From 6184cb9e280579d65d2668863b1a8d32b5d8867e Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Thu, 8 Oct 2026 17:34:24 +0000 Subject: [PATCH] Enforced proving spec: the fast-time harness's key-succession mode (section 8) Co-Authored-By: Claude Fable 5.1 --- docs/spec/proving-enforcement.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/docs/spec/proving-enforcement.md b/docs/spec/proving-enforcement.md index 5aa73292c..2b63ddaab 100644 --- a/docs/spec/proving-enforcement.md +++ b/docs/spec/proving-enforcement.md @@ -115,3 +115,5 @@ Until stage 3 lands, every stage's output is checked natively by every node, and ## 8. The fast-time harness case `infra/fast-time/proving-enforcement.mjs` (ran, PASS at 17:22 UK, section 6): three nodes on one fast-time network, two honest under the floor set a few epochs ahead (`proving_consensus_verify_daa` in the override, the boundary), one attacker with the body rule off and the verifier in trust mode. The attacker reads each shard's native statement for its own payout address from its node (`igneum_getShardPlan(block, payout)`), signs it (`igneum-miner sign-record`) and submits it with proof bytes of the seven shapes through `igneum_submitProofRecord`; its templates carry the records. Below the boundary the honest nodes accept the attacker's blocks and the v0 rule pays (the finding, observed); from the boundary every honest node refuses the carrying block (`IgneumInvalidProofRecord` or the 20-s drop) and `igneum_getProofRecords` shows no paid entry for any of the seven. The honest-pays-once case needs a real shard proof of the harness's own chain, which a CPU prover makes in minutes; the unit tests hold it meanwhile and the testnet holds it live. + +Key succession mode (`docs/design/key-succession.md`, 8 October 2026, evening): `--succession --window --next-ids --next-proof ` schedules the next pair at H on the harness's object; the honest nodes must embed both pairs. No prover runs on the harness chain, so the signal is the honest nodes' refusal reason: below H a next-pair proof is refused on its pair ("the carrier's epoch does not accept"), in the window on its statement (it proves another chain), after H+W a prior-pair proof is refused on its pair; the seven shapes pay nothing on any side. Three forges (below H, in the window, after H+W); PASS = those reasons in that order and nothing paid.