewer": "",
"claim_impact": "",
"method": "native",
"cell": "harness:same-work",
"manifest_sha": "490ebcfe",
"run_id": "pool-int-20261009-01",
"evidence": "build-1:/srv/artefacts/tas/same-work-20261008-02/pool/kit-row/README.json; build-1:/srv/artefacts/tas/same-work-20261008-02/pool/d1-pairing/README.json; build-1:/srv/artefacts/tas/same-work-20261008-03/pool/kit-row/README.json",
"in_progress": false,
"coverage": "partial: the member-side re-check over the job context (igneum-pool recheck, the pool's own share verifier per nonce against the CPU reference): the d1-pairing row PASS x3 on the class v6 object (context 02, 3,145,728 of 3,145,728, 256 of 256 shares accepted, the boundary switched), the kit row PASS x3 on the class v5 chain-seed object (context 03, the kit as pinned, the same counts), the kit row on 02 BLOCKED by the kit's V5 pins (the reason in each file); the bounded-input half (slow readers, oversized frames, floods under controlled traffic) is the pool suite's frame, admission and share tests, not a network run",
"release_identity": {
"commit": "",
"lockfile": "",
"binary": "",
"network_object": "",
"activation": "",
"commit": "release-2.0.2 5db25637 (pool tree = pool-recheck-202 909ae65b + the INT-15 switch ef98ba93); pool-2.0 587cb565 the same tree",
"lockfile": "pool/Cargo.lock at 5db25637",
"binary": "igneum-pool on build-6: 2f6378e4e0023ba0 (the kit row on 02, 00c7e1db's tree), 46e4c44080d87db3 (the kit row on 03, 909ae65b's tree); on build-4 10425cc9e216a66f (the d1-pairing row: igneum-pow 1a938abe + vendored class-v6-node-review e8773ff5)",
"network_object": "the suites: none (a crate suite); the same-work rows: context 02 the chain-seed class v6 object 0x2a1d6caab4c24564 over node1-state.igsd1 (abb58003), context 03 devnet-4's class v5 object at epoch 2, 0x81fbfa3aa413173f, over state-epoch2.igsd1 (f36e6bba)",
"activation": "none",
"profile_hashes": ""
},
"in_progress": false
"claim_impact": "INT-03/04/15: the pool's payment integrity, ledger recovery and session authorisation hold by construction in the crate on every 2.0.2 node sha named tonight; the live-network halves ride the roll. INT-16: the pool's share verdict equals the CPU reference per nonce on two live objects across a day rotation; the bounded-input half is the suite's, not a network run",
"reviewer": "",
"at": "2026-10-08T23:47:51.313Z",
"network_label": "on an island, not a network"
}
},
"approvals": {
@ -16019,7 +16063,9 @@
"implementation_complete": null,
"evidence_reproduced": null,
"claim_authorised": null
}
},
"run_id": "pool-int-20261009-01",
"evidence_path": "build-1:/srv/artefacts/tas/same-work-20261008-02/pool/kit-row/README.json; build-1:/srv/artefacts/tas/same-work-20261008-02/pool/d1-pairing/README.json; build-1:/srv/artefacts/tas/same-work-20261008-03/pool/kit-row/README.json"
},
{
"id": "INT-17",

View file

@ -0,0 +1,47 @@
{
"run_id": "pool-int-20261009-01",
"manifest_sha": "490ebcfe",
"method": "native",
"evidence_dir": "build-1:/srv/artefacts/tas/pool-review-b-20261008-01; build-1:/srv/artefacts/tas/same-work-20261008-02/pool; build-1:/srv/artefacts/tas/same-work-20261008-03/pool",
"boxes": [
"build-6",
"build-4",
"build-1"
],
"release_identity": {
"commit": "release-2.0.2 5db25637 (pool tree = pool-recheck-202 909ae65b + the INT-15 switch ef98ba93); pool-2.0 587cb565 the same tree",
"lockfile": "pool/Cargo.lock at 5db25637",
"binary": "igneum-pool on build-6: 2f6378e4e0023ba0 (the kit row on 02, 00c7e1db's tree), 46e4c44080d87db3 (the kit row on 03, 909ae65b's tree); on build-4 10425cc9e216a66f (the d1-pairing row: igneum-pow 1a938abe + vendored class-v6-node-review e8773ff5)",
"network_object": "the suites: none (a crate suite); the same-work rows: context 02 the chain-seed class v6 object 0x2a1d6caab4c24564 over node1-state.igsd1 (abb58003), context 03 devnet-4's class v5 object at epoch 2, 0x81fbfa3aa413173f, over state-epoch2.igsd1 (f36e6bba)",
"activation": "none",
"profile_hashes": ""
},
"claim_impact": "INT-03/04/15: the pool's payment integrity, ledger recovery and session authorisation hold by construction in the crate on every 2.0.2 node sha named tonight; the live-network halves ride the roll. INT-16: the pool's share verdict equals the CPU reference per nonce on two live objects across a day rotation; the bounded-input half is the suite's, not a network run",
"network_label": "on an island, not a network",
"note": "NOT RUN in progress with the evidence, never PASS by inference: a suite's green is partial coverage (the live-network halves are the roll's). The pool suite on build-6 at gate priority against every 2.0.2 node sha named 8 to 9 October 2026: 7cfa422a 53 of 53, f775c347 53, a284380b 54, d657e490 54, 94e4c6ba 54, 490ebcfe 54 (kit 1, pinned on 5db25637), cf32be79 54 (kit 2), all rc 0, each run's lines in build-6:/srv/builds/_log/builds.jsonl under IGNEUM_AGENT pool-review-b, pool-recheck, pool-binding, pool-gate-202, pool-gate-kit1, pool-gate-kit2; the 21:41 UK run's full log at build-1:/srv/artefacts/tas/pool-review-b-20261008-01/pool-suite-build-6.log. The same-work rows: 02 kit-row BLOCKED x3 (the 2.0.2 kit's node ends ProgramClass at V5, the reason in each file), 02 d1-pairing PASS x3 (the D1 pairing, not the kit; first run FAIL from the reader's genesis-day geometry, kept in the README), 03 kit-row PASS x3 (the kit as pinned). On an island, not a network: the 03 state stream was pulled at 22:18 UK from build-1's seed, one of devnet-4's islands since the epoch-3 cut; context 02's state stream is the v6 census file, no network",
"cells": [
{
"cell": "suite:pool",
"cases": [
"INT-03",
"INT-04",
"INT-15"
],
"status": "NOT RUN",
"in_progress": true,
"evidence": "build-1:/srv/artefacts/tas/pool-review-b-20261008-01/pool-suite-build-6.log; build-6:/srv/builds/_log/builds.jsonl",
"note": "the seven 2.0.2 node shas and their counts are in the batch note; partial coverage, the live-network half is the roll's"
},
{
"cell": "harness:same-work",
"cases": [
"INT-16"
],
"status": "NOT RUN",
"in_progress": true,
"evidence": "build-1:/srv/artefacts/tas/same-work-20261008-02/pool/kit-row/README.json; build-1:/srv/artefacts/tas/same-work-20261008-02/pool/d1-pairing/README.json; build-1:/srv/artefacts/tas/same-work-20261008-03/pool/kit-row/README.json",
"network_label": "on an island, not a network",
"note": "the member-side re-check: d1-pairing PASS x3 (class v6 object), kit-row 03 PASS x3 (class v5 object, the kit as pinned), kit-row 02 BLOCKED x3 (V5 pins); the bounded-input half is the suite's"
}
]
}

View file

@ -451,11 +451,17 @@
],
"cases": [
"UX-05",
"UX-04"
"UX-04",
"INT-03",
"INT-04",
"INT-15"
],
"coverage": {
"UX-05": "partial: the vote-key commitment on the wire (verify::tests::a_share_under_another_key_is_refused_before_the_hash: known-pass the member's key, known-fail another key on the share and a job naming another key, refused with code vote_key before the hash), the open pool's sidechain::check_key (the claimed key, the header's key and the reveal are one key), the same-nonce-other-template wrong_hash test, the TLS binding test; the malicious-pool run and the leave-and-retain run on the devnet-4 pair are the UX-05 batch's other evidence; review B INT-15 (8 October 2026): server::authorise_tests::a_replayed_proof_of_possession_is_not_an_authorisation (a public PoP replayed into another session, payout, pool or chain, or under another key, refused; only the challenge-bound binding v2 admits on a public network) and the_binding_policy_follows_the_network",
"UX-04": "partial: PPLNS distribution tests (fee first, never overpays, late joiner), the payout key file round trip, the signed transfer decode; the live payout path on the devnet-4 pair is the UX-04 batch's evidence; review B F12 and INT-03/INT-04 (8 October 2026): payout::intent_tests (a restart from the pre-broadcast snapshot, a lost send response, a crash on either side of the broadcast, a stuck transaction replaced under the same intent, a reorged receipt and a finality pause, a failed transaction, a ledger that cannot be written: never a duplicate or a lost obligation, finalised only under the chain's final lock) and state::ledger_tests (an unreadable ledger is refused or restored, never emptied); F13/INT-16: frame, admission and pool::share_tests (the frame bound while reading, the bounded outgoing queue, one membership per session, the nonce and in-flight bounds, the share and connection budgets); the devnet-4 pair's class (8 October 2026 21:24 UK): state_provider::tests::an_unsynced_node_hands_the_pool_no_state_and_no_job (no job on a node whose igneum_getExecStatus reads synced false, blocked or re-executing; known-failed first against the 8ff7a0f4 provider; pool-synced-guard-202 f3e99e9c on release-2.0.2, 986252e7 on pool-2.0, 52 of 52 on build-6)"
"UX-04": "partial: PPLNS distribution tests (fee first, never overpays, late joiner), the payout key file round trip, the signed transfer decode; the live payout path on the devnet-4 pair is the UX-04 batch's evidence; review B F12 and INT-03/INT-04 (8 October 2026): payout::intent_tests (a restart from the pre-broadcast snapshot, a lost send response, a crash on either side of the broadcast, a stuck transaction replaced under the same intent, a reorged receipt and a finality pause, a failed transaction, a ledger that cannot be written: never a duplicate or a lost obligation, finalised only under the chain's final lock) and state::ledger_tests (an unreadable ledger is refused or restored, never emptied); F13/INT-16: frame, admission and pool::share_tests (the frame bound while reading, the bounded outgoing queue, one membership per session, the nonce and in-flight bounds, the share and connection budgets); the devnet-4 pair's class (8 October 2026 21:24 UK): state_provider::tests::an_unsynced_node_hands_the_pool_no_state_and_no_job (no job on a node whose igneum_getExecStatus reads synced false, blocked or re-executing; known-failed first against the 8ff7a0f4 provider; pool-synced-guard-202 f3e99e9c on release-2.0.2, 986252e7 on pool-2.0, 52 of 52 on build-6)",
"INT-03": "partial: the pool suite's durable payment intent tests (payout::intent_tests: a restart from the pre-broadcast snapshot, a lost send response, a crash on either side of the broadcast, a stuck transaction replaced under the same intent, a reorged receipt and a finality pause, a failed transaction, a ledger that cannot be written: never a duplicate or a lost liability) on every 2.0.2 node sha named 8 to 9 October 2026 (7cfa422a 53, f775c347 53, a284380b 54, d657e490 54, 94e4c6ba 54, 490ebcfe 54, cf32be79 54, all rc 0 at gate priority on build-6); the live-network half (a real payout across a crash on the roll) is the roll's",
"INT-04": "partial: the pool suite's ledger tests (state::ledger_tests: a corrupt, truncated or digest-failing state.json restores the previous snapshot or refuses to start, never an empty ledger; the migration of pre-intent payments) and the disk-full test (payout::intent_tests::a_ledger_that_cannot_be_written_broadcasts_nothing) on the same seven shas; the live-network half (corruption and a reorg on the roll) is the roll's",
"INT-15": "partial: the pool suite's binding v2 and session tests (server::authorise_tests: a public PoP replayed into another session, payout, pool or chain, or under another key, refused; the policy follows the network; protocol::tests::the_session_binding_digest_is_the_nodes against consensus-core's session_binding_v2 since node ab489403) on the same seven shas; the live-network half (a 2.0.2 miner's authorize against the rolled pool) is the roll's"
}
},
"harness:economics-model": {
@ -668,11 +674,13 @@
],
"cases": [
"R2-F03-R02",
"R2-F03-R03"
"R2-F03-R03",
"INT-16"
],
"coverage": {
"R2-F03-R02": "partial until every reader has run: bit-for-bit agreement per nonce across node, CPU reference, CUDA, OpenCL, Metal and pool on one job context",
"R2-F03-R03": "partial: the day-boundary transition in phase 2 (the one transition every live network crosses hourly at 60x); a class rotation is the same test on a research object until a v6 floor is set"
"R2-F03-R03": "partial: the day-boundary transition in phase 2 (the one transition every live network crosses hourly at 60x); a class rotation is the same test on a research object until a v6 floor is set",
"INT-16": "partial: the member-side re-check over the job context (igneum-pool recheck, the pool's own share verifier per nonce against the CPU reference): the d1-pairing row PASS x3 on the class v6 object (context 02, 3,145,728 of 3,145,728, 256 of 256 shares accepted, the boundary switched), the kit row PASS x3 on the class v5 chain-seed object (context 03, the kit as pinned, the same counts), the kit row on 02 BLOCKED by the kit's V5 pins (the reason in each file); the bounded-input half (slow readers, oversized frames, floods under controlled traffic) is the pool suite's frame, admission and share tests, not a network run"
}
},
"canary:fresh-install": {
@ -823,8 +831,6 @@
"REV-F14-3": "F14 (P1, the external review): the regression's harness is the owner lane's (app lane, relay lane); not yet named in the map",
"INT-01": "INT-01 (R1 integration gate): the gate's harness is the owner lane's (proving lane (a6e8f84588b809d62)); not yet named in the map",
"INT-02": "INT-02 (R1 integration gate): the gate's harness is the owner lane's (proving lane (a6e8f84588b809d62)); not yet named in the map",
"INT-03": "INT-03 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map",
"INT-04": "INT-04 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map",
"INT-05": "INT-05 (R1 integration gate): the gate's harness is the owner lane's (node lane (a283f5f0d364ceef0)); not yet named in the map",
"INT-06": "INT-06 (R1 integration gate): the gate's harness is the owner lane's (node lane (a283f5f0d364ceef0)); not yet named in the map",
"INT-08": "INT-08 (R1 integration gate): the gate's harness is the owner lane's (CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)); not yet named in the map",
@ -834,8 +840,6 @@
"INT-12": "INT-12 (R1 integration gate): the gate's harness is the owner lane's (proving lane (a6e8f84588b809d62) and fleet lane (ac055d60427caab99)); not yet named in the map",
"INT-13": "INT-13 (R1 integration gate): the gate's harness is the owner lane's (Ember lane (a04fe3451877e2ff0) with the app lane); not yet named in the map",
"INT-14": "INT-14 (R1 integration gate): the gate's harness is the owner lane's (Ember lane (a04fe3451877e2ff0) with the app lane); not yet named in the map",
"INT-15": "INT-15 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map",
"INT-16": "INT-16 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map",
"INT-17": "INT-17 (R1 integration gate): the gate's harness is the owner lane's (proving lane (a6e8f84588b809d62)); not yet named in the map",
"INT-18": "INT-18 (R1 integration gate): the gate's harness is the owner lane's (research lane (ad6a2bd47d4a46105)); not yet named in the map",
"R2-F01-R01": "R2-F01 (P0, the external review): the regression's harness is the owner lane's (proving lane, node lane); not yet named in the map",