Merge enforced-proving 38ba56f5 into master (gate: green on 38ba56f5, recorded by tools/ci/pre-push.sh; landed on the box mirror)

This commit is contained in:
igneum-labs 2026-10-08 17:40:34 +00:00
commit de2228bfe1

View file

@ -115,3 +115,5 @@ Until stage 3 lands, every stage's output is checked natively by every node, and
## 8. The fast-time harness case ## 8. The fast-time harness case
`infra/fast-time/proving-enforcement.mjs` (ran, PASS at 17:22 UK, section 6): three nodes on one fast-time network, two honest under the floor set a few epochs ahead (`proving_consensus_verify_daa` in the override, the boundary), one attacker with the body rule off and the verifier in trust mode. The attacker reads each shard's native statement for its own payout address from its node (`igneum_getShardPlan(block, payout)`), signs it (`igneum-miner sign-record`) and submits it with proof bytes of the seven shapes through `igneum_submitProofRecord`; its templates carry the records. Below the boundary the honest nodes accept the attacker's blocks and the v0 rule pays (the finding, observed); from the boundary every honest node refuses the carrying block (`IgneumInvalidProofRecord` or the 20-s drop) and `igneum_getProofRecords` shows no paid entry for any of the seven. The honest-pays-once case needs a real shard proof of the harness's own chain, which a CPU prover makes in minutes; the unit tests hold it meanwhile and the testnet holds it live. `infra/fast-time/proving-enforcement.mjs` (ran, PASS at 17:22 UK, section 6): three nodes on one fast-time network, two honest under the floor set a few epochs ahead (`proving_consensus_verify_daa` in the override, the boundary), one attacker with the body rule off and the verifier in trust mode. The attacker reads each shard's native statement for its own payout address from its node (`igneum_getShardPlan(block, payout)`), signs it (`igneum-miner sign-record`) and submits it with proof bytes of the seven shapes through `igneum_submitProofRecord`; its templates carry the records. Below the boundary the honest nodes accept the attacker's blocks and the v0 rule pays (the finding, observed); from the boundary every honest node refuses the carrying block (`IgneumInvalidProofRecord` or the 20-s drop) and `igneum_getProofRecords` shows no paid entry for any of the seven. The honest-pays-once case needs a real shard proof of the harness's own chain, which a CPU prover makes in minutes; the unit tests hold it meanwhile and the testnet holds it live.
Key succession mode (`docs/design/key-succession.md`, 8 October 2026, evening): `--succession <H> --window <W> --next-ids <shard,aggregator> --next-proof <a real proof under the next pair>` schedules the next pair at H on the harness's object; the honest nodes must embed both pairs. No prover runs on the harness chain, so the signal is the honest nodes' refusal reason: below H a next-pair proof is refused on its pair ("the carrier's epoch does not accept"), in the window on its statement (it proves another chain), after H+W a prior-pair proof is refused on its pair; the seven shapes pay nothing on any side. Three forges (below H, in the window, after H+W); PASS = those reasons in that order and nothing paid.