diff --git a/docs/analysis/class-v6/1p5x/lab/proving-live.md b/docs/analysis/class-v6/1p5x/lab/proving-live.md new file mode 100644 index 000000000..b76dfad1b --- /dev/null +++ b/docs/analysis/class-v6/1p5x/lab/proving-live.md @@ -0,0 +1,45 @@ +# Proving live on Devnet 4: the on-chain record (9 October 2026) + +The 1.5x scoreboard's phase B row reads "a GPU earns the proving share of the block reward and a hash chip cannot". This page is the evidence that the proving share is paid on the live devnet to GPUs proving beside their miners, read from the chain and nothing else. One epoch is 3,600 DAA; Devnet 4's DAA runs at 1.0 per second (63,577 at 11:59:15Z to 63,902 at 12:04:30Z), so an epoch is one hour. + +## The rule being exercised, by file and line (node 27f54124, the 2.0.3 line) + +| what | where | +|---|---| +| 20 percent of every block subsidy to the proving pool, 80 to the producer | consensus/core/src/igneum.rs:44 (`PROVING_POOL_SHARE_PERCENT`), :87 (`proving_pool_share`) | +| a carried record pays its shard part of the pool credit to the record's payout address when valid, verified and first | igneum/exec/src/proving.rs:551 (`carried_payouts`) | +| a v1 segment (8 chain blocks, 8 shards + one aggregation) pays as one record, 1,000 bps of the credit to the aggregator | consensus/core/src/proving.rs:638 (`split_pool_credit`); igneum/exec/src/proving.rs `segment_status` Proven | +| fees v1 from DAA 0 on the devnet (the shard is the calibrated v1 size, 30,000 pgas, never the prototype) | consensus/core/src/config/params.rs:2307 (`DEVNET_PARAMS.fees_v1_activation_daa: 0`); the node reports `fees.v1ActivationDaa 0`, `shardBudget 0x7530` | +| what a prover reads and submits | `igneum_getProvingStatus`, `igneum_getAssignedShards`, `igneum_submitProofRecord`, `igneum_submitSegmentRecord`, `igneum_getSegmentRecords` (igneum/exec/src/rpc.rs:1342, :1443, :1628) | + +## What proves today + +The fleet's prover stack on rented RunPod and Vast boxes: `tools/fleet/box-prover.py` (one loop per box, beside the box's kit-2 miner, MINER=none so the miner is never paused) driving the served 0317 prover pair (`igneum-prove-host` sha256 71bc2438…, `igneum-prove-export` 263bf4ce…, SP1 6.8.1, shard program id 0x2b1a81cb…, aggregator id 0x474678f3…, the pair the node pins) and the SP1 GPU server. The same binaries are what the 2.0.3.1 HiveOS package wraps; the Mac and Windows apps carry the same prover, on by default at 23,552 MiB or more (app/igneum-app/src/provedefault.rs:23-24). Cards: RTX 4090 (24,564 MiB), RTX 3090 (24,576), L40S and RTX 6000 Ada (48 GB) as aggregators. Measured on a 4090 beside its miner: one 8-block segment in 117 to 185 s end to end (shards 48 to 52 s, aggregation 57 to 61 s), peak 13,523 to 14,899 MiB; a 16 GB card cannot hold the shard (the LAB's floor rows). + +## Baseline before the restart (read 11:50:22Z, lp-4090-02's node, chain id 4465, executed tip 31,719, DAA 62,833) + +| counter | value | +|---|---| +| paid v1 segment records since genesis | 663 = 653.93 IGN | +| distinct prover keys paid | 30 (median 4 segments a key, maximum 230) | +| payout addresses | 3 (the fleet's wallets) | +| paid v0 shard records (the pre-segment path) | 6,474 = 7,196 IGN | +| proving pool balance | 27,706 IGN | +| carried records refused as duplicates ("segment already paid") | 952 of 2,199 carried | +| carried records refused as late ("unproven", after the 600 DAA deadline) | 461 | + +Evidence file: build-1:/srv/artefacts/proving-live/prov-ledger-4465-tip31719-115022Z.json (sha256 bd3f53c18c3ffa20354ea62ade9fd5e7a5794202a71c3c369a5be71484f7143a), every segment from genesis with its paid row and carried records. + +Why payments had stopped at 11:15Z: Devnet 4's finality paused at 11:15:57Z under the hub roll (signing weight 4 to 25 percent of the frozen table), and every fleet prover gates on a finality pause (the 8 October build claims only below the finality-settled block; the V6-08 build holds after 600 s). The gate is the prover's own policy; payment never depended on finality (`carried_payouts`). The provers were restarted as generation 2 at 11:59Z with the gate lifted and the chain paid again from 12:02Z. + +## The epoch of evidence (12:02Z to EPOCH_END) + +EPOCH_TABLE + +## The sentence the row carries + +EPOCH_SENTENCE + +## Access to proving work (main's question of 13:1x UK) + +Segments are allocated by first valid record: 8 assignees per shard drawn from the keys in the record window hold a 10 DAA exclusive window (consensus/core/src/proving.rs:26, :30, :255, :305), after which any key may prove and the first valid record carried is paid; no stake, no queue; leases are off on the live nodes. A newcomer competes equally from its first record; a prover on a synced node claims within one 15-second pass (lp-4090-02 claimed 15 s after its restart). With about 227 segments an hour on this devnet and 120 to 185 s a proof, 8 to 11 provers saturate the work and every prover past that dilutes the fixed 20 percent as 1/N; about a third of carried records today are duplicate proofs. The rule change is docs/design/proving-claim-order.md (node change after 2.0.3; nothing on the chain today). diff --git a/docs/analysis/class-v6/1p5x/lab/table.md b/docs/analysis/class-v6/1p5x/lab/table.md index c985c27e7..d2c5be04c 100644 --- a/docs/analysis/class-v6/1p5x/lab/table.md +++ b/docs/analysis/class-v6/1p5x/lab/table.md @@ -170,6 +170,28 @@ on Windows and Mac where a 32 GB NVIDIA card is present, NOT LIVE on the 24 GB t the 4090's), 45.37 MH/s full against 39.71 for the twin (19.73 / 17.75 on the 4090). The F2 row re-run on the same pinned core: 10.440 ms per warp for the signing object at 2^30, 5.134 for the class v4 calibration (frozen-v6/f2-verifier-build5.txt). +- CONTROLS' done line (13:0x to 13:1x UK): the four controls and the ledger rows staged under build-1:/srv/artefacts/lab/controls/ + with SHA256SUMS (frozen-v6 with tlb/, coop-arx, progpow-094, fishhash, sector-read, etchash, autolykos; 25 MB). Autolykos2 landed + in-house and bit-exact (hashlib reference against the CUDA harness at N = 65,536 and at Ergo's live N = 227,251,815, 7.27 GB; + 216.2 / 201.8 MH/s full / twin on the rented 4090; the live-block end-to-end row owed). coop-arx's OpenCL text F1-complete on two + OpenCL platforms at all five chain lengths (the AMD tier runs the moment a card is reachable; Metal owed). Open on that lane: the + knee rows (every rented pod refuses the lock; COHORT's VM-host lock hunt reports by 14:30), the Metal text, the Ergo live-block row. +- ADVERSARY (12:5x to 13:0x): phase B tier rows on the on-chain read (commit 82330b04c; 47f16b86f with Etchash on the mirror): the + 24 GB-and-up NVIDIA tier on Windows and Mac LIVE on Devnet 4 and out-earning the board chip in phase B (the GPU's contribution per + TH after electricity 0.341 against the chip's 0.288 after its recurring cost at ten cents on the flat path); HiveOS NOT LIVE until + the 2.0.3.1 package; the 16 GB tier never (mining share only, 0.046 per TH behind the chip). ctl-etchash as a control (64 x 128 B + reads over about 3.3 GB) with the calibration line: the modelled DRAM board 765 nJ per hash against the shipped Antminer E9 Pro's + 598 (3,680 MH/s at 2,200 W, the public figure as the ledger lane quotes it): the model 1.28x pessimistic for the chip, a witness. + Phase A and B for Ravencoin, Ethereum Classic and Iron Fish in their own units (commit d7db3e596, README section 14): no fleet + recovers a board chip's spend on any of the three on any path (each chain's 24-month mining emission under one design cost: RVN + about USD 2.9 M, IRON 1.4 M, ETC 83 M at a 10,000-board fleet); phase B with no prover income: on Ravencoin the chip's operating + advantage stands in full at USD 0.123 per TH; on ETC the mining revenue per TH (0.0087) is below the board's recurring cost (0.031) + and the E9 Pro's electricity alone (0.017), a loss on both sides at ten cents. The reading: on every chain in the set the board + chip's phase B advantage is real and its phase A recovery is not at today's emissions; the proving share is the one term that lets + Igneum's live GPU tier out-earn the chip in phase B. +- The boxes (the build steward, 13:1x): the lab's ended box runs' pid files removed as stale after each pid's command line was read + dead; the steward's defaults on build-4, build-5 and build-6 stand until a lane claims with a live pid file. + ## Open rows (NOT RUN) | row | owner | clock | diff --git a/docs/analysis/class-v6/1p5x/ledger/README.md b/docs/analysis/class-v6/1p5x/ledger/README.md new file mode 100644 index 000000000..be6de15e7 --- /dev/null +++ b/docs/analysis/class-v6/1p5x/ledger/README.md @@ -0,0 +1,157 @@ +# The GPU network ledger (the 1.5x laboratory, LEDGER lane, 9 October 2026) + +Every live GPU-mined chain the lab could pin, measured the same way on the same rented cards in the same sessions, with the same +adversary method applied to each, ranked on (a) the same-node chip-to-GPU energy edge under the lab's convention, (b) the same +under ProgPoW's own premise, and (c) the two-phase economics with each chain's ACTUAL reward split (only Igneum pays a share of +every block to provers). Every number is MEASURED or WITNESS with its source on the row; a number that does not exist yet reads +"pending" with the lane that owes it, never blank; a chain the lab could not run in-house reads NOT RUN with the reason. + +The data lives in `ledger.json` beside this file; every table here, on the public page (`docs/ledger/gpu-ledger.md`, served at +/gpu-ledger) and in the reproduction kit is rendered from it by `tools/ledger/render.mjs`, so no two copies of a row can drift. +The public page carries the same tables with less of the lane bookkeeping. + + +Data: ledger.json, stamp 2026-10-09, adversarial set v3 (build-1:/srv/artefacts/lab/adv/ (README.md, design-notes/adversarial-sets-v1-v2-v3.md, rows/, SHA256SUMS); set v3 commit b2b9ee0b9 on class-v6-adversary). + + +## 1. The method (the same for every chain) + +1. **The object.** Each chain's proof of work as its own pinned reference code, built in-house from source (the in-house rule: no + downloaded miner binary; the CONTROLS lane's pins with commit ids and sha256s on build-1 under /srv/artefacts/lab/controls/). + Igneum: the frozen class v6 at the live 4 GiB dataset. Ravencoin: the official ProgPoW 0.9.4 reference kernel (KAWPOW is + ProgPoW 0.9.4 with Ravencoin's constants, so the official kernel at Raven's DAG size is a labelled PROXY). Firo: the same row + (FiroPoW differs from KAWPOW in its constants only). Iron Fish: the FishHash reference library and a bit-exact CUDA port. Ethereum + Classic: the ethash hashimoto of the pinned chfast/ethash library at ETC's current epoch. Ergo: NOT RUN (the reason on the row). +2. **The card rows** (the COHORT lane, the lab's measurement recipe, interface section 1): one rented RTX 4090 and one rented RTX + 5090, both on uncapped hosts, every chain back to back in ONE session per card at stock; board power from `nvidia-smi` at 1 Hz + (the mean from 8 s in to the end, idle not subtracted); the rate from the harness's own counter; nJ per hash = W / MH/s x 1,000; + three timed runs per cell, the median served with the spread; `clocks_sm_median` and the dataset size on every row; the + read-only twin (the same reads, the arithmetic cut) where the harness has one, giving f = J_twin / J_full, the card's memory + share. Rented containers refuse clock locks, so every row is stock; the Igneum knee rows exist only in the record. +3. **The chip rows** (the ADVERSARY lane, adversarial set v3): for each chain the cheapest credible specialist on the same node, a + complete machine (die, memory, board, PSU and host terms), modelled and labelled WITNESS; the same-node DRAM board is the energy + row, the SRAM die the residual (coexistence) row. Two conventions beside every ratio: **ours** (the cheapest programmable core, + fused where the work allows, register file sized to the work, instruction convention) and **ProgPoW's premise** (the chip must + keep a GPU-class datapath, so its edge is the compute term's 1.1x to 1.2x weighted by the card's measured memory share f). +4. **The real chip.** Ethereum Classic is the one chain on the ledger with a chip on the market, the Antminer E9 Pro; its public + rate and power go on the row as a WITNESS and the modelled DRAM board for Etchash goes beside it as the model's calibration + line: the row says how close the model's ratio sits to the ratio from the public figures. +5. **The two phases** (the lab's rulings 8c.5 and 8c.11): phase A, can a chip maker recover its spend before investment under + growing, flat and falling price paths; phase B, with the spend sunk, who exits first on operating cost, with the chain's actual + reward split: a GPU on Igneum earns the mining share plus the proving share (80 / 20 ratified), a hash chip the mining share + only; on every other chain the GPU's share is mining only (100 / 0), so the second-income term is zero by construction. +6. **The ranking rule.** Rank (a) ascending on the same-node DRAM board ratio under our convention at the WORSE of the two cards + (the lower ratio is the smaller chip edge); (b) ascending on the ProgPoW-premise ratio at the same cell; (c) phase B: whether + the chain's GPUs earn an income a hash chip cannot. A chain with any pending or proxy cell in a column is ranked provisionally + in that column and says so; a NOT RUN chain is unranked. PASS is never written; the ranking is the rows' order, nothing more. + +## 2. The card rows (MEASURED; board power; stock) + + +| chain | algorithm | dataset on the row | reward split (mining / proving) | RTX 4090 stock: nJ per hash (MH/s, W, f) | RTX 5090 stock: nJ per hash (MH/s, W, f) | twin | sources | +|---|---|---|---|---|---|---|---|---| +| Igneum | class v6, the live signing object 0x2a1d6caab4c24564 (2.0 devnet, chain id 4465) | 4.29 GB (4,294,967,296 bytes); 2^30 words, the live policy (70a6c703); 256 random 4-byte reads per hash, 62,120 instructions per hash (instruction convention) | 80 / 20 (the Token Value volume on master (D04, token-value/README.md: the 80/20 emission allocation); PROVING_POOL_SHARE_PERCENT) | 8,369 MEASURED (30.67 MH/s, 256.7 W, f 0.848; spread 0.67%; vast 55009211, driver 580; stock (the pod refused -lgc); clocks_sm_median pending the ledger session) | 5,597 MEASURED (68.66 MH/s, 384.3 W, f 0.811; spread 2.11%; vast 55006481, driver 580; stock (the pod refused -lgc); the host cap 500 W, the card drew 384) | yes (the same address stream, the arithmetic cut) | RTX 4090: build-1:/srv/artefacts/lab/ctl-v6/vast-55009211/ (rows.jsonl, SHA256SUMS); the cohort table build-1:/srv/artefacts/lab/cohort/TABLE.md; RTX 5090: build-1:/srv/artefacts/lab/ctl-v6/vast-55006481/; the cohort table build-1:/srv/artefacts/lab/cohort/TABLE.md | +| Ravencoin | KAWPOW (ProgPoW 0.9.4 with Ravencoin's kiss99 constants, 7,500-block epochs and a 512-parent DAG; live since block 1,219,736, 6 May 2020) | 6.18 GB (6,182,403,712 bytes); KAWPOW's current DAG size at Ravencoin height 4,573,707 (epoch 609, read 13:0x UK): the official ProgPoW 0.9.4 kernel built at Ethash block 18,270,000 (epoch 609, the same byte count), harness progpow-094/gpu/pp_harness_18270000; KAWPOW's own constants NOT applied, so the row is 'ProgPoW 0.9.4 official at KAWPOW's DAG size (proxy)'; 64 coalesced 256-byte reads per hash; F1 GPU = CPU on both nonces (cpu/vectors-094-kawpow-size-18270000.txt) | 100 / 0 (Ravencoin's block reward goes to the miner in full (no second income to GPUs)) | 6,920 MEASURED (prior row: kawpowminer, not the pinned kernel; a PROXY until the ledger session's pinned-kernel row lands) (58.95 MH/s, 409.0 W, f none; spread none; RunPod, the comparative lane a2ed5c31; stock) | pending: pending (COHORT, the ledger session) | yes, by construction (progpow-094/gpu/pp_twin 18270000 26 250: the 64 dependent entry reads per 16-lane hash) | RTX 4090: build-1:/srv/artefacts/lab/adv/rows/rows.md (the ctl-progpow-094 section, card rows) | +| Firo | FiroPoW (ProgPoW 0.9.4 with Firo's constants; live since block 419,264, 26 October 2021) | = Ravencoin's row | 100 / 0 | = Ravencoin's row | = Ravencoin's row | as Ravencoin | as KAWPOW: the pinned ProgPoW 0.9.4 reference; FiroPoW differs from KAWPOW only in its constants and DAG schedule, so the lab serves ONE row for both and says so | +| Iron Fish | FishHash (live since hardfork 1, April 2024) | 4.83 GB (4,831,835,776 bytes); 37,748,717 items of 128 bytes, FIXED (no epochs); 96 random 128-byte reads per hash, 9,856 lane-instructions | 100 / 0 (Iron Fish's block reward is mining only) | pending: pending (COHORT, the ledger session); CONTROLS' rate-only read 19.73 MH/s at stock, no sampler (rate only 19.73 MH/s) | pending: pending (COHORT, the ledger session); CONTROLS' rate-only sm_120 read 45.37 MH/s full, 39.71 twin, F1 PASS (rate only 45.37 MH/s) | yes (a trace replay of the kernel's own item indexes; its energy read as a bound: the twin runs 10 percent slower than the full kernel) | RTX 4090: build-1:/srv/artefacts/lab/controls/fishhash/gpu/bench-4090.log; RTX 5090: build-1:/srv/artefacts/lab/controls/fishhash/ (fishhash.md) | +| Ethereum Classic | Etchash (Ethash with ECIP-1099's 60,000-block epochs; live since block 11,700,000, November 2020) | 4.64 GB (4,638,898,816 bytes); ETC height 25,502,946 (read 12:5x UK) = Etchash epoch 425 (ECIP-1099: height / 60,000), the harness's block argument 12,750,000 (the Ethash epoch with the same size table index); 64 coalesced 128-byte reads per hash (two 64-byte half-mixes); CONTROLS' rate-only read on a 4090 at stock 29.90 MH/s full and 29.90 twin (memory-bound) | 100 / 0 (ETC's block reward is mining only) | pending: pending (COHORT, the ledger session; the harness staged 13:0x UK); CONTROLS' rate-only read 29.90 MH/s (rate only 29.90 MH/s) | pending: pending (COHORT, the ledger session; the sm_120 build from etchash/src) | yes, by construction | RTX 4090: build-1:/srv/artefacts/lab/controls/etchash/ (etchash.md) | +| Ergo | Autolykos2 (k = 32, n = 26, Blake2b-256; the table grows 5 percent every 51,200 blocks) | 7.27 GB (7,272,058,080 bytes); the live table at Ergo height 1,890,820 (api.ergoplatform.com, 13:0x UK): N = 227,251,815 elements of 32 bytes (+5 percent at height 1,894,400; the row names its height); 33 random 32-byte reads per hash; the table builds on the device in 1.5 s; CONTROLS' rate-only read on a 4090 at stock 216.2 MH/s full, 201.8 twin | 100 / 0 (Ergo's block reward is mining only) | pending: pending (COHORT, the ledger session; the harness staged 13:1x UK); CONTROLS' rate-only read 216.2 MH/s full, 201.8 twin (rate only 216.20 MH/s) | pending: pending (COHORT, the ledger session; the sm_120 build from src) | yes (a trace replay) | RTX 4090: build-1:/srv/artefacts/lab/controls/autolykos/ (autolykos.md) | + + +## 3. The chip-to-GPU edge, both conventions (WITNESS chip rows over MEASURED card rows) + + +| chain | the cheapest credible same-node DRAM board (set v3, nJ per hash, band) | ratio at the RTX 4090 stock (ours) | ratio at the RTX 5090 stock (ours) | ProgPoW-premise ratio at the RTX 4090 | ProgPoW-premise ratio at the RTX 5090 | the die as the residual (nJ; ratio at the worse card) | real chip on the market | source | +|---|---|---|---|---|---|---|---|---| +| Igneum | 1,542 (1,329 to 1,941); GDDR7 board + register file sized to the work + fused operations, N5; split memory 527 / ALU 166 / tax 849; WITNESS (modelled, complete machine, instruction convention) | 5.43x (4.31 to 6.30) | 3.63x (2.88 to 4.21) | 1.01x to 1.03x (f 0.853 measured) | 1.02x to 1.03x (f 0.811 measured on the stock pod) | 335 (N2 full-SRAM die, the coexistence row); 25.0x | none on the market | docs/analysis/class-v6/1p5x/lab/adv/v3/ledger-rows.md and ledger-rows.json (class-v6-adversary 47f16b86f); build-1:/srv/artefacts/lab/adv/rows/ctl-v6.json and rows.md (set v3, 2026-10-09T11:33Z); the die 12.0x at the 5090 knee, USD 0.77 per MH/s | +| Ravencoin | 1,757 (1,453 to 2,147); GDDR7 board + register file sized to the work + fused operations, N5; bandwidth-bound at 16 KB per hash (93 MH/s per board); split memory 647 / ALU and tax per rows.md; WITNESS (modelled on the kawpowminer census as the work proxy until CONTROLS' trace replaces it) | 3.94x (3.22 to 4.76) | pending | 1.10x to 1.20x (the premise's own figure; no measured twin on this kernel yet) | 1.10x to 1.20x (the premise's own figure; the twin row makes it measured) | 697 (N2 full-SRAM die, the coexistence row (USD 1.89 per MH/s); the cheapest specialist of any kind is near-memory base dies at 669 nJ); 9.9x | none on the market | docs/analysis/class-v6/1p5x/lab/adv/v3/ledger-rows.md and ledger-rows.json (class-v6-adversary 47f16b86f); build-1:/srv/artefacts/lab/adv/rows/ctl-progpow-094.json (set v3) | +| Firo (= Ravencoin's row) | 1,757 (1,453 to 2,147); GDDR7 board + register file sized to the work + fused operations, N5; bandwidth-bound at 16 KB per hash (93 MH/s per board); split memory 647 / ALU and tax per rows.md; WITNESS (modelled on the kawpowminer census as the work proxy until CONTROLS' trace replaces it) | 3.94x (3.22 to 4.76) | pending | 1.10x to 1.20x (the premise's own figure; no measured twin on this kernel yet) | 1.10x to 1.20x (the premise's own figure; the twin row makes it measured) | 697 (N2 full-SRAM die, the coexistence row (USD 1.89 per MH/s); the cheapest specialist of any kind is near-memory base dies at 669 nJ); 9.9x | none on the market | = Ravencoin's row | +| Iron Fish | 1,051 (881 to 1,257); GDDR7 board + register file sized to the work + fused operations, N5; bandwidth-bound at 124 MH/s per board; 95 percent of the board's energy is the memory path; split memory 529 / ALU 46 / tax 503; WITNESS (modelled; the card's cell pending, so the ratio is pending) | pending | pending | pending (needs the measured f from the twin) | pending | 170 (full SRAM dies (three N2 reticles) + sized + fused operations); pending | none on the market | build-1:/srv/artefacts/lab/adv/rows/ctl-fishhash.json and rows.md (set v3) | +| Ethereum Classic | 765 (638 to 919); GDDR7 board + register file sized to the work + fused operations, N5; USD 3.25 per MH/s; split per ledger-rows.md; WITNESS (modelled; the card cells pending, so the ratios are pending) | pending | pending | 1.10x to 1.20x (the premise's own figure; the twin row makes it measured) | 1.10x to 1.20x (the premise's own figure) | 177 (N2 full-SRAM die, the coexistence row); pending | Bitmain Antminer E9 Pro: 3,680 MH/s at 2,200 W = 598 nJ per hash, WITNESS (a manufacturer's published figure, not measured by the lab); Bitmain's stated figures as listed on minerstat's hardware page (https://minerstat.com/hardware/antminer-e9-pro): 3.68 GH/s on Ethash at 2,200 W, release 2023-02; 2,200 W / 3,680 MH/s = 0.598 J per MH = 598 nJ per hash | docs/analysis/class-v6/1p5x/lab/adv/v3/ledger-rows.md and ledger-rows.json (class-v6-adversary 47f16b86f, wording 82330b04c) | +| Ergo | pending: pending (ADVERSARY: the chip rows from CONTROLS' trace; default 15:00 UK, else pending (adversary)) | pending | pending | pending | pending | pending | none on the market | pending | + + +## 4. The two phases with each chain's actual split + + +| chain | split | phase A (before investment) | phase B (spend sunk) | an income a hash chip cannot earn | source | +|---|---|---|---|---|---| +| Igneum | 80 / 20 | before investment (24 months, the mining share 80 percent of the year-1 subsidy): the same-node board maker recovers its spend on NO fleet from 100 to 100 M boards on the growing or flat price path (100,000 boards: net USD -55.4 M on 58.8 M revenue growing; -37.6 M on 76.6 M flat); only the falling path pays it; the N2 die recovers on no path | spend sunk, flat path at USD 0.10 per kWh, the chip at 10 percent of the hash: mining revenue USD 0.354 per TH; the GPU's proving income at the ratified 20 percent share USD 0.098 per TH against the board chip's operating advantage USD 0.046 per TH (GPU electricity 0.111 less the chip's electricity, hosting and maintenance 0.066): the GPU out-earns the built board chip; the cancelling proving share 9 percent (board), 13 (hybrid), 20 (die) | yes by rule (the proving share of every block, 20 percent ratified); LIVE ON DEVNET with on-chain paid records (663 paid v1 segment records to 30 prover keys on chain 4465, the PROVING LIVE lane's file bd3f53c1 on build-1), not yet in a shipped package | build-1:/srv/artefacts/lab/adv/rows/rows.md (the two-phase section), ADVERSARY commit 545f3f8a0; ctl-v6-coexistence.json; WITNESS; phase B NOT LIVE until a shipped package runs a prover | +| Ravencoin | 100 / 0 | before investment: no fleet from 100 to 100 M machines recovers a board chip's spend on any path, because Ravencoin's whole mining emission over 24 months (about USD 2.9 M at the public price) sits below one USD 35 M design cost; 10,000 boards would take 56 percent of the 721 GH/s network and earn USD 1.6 M to 2.4 M against a USD 44 M spend | spend sunk, mining only: mining revenue USD 0.064 per TH of the chain's own hashes; the board chip's recurring cost USD 0.069 per TH at ten cents; the chip's operating advantage over the RTX 4090 at stock (6,920 nJ) USD 0.123 per TH (the GPU's electricity 0.192 less the chip's 0.069) stands in full, no prover income | no (the block reward is mining only) | docs/analysis/class-v6/1p5x/lab/adv/v3/ctl-progpow-094-coexistence.json (rows[].phase_a, rows[].phase_b_split; method lab/adv/README.md section 14), ADVERSARY commit d7db3e596 on class-v6-adversary; WITNESS, the chain's own units, the 100/0 split, the same 24-month life, design cost and fleet rule as v6, the three price paths (flat at the public price, x2 growing, x0.5 falling, the hash held); the public lines on the row | +| Firo | 100 / 0 | as KAWPOW | as KAWPOW | no | as KAWPOW; = KAWPOW's row at a 100/0 split | +| Iron Fish | 100 / 0 | before investment: no fleet from 100 to 100 M machines recovers a board chip's spend on any path; Iron Fish's whole mining emission over 24 months is about USD 1.4 M at the public price (10,000 boards would take 84 percent of the hash for USD 1.1 M to 1.6 M) | spend sunk, mining only: mining revenue USD 0.086 per TH of the chain's own hashes; the board chip's recurring cost USD 0.043 per TH at ten cents; the GPU side NOT RUN until the card cell lands; no prover income by construction | no | docs/analysis/class-v6/1p5x/lab/adv/v3/ctl-fishhash-coexistence.json, ADVERSARY commit d7db3e596 on class-v6-adversary; WITNESS, the chain's own units, the 100/0 split, the same life, design cost, fleet rule and price paths as v6; the GPU side of phase B NOT RUN until COHORT's card rows | +| Ethereum Classic | 100 / 0 | before investment: no fleet from 100 to 100 M machines recovers a board chip's spend on any path; ETC's whole mining emission over 24 months is about USD 83 M at the public price, but 10,000 boards are 2 percent of 120.9 TH/s and earn USD 1.0 M to 1.5 M, and 100,000 boards (13 percent) USD 9 M to 13 M against a USD 150 M spend | spend sunk, mining only: mining revenue USD 0.0087 per TH of the chain's own hashes, below even the modelled board's recurring cost (USD 0.031 per TH) and below the E9 Pro's own electricity at ten cents (598 nJ = USD 0.017 per TH): at the public figures nobody mines ETC at a profit at ten cents and phase B is a loss on both sides; the GPU side NOT RUN until the card cell lands | no | docs/analysis/class-v6/1p5x/lab/adv/v3/ctl-etchash-coexistence.json, ADVERSARY commit d7db3e596 on class-v6-adversary; WITNESS, the chain's own units, the 100/0 split, the same life, design cost, fleet rule and price paths as v6; the GPU side of phase B NOT RUN until COHORT's card rows | +| Ergo | 100 / 0 | pending (ADVERSARY) | pending (ADVERSARY); no prover income by construction | no | pending; pending (ADVERSARY at the 100/0 split, the public line on the row) | + + +## 5. The ranking + + +**(a) Ours, the same-node DRAM board at the worse card (the smaller chip edge first):** +No order in this column yet: a cross-chain comparison is made only between cells from the same card, state and session, and the measured cells today come from 2 sessions (lab-cohort-ctl-v6 (COHORT, 11:49 to 12:30 UK, one chain); comparative-lane a2ed5c31 (RunPod, one chain, an earlier session)); the ledger session (both cards, every chain back to back) fills it. Each chain's own number, same card and state, as it stands: +- Igneum: RTX 4090 stock 5.43x (4.31 to 6.30); RTX 5090 stock 3.63x (2.88 to 4.21) +- Ravencoin: RTX 4090 stock 3.94x (3.22 to 4.76); RTX 5090 stock pending (a pending or proxy cell in this row) +- Iron Fish: unranked in this column (no measured card cell yet) +- Ethereum Classic: unranked in this column (no measured card cell yet) +- Ergo: unranked in this column (no measured card cell yet) + +**(b) ProgPoW's premise (the chip keeps a GPU-class datapath):** +- Igneum: RTX 4090 1.01x to 1.03x (f 0.853 measured); RTX 5090 1.02x to 1.03x (f 0.811 measured on the stock pod) +- Ravencoin: RTX 4090 1.10x to 1.20x (the premise's own figure; no measured twin on this kernel yet); RTX 5090 1.10x to 1.20x (the premise's own figure; the twin row makes it measured) +- Iron Fish: RTX 4090 pending (needs the measured f from the twin); RTX 5090 pending +- Ethereum Classic: RTX 4090 1.10x to 1.20x (the premise's own figure; the twin row makes it measured); RTX 5090 1.10x to 1.20x (the premise's own figure) +- Ergo: RTX 4090 pending; RTX 5090 pending + +**(c) Phase B, an income a hash chip cannot earn:** +- Igneum: yes by rule (the proving share of every block, 20 percent ratified); LIVE ON DEVNET with on-chain paid records (663 paid v1 segment records to 30 prover keys on chain 4465, the PROVING LIVE lane's file bd3f53c1 on build-1), not yet in a shipped package +- Ravencoin: no (the block reward is mining only) +- Firo: no +- Iron Fish: no +- Ethereum Classic: no +- Ergo: no + + +## 6. The claim under test, clause by clause + +The sentence the ledger was ordered to carry, in exactly these words and nothing stronger, is served as the claim UNDER TEST with +each clause labelled by its state on the current rows; it reads as established only when every clause is SUPPORTED. The fifth +review's ruling stands (interface 8c.9): a comparative sentence needs the comparative row, and this ledger is that row. + + +**The headline, built from the supported clauses only:** under ProgPoW's own convention, the lowest measured chip-to-GPU edge of the chains on this ledger; and the only chain on this ledger whose GPUs are paid, by rule, an income a hash chip cannot earn (LIVE ON DEVNET, on-chain records (the PROVING LIVE lane, read 11:50:22Z 9 October 2026): on chain id 4465 (the Igneum 2.0 devnet) 663 paid v1 segment records (8 shards plus aggregation each) = 653.93 IGN paid from the proving pool to 30 distinct prover keys across chain blocks 3,000 to 30,687 (tip 31,719 at the read), plus 6,474 paid v0 shard records = 7,196 IGN; read by igneum_getProvingStatus, igneum_getSegmentRecords (3,965 segments) and igneum_getSegment; evidence build-1:/srv/artefacts/proving-live/prov-ledger-4465-tip31719-115022Z.json sha256 bd3f53c18c3ffa20354ea62ade9fd5e7a5794202a71c3c369a5be71484f7143a. NOT YET LIVE IN A SHIPPED PACKAGE: the payees are the fleet's prover stack (the same binaries the 2.0.3.1 HiveOS package wraps, cut 18:00 UK); the apps' prover is on by default on 24 GB cards but no app-proved record is on the record yet; a full-epoch line follows by 16:00 UK). + +The sentence as ordered, served as the claim under test: "the lowest measured chip-to-GPU edge of any live GPU network under a published method, on both conventions, and the only one whose GPUs earn income a chip cannot" + +Rule: the headline reads only what the like-for-like rows support, clause by clause (main's ruling, 13:2x UK 9 October 2026); under the ledger's own convention the measured edge per chain on the same card and state is stated as numbers, with no ranking word until the rows say so after the ledger session. + +| clause | convention | state on the current rows | why | +|---|---|---|---| +| under ProgPoW's own convention, the lowest measured chip-to-GPU edge of the chains on this ledger | ProgPoW's premise (a chip that keeps a GPU-class datapath) | SUPPORTED on the current rows | Igneum v6 1.01x to 1.03x (its measured f 0.81 to 0.85) against ProgPoW's own 1.10x to 1.20x for KAWPOW and FiroPoW; FishHash and Etchash pending their twins | +| under the ledger's convention (the cheapest credible programmable specialist, adversarial set v3), each chain's measured edge on the same card and state, as numbers | ours | NUMBERS ONLY; no ranking until the ledger session (COHORT, both cards, every chain back to back, the pinned 0.9.4 kernel, twins; 14:45 UK) | the current cells come from different sessions (the lab's cohort pods for v6, the comparative lane's pod for KAWPOW) and a cross-chain comparison is made only between cells from the same card, state and session; at the RTX 4090 at stock the cells read v6 5.4x (5.67x on the second pod) and KAWPOW 3.9x (a proxy row from an earlier session); FishHash and Etchash pending | +| and the only chain on this ledger whose GPUs are paid, by rule, an income a hash chip cannot earn | phase B, each chain's actual reward split | LABELLED BY THE PROVING LIVE LANE | the proving share (20 percent ratified) is paid to GPUs for work a hash chip cannot do; every other chain on the ledger pays mining only; the live state of that income is the PROVING LIVE lane's evidence line | + +Withdrawn: the earlier line 'KAWPOW and FiroPoW read 5 to 6x on the measured 4090 rows and v6 reads 2.35x' is withdrawn: it compared v6 at the 5090's 1,300 MHz knee with KAWPOW at the 4090 at stock, two cards and two states; the like-for-like cells are the ones on this ledger. + +The last clause's label from the PROVING LIVE lane: LIVE ON DEVNET, on-chain records (the PROVING LIVE lane, read 11:50:22Z 9 October 2026): on chain id 4465 (the Igneum 2.0 devnet) 663 paid v1 segment records (8 shards plus aggregation each) = 653.93 IGN paid from the proving pool to 30 distinct prover keys across chain blocks 3,000 to 30,687 (tip 31,719 at the read), plus 6,474 paid v0 shard records = 7,196 IGN; read by igneum_getProvingStatus, igneum_getSegmentRecords (3,965 segments) and igneum_getSegment; evidence build-1:/srv/artefacts/proving-live/prov-ledger-4465-tip31719-115022Z.json sha256 bd3f53c18c3ffa20354ea62ade9fd5e7a5794202a71c3c369a5be71484f7143a. NOT YET LIVE IN A SHIPPED PACKAGE: the payees are the fleet's prover stack (the same binaries the 2.0.3.1 HiveOS package wraps, cut 18:00 UK); the apps' prover is on by default on 24 GB cards but no app-proved record is on the record yet; a full-epoch line follows by 16:00 UK + + +## 7. The reproduction kit + +build-1:/srv/artefacts/ledger// (the stamp and the sha256 of the kit on the row below when it lands): the pinned controls +(the frozen v6 pack and twin, the ProgPoW 0.9.4 reference harness, the FishHash harness, the Etchash harness when staged), the +gen-6 Igneum worker, the lab's sampler and session script, the chain references by commit and sha, SHA256SUMS, and a README with +one command per card and the expected rows within their bands (ROWS.md, rendered from ledger.json). Anyone with a 4090 can run it. + +| item | state | +|---|---| +| the kit on build-1 | pending (16:30 UK clock) | +| the kit's sha256 | pending | +| the public page | pending (17:30 UK clock; /gpu-ledger) | + +## 8. Faults and corrections (reported once) + +| when (UK) | what | state | +|---|---|---| +| 13:1x | the brief's "Ravencoin's own 1.5x claim" has no source in the pinned ProgPoW text (the README states 1.1x to 1.2x); the row carries the README's figure and the brief's figure as NOT FOUND | on the row | +| 13:1x | the earlier like-for-like line ("KAWPOW 5 to 6x against v6 2.35x") compared v6 at the 5090 knee with KAWPOW at the 4090 stock; at the same cell (4090 stock, set v3) the rows read v6 5.4x against KAWPOW 3.9x (proxy), so clause (a) of the claim is NOT SUPPORTED on today's rows | reported to main 13:1x; the ledger session's pinned-kernel rows decide | +| 13:0x | the lab's cohort cells stand in for the ledger session's cells until COHORT's back-to-back rows land (clock 14:45) | pending | diff --git a/docs/analysis/class-v6/1p5x/ledger/ledger.json b/docs/analysis/class-v6/1p5x/ledger/ledger.json new file mode 100644 index 000000000..88677dae5 --- /dev/null +++ b/docs/analysis/class-v6/1p5x/ledger/ledger.json @@ -0,0 +1,195 @@ +{ + "title": "The GPU network ledger", + "stamp": "2026-10-09", + "adversarial_set": "v3", + "adversarial_set_source": "build-1:/srv/artefacts/lab/adv/ (README.md, design-notes/adversarial-sets-v1-v2-v3.md, rows/, SHA256SUMS); set v3 commit b2b9ee0b9 on class-v6-adversary", + "cards": [ + {"id": "4090", "name": "RTX 4090", "state": "stock", "note": "uncapped host (450 of 450 W)"}, + {"id": "5090", "name": "RTX 5090", "state": "stock", "note": "uncapped host (575 or 600 W at default)"} + ], + "ranking_rule": "Rank (a) ascending on the same-node DRAM board ratio under the ledger's convention at the WORSE of the two cards (the lower ratio is the smaller chip edge); (b) ascending on the ProgPoW-premise ratio at the same cell; (c) phase B: whether the chain's GPUs earn an income a hash chip cannot. A cross-chain comparison is made only between cells from the SAME card, the SAME state and the SAME session (main's ruling, 13:2x UK 9 October 2026); until the ledger session's cells exist the (a) column shows each chain's own number and no order. A chain with any pending or proxy cell in a column is ranked provisionally in that column and says so; a NOT RUN chain is unranked.", + "mechanism": { + "title": "Why the two honest-convention edges differ: the shape of the memory traffic", + "rows": [ + {"chain": "Igneum v6", "traffic": "256 dependent random reads of one 32-byte sector each per hash over 4 GiB (8 KB moved, 1 KB consumed); the card is activation-bound: 7.86 G sector reads per second on the 4090 at its tFAW form, 17.6 G on the 5090", "card_cost": "27 to 31 nJ per random sector read all-in on the 4090 at stock (X7 and the sector-read rows); the ALU runs in the reads' shadow (f 0.85)", "chip_cost": "about 2.1 nJ per read on the chip's own GDDR7 board (1.2 on HBM3, 0.7 beside the bank): s = 12.8", "consequence": "the chip's edge on random reads is the largest of any term in the model; a read-dominated object carries it in full"}, + {"chain": "Ravencoin KAWPOW (and FiroPoW)", "traffic": "64 coalesced 256-byte DAG entries per 16-lane hash = 16 KB streamed per hash; the card is bandwidth-bound (1.03 TB/s at 62.6 MH/s on the 4090; 93 MH/s per modelled board)", "card_cost": "a coalesced 256-byte read costs the card far less per byte than a scattered sector (modelled 35 nJ per 256-byte entry against 27 nJ per 32-byte sector)", "chip_cost": "the chip streams the same bytes at the same DRAM bandwidth bound; its gain is on the per-byte energy and the 18 random-math ops per loop (a GPU-class datapath on the premise, fused lanes under ours)", "consequence": "a smaller memory-term gap, so a smaller honest-convention edge at the same card; the price is a DAG that grows (8.38 GB at Ethereum's epoch 871 for the control) and a 16 KB stream per hash"}, + {"chain": "Iron Fish FishHash", "traffic": "96 random 128-byte lines per hash over a fixed 4.83 GB (12 KB per hash, every byte consumed): between the two shapes (four sectors per activation)", "card_cost": "pending the measured cell (CONTROLS' rate-only read 242 GB/s of lines at 19.73 MH/s on the 4090)", "chip_cost": "95 percent of the modelled board's energy is its memory path", "consequence": "the ratio is pending its card cell"}, + {"chain": "Ethereum Classic Etchash", "traffic": "64 loops of two 64-byte half-mixes = 128-byte coalesced reads per hash over the epoch DAG; bandwidth-bound", "card_cost": "pending", "chip_cost": "the one chip that exists (the E9 Pro) on this shape", "consequence": "the calibration line"} + ], + "note": "Stated as the mechanism, not as a mitigation: the lab's X7 verdict is that no read-dominated design reaches a small edge against a chip with its own memory on the same node, and the ledger shows the shape of each chain's traffic beside its ratio so a reader sees where each number comes from." + }, + "chains": [ + { + "id": "igneum-v6", + "chain": "Igneum", + "algorithm": "class v6, the live signing object 0x2a1d6caab4c24564 (2.0 devnet, chain id 4465)", + "control": "ctl-v6", + "pin": "tree 1a938abe4; pack x1-ctrl-ds30.tgz sha256 7606c13d92546e44feef485fde25716a206643e6466ef5d5251d41354eee9532; read-only twin x1-ctrl-ds30-readonly.tgz 7629ed9598c0297533c03d4a9cbd83338d47a7693a26dc8b86566f3f0982174b; worker igneum-worker-cuda-gen6 804a6f7fea10a62e07cf6cd01e99331de5149e683112b5870fc25d1e11e199bd (COHORT's rows on worker f5f3846c, kit bf9b85d6); build-1:/srv/artefacts/lab/controls/frozen-v6/", + "dataset_bytes": 4294967296, + "dataset_note": "2^30 words, the live policy (70a6c703); 256 random 4-byte reads per hash, 62,120 instructions per hash (instruction convention)", + "twin": "yes (the same address stream, the arithmetic cut)", + "split": {"mining": 80, "proving": 20, "source": "the Token Value volume on master (D04, token-value/README.md: the 80/20 emission allocation); PROVING_POOL_SHARE_PERCENT"}, + "own_claim": "none published as a number; the lab's X0 record: the same-node DRAM board 2.35x at the 5090 knee (set v0), 2.60x (set v3)", + "cells": { + "4090": {"status": "MEASURED", "session": "lab-cohort-ctl-v6 (COHORT, 11:49 to 12:30 UK, one chain)", "nj": 8368.9, "mhs": 30.673, "w": 256.7, "f": 0.848, "twin_nj": 7098.9, "spread_pct": 0.67, "clock": "stock (the pod refused -lgc); clocks_sm_median pending the ledger session", "pod": "vast 55009211, driver 580", "source": "build-1:/srv/artefacts/lab/ctl-v6/vast-55009211/ (rows.jsonl, SHA256SUMS); the cohort table build-1:/srv/artefacts/lab/cohort/TABLE.md", "note": "the lab's cohort cell (median of three); the second uncapped 4090 (vast 55006526) read 8,751; the ledger session's own row replaces this cell when it lands"}, + "5090": {"status": "MEASURED", "session": "lab-cohort-ctl-v6 (COHORT, 11:49 to 12:30 UK, one chain)", "nj": 5597.1, "mhs": 68.661, "w": 384.3, "f": 0.811, "twin_nj": 4537.6, "spread_pct": 2.11, "clock": "stock (the pod refused -lgc); the host cap 500 W, the card drew 384", "pod": "vast 55006481, driver 580", "source": "build-1:/srv/artefacts/lab/ctl-v6/vast-55006481/; the cohort table build-1:/srv/artefacts/lab/cohort/TABLE.md", "note": "the lab's cohort cell; the ledger session's uncapped-host row replaces it when it lands"} + }, + "adversary": { + "status": "WITNESS (modelled, complete machine, instruction convention)", + "board": {"low": 1329, "nominal": 1542, "high": 1941, "design": "GDDR7 board + register file sized to the work + fused operations, N5", "split_nj": "memory 527 / ALU 166 / tax 849"}, + "die": {"nominal": 335, "design": "N2 full-SRAM die, the coexistence row"}, + "premise": {"4090": "1.01x to 1.03x (f 0.853 measured)", "5090": "1.02x to 1.03x (f 0.811 measured on the stock pod)"}, + "source": "docs/analysis/class-v6/1p5x/lab/adv/v3/ledger-rows.md and ledger-rows.json (class-v6-adversary 47f16b86f); build-1:/srv/artefacts/lab/adv/rows/ctl-v6.json and rows.md (set v3, 2026-10-09T11:33Z); the die 12.0x at the 5090 knee, USD 0.77 per MH/s" + }, + "real_chip": null, + "phases": { + "status": "WITNESS; phase B NOT LIVE until a shipped package runs a prover", + "A": "before investment (24 months, the mining share 80 percent of the year-1 subsidy): the same-node board maker recovers its spend on NO fleet from 100 to 100 M boards on the growing or flat price path (100,000 boards: net USD -55.4 M on 58.8 M revenue growing; -37.6 M on 76.6 M flat); only the falling path pays it; the N2 die recovers on no path", + "B": "spend sunk, flat path at USD 0.10 per kWh, the chip at 10 percent of the hash: mining revenue USD 0.354 per TH; the GPU's proving income at the ratified 20 percent share USD 0.098 per TH against the board chip's operating advantage USD 0.046 per TH (GPU electricity 0.111 less the chip's electricity, hosting and maintenance 0.066): the GPU out-earns the built board chip; the cancelling proving share 9 percent (board), 13 (hybrid), 20 (die)", + "income_a_chip_cannot_earn": "yes by rule (the proving share of every block, 20 percent ratified); LIVE ON DEVNET with on-chain paid records (663 paid v1 segment records to 30 prover keys on chain 4465, the PROVING LIVE lane's file bd3f53c1 on build-1), not yet in a shipped package", + "source": "build-1:/srv/artefacts/lab/adv/rows/rows.md (the two-phase section), ADVERSARY commit 545f3f8a0; ctl-v6-coexistence.json" + } + }, + { + "id": "rvn-kawpow", + "chain": "Ravencoin", + "algorithm": "KAWPOW (ProgPoW 0.9.4 with Ravencoin's kiss99 constants, 7,500-block epochs and a 512-parent DAG; live since block 1,219,736, 6 May 2020)", + "control": "ctl-progpow-094", + "pin": "ifdefelse/ProgPOW d035ae56536d2e6fc71aad609ac5085c9785d1b3, the reference's own CUDA kernel text, DAG generator and light cache (256 parents as the code implements); harness progpow-094/gpu/pp_harness_, CPU reference cpu/pp094_ref; build-1:/srv/artefacts/lab/controls/progpow-094/ (SHA256SUMS)", + "dataset_bytes": 6182403712, + "dataset_note": "KAWPOW's current DAG size at Ravencoin height 4,573,707 (epoch 609, read 13:0x UK): the official ProgPoW 0.9.4 kernel built at Ethash block 18,270,000 (epoch 609, the same byte count), harness progpow-094/gpu/pp_harness_18270000; KAWPOW's own constants NOT applied, so the row is 'ProgPoW 0.9.4 official at KAWPOW's DAG size (proxy)'; 64 coalesced 256-byte reads per hash; F1 GPU = CPU on both nonces (cpu/vectors-094-kawpow-size-18270000.txt)", + "twin": "yes, by construction (progpow-094/gpu/pp_twin 18270000 26 250: the 64 dependent entry reads per 16-lane hash)", + "split": {"mining": 100, "proving": 0, "source": "Ravencoin's block reward goes to the miner in full (no second income to GPUs)"}, + "public": {"block_reward": "1,250 RVN", "block_time": "60 s", "network_hash": "721.3 GH/s", "price_usd": "0.0022", "source": "minerstat.com/coin/RVN, read 9 October 2026 13:3x UK (public figures, not measured by the lab)"}, + "own_claim": "the ProgPoW README (the pinned commit) states a specialised chip gains 1.1x to 1.2x on ProgPoW's premise (the chip keeps a GPU-class datapath). The figure 1.5x quoted in the ledger's brief as Ravencoin's own claim has no source in the pinned text or on the record: NOT FOUND; the row carries the README's 1.1x to 1.2x", + "cells": { + "4090": {"status": "MEASURED (prior row: kawpowminer, not the pinned kernel; a PROXY until the ledger session's pinned-kernel row lands)", "session": "comparative-lane a2ed5c31 (RunPod, one chain, an earlier session)", "nj": 6920, "mhs": 58.95, "w": 409, "f": null, "twin_nj": null, "spread_pct": null, "clock": "stock", "pod": "RunPod, the comparative lane a2ed5c31", "source": "build-1:/srv/artefacts/lab/adv/rows/rows.md (the ctl-progpow-094 section, card rows)", "note": "407 to 411 W at 58.95 MH/s; the ledger session re-measures with the pinned official kernel at Raven's DAG size (CONTROLS' rate-only read on a 4090 at stock: 58.95 MH/s full, the twin 60.99), board power sampled, median of three, the twin beside it"}, + "5090": {"status": "pending (COHORT, the ledger session)", "session": "pending", "nj": null, "mhs": null, "w": null, "f": null, "twin_nj": null, "spread_pct": null, "clock": "stock", "pod": "pending", "source": "pending", "note": ""} + }, + "adversary": { + "status": "WITNESS (modelled on the kawpowminer census as the work proxy until CONTROLS' trace replaces it)", + "board": {"low": 1453, "nominal": 1757, "high": 2147, "design": "GDDR7 board + register file sized to the work + fused operations, N5; bandwidth-bound at 16 KB per hash (93 MH/s per board)", "split_nj": "memory 647 / ALU and tax per rows.md"}, + "die": {"nominal": 697, "design": "N2 full-SRAM die, the coexistence row (USD 1.89 per MH/s); the cheapest specialist of any kind is near-memory base dies at 669 nJ"}, + "premise": {"4090": "1.10x to 1.20x (the premise's own figure; no measured twin on this kernel yet)", "5090": "1.10x to 1.20x (the premise's own figure; the twin row makes it measured)"}, + "source": "docs/analysis/class-v6/1p5x/lab/adv/v3/ledger-rows.md and ledger-rows.json (class-v6-adversary 47f16b86f); build-1:/srv/artefacts/lab/adv/rows/ctl-progpow-094.json (set v3)" + }, + "real_chip": null, + "phases": { + "status": "WITNESS, the chain's own units, the 100/0 split, the same 24-month life, design cost and fleet rule as v6, the three price paths (flat at the public price, x2 growing, x0.5 falling, the hash held); the public lines on the row", + "A": "before investment: no fleet from 100 to 100 M machines recovers a board chip's spend on any path, because Ravencoin's whole mining emission over 24 months (about USD 2.9 M at the public price) sits below one USD 35 M design cost; 10,000 boards would take 56 percent of the 721 GH/s network and earn USD 1.6 M to 2.4 M against a USD 44 M spend", + "B": "spend sunk, mining only: mining revenue USD 0.064 per TH of the chain's own hashes; the board chip's recurring cost USD 0.069 per TH at ten cents; the chip's operating advantage over the RTX 4090 at stock (6,920 nJ) USD 0.123 per TH (the GPU's electricity 0.192 less the chip's 0.069) stands in full, no prover income", + "income_a_chip_cannot_earn": "no (the block reward is mining only)", + "source": "docs/analysis/class-v6/1p5x/lab/adv/v3/ctl-progpow-094-coexistence.json (rows[].phase_a, rows[].phase_b_split; method lab/adv/README.md section 14), ADVERSARY commit d7db3e596 on class-v6-adversary" + } + }, + { + "id": "firo-firopow", + "chain": "Firo", + "algorithm": "FiroPoW (ProgPoW 0.9.4 with Firo's constants; live since block 419,264, 26 October 2021)", + "control": "ctl-progpow-094 (the same row as KAWPOW)", + "pin": "as KAWPOW: the pinned ProgPoW 0.9.4 reference; FiroPoW differs from KAWPOW only in its constants and DAG schedule, so the lab serves ONE row for both and says so", + "dataset_bytes": null, + "dataset_note": "= KAWPOW's row (its own DAG schedule is not measured separately)", + "twin": "as KAWPOW", + "split": {"mining": 100, "proving": 0, "source": "Firo's block reward splits between miners, masternodes and the development fund; the GPU's share is mining only (no proving income)"}, + "own_claim": "as ProgPoW's: 1.1x to 1.2x on its premise", + "same_row_as": "rvn-kawpow", + "cells": {}, + "adversary": {"status": "= KAWPOW's row", "board": null, "die": null, "premise": {}, "source": "as KAWPOW"}, + "real_chip": null, + "phases": {"status": "= KAWPOW's row at a 100/0 split", "A": "as KAWPOW", "B": "as KAWPOW", "income_a_chip_cannot_earn": "no", "source": "as KAWPOW"} + }, + { + "id": "ironfish-fishhash", + "chain": "Iron Fish", + "algorithm": "FishHash (live since hardfork 1, April 2024)", + "control": "ctl-fishhash", + "pin": "iron-fish/fish-hash 823531c002e78259759f8b1f36ac9121c32059b1 (cpp/FishHash.cpp; the spec FishHash.pdf sha256 869870b9...); the lab's CUDA implementation bit-exact with the library on 64 items and 256 hashes, fingerprint f841605125ce375e; gpu/fh_cuda, cpu/fh_cli; build-1:/srv/artefacts/lab/controls/fishhash/ (SHA256SUMS)", + "dataset_bytes": 4831835776, + "dataset_note": "37,748,717 items of 128 bytes, FIXED (no epochs); 96 random 128-byte reads per hash, 9,856 lane-instructions", + "twin": "yes (a trace replay of the kernel's own item indexes; its energy read as a bound: the twin runs 10 percent slower than the full kernel)", + "split": {"mining": 100, "proving": 0, "source": "Iron Fish's block reward is mining only"}, + "public": {"block_reward": "17.25 IRON", "block_time": "61 s", "network_hash": "229.5 GH/s", "price_usd": "0.07", "source": "minerstat.com/coin/IRON, read 9 October 2026 13:3x UK (public figures, not measured by the lab)"}, + "own_claim": "none as a chip-edge number; the Trail of Bits review (Iron Fish blog, 14 May 2024) is the published outside check", + "cells": { + "4090": {"status": "pending (COHORT, the ledger session); CONTROLS' rate-only read 19.73 MH/s at stock, no sampler", "nj": null, "mhs": 19.73, "w": null, "f": null, "twin_nj": null, "spread_pct": null, "clock": "stock", "pod": "CONTROLS' rented 4090 (rate only)", "source": "build-1:/srv/artefacts/lab/controls/fishhash/gpu/bench-4090.log", "note": "242 GB/s of 128-byte lines at that rate"}, + "5090": {"status": "pending (COHORT, the ledger session); CONTROLS' rate-only sm_120 read 45.37 MH/s full, 39.71 twin, F1 PASS", "nj": null, "mhs": 45.37, "w": null, "f": null, "twin_nj": null, "spread_pct": null, "clock": "stock", "pod": "CONTROLS' rented 5090 (rate only)", "source": "build-1:/srv/artefacts/lab/controls/fishhash/ (fishhash.md)", "note": ""} + }, + "adversary": { + "status": "WITNESS (modelled; the card's cell pending, so the ratio is pending)", + "board": {"low": 881, "nominal": 1051, "high": 1257, "design": "GDDR7 board + register file sized to the work + fused operations, N5; bandwidth-bound at 124 MH/s per board; 95 percent of the board's energy is the memory path", "split_nj": "memory 529 / ALU 46 / tax 503"}, + "die": {"nominal": 170, "design": "full SRAM dies (three N2 reticles) + sized + fused operations"}, + "premise": {"4090": "pending (needs the measured f from the twin)", "5090": "pending"}, + "source": "build-1:/srv/artefacts/lab/adv/rows/ctl-fishhash.json and rows.md (set v3)" + }, + "real_chip": null, + "phases": {"status": "WITNESS, the chain's own units, the 100/0 split, the same life, design cost, fleet rule and price paths as v6; the GPU side of phase B NOT RUN until COHORT's card rows", "A": "before investment: no fleet from 100 to 100 M machines recovers a board chip's spend on any path; Iron Fish's whole mining emission over 24 months is about USD 1.4 M at the public price (10,000 boards would take 84 percent of the hash for USD 1.1 M to 1.6 M)", "B": "spend sunk, mining only: mining revenue USD 0.086 per TH of the chain's own hashes; the board chip's recurring cost USD 0.043 per TH at ten cents; the GPU side NOT RUN until the card cell lands; no prover income by construction", "income_a_chip_cannot_earn": "no", "source": "docs/analysis/class-v6/1p5x/lab/adv/v3/ctl-fishhash-coexistence.json, ADVERSARY commit d7db3e596 on class-v6-adversary"} + }, + { + "id": "etc-etchash", + "chain": "Ethereum Classic", + "algorithm": "Etchash (Ethash with ECIP-1099's 60,000-block epochs; live since block 11,700,000, November 2020)", + "control": "ctl-etchash (new for the ledger)", + "pin": "a CUDA hashimoto over the pinned chfast/ethash v0.8.0 library's light cache and the ProgPOW repo's reference DAG generator (libethash objects), checked against ethash::hash on the CPU at block 0 and at the live epoch (F1: GPU = CPU on both nonces); gpu/etchash_cuda (`check `, `bench 22 250`, `bench 22 250 twin`), cpu/etc_ref; build-1:/srv/artefacts/lab/controls/etchash/ (SHA256SUMS; etchash.md)", + "dataset_bytes": 4638898816, + "dataset_note": "ETC height 25,502,946 (read 12:5x UK) = Etchash epoch 425 (ECIP-1099: height / 60,000), the harness's block argument 12,750,000 (the Ethash epoch with the same size table index); 64 coalesced 128-byte reads per hash (two 64-byte half-mixes); CONTROLS' rate-only read on a 4090 at stock 29.90 MH/s full and 29.90 twin (memory-bound)", + "twin": "yes, by construction", + "split": {"mining": 100, "proving": 0, "source": "ETC's block reward is mining only"}, + "public": {"block_reward": "2.048 ETC", "block_time": "16 s", "network_hash": "120.9 TH/s", "price_usd": "8.24", "source": "minerstat.com/coin/ETC, read 9 October 2026 13:3x UK (public figures, not measured by the lab)"}, + "own_claim": "none; the chain accepts chips (the Antminer E9 Pro mines it)", + "cells": { + "4090": {"status": "pending (COHORT, the ledger session; the harness staged 13:0x UK); CONTROLS' rate-only read 29.90 MH/s", "nj": null, "mhs": 29.90, "w": null, "f": null, "twin_nj": null, "spread_pct": null, "clock": "stock", "pod": "CONTROLS' rented 4090 (rate only)", "source": "build-1:/srv/artefacts/lab/controls/etchash/ (etchash.md)", "note": ""}, + "5090": {"status": "pending (COHORT, the ledger session; the sm_120 build from etchash/src)", "nj": null, "mhs": null, "w": null, "f": null, "twin_nj": null, "spread_pct": null, "clock": "stock", "pod": "pending", "source": "pending", "note": ""} + }, + "adversary": { + "status": "WITNESS (modelled; the card cells pending, so the ratios are pending)", + "board": {"low": 638, "nominal": 765, "high": 919, "design": "GDDR7 board + register file sized to the work + fused operations, N5; USD 3.25 per MH/s", "split_nj": "per ledger-rows.md"}, + "die": {"nominal": 177, "design": "N2 full-SRAM die, the coexistence row"}, + "premise": {"4090": "1.10x to 1.20x (the premise's own figure; the twin row makes it measured)", "5090": "1.10x to 1.20x (the premise's own figure)"}, + "source": "docs/analysis/class-v6/1p5x/lab/adv/v3/ledger-rows.md and ledger-rows.json (class-v6-adversary 47f16b86f, wording 82330b04c)", + "calibration": "the modelled same-node DRAM board 765 nJ per hash against the Antminer E9 Pro's 598 from its public figures: the model reads 1.28x PESSIMISTIC for the chip (it gives the chip more energy than the one real chip spends); a witness, never a ceiling" + }, + "real_chip": { + "name": "Bitmain Antminer E9 Pro", + "mhs": 3680, + "w": 2200, + "nj": 597.8, + "status": "WITNESS (a manufacturer's published figure, not measured by the lab)", + "source": "Bitmain's stated figures as listed on minerstat's hardware page (https://minerstat.com/hardware/antminer-e9-pro): 3.68 GH/s on Ethash at 2,200 W, release 2023-02; 2,200 W / 3,680 MH/s = 0.598 J per MH = 598 nJ per hash", + "note": "the ONE live GPU-mined chain with a chip on the market; the modelled board (765 nJ) sits beside it: 1.28x pessimistic for the chip" + }, + "phases": {"status": "WITNESS, the chain's own units, the 100/0 split, the same life, design cost, fleet rule and price paths as v6; the GPU side of phase B NOT RUN until COHORT's card rows", "A": "before investment: no fleet from 100 to 100 M machines recovers a board chip's spend on any path; ETC's whole mining emission over 24 months is about USD 83 M at the public price, but 10,000 boards are 2 percent of 120.9 TH/s and earn USD 1.0 M to 1.5 M, and 100,000 boards (13 percent) USD 9 M to 13 M against a USD 150 M spend", "B": "spend sunk, mining only: mining revenue USD 0.0087 per TH of the chain's own hashes, below even the modelled board's recurring cost (USD 0.031 per TH) and below the E9 Pro's own electricity at ten cents (598 nJ = USD 0.017 per TH): at the public figures nobody mines ETC at a profit at ten cents and phase B is a loss on both sides; the GPU side NOT RUN until the card cell lands", "income_a_chip_cannot_earn": "no", "source": "docs/analysis/class-v6/1p5x/lab/adv/v3/ctl-etchash-coexistence.json, ADVERSARY commit d7db3e596 on class-v6-adversary"} + }, + { + "id": "ergo-autolykos2", + "chain": "Ergo", + "algorithm": "Autolykos2 (k = 32, n = 26, Blake2b-256; the table grows 5 percent every 51,200 blocks)", + "control": "ctl-autolykos (new for the ledger, landed 13:1x UK)", + "pin": "the published text ergoplatform/ergo master 3a6b00d3, AutolykosPowScheme.scala (sha256 330ae870...; the copy in src/), implemented in-house: CPU reference src/autolykos_ref.py (hashlib's Blake2b, lazy elements), GPU gpu/autolykos_cuda (`check < fixtures`, `bench 20 250`, `bench ... twin`; sm_89, the sm_120 build from src); F1 at N = 65,536 and at the live table: elements 0 and last, 64 hits and the 256-hit fingerprints equal the reference's (f3cf1fd34d1002fa small, b6d07a7b15956179 live); build-1:/srv/artefacts/lab/controls/autolykos/ (SHA256SUMS; autolykos.md). CAVEAT on the row: the fixtures are the lab's own from an independent implementation of the published text (the reference repository has no known-answer v2 hit vector); the end-to-end check against a live Ergo block is owed, not claimed", + "dataset_bytes": 7272058080, + "dataset_note": "the live table at Ergo height 1,890,820 (api.ergoplatform.com, 13:0x UK): N = 227,251,815 elements of 32 bytes (+5 percent at height 1,894,400; the row names its height); 33 random 32-byte reads per hash; the table builds on the device in 1.5 s; CONTROLS' rate-only read on a 4090 at stock 216.2 MH/s full, 201.8 twin", + "twin": "yes (a trace replay)", + "split": {"mining": 100, "proving": 0, "source": "Ergo's block reward is mining only"}, + "public": {"block_reward": "3.009 ERG", "block_time": "120 s", "network_hash": "569.1 GH/s", "price_usd": "0.29", "source": "minerstat.com/coin/ERG, read 9 October 2026 13:4x UK (public figures, not measured by the lab)"}, + "own_claim": "none on the record as a chip-edge number", + "cells": { + "4090": {"status": "pending (COHORT, the ledger session; the harness staged 13:1x UK); CONTROLS' rate-only read 216.2 MH/s full, 201.8 twin", "session": "pending", "nj": null, "mhs": 216.2, "w": null, "f": null, "twin_nj": null, "spread_pct": null, "clock": "stock", "pod": "CONTROLS' rented 4090 (rate only)", "source": "build-1:/srv/artefacts/lab/controls/autolykos/ (autolykos.md)", "note": ""}, + "5090": {"status": "pending (COHORT, the ledger session; the sm_120 build from src)", "session": "pending", "nj": null, "mhs": null, "w": null, "f": null, "twin_nj": null, "spread_pct": null, "clock": "stock", "pod": "pending", "source": "pending", "note": ""} + }, + "adversary": {"status": "pending (ADVERSARY: the chip rows from CONTROLS' trace; default 15:00 UK, else pending (adversary))", "board": null, "die": null, "premise": {"4090": "pending", "5090": "pending"}, "source": "pending"}, + "real_chip": null, + "phases": {"status": "pending (ADVERSARY at the 100/0 split, the public line on the row)", "A": "pending (ADVERSARY)", "B": "pending (ADVERSARY); no prover income by construction", "income_a_chip_cannot_earn": "no", "source": "pending"} + } + ], + "claim": { + "ordered_sentence": "the lowest measured chip-to-GPU edge of any live GPU network under a published method, on both conventions, and the only one whose GPUs earn income a chip cannot", + "headline_rule": "the headline reads only what the like-for-like rows support, clause by clause (main's ruling, 13:2x UK 9 October 2026); under the ledger's own convention the measured edge per chain on the same card and state is stated as numbers, with no ranking word until the rows say so after the ledger session", + "clauses": [ + {"text": "under ProgPoW's own convention, the lowest measured chip-to-GPU edge of the chains on this ledger", "convention": "ProgPoW's premise (a chip that keeps a GPU-class datapath)", "state": "SUPPORTED on the current rows", "why": "Igneum v6 1.01x to 1.03x (its measured f 0.81 to 0.85) against ProgPoW's own 1.10x to 1.20x for KAWPOW and FiroPoW; FishHash and Etchash pending their twins"}, + {"text": "under the ledger's convention (the cheapest credible programmable specialist, adversarial set v3), each chain's measured edge on the same card and state, as numbers", "convention": "ours", "state": "NUMBERS ONLY; no ranking until the ledger session (COHORT, both cards, every chain back to back, the pinned 0.9.4 kernel, twins; 14:45 UK)", "why": "the current cells come from different sessions (the lab's cohort pods for v6, the comparative lane's pod for KAWPOW) and a cross-chain comparison is made only between cells from the same card, state and session; at the RTX 4090 at stock the cells read v6 5.4x (5.67x on the second pod) and KAWPOW 3.9x (a proxy row from an earlier session); FishHash and Etchash pending"}, + {"text": "and the only chain on this ledger whose GPUs are paid, by rule, an income a hash chip cannot earn", "convention": "phase B, each chain's actual reward split", "state": "LABELLED BY THE PROVING LIVE LANE", "why": "the proving share (20 percent ratified) is paid to GPUs for work a hash chip cannot do; every other chain on the ledger pays mining only; the live state of that income is the PROVING LIVE lane's evidence line"} + ], + "withdrawn": "the earlier line 'KAWPOW and FiroPoW read 5 to 6x on the measured 4090 rows and v6 reads 2.35x' is withdrawn: it compared v6 at the 5090's 1,300 MHz knee with KAWPOW at the 4090 at stock, two cards and two states; the like-for-like cells are the ones on this ledger", + "proving_live_label": "LIVE ON DEVNET, on-chain records (the PROVING LIVE lane, read 11:50:22Z 9 October 2026): on chain id 4465 (the Igneum 2.0 devnet) 663 paid v1 segment records (8 shards plus aggregation each) = 653.93 IGN paid from the proving pool to 30 distinct prover keys across chain blocks 3,000 to 30,687 (tip 31,719 at the read), plus 6,474 paid v0 shard records = 7,196 IGN; read by igneum_getProvingStatus, igneum_getSegmentRecords (3,965 segments) and igneum_getSegment; evidence build-1:/srv/artefacts/proving-live/prov-ledger-4465-tip31719-115022Z.json sha256 bd3f53c18c3ffa20354ea62ade9fd5e7a5794202a71c3c369a5be71484f7143a. NOT YET LIVE IN A SHIPPED PACKAGE: the payees are the fleet's prover stack (the same binaries the 2.0.3.1 HiveOS package wraps, cut 18:00 UK); the apps' prover is on by default on 24 GB cards but no app-proved record is on the record yet; a full-epoch line follows by 16:00 UK" + } +} diff --git a/docs/design/proving-claim-order.md b/docs/design/proving-claim-order.md new file mode 100644 index 000000000..73e20bafe --- /dev/null +++ b/docs/design/proving-claim-order.md @@ -0,0 +1,44 @@ +# Proving claim order (9 October 2026) + +How segments are allocated among provers today, what it wastes, and the rule change proposed for the node after 2.0.3. Nothing in this document changes the chain today. Approved as a design item by main at 13:2x UK on 9 October 2026, after the PROVING LIVE lane's on-chain read. + +## The rule today, by file and line (node 27f54124, release-2.0.3 line) + +| step | rule | where | +|---|---|---| +| assignment | 8 assignees per shard, drawn deterministically from the distinct prover keys seen in the record window (`assign(epoch_seed, block, shard, window)`) | consensus/core/src/proving.rs:26, :255 | +| exclusive window | inside the first 10 DAA after a segment only an assignee's record is paid; after that every key may prove it | consensus/core/src/proving.rs:30, :305 | +| payment | the first valid record carried in a block is paid; every later record for the same segment is refused "segment already paid" | igneum/exec/src/proving.rs:551 to :572 (`carried_payouts`), `segment_status` Proven | +| pool share | 20 percent of every block subsidy, split over the segment's shards with 1,000 bps to the aggregator | consensus/core/src/igneum.rs:44, :87; consensus/core/src/proving.rs:638 (`split_pool_credit`) | +| leases | V6-08 leases (300 DAA, three abandons an hour, 120 DAA penalty) exist in the node but are node-local and OFF on the live nodes (`igneum_getProvingStatus` reports `leases: null`; `IGNEUM_PROVING_LEASES` unset) | igneum/exec/src/proving.rs:110, :129 | +| the prover's pick | every whole, open, unpaid segment of the last 600 chain blocks whose deadline (last DAA + 600) is at least 240 DAA ahead, ranked by FNV-1a(first, key): a per-key random order | tools/fleet/box-prover.py `candidates()` | + +No stake, no queue, no price. A new key is not an assignee until its first record is carried (10 seconds of exclusivity it cannot use, nothing more); from then on it competes at first-valid-record-wins with the same random order as every other key. + +## What it costs, measured on Devnet 4 (chain id 4465) + +Read on 9 October 2026 at 11:50:22Z from lp-4090-02's node (`igneum_getSegmentRecords` for every one of 3,965 v1 segments from genesis to chain block 31,719; the file is build-1:/srv/artefacts/proving-live/prov-ledger-4465-tip31719-115022Z.json, sha256 bd3f53c18c3ffa20354ea62ade9fd5e7a5794202a71c3c369a5be71484f7143a). + +| carried segment records | count | share | +|---|---|---| +| paid (first valid record) | 663 | 30 percent | +| refused "segment already paid" (a duplicate proof of a paid segment) | 952 | 43 percent | +| refused "unproven" (carried after the segment's deadline) | 461 | 21 percent | +| refused "block ... is not chain block N on this chain" (proved on a fork) | 77 | 4 percent | +| refused on the chain link ("segment ... does not chain to ...") | 46 | 2 percent | +| total carried | 2,199 | | + +In the morning's run alone (chain blocks 28,000 to 30,999, about 06:00 to 11:00Z, 30 to 40 provers on one chain): 148 segments paid, 369 duplicate records refused, 109 late records refused. Two and a half duplicate proofs for every paid one: with 30 to 40 provers over about 22 claimable segments at a time (the margin window is 360 DAA wide at 2 DAA per chain block and 8 blocks per segment), the per-key random order collides by chance, and every collision is a 120-second GPU proof thrown away. + +Capacity: 3,600 DAA an epoch = about 1,817 chain blocks = about 227 segments an hour at 0.505 chain blocks per DAA; one 4090 proves a segment in 120 to 185 seconds beside its miner, so the work saturates at 8 to 11 provers and every prover past that dilutes the fixed 20 percent as 1/N. The 663 paid segments went to 30 keys with a median of 4 and a maximum of 230 per key; the skew is uptime (which boxes were on the chain when), not the rule. + +## The proposal (node change after 2.0.3; nothing on the chain today) + +Two consensus-free changes, both node-local, both deterministic from data every node already holds: + +1. Template side (the producer): when a template is built and the pool holds more than one verified record for a segment, carry the record of the key whose FNV-1a(first, key) is smallest, not the first received. A duplicate still costs the prover its proof, but the pick no longer depends on network arrival order, so a prover that ranks itself can predict whether its proof will be the one carried. +2. Prover side (box-prover.py and the app's prover): claim a segment only when the key's rank by FNV-1a(first, key) among the keys in the record window is below ceil(K / M), with K the number of keys in the window and M the number of claimable segments in the margin; otherwise take the next segment in its own order. With the template rule above this makes the carried record and the claimed record the same one in expectation, and the duplicate rate falls to the rate of keys that join or leave inside one margin window. + +Default: the prover side ships first (a script change, no node release); the template side rides the first node cut after 2.0.3 with a fast-time case (two provers, one segment, the lower rank carried). Measured target: duplicates under 10 percent of carried records over an epoch, read the same way as the table above. + +What this is not: not a lease (leases are node-local and cannot order claims across boxes), not a stake, not a queue a newcomer waits in. A new key's rank is as random as any other's from its first record. diff --git a/docs/ledger/gpu-ledger.md b/docs/ledger/gpu-ledger.md new file mode 100644 index 000000000..a19355996 --- /dev/null +++ b/docs/ledger/gpu-ledger.md @@ -0,0 +1,136 @@ +# The GPU network ledger + +Every live GPU-mined chain we could pin, measured the same way on the same rented cards in the same sessions, with the same +chip-design method applied to each, and ranked. Igneum sits in the table as one row among the others, under the same rules. Every +number is measured or a labelled model with its source; a number that does not exist yet says "pending" and names who owes it; a +chain we could not run in-house says NOT RUN and why. The full record with the lane bookkeeping is in the repository at +docs/analysis/class-v6/1p5x/ledger/ (README.md and ledger.json); this page is rendered from the same data file. + + +Data: ledger.json, stamp 2026-10-09, adversarial set v3 (build-1:/srv/artefacts/lab/adv/ (README.md, design-notes/adversarial-sets-v1-v2-v3.md, rows/, SHA256SUMS); set v3 commit b2b9ee0b9 on class-v6-adversary). + + +## The method, the same for every chain + +1. **The object.** Each chain's proof of work as its own pinned reference code, built from source (no downloaded miner binaries): + Igneum's frozen class v6 at its live 4 GiB dataset; the official ProgPoW 0.9.4 reference kernel for Ravencoin's KAWPOW (which is + ProgPoW 0.9.4 with Ravencoin's constants, so the row is a labelled proxy) and the same row for Firo's FiroPoW; Iron Fish's + FishHash reference library with a bit-exact CUDA port; the pinned chfast/ethash library's hashimoto at Ethereum Classic's + current epoch; Ergo's Autolykos2 NOT RUN (the reason on the row). +2. **The card rows.** One rented RTX 4090 and one rented RTX 5090 on uncapped hosts, every chain back to back in one session per + card at stock clocks; board power sampled at 1 Hz (idle not subtracted); nJ per hash = watts over MH/s; three runs, the median + with its spread; the dataset size and the card's clock on every row; a read-only twin (the same memory reads, the arithmetic + cut) where the harness has one, giving the card's memory share f. +3. **The chip rows.** For each chain, the cheapest credible specialist chip on the same process node as the card, as a complete + machine, modelled and labelled as a model (never measured): the DRAM-board chip is the energy row, the full-SRAM die the + residual. Two conventions beside every ratio: ours (the cheapest programmable core, fused where the work allows) and ProgPoW's + own premise (the chip must keep a GPU-class datapath, so its edge is 1.1x to 1.2x on the compute term, weighted by f). +4. **The real chip.** Ethereum Classic is the one chain here with a chip on the market, the Antminer E9 Pro; its published rate + and power sit on the row, and our modelled chip for Etchash sits beside it as the calibration of the model. +5. **The two phases.** Before investment: can a chip maker recover its spend under growing, flat and falling prices. After, with + the spend sunk: who exits first on operating cost, with each chain's actual reward split. On Igneum a GPU earns the mining share + plus the proving share (80 / 20); a hash chip earns the mining share only. On every other chain here the GPU earns mining only, + so the second-income term is zero by construction. +6. **The ranking.** (a) ascending on the DRAM-board ratio under our convention at the worse of the two cards (the lower ratio is + the smaller chip edge); (b) the same under ProgPoW's premise; (c) whether the chain's GPUs earn an income a hash chip cannot. A + chain with a pending or proxy cell is ranked provisionally and says so; a NOT RUN chain is unranked. + +## The card rows (measured, board power, stock) + + +| chain | algorithm | dataset on the row | reward split (mining / proving) | RTX 4090 stock: nJ per hash (MH/s, W, f) | RTX 5090 stock: nJ per hash (MH/s, W, f) | twin | sources | +|---|---|---|---|---|---|---|---|---| +| Igneum | class v6, the live signing object 0x2a1d6caab4c24564 (2.0 devnet, chain id 4465) | 4.29 GB (4,294,967,296 bytes); 2^30 words, the live policy (70a6c703); 256 random 4-byte reads per hash, 62,120 instructions per hash (instruction convention) | 80 / 20 (the Token Value volume on master (D04, token-value/README.md: the 80/20 emission allocation); PROVING_POOL_SHARE_PERCENT) | 8,369 MEASURED (30.67 MH/s, 256.7 W, f 0.848; spread 0.67%; vast 55009211, driver 580; stock (the pod refused -lgc); clocks_sm_median pending the ledger session) | 5,597 MEASURED (68.66 MH/s, 384.3 W, f 0.811; spread 2.11%; vast 55006481, driver 580; stock (the pod refused -lgc); the host cap 500 W, the card drew 384) | yes (the same address stream, the arithmetic cut) | RTX 4090: build-1:/srv/artefacts/lab/ctl-v6/vast-55009211/ (rows.jsonl, SHA256SUMS); the cohort table build-1:/srv/artefacts/lab/cohort/TABLE.md; RTX 5090: build-1:/srv/artefacts/lab/ctl-v6/vast-55006481/; the cohort table build-1:/srv/artefacts/lab/cohort/TABLE.md | +| Ravencoin | KAWPOW (ProgPoW 0.9.4 with Ravencoin's kiss99 constants, 7,500-block epochs and a 512-parent DAG; live since block 1,219,736, 6 May 2020) | 6.18 GB (6,182,403,712 bytes); KAWPOW's current DAG size at Ravencoin height 4,573,707 (epoch 609, read 13:0x UK): the official ProgPoW 0.9.4 kernel built at Ethash block 18,270,000 (epoch 609, the same byte count), harness progpow-094/gpu/pp_harness_18270000; KAWPOW's own constants NOT applied, so the row is 'ProgPoW 0.9.4 official at KAWPOW's DAG size (proxy)'; 64 coalesced 256-byte reads per hash; F1 GPU = CPU on both nonces (cpu/vectors-094-kawpow-size-18270000.txt) | 100 / 0 (Ravencoin's block reward goes to the miner in full (no second income to GPUs)) | 6,920 MEASURED (prior row: kawpowminer, not the pinned kernel; a PROXY until the ledger session's pinned-kernel row lands) (58.95 MH/s, 409.0 W, f none; spread none; RunPod, the comparative lane a2ed5c31; stock) | pending: pending (COHORT, the ledger session) | yes, by construction (progpow-094/gpu/pp_twin 18270000 26 250: the 64 dependent entry reads per 16-lane hash) | RTX 4090: build-1:/srv/artefacts/lab/adv/rows/rows.md (the ctl-progpow-094 section, card rows) | +| Firo | FiroPoW (ProgPoW 0.9.4 with Firo's constants; live since block 419,264, 26 October 2021) | = Ravencoin's row | 100 / 0 | = Ravencoin's row | = Ravencoin's row | as Ravencoin | as KAWPOW: the pinned ProgPoW 0.9.4 reference; FiroPoW differs from KAWPOW only in its constants and DAG schedule, so the lab serves ONE row for both and says so | +| Iron Fish | FishHash (live since hardfork 1, April 2024) | 4.83 GB (4,831,835,776 bytes); 37,748,717 items of 128 bytes, FIXED (no epochs); 96 random 128-byte reads per hash, 9,856 lane-instructions | 100 / 0 (Iron Fish's block reward is mining only) | pending: pending (COHORT, the ledger session); CONTROLS' rate-only read 19.73 MH/s at stock, no sampler (rate only 19.73 MH/s) | pending: pending (COHORT, the ledger session); CONTROLS' rate-only sm_120 read 45.37 MH/s full, 39.71 twin, F1 PASS (rate only 45.37 MH/s) | yes (a trace replay of the kernel's own item indexes; its energy read as a bound: the twin runs 10 percent slower than the full kernel) | RTX 4090: build-1:/srv/artefacts/lab/controls/fishhash/gpu/bench-4090.log; RTX 5090: build-1:/srv/artefacts/lab/controls/fishhash/ (fishhash.md) | +| Ethereum Classic | Etchash (Ethash with ECIP-1099's 60,000-block epochs; live since block 11,700,000, November 2020) | 4.64 GB (4,638,898,816 bytes); ETC height 25,502,946 (read 12:5x UK) = Etchash epoch 425 (ECIP-1099: height / 60,000), the harness's block argument 12,750,000 (the Ethash epoch with the same size table index); 64 coalesced 128-byte reads per hash (two 64-byte half-mixes); CONTROLS' rate-only read on a 4090 at stock 29.90 MH/s full and 29.90 twin (memory-bound) | 100 / 0 (ETC's block reward is mining only) | pending: pending (COHORT, the ledger session; the harness staged 13:0x UK); CONTROLS' rate-only read 29.90 MH/s (rate only 29.90 MH/s) | pending: pending (COHORT, the ledger session; the sm_120 build from etchash/src) | yes, by construction | RTX 4090: build-1:/srv/artefacts/lab/controls/etchash/ (etchash.md) | +| Ergo | Autolykos2 (k = 32, n = 26, Blake2b-256; the table grows 5 percent every 51,200 blocks) | 7.27 GB (7,272,058,080 bytes); the live table at Ergo height 1,890,820 (api.ergoplatform.com, 13:0x UK): N = 227,251,815 elements of 32 bytes (+5 percent at height 1,894,400; the row names its height); 33 random 32-byte reads per hash; the table builds on the device in 1.5 s; CONTROLS' rate-only read on a 4090 at stock 216.2 MH/s full, 201.8 twin | 100 / 0 (Ergo's block reward is mining only) | pending: pending (COHORT, the ledger session; the harness staged 13:1x UK); CONTROLS' rate-only read 216.2 MH/s full, 201.8 twin (rate only 216.20 MH/s) | pending: pending (COHORT, the ledger session; the sm_120 build from src) | yes (a trace replay) | RTX 4090: build-1:/srv/artefacts/lab/controls/autolykos/ (autolykos.md) | + + +## The chip-to-GPU edge, both conventions + + +| chain | the cheapest credible same-node DRAM board (set v3, nJ per hash, band) | ratio at the RTX 4090 stock (ours) | ratio at the RTX 5090 stock (ours) | ProgPoW-premise ratio at the RTX 4090 | ProgPoW-premise ratio at the RTX 5090 | the die as the residual (nJ; ratio at the worse card) | real chip on the market | source | +|---|---|---|---|---|---|---|---|---| +| Igneum | 1,542 (1,329 to 1,941); GDDR7 board + register file sized to the work + fused operations, N5; split memory 527 / ALU 166 / tax 849; WITNESS (modelled, complete machine, instruction convention) | 5.43x (4.31 to 6.30) | 3.63x (2.88 to 4.21) | 1.01x to 1.03x (f 0.853 measured) | 1.02x to 1.03x (f 0.811 measured on the stock pod) | 335 (N2 full-SRAM die, the coexistence row); 25.0x | none on the market | docs/analysis/class-v6/1p5x/lab/adv/v3/ledger-rows.md and ledger-rows.json (class-v6-adversary 47f16b86f); build-1:/srv/artefacts/lab/adv/rows/ctl-v6.json and rows.md (set v3, 2026-10-09T11:33Z); the die 12.0x at the 5090 knee, USD 0.77 per MH/s | +| Ravencoin | 1,757 (1,453 to 2,147); GDDR7 board + register file sized to the work + fused operations, N5; bandwidth-bound at 16 KB per hash (93 MH/s per board); split memory 647 / ALU and tax per rows.md; WITNESS (modelled on the kawpowminer census as the work proxy until CONTROLS' trace replaces it) | 3.94x (3.22 to 4.76) | pending | 1.10x to 1.20x (the premise's own figure; no measured twin on this kernel yet) | 1.10x to 1.20x (the premise's own figure; the twin row makes it measured) | 697 (N2 full-SRAM die, the coexistence row (USD 1.89 per MH/s); the cheapest specialist of any kind is near-memory base dies at 669 nJ); 9.9x | none on the market | docs/analysis/class-v6/1p5x/lab/adv/v3/ledger-rows.md and ledger-rows.json (class-v6-adversary 47f16b86f); build-1:/srv/artefacts/lab/adv/rows/ctl-progpow-094.json (set v3) | +| Firo (= Ravencoin's row) | 1,757 (1,453 to 2,147); GDDR7 board + register file sized to the work + fused operations, N5; bandwidth-bound at 16 KB per hash (93 MH/s per board); split memory 647 / ALU and tax per rows.md; WITNESS (modelled on the kawpowminer census as the work proxy until CONTROLS' trace replaces it) | 3.94x (3.22 to 4.76) | pending | 1.10x to 1.20x (the premise's own figure; no measured twin on this kernel yet) | 1.10x to 1.20x (the premise's own figure; the twin row makes it measured) | 697 (N2 full-SRAM die, the coexistence row (USD 1.89 per MH/s); the cheapest specialist of any kind is near-memory base dies at 669 nJ); 9.9x | none on the market | = Ravencoin's row | +| Iron Fish | 1,051 (881 to 1,257); GDDR7 board + register file sized to the work + fused operations, N5; bandwidth-bound at 124 MH/s per board; 95 percent of the board's energy is the memory path; split memory 529 / ALU 46 / tax 503; WITNESS (modelled; the card's cell pending, so the ratio is pending) | pending | pending | pending (needs the measured f from the twin) | pending | 170 (full SRAM dies (three N2 reticles) + sized + fused operations); pending | none on the market | build-1:/srv/artefacts/lab/adv/rows/ctl-fishhash.json and rows.md (set v3) | +| Ethereum Classic | 765 (638 to 919); GDDR7 board + register file sized to the work + fused operations, N5; USD 3.25 per MH/s; split per ledger-rows.md; WITNESS (modelled; the card cells pending, so the ratios are pending) | pending | pending | 1.10x to 1.20x (the premise's own figure; the twin row makes it measured) | 1.10x to 1.20x (the premise's own figure) | 177 (N2 full-SRAM die, the coexistence row); pending | Bitmain Antminer E9 Pro: 3,680 MH/s at 2,200 W = 598 nJ per hash, WITNESS (a manufacturer's published figure, not measured by the lab); Bitmain's stated figures as listed on minerstat's hardware page (https://minerstat.com/hardware/antminer-e9-pro): 3.68 GH/s on Ethash at 2,200 W, release 2023-02; 2,200 W / 3,680 MH/s = 0.598 J per MH = 598 nJ per hash | docs/analysis/class-v6/1p5x/lab/adv/v3/ledger-rows.md and ledger-rows.json (class-v6-adversary 47f16b86f, wording 82330b04c) | +| Ergo | pending: pending (ADVERSARY: the chip rows from CONTROLS' trace; default 15:00 UK, else pending (adversary)) | pending | pending | pending | pending | pending | none on the market | pending | + + +## The two phases with each chain's actual split + + +| chain | split | phase A (before investment) | phase B (spend sunk) | an income a hash chip cannot earn | source | +|---|---|---|---|---|---| +| Igneum | 80 / 20 | before investment (24 months, the mining share 80 percent of the year-1 subsidy): the same-node board maker recovers its spend on NO fleet from 100 to 100 M boards on the growing or flat price path (100,000 boards: net USD -55.4 M on 58.8 M revenue growing; -37.6 M on 76.6 M flat); only the falling path pays it; the N2 die recovers on no path | spend sunk, flat path at USD 0.10 per kWh, the chip at 10 percent of the hash: mining revenue USD 0.354 per TH; the GPU's proving income at the ratified 20 percent share USD 0.098 per TH against the board chip's operating advantage USD 0.046 per TH (GPU electricity 0.111 less the chip's electricity, hosting and maintenance 0.066): the GPU out-earns the built board chip; the cancelling proving share 9 percent (board), 13 (hybrid), 20 (die) | yes by rule (the proving share of every block, 20 percent ratified); LIVE ON DEVNET with on-chain paid records (663 paid v1 segment records to 30 prover keys on chain 4465, the PROVING LIVE lane's file bd3f53c1 on build-1), not yet in a shipped package | build-1:/srv/artefacts/lab/adv/rows/rows.md (the two-phase section), ADVERSARY commit 545f3f8a0; ctl-v6-coexistence.json; WITNESS; phase B NOT LIVE until a shipped package runs a prover | +| Ravencoin | 100 / 0 | before investment: no fleet from 100 to 100 M machines recovers a board chip's spend on any path, because Ravencoin's whole mining emission over 24 months (about USD 2.9 M at the public price) sits below one USD 35 M design cost; 10,000 boards would take 56 percent of the 721 GH/s network and earn USD 1.6 M to 2.4 M against a USD 44 M spend | spend sunk, mining only: mining revenue USD 0.064 per TH of the chain's own hashes; the board chip's recurring cost USD 0.069 per TH at ten cents; the chip's operating advantage over the RTX 4090 at stock (6,920 nJ) USD 0.123 per TH (the GPU's electricity 0.192 less the chip's 0.069) stands in full, no prover income | no (the block reward is mining only) | docs/analysis/class-v6/1p5x/lab/adv/v3/ctl-progpow-094-coexistence.json (rows[].phase_a, rows[].phase_b_split; method lab/adv/README.md section 14), ADVERSARY commit d7db3e596 on class-v6-adversary; WITNESS, the chain's own units, the 100/0 split, the same 24-month life, design cost and fleet rule as v6, the three price paths (flat at the public price, x2 growing, x0.5 falling, the hash held); the public lines on the row | +| Firo | 100 / 0 | as KAWPOW | as KAWPOW | no | as KAWPOW; = KAWPOW's row at a 100/0 split | +| Iron Fish | 100 / 0 | before investment: no fleet from 100 to 100 M machines recovers a board chip's spend on any path; Iron Fish's whole mining emission over 24 months is about USD 1.4 M at the public price (10,000 boards would take 84 percent of the hash for USD 1.1 M to 1.6 M) | spend sunk, mining only: mining revenue USD 0.086 per TH of the chain's own hashes; the board chip's recurring cost USD 0.043 per TH at ten cents; the GPU side NOT RUN until the card cell lands; no prover income by construction | no | docs/analysis/class-v6/1p5x/lab/adv/v3/ctl-fishhash-coexistence.json, ADVERSARY commit d7db3e596 on class-v6-adversary; WITNESS, the chain's own units, the 100/0 split, the same life, design cost, fleet rule and price paths as v6; the GPU side of phase B NOT RUN until COHORT's card rows | +| Ethereum Classic | 100 / 0 | before investment: no fleet from 100 to 100 M machines recovers a board chip's spend on any path; ETC's whole mining emission over 24 months is about USD 83 M at the public price, but 10,000 boards are 2 percent of 120.9 TH/s and earn USD 1.0 M to 1.5 M, and 100,000 boards (13 percent) USD 9 M to 13 M against a USD 150 M spend | spend sunk, mining only: mining revenue USD 0.0087 per TH of the chain's own hashes, below even the modelled board's recurring cost (USD 0.031 per TH) and below the E9 Pro's own electricity at ten cents (598 nJ = USD 0.017 per TH): at the public figures nobody mines ETC at a profit at ten cents and phase B is a loss on both sides; the GPU side NOT RUN until the card cell lands | no | docs/analysis/class-v6/1p5x/lab/adv/v3/ctl-etchash-coexistence.json, ADVERSARY commit d7db3e596 on class-v6-adversary; WITNESS, the chain's own units, the 100/0 split, the same life, design cost, fleet rule and price paths as v6; the GPU side of phase B NOT RUN until COHORT's card rows | +| Ergo | 100 / 0 | pending (ADVERSARY) | pending (ADVERSARY); no prover income by construction | no | pending; pending (ADVERSARY at the 100/0 split, the public line on the row) | + + +## The ranking + + +**(a) Ours, the same-node DRAM board at the worse card (the smaller chip edge first):** +No order in this column yet: a cross-chain comparison is made only between cells from the same card, state and session, and the measured cells today come from 2 sessions (lab-cohort-ctl-v6 (COHORT, 11:49 to 12:30 UK, one chain); comparative-lane a2ed5c31 (RunPod, one chain, an earlier session)); the ledger session (both cards, every chain back to back) fills it. Each chain's own number, same card and state, as it stands: +- Igneum: RTX 4090 stock 5.43x (4.31 to 6.30); RTX 5090 stock 3.63x (2.88 to 4.21) +- Ravencoin: RTX 4090 stock 3.94x (3.22 to 4.76); RTX 5090 stock pending (a pending or proxy cell in this row) +- Iron Fish: unranked in this column (no measured card cell yet) +- Ethereum Classic: unranked in this column (no measured card cell yet) +- Ergo: unranked in this column (no measured card cell yet) + +**(b) ProgPoW's premise (the chip keeps a GPU-class datapath):** +- Igneum: RTX 4090 1.01x to 1.03x (f 0.853 measured); RTX 5090 1.02x to 1.03x (f 0.811 measured on the stock pod) +- Ravencoin: RTX 4090 1.10x to 1.20x (the premise's own figure; no measured twin on this kernel yet); RTX 5090 1.10x to 1.20x (the premise's own figure; the twin row makes it measured) +- Iron Fish: RTX 4090 pending (needs the measured f from the twin); RTX 5090 pending +- Ethereum Classic: RTX 4090 1.10x to 1.20x (the premise's own figure; the twin row makes it measured); RTX 5090 1.10x to 1.20x (the premise's own figure) +- Ergo: RTX 4090 pending; RTX 5090 pending + +**(c) Phase B, an income a hash chip cannot earn:** +- Igneum: yes by rule (the proving share of every block, 20 percent ratified); LIVE ON DEVNET with on-chain paid records (663 paid v1 segment records to 30 prover keys on chain 4465, the PROVING LIVE lane's file bd3f53c1 on build-1), not yet in a shipped package +- Ravencoin: no (the block reward is mining only) +- Firo: no +- Iron Fish: no +- Ethereum Classic: no +- Ergo: no + + +## The claim under test, clause by clause + +The sentence below is served as a claim under test, each clause labelled by its state on the rows above. It reads as established +only when every clause is supported; today it is not, and the table says which clause and why. + + +**The headline, built from the supported clauses only:** under ProgPoW's own convention, the lowest measured chip-to-GPU edge of the chains on this ledger; and the only chain on this ledger whose GPUs are paid, by rule, an income a hash chip cannot earn (LIVE ON DEVNET, on-chain records (the PROVING LIVE lane, read 11:50:22Z 9 October 2026): on chain id 4465 (the Igneum 2.0 devnet) 663 paid v1 segment records (8 shards plus aggregation each) = 653.93 IGN paid from the proving pool to 30 distinct prover keys across chain blocks 3,000 to 30,687 (tip 31,719 at the read), plus 6,474 paid v0 shard records = 7,196 IGN; read by igneum_getProvingStatus, igneum_getSegmentRecords (3,965 segments) and igneum_getSegment; evidence build-1:/srv/artefacts/proving-live/prov-ledger-4465-tip31719-115022Z.json sha256 bd3f53c18c3ffa20354ea62ade9fd5e7a5794202a71c3c369a5be71484f7143a. NOT YET LIVE IN A SHIPPED PACKAGE: the payees are the fleet's prover stack (the same binaries the 2.0.3.1 HiveOS package wraps, cut 18:00 UK); the apps' prover is on by default on 24 GB cards but no app-proved record is on the record yet; a full-epoch line follows by 16:00 UK). + +The sentence as ordered, served as the claim under test: "the lowest measured chip-to-GPU edge of any live GPU network under a published method, on both conventions, and the only one whose GPUs earn income a chip cannot" + +Rule: the headline reads only what the like-for-like rows support, clause by clause (main's ruling, 13:2x UK 9 October 2026); under the ledger's own convention the measured edge per chain on the same card and state is stated as numbers, with no ranking word until the rows say so after the ledger session. + +| clause | convention | state on the current rows | why | +|---|---|---|---| +| under ProgPoW's own convention, the lowest measured chip-to-GPU edge of the chains on this ledger | ProgPoW's premise (a chip that keeps a GPU-class datapath) | SUPPORTED on the current rows | Igneum v6 1.01x to 1.03x (its measured f 0.81 to 0.85) against ProgPoW's own 1.10x to 1.20x for KAWPOW and FiroPoW; FishHash and Etchash pending their twins | +| under the ledger's convention (the cheapest credible programmable specialist, adversarial set v3), each chain's measured edge on the same card and state, as numbers | ours | NUMBERS ONLY; no ranking until the ledger session (COHORT, both cards, every chain back to back, the pinned 0.9.4 kernel, twins; 14:45 UK) | the current cells come from different sessions (the lab's cohort pods for v6, the comparative lane's pod for KAWPOW) and a cross-chain comparison is made only between cells from the same card, state and session; at the RTX 4090 at stock the cells read v6 5.4x (5.67x on the second pod) and KAWPOW 3.9x (a proxy row from an earlier session); FishHash and Etchash pending | +| and the only chain on this ledger whose GPUs are paid, by rule, an income a hash chip cannot earn | phase B, each chain's actual reward split | LABELLED BY THE PROVING LIVE LANE | the proving share (20 percent ratified) is paid to GPUs for work a hash chip cannot do; every other chain on the ledger pays mining only; the live state of that income is the PROVING LIVE lane's evidence line | + +Withdrawn: the earlier line 'KAWPOW and FiroPoW read 5 to 6x on the measured 4090 rows and v6 reads 2.35x' is withdrawn: it compared v6 at the 5090's 1,300 MHz knee with KAWPOW at the 4090 at stock, two cards and two states; the like-for-like cells are the ones on this ledger. + +The last clause's label from the PROVING LIVE lane: LIVE ON DEVNET, on-chain records (the PROVING LIVE lane, read 11:50:22Z 9 October 2026): on chain id 4465 (the Igneum 2.0 devnet) 663 paid v1 segment records (8 shards plus aggregation each) = 653.93 IGN paid from the proving pool to 30 distinct prover keys across chain blocks 3,000 to 30,687 (tip 31,719 at the read), plus 6,474 paid v0 shard records = 7,196 IGN; read by igneum_getProvingStatus, igneum_getSegmentRecords (3,965 segments) and igneum_getSegment; evidence build-1:/srv/artefacts/proving-live/prov-ledger-4465-tip31719-115022Z.json sha256 bd3f53c18c3ffa20354ea62ade9fd5e7a5794202a71c3c369a5be71484f7143a. NOT YET LIVE IN A SHIPPED PACKAGE: the payees are the fleet's prover stack (the same binaries the 2.0.3.1 HiveOS package wraps, cut 18:00 UK); the apps' prover is on by default on 24 GB cards but no app-proved record is on the record yet; a full-epoch line follows by 16:00 UK + + +## Reproduce it tonight + +The reproduction kit (the pinned references, the harnesses, the sampler, the session script, SHA256SUMS and the expected rows with +their bands) is published from the build host when it lands; the link and its sha256 go here. One command per card; a 4090 at +stock on an uncapped host reproduces the Igneum row inside its band in under ten minutes after the dataset builds. + +| item | state | +|---|---| +| the kit | pending | +| the kit's sha256 | pending | diff --git a/docs/plans/igneum-2.0-test-registry.json b/docs/plans/igneum-2.0-test-registry.json index 8a32a3037..c5c2cf27b 100644 --- a/docs/plans/igneum-2.0-test-registry.json +++ b/docs/plans/igneum-2.0-test-registry.json @@ -20434,7 +20434,7 @@ "plan_status": "NOT RUN", "run_id": "lab-20261009-01", "evidence_path": "docs/analysis/class-v6/1p5x/lab/README.md; docs/analysis/class-v6/1p5x/lab/table.md", - "updated": "2026-10-09T12:04:23.606Z", + "updated": "2026-10-09T12:15:20.071Z", "evidence_record": { "requirement_id": "R15-01", "decision": "NOT RUN", @@ -20455,8 +20455,8 @@ }, "claim_impact": "none", "reviewer": "", - "at": "2026-10-09T12:04:23.606Z", - "note": "The lab's interface and the candidate table at the fan-out: the frozen v6 control carried from the record (the house 5090 at its knee 4,011 nJ per hash, board power; the X0 amendment 5b rows: the DRAM board 2.35x same node WITNESS, the N2 die 7.8x the worst credible), the cohort rows for the 3090, the 5080 and the AMD and Intel tiers NOT RUN, adversarial set v1 pending; the three other controls (ProgPoW 0.9.4 reference, FishHash, the cooperative ARX candidate) NOT RUN with their clocks. No score is the lab's until the cohort and the adversary rows are in; R15-01, R15-08 and R15-09 stay NOT RUN until read. X10 (cand-x10) joins the table NOT RUN with its per-lane assignments and clocks; COHORT's ctl-v6 denominator set is in flight on eight rented pods. 12:1x UK: adversarial set v1 on the table (the frozen v6's same-node board 2.57x, 2.04 to 3.00, the fused tail CLAIMED until the routed lanes land; the die 11.4x as a coexistence row); the coexistence table (interface section 8b) added as the scoreboard's headline; SEARCH's first screen recorded as SCREEN rejections. Still NOT RUN: no cohort score until COHORT's eight rows are read back. 12:2x UK: set v2 (the routed fused-ARX lanes) makes the v6 board 2.60x a WITNESS; the ctl-v6 coexistence table (the board holds at every price; the N2 die pushes the GPU owner out above 14,300 dies at USD 0.10) is the headline; X10 SCREEN with the card modelled (the board 3.00x at 118 loads). Still NOT RUN: the cohort rows in their timed runs. 12:3x UK: the first cohort cells (ctl-v6 at stock on rented 5090, 5080 and 3090 pods: the worst cell the 3090 at 8,429 nJ = 5.46x on set v2's same-node board, PARTIAL, the dataset size under decision after CONTROLS measured the live 4 GiB object at 2.4x the 1 GiB research pack's rate); X10's first measured cell (cand-x10b on the 4090 at stock 3,653 nJ per lane-work = 5.8x on the board; the fold buys nothing); set v3 (routed 64-register and multiply-xor lanes); the fourth to sixth review rulings (8c); the 4 GiB rule (8e). Every row still NOT RUN until read. 12:4x UK: ctl-v6's first full score over the NVIDIA cohort at stock (the worst cell the RTX 4090 uncapped 8,751 nJ = 5.67x on set v2's same-node board; every cell at 4 GiB, the earlier 2.4x reading an instrument artefact, corrected once); the two-phase rows (ADVERSARY 545f3f8a0, 36d17b15c): phase B NOT LIVE until a shipped package proves, the shipping row open; SEARCH's twenty candidates on set v3 none under 1.5x on any cell (SCREEN). Every row still NOT RUN until read. 13:0x UK: the decider closed on both cards (the 4 GiB object costs 2.0 to 2.9 percent of rate against its 1 GiB export; the 2.4x reading withdrawn as a contention fault); the read-headroom row answered (both cards at their activation limit); the uncapped 5090 cell 5,980 nJ = 3.88x on the board; the shipping row's facts by file and line with the Devnet 4 correction (a 24 GB card proves the v1 shard now; the proving row NOT LIVE until the epoch record by 16:00); the 4 GiB cap defined as the mining dataset floor only; the founder's ledger order (8f) applied. Every row still NOT RUN until read. | The 1.5x adversarial comparison laboratory (the founder's order, 9 October 2026, 11:4x UK): one evaluation for every control and candidate (the measurement recipe with the read-only twin for the memory share, the adversary interface returning the lowest credible specialist energy per design as a complete machine with WITNESS or BOUND labels, the score as the worst comparison over the required cohort same node and one node ahead, the rejection filters F1 to F6, the regression set REG-01 to REG-08 from the 8 and 9 October failures). Every row NOT RUN until the panel reads it; the first measured score (the frozen v6 control on the cohort against adversarial set v1) lands as a later batch under this cell. Amended 11:5x UK: X10, the full-sector fold candidate of the founder's third review, added as cand-x10 with the scoped same-node board claim (the die and node-ahead chips as coexistence rows); the AMD and Intel tiers NOT RUN on every candidate (no rented card; the house rigs unreachable by software) until a card is found." + "at": "2026-10-09T12:15:20.071Z", + "note": "The lab's interface and the candidate table at the fan-out: the frozen v6 control carried from the record (the house 5090 at its knee 4,011 nJ per hash, board power; the X0 amendment 5b rows: the DRAM board 2.35x same node WITNESS, the N2 die 7.8x the worst credible), the cohort rows for the 3090, the 5080 and the AMD and Intel tiers NOT RUN, adversarial set v1 pending; the three other controls (ProgPoW 0.9.4 reference, FishHash, the cooperative ARX candidate) NOT RUN with their clocks. No score is the lab's until the cohort and the adversary rows are in; R15-01, R15-08 and R15-09 stay NOT RUN until read. X10 (cand-x10) joins the table NOT RUN with its per-lane assignments and clocks; COHORT's ctl-v6 denominator set is in flight on eight rented pods. 12:1x UK: adversarial set v1 on the table (the frozen v6's same-node board 2.57x, 2.04 to 3.00, the fused tail CLAIMED until the routed lanes land; the die 11.4x as a coexistence row); the coexistence table (interface section 8b) added as the scoreboard's headline; SEARCH's first screen recorded as SCREEN rejections. Still NOT RUN: no cohort score until COHORT's eight rows are read back. 12:2x UK: set v2 (the routed fused-ARX lanes) makes the v6 board 2.60x a WITNESS; the ctl-v6 coexistence table (the board holds at every price; the N2 die pushes the GPU owner out above 14,300 dies at USD 0.10) is the headline; X10 SCREEN with the card modelled (the board 3.00x at 118 loads). Still NOT RUN: the cohort rows in their timed runs. 12:3x UK: the first cohort cells (ctl-v6 at stock on rented 5090, 5080 and 3090 pods: the worst cell the 3090 at 8,429 nJ = 5.46x on set v2's same-node board, PARTIAL, the dataset size under decision after CONTROLS measured the live 4 GiB object at 2.4x the 1 GiB research pack's rate); X10's first measured cell (cand-x10b on the 4090 at stock 3,653 nJ per lane-work = 5.8x on the board; the fold buys nothing); set v3 (routed 64-register and multiply-xor lanes); the fourth to sixth review rulings (8c); the 4 GiB rule (8e). Every row still NOT RUN until read. 12:4x UK: ctl-v6's first full score over the NVIDIA cohort at stock (the worst cell the RTX 4090 uncapped 8,751 nJ = 5.67x on set v2's same-node board; every cell at 4 GiB, the earlier 2.4x reading an instrument artefact, corrected once); the two-phase rows (ADVERSARY 545f3f8a0, 36d17b15c): phase B NOT LIVE until a shipped package proves, the shipping row open; SEARCH's twenty candidates on set v3 none under 1.5x on any cell (SCREEN). Every row still NOT RUN until read. 13:0x UK: the decider closed on both cards (the 4 GiB object costs 2.0 to 2.9 percent of rate against its 1 GiB export; the 2.4x reading withdrawn as a contention fault); the read-headroom row answered (both cards at their activation limit); the uncapped 5090 cell 5,980 nJ = 3.88x on the board; the shipping row's facts by file and line with the Devnet 4 correction (a 24 GB card proves the v1 shard now; the proving row NOT LIVE until the epoch record by 16:00); the 4 GiB cap defined as the mining dataset floor only; the founder's ledger order (8f) applied. Every row still NOT RUN until read. 13:1x UK: CONTROLS' done line (the four controls, Etchash and Autolykos2 staged bit-exact with SUMS); ADVERSARY's cross-chain phase A and B (no chain's emission recovers a board chip; the proving share the one term) and the E9 Pro calibration (1.28x pessimistic); the first founder bundle 985afee6. Every row still NOT RUN until read. | The 1.5x adversarial comparison laboratory (the founder's order, 9 October 2026, 11:4x UK): one evaluation for every control and candidate (the measurement recipe with the read-only twin for the memory share, the adversary interface returning the lowest credible specialist energy per design as a complete machine with WITNESS or BOUND labels, the score as the worst comparison over the required cohort same node and one node ahead, the rejection filters F1 to F6, the regression set REG-01 to REG-08 from the 8 and 9 October failures). Every row NOT RUN until the panel reads it; the first measured score (the frozen v6 control on the cohort against adversarial set v1) lands as a later batch under this cell. Amended 11:5x UK: X10, the full-sector fold candidate of the founder's third review, added as cand-x10 with the scoped same-node board claim (the die and node-ahead chips as coexistence rows); the AMD and Intel tiers NOT RUN on every candidate (no rented card; the house rigs unreachable by software) until a card is found." }, "evidence_records": { "lab:candidate": { @@ -20479,8 +20479,8 @@ }, "claim_impact": "none", "reviewer": "", - "at": "2026-10-09T12:04:23.606Z", - "note": "The lab's interface and the candidate table at the fan-out: the frozen v6 control carried from the record (the house 5090 at its knee 4,011 nJ per hash, board power; the X0 amendment 5b rows: the DRAM board 2.35x same node WITNESS, the N2 die 7.8x the worst credible), the cohort rows for the 3090, the 5080 and the AMD and Intel tiers NOT RUN, adversarial set v1 pending; the three other controls (ProgPoW 0.9.4 reference, FishHash, the cooperative ARX candidate) NOT RUN with their clocks. No score is the lab's until the cohort and the adversary rows are in; R15-01, R15-08 and R15-09 stay NOT RUN until read. X10 (cand-x10) joins the table NOT RUN with its per-lane assignments and clocks; COHORT's ctl-v6 denominator set is in flight on eight rented pods. 12:1x UK: adversarial set v1 on the table (the frozen v6's same-node board 2.57x, 2.04 to 3.00, the fused tail CLAIMED until the routed lanes land; the die 11.4x as a coexistence row); the coexistence table (interface section 8b) added as the scoreboard's headline; SEARCH's first screen recorded as SCREEN rejections. Still NOT RUN: no cohort score until COHORT's eight rows are read back. 12:2x UK: set v2 (the routed fused-ARX lanes) makes the v6 board 2.60x a WITNESS; the ctl-v6 coexistence table (the board holds at every price; the N2 die pushes the GPU owner out above 14,300 dies at USD 0.10) is the headline; X10 SCREEN with the card modelled (the board 3.00x at 118 loads). Still NOT RUN: the cohort rows in their timed runs. 12:3x UK: the first cohort cells (ctl-v6 at stock on rented 5090, 5080 and 3090 pods: the worst cell the 3090 at 8,429 nJ = 5.46x on set v2's same-node board, PARTIAL, the dataset size under decision after CONTROLS measured the live 4 GiB object at 2.4x the 1 GiB research pack's rate); X10's first measured cell (cand-x10b on the 4090 at stock 3,653 nJ per lane-work = 5.8x on the board; the fold buys nothing); set v3 (routed 64-register and multiply-xor lanes); the fourth to sixth review rulings (8c); the 4 GiB rule (8e). Every row still NOT RUN until read. 12:4x UK: ctl-v6's first full score over the NVIDIA cohort at stock (the worst cell the RTX 4090 uncapped 8,751 nJ = 5.67x on set v2's same-node board; every cell at 4 GiB, the earlier 2.4x reading an instrument artefact, corrected once); the two-phase rows (ADVERSARY 545f3f8a0, 36d17b15c): phase B NOT LIVE until a shipped package proves, the shipping row open; SEARCH's twenty candidates on set v3 none under 1.5x on any cell (SCREEN). Every row still NOT RUN until read. 13:0x UK: the decider closed on both cards (the 4 GiB object costs 2.0 to 2.9 percent of rate against its 1 GiB export; the 2.4x reading withdrawn as a contention fault); the read-headroom row answered (both cards at their activation limit); the uncapped 5090 cell 5,980 nJ = 3.88x on the board; the shipping row's facts by file and line with the Devnet 4 correction (a 24 GB card proves the v1 shard now; the proving row NOT LIVE until the epoch record by 16:00); the 4 GiB cap defined as the mining dataset floor only; the founder's ledger order (8f) applied. Every row still NOT RUN until read. | The 1.5x adversarial comparison laboratory (the founder's order, 9 October 2026, 11:4x UK): one evaluation for every control and candidate (the measurement recipe with the read-only twin for the memory share, the adversary interface returning the lowest credible specialist energy per design as a complete machine with WITNESS or BOUND labels, the score as the worst comparison over the required cohort same node and one node ahead, the rejection filters F1 to F6, the regression set REG-01 to REG-08 from the 8 and 9 October failures). Every row NOT RUN until the panel reads it; the first measured score (the frozen v6 control on the cohort against adversarial set v1) lands as a later batch under this cell. Amended 11:5x UK: X10, the full-sector fold candidate of the founder's third review, added as cand-x10 with the scoped same-node board claim (the die and node-ahead chips as coexistence rows); the AMD and Intel tiers NOT RUN on every candidate (no rented card; the house rigs unreachable by software) until a card is found." + "at": "2026-10-09T12:15:20.071Z", + "note": "The lab's interface and the candidate table at the fan-out: the frozen v6 control carried from the record (the house 5090 at its knee 4,011 nJ per hash, board power; the X0 amendment 5b rows: the DRAM board 2.35x same node WITNESS, the N2 die 7.8x the worst credible), the cohort rows for the 3090, the 5080 and the AMD and Intel tiers NOT RUN, adversarial set v1 pending; the three other controls (ProgPoW 0.9.4 reference, FishHash, the cooperative ARX candidate) NOT RUN with their clocks. No score is the lab's until the cohort and the adversary rows are in; R15-01, R15-08 and R15-09 stay NOT RUN until read. X10 (cand-x10) joins the table NOT RUN with its per-lane assignments and clocks; COHORT's ctl-v6 denominator set is in flight on eight rented pods. 12:1x UK: adversarial set v1 on the table (the frozen v6's same-node board 2.57x, 2.04 to 3.00, the fused tail CLAIMED until the routed lanes land; the die 11.4x as a coexistence row); the coexistence table (interface section 8b) added as the scoreboard's headline; SEARCH's first screen recorded as SCREEN rejections. Still NOT RUN: no cohort score until COHORT's eight rows are read back. 12:2x UK: set v2 (the routed fused-ARX lanes) makes the v6 board 2.60x a WITNESS; the ctl-v6 coexistence table (the board holds at every price; the N2 die pushes the GPU owner out above 14,300 dies at USD 0.10) is the headline; X10 SCREEN with the card modelled (the board 3.00x at 118 loads). Still NOT RUN: the cohort rows in their timed runs. 12:3x UK: the first cohort cells (ctl-v6 at stock on rented 5090, 5080 and 3090 pods: the worst cell the 3090 at 8,429 nJ = 5.46x on set v2's same-node board, PARTIAL, the dataset size under decision after CONTROLS measured the live 4 GiB object at 2.4x the 1 GiB research pack's rate); X10's first measured cell (cand-x10b on the 4090 at stock 3,653 nJ per lane-work = 5.8x on the board; the fold buys nothing); set v3 (routed 64-register and multiply-xor lanes); the fourth to sixth review rulings (8c); the 4 GiB rule (8e). Every row still NOT RUN until read. 12:4x UK: ctl-v6's first full score over the NVIDIA cohort at stock (the worst cell the RTX 4090 uncapped 8,751 nJ = 5.67x on set v2's same-node board; every cell at 4 GiB, the earlier 2.4x reading an instrument artefact, corrected once); the two-phase rows (ADVERSARY 545f3f8a0, 36d17b15c): phase B NOT LIVE until a shipped package proves, the shipping row open; SEARCH's twenty candidates on set v3 none under 1.5x on any cell (SCREEN). Every row still NOT RUN until read. 13:0x UK: the decider closed on both cards (the 4 GiB object costs 2.0 to 2.9 percent of rate against its 1 GiB export; the 2.4x reading withdrawn as a contention fault); the read-headroom row answered (both cards at their activation limit); the uncapped 5090 cell 5,980 nJ = 3.88x on the board; the shipping row's facts by file and line with the Devnet 4 correction (a 24 GB card proves the v1 shard now; the proving row NOT LIVE until the epoch record by 16:00); the 4 GiB cap defined as the mining dataset floor only; the founder's ledger order (8f) applied. Every row still NOT RUN until read. 13:1x UK: CONTROLS' done line (the four controls, Etchash and Autolykos2 staged bit-exact with SUMS); ADVERSARY's cross-chain phase A and B (no chain's emission recovers a board chip; the proving share the one term) and the E9 Pro calibration (1.28x pessimistic); the first founder bundle 985afee6. Every row still NOT RUN until read. | The 1.5x adversarial comparison laboratory (the founder's order, 9 October 2026, 11:4x UK): one evaluation for every control and candidate (the measurement recipe with the read-only twin for the memory share, the adversary interface returning the lowest credible specialist energy per design as a complete machine with WITNESS or BOUND labels, the score as the worst comparison over the required cohort same node and one node ahead, the rejection filters F1 to F6, the regression set REG-01 to REG-08 from the 8 and 9 October failures). Every row NOT RUN until the panel reads it; the first measured score (the frozen v6 control on the cohort against adversarial set v1) lands as a later batch under this cell. Amended 11:5x UK: X10, the full-sector fold candidate of the founder's third review, added as cand-x10 with the scoped same-node board claim (the die and node-ahead chips as coexistence rows); the AMD and Intel tiers NOT RUN on every candidate (no rented card; the house rigs unreachable by software) until a card is found." } }, "in_progress_since": "2026-10-09T10:48:54.646Z", @@ -21144,7 +21144,7 @@ "plan_status": "NOT RUN", "run_id": "lab-20261009-01", "evidence_path": "docs/analysis/class-v6/1p5x/lab/README.md; docs/analysis/class-v6/1p5x/lab/table.md", - "updated": "2026-10-09T12:04:23.606Z", + "updated": "2026-10-09T12:15:20.071Z", "evidence_record": { "requirement_id": "R15-08", "decision": "NOT RUN", @@ -21165,8 +21165,8 @@ }, "claim_impact": "none", "reviewer": "", - "at": "2026-10-09T12:04:23.606Z", - "note": "The lab's interface and the candidate table at the fan-out: the frozen v6 control carried from the record (the house 5090 at its knee 4,011 nJ per hash, board power; the X0 amendment 5b rows: the DRAM board 2.35x same node WITNESS, the N2 die 7.8x the worst credible), the cohort rows for the 3090, the 5080 and the AMD and Intel tiers NOT RUN, adversarial set v1 pending; the three other controls (ProgPoW 0.9.4 reference, FishHash, the cooperative ARX candidate) NOT RUN with their clocks. No score is the lab's until the cohort and the adversary rows are in; R15-01, R15-08 and R15-09 stay NOT RUN until read. X10 (cand-x10) joins the table NOT RUN with its per-lane assignments and clocks; COHORT's ctl-v6 denominator set is in flight on eight rented pods. 12:1x UK: adversarial set v1 on the table (the frozen v6's same-node board 2.57x, 2.04 to 3.00, the fused tail CLAIMED until the routed lanes land; the die 11.4x as a coexistence row); the coexistence table (interface section 8b) added as the scoreboard's headline; SEARCH's first screen recorded as SCREEN rejections. Still NOT RUN: no cohort score until COHORT's eight rows are read back. 12:2x UK: set v2 (the routed fused-ARX lanes) makes the v6 board 2.60x a WITNESS; the ctl-v6 coexistence table (the board holds at every price; the N2 die pushes the GPU owner out above 14,300 dies at USD 0.10) is the headline; X10 SCREEN with the card modelled (the board 3.00x at 118 loads). Still NOT RUN: the cohort rows in their timed runs. 12:3x UK: the first cohort cells (ctl-v6 at stock on rented 5090, 5080 and 3090 pods: the worst cell the 3090 at 8,429 nJ = 5.46x on set v2's same-node board, PARTIAL, the dataset size under decision after CONTROLS measured the live 4 GiB object at 2.4x the 1 GiB research pack's rate); X10's first measured cell (cand-x10b on the 4090 at stock 3,653 nJ per lane-work = 5.8x on the board; the fold buys nothing); set v3 (routed 64-register and multiply-xor lanes); the fourth to sixth review rulings (8c); the 4 GiB rule (8e). Every row still NOT RUN until read. 12:4x UK: ctl-v6's first full score over the NVIDIA cohort at stock (the worst cell the RTX 4090 uncapped 8,751 nJ = 5.67x on set v2's same-node board; every cell at 4 GiB, the earlier 2.4x reading an instrument artefact, corrected once); the two-phase rows (ADVERSARY 545f3f8a0, 36d17b15c): phase B NOT LIVE until a shipped package proves, the shipping row open; SEARCH's twenty candidates on set v3 none under 1.5x on any cell (SCREEN). Every row still NOT RUN until read. 13:0x UK: the decider closed on both cards (the 4 GiB object costs 2.0 to 2.9 percent of rate against its 1 GiB export; the 2.4x reading withdrawn as a contention fault); the read-headroom row answered (both cards at their activation limit); the uncapped 5090 cell 5,980 nJ = 3.88x on the board; the shipping row's facts by file and line with the Devnet 4 correction (a 24 GB card proves the v1 shard now; the proving row NOT LIVE until the epoch record by 16:00); the 4 GiB cap defined as the mining dataset floor only; the founder's ledger order (8f) applied. Every row still NOT RUN until read. | The 1.5x adversarial comparison laboratory (the founder's order, 9 October 2026, 11:4x UK): one evaluation for every control and candidate (the measurement recipe with the read-only twin for the memory share, the adversary interface returning the lowest credible specialist energy per design as a complete machine with WITNESS or BOUND labels, the score as the worst comparison over the required cohort same node and one node ahead, the rejection filters F1 to F6, the regression set REG-01 to REG-08 from the 8 and 9 October failures). Every row NOT RUN until the panel reads it; the first measured score (the frozen v6 control on the cohort against adversarial set v1) lands as a later batch under this cell. Amended 11:5x UK: X10, the full-sector fold candidate of the founder's third review, added as cand-x10 with the scoped same-node board claim (the die and node-ahead chips as coexistence rows); the AMD and Intel tiers NOT RUN on every candidate (no rented card; the house rigs unreachable by software) until a card is found." + "at": "2026-10-09T12:15:20.071Z", + "note": "The lab's interface and the candidate table at the fan-out: the frozen v6 control carried from the record (the house 5090 at its knee 4,011 nJ per hash, board power; the X0 amendment 5b rows: the DRAM board 2.35x same node WITNESS, the N2 die 7.8x the worst credible), the cohort rows for the 3090, the 5080 and the AMD and Intel tiers NOT RUN, adversarial set v1 pending; the three other controls (ProgPoW 0.9.4 reference, FishHash, the cooperative ARX candidate) NOT RUN with their clocks. No score is the lab's until the cohort and the adversary rows are in; R15-01, R15-08 and R15-09 stay NOT RUN until read. X10 (cand-x10) joins the table NOT RUN with its per-lane assignments and clocks; COHORT's ctl-v6 denominator set is in flight on eight rented pods. 12:1x UK: adversarial set v1 on the table (the frozen v6's same-node board 2.57x, 2.04 to 3.00, the fused tail CLAIMED until the routed lanes land; the die 11.4x as a coexistence row); the coexistence table (interface section 8b) added as the scoreboard's headline; SEARCH's first screen recorded as SCREEN rejections. Still NOT RUN: no cohort score until COHORT's eight rows are read back. 12:2x UK: set v2 (the routed fused-ARX lanes) makes the v6 board 2.60x a WITNESS; the ctl-v6 coexistence table (the board holds at every price; the N2 die pushes the GPU owner out above 14,300 dies at USD 0.10) is the headline; X10 SCREEN with the card modelled (the board 3.00x at 118 loads). Still NOT RUN: the cohort rows in their timed runs. 12:3x UK: the first cohort cells (ctl-v6 at stock on rented 5090, 5080 and 3090 pods: the worst cell the 3090 at 8,429 nJ = 5.46x on set v2's same-node board, PARTIAL, the dataset size under decision after CONTROLS measured the live 4 GiB object at 2.4x the 1 GiB research pack's rate); X10's first measured cell (cand-x10b on the 4090 at stock 3,653 nJ per lane-work = 5.8x on the board; the fold buys nothing); set v3 (routed 64-register and multiply-xor lanes); the fourth to sixth review rulings (8c); the 4 GiB rule (8e). Every row still NOT RUN until read. 12:4x UK: ctl-v6's first full score over the NVIDIA cohort at stock (the worst cell the RTX 4090 uncapped 8,751 nJ = 5.67x on set v2's same-node board; every cell at 4 GiB, the earlier 2.4x reading an instrument artefact, corrected once); the two-phase rows (ADVERSARY 545f3f8a0, 36d17b15c): phase B NOT LIVE until a shipped package proves, the shipping row open; SEARCH's twenty candidates on set v3 none under 1.5x on any cell (SCREEN). Every row still NOT RUN until read. 13:0x UK: the decider closed on both cards (the 4 GiB object costs 2.0 to 2.9 percent of rate against its 1 GiB export; the 2.4x reading withdrawn as a contention fault); the read-headroom row answered (both cards at their activation limit); the uncapped 5090 cell 5,980 nJ = 3.88x on the board; the shipping row's facts by file and line with the Devnet 4 correction (a 24 GB card proves the v1 shard now; the proving row NOT LIVE until the epoch record by 16:00); the 4 GiB cap defined as the mining dataset floor only; the founder's ledger order (8f) applied. Every row still NOT RUN until read. 13:1x UK: CONTROLS' done line (the four controls, Etchash and Autolykos2 staged bit-exact with SUMS); ADVERSARY's cross-chain phase A and B (no chain's emission recovers a board chip; the proving share the one term) and the E9 Pro calibration (1.28x pessimistic); the first founder bundle 985afee6. Every row still NOT RUN until read. | The 1.5x adversarial comparison laboratory (the founder's order, 9 October 2026, 11:4x UK): one evaluation for every control and candidate (the measurement recipe with the read-only twin for the memory share, the adversary interface returning the lowest credible specialist energy per design as a complete machine with WITNESS or BOUND labels, the score as the worst comparison over the required cohort same node and one node ahead, the rejection filters F1 to F6, the regression set REG-01 to REG-08 from the 8 and 9 October failures). Every row NOT RUN until the panel reads it; the first measured score (the frozen v6 control on the cohort against adversarial set v1) lands as a later batch under this cell. Amended 11:5x UK: X10, the full-sector fold candidate of the founder's third review, added as cand-x10 with the scoped same-node board claim (the die and node-ahead chips as coexistence rows); the AMD and Intel tiers NOT RUN on every candidate (no rented card; the house rigs unreachable by software) until a card is found." }, "evidence_records": { "lab:candidate": { @@ -21189,8 +21189,8 @@ }, "claim_impact": "none", "reviewer": "", - "at": "2026-10-09T12:04:23.606Z", - "note": "The lab's interface and the candidate table at the fan-out: the frozen v6 control carried from the record (the house 5090 at its knee 4,011 nJ per hash, board power; the X0 amendment 5b rows: the DRAM board 2.35x same node WITNESS, the N2 die 7.8x the worst credible), the cohort rows for the 3090, the 5080 and the AMD and Intel tiers NOT RUN, adversarial set v1 pending; the three other controls (ProgPoW 0.9.4 reference, FishHash, the cooperative ARX candidate) NOT RUN with their clocks. No score is the lab's until the cohort and the adversary rows are in; R15-01, R15-08 and R15-09 stay NOT RUN until read. X10 (cand-x10) joins the table NOT RUN with its per-lane assignments and clocks; COHORT's ctl-v6 denominator set is in flight on eight rented pods. 12:1x UK: adversarial set v1 on the table (the frozen v6's same-node board 2.57x, 2.04 to 3.00, the fused tail CLAIMED until the routed lanes land; the die 11.4x as a coexistence row); the coexistence table (interface section 8b) added as the scoreboard's headline; SEARCH's first screen recorded as SCREEN rejections. Still NOT RUN: no cohort score until COHORT's eight rows are read back. 12:2x UK: set v2 (the routed fused-ARX lanes) makes the v6 board 2.60x a WITNESS; the ctl-v6 coexistence table (the board holds at every price; the N2 die pushes the GPU owner out above 14,300 dies at USD 0.10) is the headline; X10 SCREEN with the card modelled (the board 3.00x at 118 loads). Still NOT RUN: the cohort rows in their timed runs. 12:3x UK: the first cohort cells (ctl-v6 at stock on rented 5090, 5080 and 3090 pods: the worst cell the 3090 at 8,429 nJ = 5.46x on set v2's same-node board, PARTIAL, the dataset size under decision after CONTROLS measured the live 4 GiB object at 2.4x the 1 GiB research pack's rate); X10's first measured cell (cand-x10b on the 4090 at stock 3,653 nJ per lane-work = 5.8x on the board; the fold buys nothing); set v3 (routed 64-register and multiply-xor lanes); the fourth to sixth review rulings (8c); the 4 GiB rule (8e). Every row still NOT RUN until read. 12:4x UK: ctl-v6's first full score over the NVIDIA cohort at stock (the worst cell the RTX 4090 uncapped 8,751 nJ = 5.67x on set v2's same-node board; every cell at 4 GiB, the earlier 2.4x reading an instrument artefact, corrected once); the two-phase rows (ADVERSARY 545f3f8a0, 36d17b15c): phase B NOT LIVE until a shipped package proves, the shipping row open; SEARCH's twenty candidates on set v3 none under 1.5x on any cell (SCREEN). Every row still NOT RUN until read. 13:0x UK: the decider closed on both cards (the 4 GiB object costs 2.0 to 2.9 percent of rate against its 1 GiB export; the 2.4x reading withdrawn as a contention fault); the read-headroom row answered (both cards at their activation limit); the uncapped 5090 cell 5,980 nJ = 3.88x on the board; the shipping row's facts by file and line with the Devnet 4 correction (a 24 GB card proves the v1 shard now; the proving row NOT LIVE until the epoch record by 16:00); the 4 GiB cap defined as the mining dataset floor only; the founder's ledger order (8f) applied. Every row still NOT RUN until read. | The 1.5x adversarial comparison laboratory (the founder's order, 9 October 2026, 11:4x UK): one evaluation for every control and candidate (the measurement recipe with the read-only twin for the memory share, the adversary interface returning the lowest credible specialist energy per design as a complete machine with WITNESS or BOUND labels, the score as the worst comparison over the required cohort same node and one node ahead, the rejection filters F1 to F6, the regression set REG-01 to REG-08 from the 8 and 9 October failures). Every row NOT RUN until the panel reads it; the first measured score (the frozen v6 control on the cohort against adversarial set v1) lands as a later batch under this cell. Amended 11:5x UK: X10, the full-sector fold candidate of the founder's third review, added as cand-x10 with the scoped same-node board claim (the die and node-ahead chips as coexistence rows); the AMD and Intel tiers NOT RUN on every candidate (no rented card; the house rigs unreachable by software) until a card is found." + "at": "2026-10-09T12:15:20.071Z", + "note": "The lab's interface and the candidate table at the fan-out: the frozen v6 control carried from the record (the house 5090 at its knee 4,011 nJ per hash, board power; the X0 amendment 5b rows: the DRAM board 2.35x same node WITNESS, the N2 die 7.8x the worst credible), the cohort rows for the 3090, the 5080 and the AMD and Intel tiers NOT RUN, adversarial set v1 pending; the three other controls (ProgPoW 0.9.4 reference, FishHash, the cooperative ARX candidate) NOT RUN with their clocks. No score is the lab's until the cohort and the adversary rows are in; R15-01, R15-08 and R15-09 stay NOT RUN until read. X10 (cand-x10) joins the table NOT RUN with its per-lane assignments and clocks; COHORT's ctl-v6 denominator set is in flight on eight rented pods. 12:1x UK: adversarial set v1 on the table (the frozen v6's same-node board 2.57x, 2.04 to 3.00, the fused tail CLAIMED until the routed lanes land; the die 11.4x as a coexistence row); the coexistence table (interface section 8b) added as the scoreboard's headline; SEARCH's first screen recorded as SCREEN rejections. Still NOT RUN: no cohort score until COHORT's eight rows are read back. 12:2x UK: set v2 (the routed fused-ARX lanes) makes the v6 board 2.60x a WITNESS; the ctl-v6 coexistence table (the board holds at every price; the N2 die pushes the GPU owner out above 14,300 dies at USD 0.10) is the headline; X10 SCREEN with the card modelled (the board 3.00x at 118 loads). Still NOT RUN: the cohort rows in their timed runs. 12:3x UK: the first cohort cells (ctl-v6 at stock on rented 5090, 5080 and 3090 pods: the worst cell the 3090 at 8,429 nJ = 5.46x on set v2's same-node board, PARTIAL, the dataset size under decision after CONTROLS measured the live 4 GiB object at 2.4x the 1 GiB research pack's rate); X10's first measured cell (cand-x10b on the 4090 at stock 3,653 nJ per lane-work = 5.8x on the board; the fold buys nothing); set v3 (routed 64-register and multiply-xor lanes); the fourth to sixth review rulings (8c); the 4 GiB rule (8e). Every row still NOT RUN until read. 12:4x UK: ctl-v6's first full score over the NVIDIA cohort at stock (the worst cell the RTX 4090 uncapped 8,751 nJ = 5.67x on set v2's same-node board; every cell at 4 GiB, the earlier 2.4x reading an instrument artefact, corrected once); the two-phase rows (ADVERSARY 545f3f8a0, 36d17b15c): phase B NOT LIVE until a shipped package proves, the shipping row open; SEARCH's twenty candidates on set v3 none under 1.5x on any cell (SCREEN). Every row still NOT RUN until read. 13:0x UK: the decider closed on both cards (the 4 GiB object costs 2.0 to 2.9 percent of rate against its 1 GiB export; the 2.4x reading withdrawn as a contention fault); the read-headroom row answered (both cards at their activation limit); the uncapped 5090 cell 5,980 nJ = 3.88x on the board; the shipping row's facts by file and line with the Devnet 4 correction (a 24 GB card proves the v1 shard now; the proving row NOT LIVE until the epoch record by 16:00); the 4 GiB cap defined as the mining dataset floor only; the founder's ledger order (8f) applied. Every row still NOT RUN until read. 13:1x UK: CONTROLS' done line (the four controls, Etchash and Autolykos2 staged bit-exact with SUMS); ADVERSARY's cross-chain phase A and B (no chain's emission recovers a board chip; the proving share the one term) and the E9 Pro calibration (1.28x pessimistic); the first founder bundle 985afee6. Every row still NOT RUN until read. | The 1.5x adversarial comparison laboratory (the founder's order, 9 October 2026, 11:4x UK): one evaluation for every control and candidate (the measurement recipe with the read-only twin for the memory share, the adversary interface returning the lowest credible specialist energy per design as a complete machine with WITNESS or BOUND labels, the score as the worst comparison over the required cohort same node and one node ahead, the rejection filters F1 to F6, the regression set REG-01 to REG-08 from the 8 and 9 October failures). Every row NOT RUN until the panel reads it; the first measured score (the frozen v6 control on the cohort against adversarial set v1) lands as a later batch under this cell. Amended 11:5x UK: X10, the full-sector fold candidate of the founder's third review, added as cand-x10 with the scoped same-node board claim (the die and node-ahead chips as coexistence rows); the AMD and Intel tiers NOT RUN on every candidate (no rented card; the house rigs unreachable by software) until a card is found." } }, "in_progress_since": "2026-10-09T10:48:54.646Z", @@ -21234,7 +21234,7 @@ "plan_status": "NOT RUN", "run_id": "lab-20261009-01", "evidence_path": "docs/analysis/class-v6/1p5x/lab/README.md; docs/analysis/class-v6/1p5x/lab/table.md", - "updated": "2026-10-09T12:04:23.606Z", + "updated": "2026-10-09T12:15:20.071Z", "evidence_record": { "requirement_id": "R15-09", "decision": "NOT RUN", @@ -21255,8 +21255,8 @@ }, "claim_impact": "none", "reviewer": "", - "at": "2026-10-09T12:04:23.606Z", - "note": "The lab's interface and the candidate table at the fan-out: the frozen v6 control carried from the record (the house 5090 at its knee 4,011 nJ per hash, board power; the X0 amendment 5b rows: the DRAM board 2.35x same node WITNESS, the N2 die 7.8x the worst credible), the cohort rows for the 3090, the 5080 and the AMD and Intel tiers NOT RUN, adversarial set v1 pending; the three other controls (ProgPoW 0.9.4 reference, FishHash, the cooperative ARX candidate) NOT RUN with their clocks. No score is the lab's until the cohort and the adversary rows are in; R15-01, R15-08 and R15-09 stay NOT RUN until read. X10 (cand-x10) joins the table NOT RUN with its per-lane assignments and clocks; COHORT's ctl-v6 denominator set is in flight on eight rented pods. 12:1x UK: adversarial set v1 on the table (the frozen v6's same-node board 2.57x, 2.04 to 3.00, the fused tail CLAIMED until the routed lanes land; the die 11.4x as a coexistence row); the coexistence table (interface section 8b) added as the scoreboard's headline; SEARCH's first screen recorded as SCREEN rejections. Still NOT RUN: no cohort score until COHORT's eight rows are read back. 12:2x UK: set v2 (the routed fused-ARX lanes) makes the v6 board 2.60x a WITNESS; the ctl-v6 coexistence table (the board holds at every price; the N2 die pushes the GPU owner out above 14,300 dies at USD 0.10) is the headline; X10 SCREEN with the card modelled (the board 3.00x at 118 loads). Still NOT RUN: the cohort rows in their timed runs. 12:3x UK: the first cohort cells (ctl-v6 at stock on rented 5090, 5080 and 3090 pods: the worst cell the 3090 at 8,429 nJ = 5.46x on set v2's same-node board, PARTIAL, the dataset size under decision after CONTROLS measured the live 4 GiB object at 2.4x the 1 GiB research pack's rate); X10's first measured cell (cand-x10b on the 4090 at stock 3,653 nJ per lane-work = 5.8x on the board; the fold buys nothing); set v3 (routed 64-register and multiply-xor lanes); the fourth to sixth review rulings (8c); the 4 GiB rule (8e). Every row still NOT RUN until read. 12:4x UK: ctl-v6's first full score over the NVIDIA cohort at stock (the worst cell the RTX 4090 uncapped 8,751 nJ = 5.67x on set v2's same-node board; every cell at 4 GiB, the earlier 2.4x reading an instrument artefact, corrected once); the two-phase rows (ADVERSARY 545f3f8a0, 36d17b15c): phase B NOT LIVE until a shipped package proves, the shipping row open; SEARCH's twenty candidates on set v3 none under 1.5x on any cell (SCREEN). Every row still NOT RUN until read. 13:0x UK: the decider closed on both cards (the 4 GiB object costs 2.0 to 2.9 percent of rate against its 1 GiB export; the 2.4x reading withdrawn as a contention fault); the read-headroom row answered (both cards at their activation limit); the uncapped 5090 cell 5,980 nJ = 3.88x on the board; the shipping row's facts by file and line with the Devnet 4 correction (a 24 GB card proves the v1 shard now; the proving row NOT LIVE until the epoch record by 16:00); the 4 GiB cap defined as the mining dataset floor only; the founder's ledger order (8f) applied. Every row still NOT RUN until read. | The 1.5x adversarial comparison laboratory (the founder's order, 9 October 2026, 11:4x UK): one evaluation for every control and candidate (the measurement recipe with the read-only twin for the memory share, the adversary interface returning the lowest credible specialist energy per design as a complete machine with WITNESS or BOUND labels, the score as the worst comparison over the required cohort same node and one node ahead, the rejection filters F1 to F6, the regression set REG-01 to REG-08 from the 8 and 9 October failures). Every row NOT RUN until the panel reads it; the first measured score (the frozen v6 control on the cohort against adversarial set v1) lands as a later batch under this cell. Amended 11:5x UK: X10, the full-sector fold candidate of the founder's third review, added as cand-x10 with the scoped same-node board claim (the die and node-ahead chips as coexistence rows); the AMD and Intel tiers NOT RUN on every candidate (no rented card; the house rigs unreachable by software) until a card is found." + "at": "2026-10-09T12:15:20.071Z", + "note": "The lab's interface and the candidate table at the fan-out: the frozen v6 control carried from the record (the house 5090 at its knee 4,011 nJ per hash, board power; the X0 amendment 5b rows: the DRAM board 2.35x same node WITNESS, the N2 die 7.8x the worst credible), the cohort rows for the 3090, the 5080 and the AMD and Intel tiers NOT RUN, adversarial set v1 pending; the three other controls (ProgPoW 0.9.4 reference, FishHash, the cooperative ARX candidate) NOT RUN with their clocks. No score is the lab's until the cohort and the adversary rows are in; R15-01, R15-08 and R15-09 stay NOT RUN until read. X10 (cand-x10) joins the table NOT RUN with its per-lane assignments and clocks; COHORT's ctl-v6 denominator set is in flight on eight rented pods. 12:1x UK: adversarial set v1 on the table (the frozen v6's same-node board 2.57x, 2.04 to 3.00, the fused tail CLAIMED until the routed lanes land; the die 11.4x as a coexistence row); the coexistence table (interface section 8b) added as the scoreboard's headline; SEARCH's first screen recorded as SCREEN rejections. Still NOT RUN: no cohort score until COHORT's eight rows are read back. 12:2x UK: set v2 (the routed fused-ARX lanes) makes the v6 board 2.60x a WITNESS; the ctl-v6 coexistence table (the board holds at every price; the N2 die pushes the GPU owner out above 14,300 dies at USD 0.10) is the headline; X10 SCREEN with the card modelled (the board 3.00x at 118 loads). Still NOT RUN: the cohort rows in their timed runs. 12:3x UK: the first cohort cells (ctl-v6 at stock on rented 5090, 5080 and 3090 pods: the worst cell the 3090 at 8,429 nJ = 5.46x on set v2's same-node board, PARTIAL, the dataset size under decision after CONTROLS measured the live 4 GiB object at 2.4x the 1 GiB research pack's rate); X10's first measured cell (cand-x10b on the 4090 at stock 3,653 nJ per lane-work = 5.8x on the board; the fold buys nothing); set v3 (routed 64-register and multiply-xor lanes); the fourth to sixth review rulings (8c); the 4 GiB rule (8e). Every row still NOT RUN until read. 12:4x UK: ctl-v6's first full score over the NVIDIA cohort at stock (the worst cell the RTX 4090 uncapped 8,751 nJ = 5.67x on set v2's same-node board; every cell at 4 GiB, the earlier 2.4x reading an instrument artefact, corrected once); the two-phase rows (ADVERSARY 545f3f8a0, 36d17b15c): phase B NOT LIVE until a shipped package proves, the shipping row open; SEARCH's twenty candidates on set v3 none under 1.5x on any cell (SCREEN). Every row still NOT RUN until read. 13:0x UK: the decider closed on both cards (the 4 GiB object costs 2.0 to 2.9 percent of rate against its 1 GiB export; the 2.4x reading withdrawn as a contention fault); the read-headroom row answered (both cards at their activation limit); the uncapped 5090 cell 5,980 nJ = 3.88x on the board; the shipping row's facts by file and line with the Devnet 4 correction (a 24 GB card proves the v1 shard now; the proving row NOT LIVE until the epoch record by 16:00); the 4 GiB cap defined as the mining dataset floor only; the founder's ledger order (8f) applied. Every row still NOT RUN until read. 13:1x UK: CONTROLS' done line (the four controls, Etchash and Autolykos2 staged bit-exact with SUMS); ADVERSARY's cross-chain phase A and B (no chain's emission recovers a board chip; the proving share the one term) and the E9 Pro calibration (1.28x pessimistic); the first founder bundle 985afee6. Every row still NOT RUN until read. | The 1.5x adversarial comparison laboratory (the founder's order, 9 October 2026, 11:4x UK): one evaluation for every control and candidate (the measurement recipe with the read-only twin for the memory share, the adversary interface returning the lowest credible specialist energy per design as a complete machine with WITNESS or BOUND labels, the score as the worst comparison over the required cohort same node and one node ahead, the rejection filters F1 to F6, the regression set REG-01 to REG-08 from the 8 and 9 October failures). Every row NOT RUN until the panel reads it; the first measured score (the frozen v6 control on the cohort against adversarial set v1) lands as a later batch under this cell. Amended 11:5x UK: X10, the full-sector fold candidate of the founder's third review, added as cand-x10 with the scoped same-node board claim (the die and node-ahead chips as coexistence rows); the AMD and Intel tiers NOT RUN on every candidate (no rented card; the house rigs unreachable by software) until a card is found." }, "evidence_records": { "lab:candidate": { @@ -21279,8 +21279,8 @@ }, "claim_impact": "none", "reviewer": "", - "at": "2026-10-09T12:04:23.606Z", - "note": "The lab's interface and the candidate table at the fan-out: the frozen v6 control carried from the record (the house 5090 at its knee 4,011 nJ per hash, board power; the X0 amendment 5b rows: the DRAM board 2.35x same node WITNESS, the N2 die 7.8x the worst credible), the cohort rows for the 3090, the 5080 and the AMD and Intel tiers NOT RUN, adversarial set v1 pending; the three other controls (ProgPoW 0.9.4 reference, FishHash, the cooperative ARX candidate) NOT RUN with their clocks. No score is the lab's until the cohort and the adversary rows are in; R15-01, R15-08 and R15-09 stay NOT RUN until read. X10 (cand-x10) joins the table NOT RUN with its per-lane assignments and clocks; COHORT's ctl-v6 denominator set is in flight on eight rented pods. 12:1x UK: adversarial set v1 on the table (the frozen v6's same-node board 2.57x, 2.04 to 3.00, the fused tail CLAIMED until the routed lanes land; the die 11.4x as a coexistence row); the coexistence table (interface section 8b) added as the scoreboard's headline; SEARCH's first screen recorded as SCREEN rejections. Still NOT RUN: no cohort score until COHORT's eight rows are read back. 12:2x UK: set v2 (the routed fused-ARX lanes) makes the v6 board 2.60x a WITNESS; the ctl-v6 coexistence table (the board holds at every price; the N2 die pushes the GPU owner out above 14,300 dies at USD 0.10) is the headline; X10 SCREEN with the card modelled (the board 3.00x at 118 loads). Still NOT RUN: the cohort rows in their timed runs. 12:3x UK: the first cohort cells (ctl-v6 at stock on rented 5090, 5080 and 3090 pods: the worst cell the 3090 at 8,429 nJ = 5.46x on set v2's same-node board, PARTIAL, the dataset size under decision after CONTROLS measured the live 4 GiB object at 2.4x the 1 GiB research pack's rate); X10's first measured cell (cand-x10b on the 4090 at stock 3,653 nJ per lane-work = 5.8x on the board; the fold buys nothing); set v3 (routed 64-register and multiply-xor lanes); the fourth to sixth review rulings (8c); the 4 GiB rule (8e). Every row still NOT RUN until read. 12:4x UK: ctl-v6's first full score over the NVIDIA cohort at stock (the worst cell the RTX 4090 uncapped 8,751 nJ = 5.67x on set v2's same-node board; every cell at 4 GiB, the earlier 2.4x reading an instrument artefact, corrected once); the two-phase rows (ADVERSARY 545f3f8a0, 36d17b15c): phase B NOT LIVE until a shipped package proves, the shipping row open; SEARCH's twenty candidates on set v3 none under 1.5x on any cell (SCREEN). Every row still NOT RUN until read. 13:0x UK: the decider closed on both cards (the 4 GiB object costs 2.0 to 2.9 percent of rate against its 1 GiB export; the 2.4x reading withdrawn as a contention fault); the read-headroom row answered (both cards at their activation limit); the uncapped 5090 cell 5,980 nJ = 3.88x on the board; the shipping row's facts by file and line with the Devnet 4 correction (a 24 GB card proves the v1 shard now; the proving row NOT LIVE until the epoch record by 16:00); the 4 GiB cap defined as the mining dataset floor only; the founder's ledger order (8f) applied. Every row still NOT RUN until read. | The 1.5x adversarial comparison laboratory (the founder's order, 9 October 2026, 11:4x UK): one evaluation for every control and candidate (the measurement recipe with the read-only twin for the memory share, the adversary interface returning the lowest credible specialist energy per design as a complete machine with WITNESS or BOUND labels, the score as the worst comparison over the required cohort same node and one node ahead, the rejection filters F1 to F6, the regression set REG-01 to REG-08 from the 8 and 9 October failures). Every row NOT RUN until the panel reads it; the first measured score (the frozen v6 control on the cohort against adversarial set v1) lands as a later batch under this cell. Amended 11:5x UK: X10, the full-sector fold candidate of the founder's third review, added as cand-x10 with the scoped same-node board claim (the die and node-ahead chips as coexistence rows); the AMD and Intel tiers NOT RUN on every candidate (no rented card; the house rigs unreachable by software) until a card is found." + "at": "2026-10-09T12:15:20.071Z", + "note": "The lab's interface and the candidate table at the fan-out: the frozen v6 control carried from the record (the house 5090 at its knee 4,011 nJ per hash, board power; the X0 amendment 5b rows: the DRAM board 2.35x same node WITNESS, the N2 die 7.8x the worst credible), the cohort rows for the 3090, the 5080 and the AMD and Intel tiers NOT RUN, adversarial set v1 pending; the three other controls (ProgPoW 0.9.4 reference, FishHash, the cooperative ARX candidate) NOT RUN with their clocks. No score is the lab's until the cohort and the adversary rows are in; R15-01, R15-08 and R15-09 stay NOT RUN until read. X10 (cand-x10) joins the table NOT RUN with its per-lane assignments and clocks; COHORT's ctl-v6 denominator set is in flight on eight rented pods. 12:1x UK: adversarial set v1 on the table (the frozen v6's same-node board 2.57x, 2.04 to 3.00, the fused tail CLAIMED until the routed lanes land; the die 11.4x as a coexistence row); the coexistence table (interface section 8b) added as the scoreboard's headline; SEARCH's first screen recorded as SCREEN rejections. Still NOT RUN: no cohort score until COHORT's eight rows are read back. 12:2x UK: set v2 (the routed fused-ARX lanes) makes the v6 board 2.60x a WITNESS; the ctl-v6 coexistence table (the board holds at every price; the N2 die pushes the GPU owner out above 14,300 dies at USD 0.10) is the headline; X10 SCREEN with the card modelled (the board 3.00x at 118 loads). Still NOT RUN: the cohort rows in their timed runs. 12:3x UK: the first cohort cells (ctl-v6 at stock on rented 5090, 5080 and 3090 pods: the worst cell the 3090 at 8,429 nJ = 5.46x on set v2's same-node board, PARTIAL, the dataset size under decision after CONTROLS measured the live 4 GiB object at 2.4x the 1 GiB research pack's rate); X10's first measured cell (cand-x10b on the 4090 at stock 3,653 nJ per lane-work = 5.8x on the board; the fold buys nothing); set v3 (routed 64-register and multiply-xor lanes); the fourth to sixth review rulings (8c); the 4 GiB rule (8e). Every row still NOT RUN until read. 12:4x UK: ctl-v6's first full score over the NVIDIA cohort at stock (the worst cell the RTX 4090 uncapped 8,751 nJ = 5.67x on set v2's same-node board; every cell at 4 GiB, the earlier 2.4x reading an instrument artefact, corrected once); the two-phase rows (ADVERSARY 545f3f8a0, 36d17b15c): phase B NOT LIVE until a shipped package proves, the shipping row open; SEARCH's twenty candidates on set v3 none under 1.5x on any cell (SCREEN). Every row still NOT RUN until read. 13:0x UK: the decider closed on both cards (the 4 GiB object costs 2.0 to 2.9 percent of rate against its 1 GiB export; the 2.4x reading withdrawn as a contention fault); the read-headroom row answered (both cards at their activation limit); the uncapped 5090 cell 5,980 nJ = 3.88x on the board; the shipping row's facts by file and line with the Devnet 4 correction (a 24 GB card proves the v1 shard now; the proving row NOT LIVE until the epoch record by 16:00); the 4 GiB cap defined as the mining dataset floor only; the founder's ledger order (8f) applied. Every row still NOT RUN until read. 13:1x UK: CONTROLS' done line (the four controls, Etchash and Autolykos2 staged bit-exact with SUMS); ADVERSARY's cross-chain phase A and B (no chain's emission recovers a board chip; the proving share the one term) and the E9 Pro calibration (1.28x pessimistic); the first founder bundle 985afee6. Every row still NOT RUN until read. | The 1.5x adversarial comparison laboratory (the founder's order, 9 October 2026, 11:4x UK): one evaluation for every control and candidate (the measurement recipe with the read-only twin for the memory share, the adversary interface returning the lowest credible specialist energy per design as a complete machine with WITNESS or BOUND labels, the score as the worst comparison over the required cohort same node and one node ahead, the rejection filters F1 to F6, the regression set REG-01 to REG-08 from the 8 and 9 October failures). Every row NOT RUN until the panel reads it; the first measured score (the frozen v6 control on the cohort against adversarial set v1) lands as a later batch under this cell. Amended 11:5x UK: X10, the full-sector fold candidate of the founder's third review, added as cand-x10 with the scoped same-node board claim (the die and node-ahead chips as coexistence rows); the AMD and Intel tiers NOT RUN on every candidate (no rented card; the house rigs unreachable by software) until a card is found." } }, "in_progress_since": "2026-10-09T10:48:54.646Z", diff --git a/site/404.html b/site/404.html index 71c3126ff..898162924 100644 --- a/site/404.html +++ b/site/404.html @@ -120,6 +120,7 @@ main{flex:1} EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -160,6 +161,7 @@ main{flex:1} EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -268,6 +270,7 @@ main{flex:1} Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/acceptance.html b/site/acceptance.html index b103fb51e..5cbe5e592 100644 --- a/site/acceptance.html +++ b/site/acceptance.html @@ -4,13 +4,13 @@ Igneum Test and Acceptance Standard: every case, shown as it passes - + - + @@ -24,7 +24,7 @@ - + @@ -263,6 +263,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -303,6 +304,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -368,8 +370,8 @@
-
Igneum 2.0 acceptance

Test and Acceptance Standard 1.0

Every case of the standard, shown as it is run, in the standard’s own words. A checklist, never a completion score: a gate passes only when every case it depends on has passed.

Basis IGNEUM_2.0_Plan.pdf, 37 pages, 8 October 2026. The standard runs to 73 pages. Registry dated 8 October 2026.

APPROVED AS PROPOSED 8 OCTOBER 2026P13 DEFERRED

Test and Acceptance Standard 1.0: APPROVED AS PROPOSED by the founder, 8 October 2026; P13 (maintenance continuity) DEFERRED; 262 cases: 8 passed under the standard, 0 running with team evidence, 7 failed, 247 not run, 0 deferred

  • 8 pass
  • 7 fail
  • 0 blocked
  • 0 running
  • 247 not run
  • 0 deferred
The gates

Five gates, and the freeze before them.

A gate reads NOT RUN until every case it depends on has run, RUNNING while any is running, BLOCKED if any is blocked, FAIL if any fails, and PASS only when every case passes. No gate is weighted into an average.

G0NOT RUN

Freeze

Release identity

No formal run or public pass before approval.

8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred

  • GOV8 casesNOT RUN
G1NOT RUN

Baseline

D1

No validated hardware claim without reproduction.

16 cases: 1 passed under the standard, 0 running with team evidence, 15 not run, 0 deferred

  • GOV8 casesNOT RUN
  • GPU8 casesNOT RUN
G2FAIL

Experiments

D2

No improvement claim from a negative hypothesis.

32 cases: 1 passed under the standard, 0 running with team evidence, 2 failed, 29 not run, 0 deferred

  • GOV8 casesNOT RUN
  • GPU8 casesNOT RUN
  • POW8 casesFAIL
  • ROT8 casesNOT RUN
G3NOT RUN

Adversary

D3

No broad resistance claim from one weak design.

16 cases: 0 passed under the standard, 0 running with team evidence, 16 not run, 0 deferred

  • GOV8 casesNOT RUN
  • ADV8 casesNOT RUN
G4FAIL

Coexistence

D4

No durability claim based on assumed chip expiry.

24 cases: 0 passed under the standard, 0 running with team evidence, 1 failed, 23 not run, 0 deferred

  • GOV8 casesNOT RUN
  • ECO8 casesFAIL
  • INC8 casesNOT RUN
G5NOT RUN

No rescue

D5

No no-rescue claim from a founder-supported demo.

56 cases: 5 passed under the standard, 0 running with team evidence, 51 not run, 0 deferred

  • GOV8 casesNOT RUN
  • ROT8 casesNOT RUN
  • ZKP8 casesNOT RUN
  • INC8 casesNOT RUN
  • FIN8 casesNOT RUN
  • OPS8 casesNOT RUN
  • UX8 casesNOT RUN

The three named gates

FAIL

Technical readiness

Execution control

No mainnet-ready claim with missing enforcement or safety.

64 cases: 6 passed under the standard, 0 running with team evidence, 5 failed, 53 not run, 0 deferred

  • GOV8 casesNOT RUN
  • POW8 casesFAIL
  • EVM8 casesNOT RUN
  • ZKP8 casesNOT RUN
  • CAP8 casesNOT RUN
  • FIN8 casesNOT RUN
  • VER8 casesFAIL
  • UX8 casesNOT RUN
NOT RUN

Commercial evidence

Execution control

Devnet activity is insufficient.

24 cases: 0 passed under the standard, 0 running with team evidence, 24 not run, 0 deferred

  • GOV8 casesNOT RUN
  • CAP8 casesNOT RUN
  • COM8 casesNOT RUN
FAIL

Leadership-contender decision

Execution control

Supports a scoped contention assessment, not a guaranteed rank.

262 cases: 8 passed under the standard, 0 running with team evidence, 7 failed, 247 not run, 0 deferred

  • GOV8 casesNOT RUN
  • GPU8 casesNOT RUN
  • POW8 casesFAIL
  • ADV8 casesNOT RUN
  • ROT8 casesNOT RUN
  • ECO8 casesFAIL
  • EVM8 casesNOT RUN
  • ZKP8 casesNOT RUN
  • CAP8 casesNOT RUN
  • INC8 casesNOT RUN
  • FIN8 casesNOT RUN
  • VER8 casesFAIL
  • OPS8 casesNOT RUN
  • UX8 casesNOT RUN
  • COM8 casesNOT RUN
  • LEAD8 casesNOT RUN
  • REV44 casesNOT RUN
  • INT18 casesFAIL
  • VR40 casesNOT RUN
  • TV32 casesNOT RUN
01GOV

Release identity and evidence

Prevent a favourable result from being attached to the wrong code, assumptions or public claim.

NOT RUN
Owner
Release lead + independent assurance
Gate
G0 / all gates G0 G1 G2 G3 G4 G5
Fixtures
F0 manifest; F1 source/build archives; F9 evidence vault
Plan pages
5, 21, 23, 25, 26, 27
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
GOV-01Freeze the release and its claimsPriority BLOCKERProfile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 08:43 UK

Setup

Candidate source, binaries, public documentation and the 2.0 plan are available; no run is yet accepted.

Steps

  1. Record exact commits, binary hashes, dependencies, genesis/network identity, mining class, datasets, execution fork, verifier IDs and fee rules in F0.
  2. Map every promised capability and plan requirement to a test ID; distinguish supported mining, proving and wallet combinations.
  3. Sign the manifest with protocol, product and independent review owners before confirmatory runs.

Accept

Every material rule and claim has an unambiguous version and test. Conflicts or unknown activation rules produce BLOCKED, not an inferred default. Changes create a new manifest and invalidate affected results.

Evidence the case requires

Signed F0; source-to-test map; claim inventory; unresolved-field register.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Run
f0-signing-20261008-2330
Design status
NOT RUN
Standard page
18
Plan pages
5, 21, 23, 25, 26, 27
GOV-02Approve thresholds before resultsPriority BLOCKERProfile P00NOT RUNEvidence recordLast run 8 Oct 2026, 21:10 UK

Setup

This manual supplies proposed test thresholds, not source-approved protocol parameters.

Steps

  1. Approve or replace every P-profile before confirmatory testing; give each change a rationale and independent approver.
  2. Register hardware cohorts, mandatory economic worlds, customer workloads, peer dimensions and exclusion rules.
  3. Lock the profile hash and hold out seeds/workloads from the developers doing optimisation.

Accept

No decision-critical field is TBD. Numeric limits are frozen, commercially meaningful and not chosen from observed results. A weakened limit after failure requires a new protocol, full affected rerun and explicit claim downgrade review.

Evidence the case requires

Approved profile register; timestamped holdout commitments; change log.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
CI steward (a2ecfa95d3206016c)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
18
Plan pages
5, 21, 23, 25, 26, 27
GOV-03Reproduce builds outside the founding teamPriority BLOCKERProfile P00, P02NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Provide public source and documented build instructions to three unaffiliated operators.

Steps

  1. Build on clean declared environments without private files, tokens or founder assistance.
  2. Compare reproducible payload hashes; isolate signatures, notarisation and permitted non-deterministic wrappers.
  3. Run reference vectors and restart a node using only documented artifacts.

Accept

All independent builds reproduce the same consensus payload or an independently explained, pre-approved wrapper difference; reference outputs match exactly. Missing private prerequisites block release.

Evidence the case requires

Build logs; dependency lockfiles; binary comparison; operator attestations.

Method
Independent reproduction
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Design status
NOT RUN
Standard page
18
Plan pages
5, 21, 23, 25, 26, 27
GOV-04Preserve raw and negative evidencePriority BLOCKERProfile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Enable append-only storage for run outputs and a separate analysis workspace.

Steps

  1. Capture failed, aborted and successful runs with timestamps, seeds and environment hashes.
  2. Recompute one published figure from raw records on a clean machine.
  3. Modify a retained artifact deliberately and test integrity verification.

Accept

Every headline can be regenerated; tampering is detected; exclusions have pre-registered reasons. Failed or missing runs remain visible and are never replaced silently by a successful retry.

Evidence the case requires

Artifact manifest; hashes; reproduction script; exclusion ledger; negative-run archive.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
CI steward (a2ecfa95d3206016c)
Design status
NOT RUN
Standard page
19
Plan pages
5, 21, 23, 25, 26, 27
GOV-05Prove the test oracle detects broken behaviourPriority BLOCKERProfile P01NOT RUNEvidence none yetLast run 8 Oct 2026, 19:28 UK

Setup

Create controlled defective variants on an isolated network only.

Steps

  1. Disable proof verification, change one reward, accept an expired authority set and alter one hash output in separate mutants.
  2. Run the corresponding ZKP, INC, FIN and POW tests without telling the runner which mutant is active.
  3. Confirm the baseline still accepts authorised valid cases.

Accept

Every deliberately introduced fault is caught by its mapped test; valid controls pass. Any undetected critical mutant blocks acceptance of that test family until the oracle is repaired.

Evidence the case requires

Mutation catalogue; blinded run results; baseline controls; oracle review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fast-time lane (a8be71a0db962911c)
Run
200-417c4a57-b2
Design status
NOT RUN
Standard page
19
Plan pages
5, 21, 23, 25, 26, 27
GOV-06Enforce scope and optional-feature disciplinePriority BLOCKERProfile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 08:36 UK

Setup

Inventory FP32 experiments, receipts/oracles and all retained or excluded mining levers.

Steps

  1. Mark each capability CORE, CLAIMED-OPTIONAL or EXCLUDED before release testing.
  2. For excluded code, check binaries, protocol activation and product copy for accidental enablement or implied availability.
  3. For each claimed option, require the complete associated test set rather than a demonstration.

Accept

Every core and claimed-option obligation passes. Excluded items are shown as EXCLUDED, never PASS and never counted as achievements. Removing a failed core requirement prevents an all-2.0-pass claim.

Evidence the case requires

Scope manifest; activation scan; product-copy comparison; exclusions register.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
CI steward (a2ecfa95d3206016c)
Run
site-gate-20261009-01
Design status
NOT RUN
Standard page
19
Plan pages
5, 21, 23, 25, 26, 27
GOV-07Independent review and finding closurePriority BLOCKERProfile P09NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Nominate reviewers with declared conflicts and scopes covering cryptography, consensus and hardware.

Steps

  1. Provide pinned code, raw data, adversarial models and prior failures, including negative results.
  2. Track each finding to remediation and an independent retest; do not use the author as sole approver.
  3. Have reviewers state unreviewed surfaces and model limitations in their signed conclusions.

Accept

No unresolved critical or high-severity finding affects the claimed release. A finite review is described by scope, not as proof of universal security. Independent reproduction and review are both evidenced.

Evidence the case requires

Signed scoped reports; conflict declarations; finding/retest ledger.

Method
Independent specialist review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
20
Plan pages
5, 21, 23, 25, 26, 27
GOV-08Invalidate stale evidence and control public statusPriority BLOCKERProfile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Create a simulated post-test change to a verifier, mining class, dataset and fee rule.

Steps

  1. Calculate affected test dependencies and invalidate their former PASS statuses.
  2. Regenerate public status pages from F0 and the evidence register.
  3. Attempt to publish a rank-one, guaranteed-profit or automatic-chip-death claim without the required evidence.

Accept

Affected gates return to NOT RUN or BLOCKED. Public claims retain version, limits and date; unsupported claims are withheld. No stale result remains attached to a different release.

Evidence the case requires

Dependency impact report; regenerated status page; rejected claim examples.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
CI steward (a2ecfa95d3206016c)
Design status
NOT RUN
Standard page
20
Plan pages
5, 21, 23, 25, 26, 27
02GPU

Whole-system GPU measurements

Close the pending measurements and evaluate the actual configuration, including costs hidden by kernel-only results.

NOT RUN
Owner
GPU lead + three independent operators
Gate
G1 / G2 G1 G2
Fixtures
F2 retail-hardware cohort; F3 paired benchmark workloads; F9 calibrated evidence
Plan pages
6, 7, 8, 14, 18, 23
8 cases: 1 passed under the standard, 0 running with team evidence, 7 not run, 0 deferred
GPU-01Cover the declared commodity populationPriority GATEProfile P02NOT RUNEvidence none yetLast run 8 Oct 2026, 22:49 UK

Setup

Freeze the P02 cohort, supported role matrix and the final v6 configuration.

Steps

  1. Inventory physical SKU, usable memory, driver, operating system, firmware, cooling and acquisition channel.
  2. Run mining on every supported cohort cell and proving on every separately advertised prover cell.
  3. Include lower-memory, used-generation and all advertised vendor cases; retain unsupported results separately.

Accept

All declared cells are tested, with no after-the-fact removal of weak cards. At least the P02 minimum coverage is met. Mining-only support is never reported as proof-generation support.

Evidence the case requires

Cohort manifest; compatibility matrix; raw results by SKU and role.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
p02-fleet-pods-20261008-01
Design status
NOT RUN
Standard page
21
Plan pages
6, 7, 8, 14, 18, 23
GPU-02Reproduce Ember clock-lock savingsPriority GATEProfile P02, P03PASSEvidence recordLast run 9 Oct 2026, 04:58 UK

Setup

Use paired stock and tuned runs on the same board, host, workload and ambient conditions.

Steps

  1. Warm to stability; randomise stock/tuned order and run P02 repeated sessions.
  2. Measure accepted work, calibrated wall energy, device telemetry and rejected work.
  3. Calculate paired energy and rate changes with run-level uncertainty, retaining failed tuning attempts.

Accept

Tuning preserves correctness and meets approved P03 operating limits. The historical 34-41% saving and under-2% rate-loss statement is reproduced only for qualifying configurations; otherwise that claim is corrected. Existing savings are not counted twice.

Evidence the case requires

Raw power/time series; paired analysis; tuning settings; claim-by-SKU table.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
hash-lane-20261009-batch4
Design status
NOT RUN
Standard page
21
Plan pages
6, 7, 8, 14, 18, 23
GPU-03Measure the real 64-register GPU costPriority GATEProfile P02, P03NOT RUNEvidence none yetLast run 9 Oct 2026, 04:58 UK

Setup

Build the baseline and window variant with identical dataset, reads and semantic workload.

Steps

  1. Inspect compiled register allocation, spills, occupancy and memory traffic on each supported backend.
  2. Measure paired complete-system energy and accepted throughput, including host work.
  3. Repeat during proving coexistence and expose any memory or scheduling cliff.

Accept

Any production window meets P03 budgets for every mandatory SKU; no hidden spills or correctness changes. Zero GPU cost is claimed only where measurement supports it within uncertainty. Results feed the redesigned adversary, not an old core estimate.

Evidence the case requires

Compiler reports; allocation traces; paired energy/rate data; coexistence runs.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
hash-lane-20261009-batch4
Design status
NOT RUN
Standard page
21
Plan pages
6, 7, 8, 14, 18, 23
GPU-04Find the memory-clock operating ladderPriority BLOCKERProfile P01, P02NOT RUNEvidence recordLast run 8 Oct 2026, 22:00 UK

Setup

Use safe vendor-supported settings only; record operator permission and original settings.

Steps

  1. Sweep approved core and memory operating points while holding workload constant.
  2. Measure error rate, accepted throughput, wall energy and thermal equilibrium.
  3. Repeat the selected knee after reboot and restore defaults after a failed or interrupted tuning session.

Accept

Selected profiles are stable, reproducible and not dependent on unsafe clocks. Every accepted hash remains correct; saved settings restore predictably. Tuning failure leaves a working safe configuration.

Evidence the case requires

Clock ladder; safe bounds; thermal/error logs; reboot and rollback record.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
22
Plan pages
6, 7, 8, 14, 18, 23
GPU-05Test dataset fit and support-horizon costsPriority BLOCKERProfile P01, P02, P06NOT RUNEvidence none yetLast run 9 Oct 2026, 04:58 UK

Setup

Test 5.5, 8.5 and 11.5 GiB only as source-proposed candidates; F0 determines activated sizes.

Steps

  1. Measure allocation plus driver, display, prover and OS headroom on the 8 GB and other cohort tiers.
  2. Run near-full-memory, fragmentation, restart and next-epoch construction scenarios.
  3. Compare time-sharing/eviction with concurrent mining/proving, including reload cost.

Accept

Every advertised combination completes without OOM or silent corruption. Unsupported future sizes are identified before activation. GPU exclusions and lost proving capacity appear in ECO evaluation; retirement of a tier is not a success metric.

Evidence the case requires

Memory budget per SKU; OOM traces; support horizon; concurrency cost table.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
hash-lane-20261009-batch4
Design status
NOT RUN
Standard page
22
Plan pages
6, 7, 8, 14, 18, 23
GPU-06Measure accepted work under ordinary connectivityPriority GATEProfile P02, P10NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use the same hardware against clean, delayed, lossy and intermittent links in F4.

Steps

  1. Measure kernel rate and accepted work separately under home and datacentre link profiles.
  2. Include reconnects, template changes, expired submissions and pool failover.
  3. Attribute loss to network, local software, validation and protocol causes.

Accept

Results use accepted work, never kernel rate alone. Ordinary-link incremental rejection stays within P10; all losses remain priced in ECO. Unreachable links may pause but must not claim paid work.

Evidence the case requires

Per-submission ledger; network trace; rejection reasons; accepted-work comparison.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
22
Plan pages
6, 7, 8, 14, 18, 23
GPU-07Survive sustained thermal and power operationPriority BLOCKERProfile P01, P02, P10NOT RUNEvidence recordLast run 8 Oct 2026, 22:00 UK

Setup

Run the selected profile on actual reference machines for the P02 soak period.

Steps

  1. Track wall power, temperatures, clocks, memory and accepted work continuously.
  2. Inject safe power interruptions, process restarts and normal competing desktop load.
  3. Check restored settings and compare late-run efficiency with the first stable period.

Accept

No invalid work or unsafe persistent settings; P02/P10 stability limits hold. Thermal throttling, crashes and recovery time remain in throughput and energy denominators. A crash-free short benchmark cannot substitute for the soak.

Evidence the case requires

Seven-day time series; crash reports; settings-restoration checks; drift analysis.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
23
Plan pages
6, 7, 8, 14, 18, 23
GPU-08Reproduce the full baseline independentlyPriority GATEProfile P02NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Three unaffiliated operators receive F0, F2 and F3, including the final miner/prover build.

Steps

  1. Repeat identical-SKU paired runs with documented meter calibration and environment differences.
  2. Recompute joules and total cost per accepted work from the shared raw schema.
  3. Investigate divergence before accepting a pooled headline or uncertainty band.

Accept

Reproductions meet P02 tolerance and exact correctness. No unexplained divergence or selectively missing low-end cell remains. Report manufactured GPU measurements separately from modelled specialist estimates.

Evidence the case requires

Three signed reproduction packs; reconciliation report; final baseline table.

Method
Independent reproduction
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
23
Plan pages
6, 7, 8, 14, 18, 23
03POW

Proof-of-work correctness and coupling

Find semantic disagreements and structural shortcuts before treating a harder-looking program as a stronger defence.

FAIL
Owner
Cryptography + GPU lead
Gate
G2 / technical readiness G2
Fixtures
F0 rule set; F3 independent CPU/GPU oracles; F5 mutation corpus
Plan pages
7, 9, 10, 23
8 cases: 0 passed under the standard, 0 running with team evidence, 2 failed, 6 not run, 0 deferred
POW-01Match independent execution across every backendPriority BLOCKERProfile P01NOT RUNEvidence none yetLast run 9 Oct 2026, 06:16 UK

Setup

Implement an independently written reference evaluator, not a wrapper around the production GPU path.

Steps

  1. Execute the P01 corpus across every family, boundary seed and supported backend.
  2. Exercise zero, maximum, sign, shift, rotate, overflow and unaligned-address cases allowed by the spec.
  3. Minimise every mismatch and rerun it on clean builds.

Accept

Bit-for-bit agreement for all valid cases and identical rejection for invalid cases. One unexplained mismatch is a blocker. Large sample counts are evidence of testing, not proof that unseen disagreements cannot exist.

Evidence the case requires

Reference implementation review; seeds/vectors; backend matrix; mismatch archive.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
same-work-20261008-01
Design status
NOT RUN
Standard page
24
Plan pages
7, 9, 10, 23
POW-02Validate generated programs and index foldingPriority BLOCKERProfile P01NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Use the frozen grammar, opcode semantics and index-fold rule; include boundary and malformed programs.

Steps

  1. Enumerate small constrained programs and fuzz the full generator at P01 depth.
  2. Check bounds, valid dependencies, address distribution and forbidden encodings.
  3. Compare source-level operations with optimised compiled code for removed or altered work.

Accept

No accepted program violates semantics, termination or memory bounds. Distribution claims have predeclared tests and effect-size limits; passing randomness checks is not treated as a cryptographic proof.

Evidence the case requires

Generator/fuzzer logs; reduced counterexamples; disassembly comparison; index tests.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
24
Plan pages
7, 9, 10, 23
POW-03Test whether live state is unavoidablePriority GATEProfile P03, P04FAILEvidence none yetLast run 9 Oct 2026, 08:32 UK

Setup

Take the 64-register candidate and the cheapest independently proposed storage organisations.

Steps

  1. Trace value liveness across dependent reads and final output, distinguishing distinct information from duplicated values.
  2. Try banking, compression, recomputation, fewer ports and time-multiplexed contexts.
  3. Quantify the best complete-system cost/throughput trade-off rather than the reference register count.

Accept

Production selection is supported by measured or physically modelled penalties after these alternatives. G2 requires the P03 improvement; an attractive source-level register count alone does not pass.

Evidence the case requires

Liveness traces; alternative implementations; Pareto table; reviewer analysis.

Method
Experiment + independent hardware review
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261009-placed-32lane
Design status
NOT RUN
Standard page
24
Plan pages
7, 9, 10, 23
POW-04Evaluate connected-resource restructuringPriority GATEProfile P03, P04NOT RUNEvidence none yetLast run 9 Oct 2026, 08:32 UK

Setup

Use a candidate initially matched to baseline instruction count, read count and dataset size.

Steps

  1. Connect state, addresses, arithmetic and lane communication according to the written hypothesis.
  2. Measure GPU cost and allow the specialist reviewer to redesign the entire core.
  3. Repeat on held-out program seeds and compare the worst supported adversary, not only the original design.

Accept

The selected upgrade meets P03 and improves the adversarial result outside declared uncertainty. A negative experiment remains a negative outcome; adopting a different design requires a new frozen comparison.

Evidence the case requires

Matched workloads; GPU runs; redesigned core estimates; held-out results.

Method
Controlled experiment
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261009-placed-32lane
Design status
NOT RUN
Standard page
25
Plan pages
7, 9, 10, 23
POW-05Prevent amortised cheap winning attemptsPriority BLOCKERProfile P01, P04NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Prepare valid templates, nonces, intermediate-state captures and independent acceptance checks.

Steps

  1. Vary nonce, payout identity, transactions, roots and other committed fields after expensive work.
  2. Try replay, precomputation, shared prefixes, partial evaluation and many cheap suffix candidates.
  3. Price any valid strategy against fresh evaluation; independently review all bindings.

Accept

Invalid modifications are rejected. Any valid cost-saving strategy is incorporated into ADV and must still meet P04/ECO gates. No unresolved shortcut is hidden behind passing reference vectors.

Evidence the case requires

Attack implementations; valid/invalid controls; work-cost analysis; binding review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
pool design seat (a3832b1c3b274b310)
Run
binding-review-2026-10-08-a05
Design status
NOT RUN
Standard page
25
Plan pages
7, 9, 10, 23
POW-06Bound verifier work and malformed-input costPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 19:28 UK

Setup

Use ordinary CPU validators with a manifest-defined resource budget and untrusted submissions.

Steps

  1. Submit shortest/longest programs, malformed encodings and adversarial memory references.
  2. Measure verification time, peak memory and work amplification across valid and invalid inputs.
  3. Sustain the approved hostile request rate while ordinary valid traffic continues.

Accept

All semantics remain correct and P09 resource budgets hold. Invalid traffic cannot cause unbounded allocation, crashes or disproportionate free work. Rate limits must not replace consensus validation.

Evidence the case requires

CPU profiles; adversarial corpus; allocation traces; valid-traffic latency.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
p01-partb-20261008-01
Design status
NOT RUN
Standard page
25
Plan pages
7, 9, 10, 23
POW-07Constrain any mixed-resource or FP32 branchPriority BLOCKERProfile P00, P01, P03FAILEvidence none yetLast run 8 Oct 2026, 22:00 UK

Setup

If this branch is excluded, verify that it is unreachable and not claimed; if included, use a separate frozen candidate.

Steps

  1. Specify exact rounding, fusion, special values and backend behaviour before compiling.
  2. Differentially test all supported architectures and allow numerical-domain simplification in the specialist model.
  3. Include verifier cost and candidate energy in P03/P04, not just arithmetic-unit area.

Accept

Included branches achieve exact agreed semantics and all hardware budgets. An excluded branch earns no performance credit. No approximate operation or unspecified compiler choice enters consensus.

Evidence the case requires

Scope decision; semantic specification; vectors; simplified datapath model.

Method
Conditional implementation test
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
kills-20261008
Design status
NOT RUN
Standard page
26
Plan pages
7, 9, 10, 23
POW-08Keep rejected mechanisms out of the shipped claimPriority GATEProfile P00, P03NOT RUNEvidence none yetLast run 9 Oct 2026, 04:58 UK

Setup

Inventory long programs, select trees, SM gating, wider reads, sealed classes, random epoch lengths, per-tier scoring and VRF draws.

Steps

  1. Retain their historic negative tests and realistic SRAM instruction-memory control.
  2. Inspect the release for reintroduction through renamed settings or hidden paths.
  3. Require a new written hypothesis and complete adversarial retest for any proposed return.

Accept

Excluded levers remain excluded unless separately approved and retested. Flip-flop instruction-memory area is never presented as the cost of a realistic SRAM implementation.

Evidence the case requires

Decision register; binary/config scan; negative-control results.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
hash-lane-20261009-batch4
Design status
NOT RUN
Standard page
26
Plan pages
7, 9, 10, 23
04ADV

Programmable specialist adversaries

Give the opponent permission to adapt, share resources and remain operational; test cost rather than imagined chip death.

NOT RUN
Owner
Independent hardware team
Gate
G3 G3
Fixtures
F2 reference GPUs; F6 RTL/physical models; all published families
Plan pages
8, 10, 12, 22, 23
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
ADV-01Build a multi-family programmable opponentPriority GATEProfile P01, P04NOT RUNEvidence recordLast run 9 Oct 2026, 08:32 UK

Setup

Provide the complete published family bank and future known parameter schedule to the reviewer.

Steps

  1. Design one programmable architecture that supports all retained families, including firmware and emulation paths.
  2. Optimise clocks, lanes, ports and pipelines without requiring a graphics-card layout.
  3. Verify its outputs against POW vectors before measuring any advantage.

Accept

At least the P04 design diversity is evaluated; every estimated competitive design is functionally validated. Inability of one narrow design to adapt is not evidence that all chips expire.

Evidence the case requires

Architecture reports; functional simulations; adaptation matrix; reviewer signature.

Method
Independent hardware study
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261009-placed-32lane
Design status
NOT RUN
Standard page
27
Plan pages
8, 10, 12, 22, 23
ADV-02Price shared, reduced and reconstructed memoryPriority GATEProfile P04NOT RUNEvidence recordLast run 8 Oct 2026, 21:41 UK

Setup

Allow multiple engines to share a dataset and to store selected fractions rather than a complete per-engine copy.

Steps

  1. Sweep sharing factors, memory fractions, caches and recomputation depth across many simultaneous hashes.
  2. Include construction/update amortisation, bandwidth contention and retained state.
  3. Take the most favourable feasible point for the specialist into the complete-board model.

Accept

No omitted feasible trade-off materially lowers the accepted cost estimate. Any winning alternative is included in P04 and ECO; capacity alone is not accepted as an energy bound.

Evidence the case requires

Sweep definitions; energy/bandwidth data; best-feasible envelope; excluded-design reasons.

Method
Model + adversarial implementation
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261008-placed-8lane
Design status
NOT RUN
Standard page
27
Plan pages
8, 10, 12, 22, 23
ADV-03Attack with data-local and hybrid executionPriority GATEProfile P04NOT RUNEvidence recordLast run 9 Oct 2026, 08:32 UK

Setup

Permit distributed memories, state migration and companion CPU/GPU/FPGA components.

Steps

  1. Compare moving computation, intermediate state or fetched data to each read location.
  2. Test specialised mining alongside outsourced proof generation rather than assuming one physical GPU does both.
  3. Include interconnect, host, synchronisation, idle and conversion costs.

Accept

The cheapest feasible combined system is included in the adversarial envelope and economic model. A worker identity or account is never treated as proof of a single physical device.

Evidence the case requires

Hybrid architecture diagrams; traffic traces; system cost and energy ledger.

Method
Independent system modelling
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261009-placed-32lane
Design status
NOT RUN
Standard page
27
Plan pages
8, 10, 12, 22, 23
ADV-04Measure profitable selective participationPriority GATEProfile P04, P12NOT RUNEvidence recordLast run 8 Oct 2026, 21:41 UK

Setup

Use all declared families plus held-out generated programs and the protocol difficulty rule.

Steps

  1. Identify favourable execution paths and add cheap fallbacks for other periods.
  2. Simulate entry/exit around profitable periods, including idle time, compilation and re-entry costs.
  3. Evaluate revenue and costs across the full schedule, not just average program energy.

Accept

Intermittent specialists meet P04/ECO limits when evaluated on full-period economics. A weak tail cannot be concealed by a favourable mean; known valid shortcuts must be priced.

Evidence the case requires

Per-program advantage distribution; policy simulator; full-period returns.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261008-placed-8lane
Design status
NOT RUN
Standard page
28
Plan pages
8, 10, 12, 22, 23
ADV-05Validate physical and complete-board costsPriority GATEProfile P04NOT RUNEvidence none yetLast run 9 Oct 2026, 08:32 UK

Setup

Use feasible process/library assumptions and documented component boundaries; no fabricated foundry access.

Steps

  1. Model SRAM macros, ports, wiring, clocking, memory PHYs, external memory, host and power conversion.
  2. Run place-and-route where available; mark unmodelled items as uncertainty rather than zero.
  3. Compare against a calibrated existing hardware block or equivalent validation case.

Accept

No decision-critical cost is omitted. Physically unvalidated or proprietary estimates are labelled and independently bounded; synthesis alone cannot earn a manufactured-chip claim.

Evidence the case requires

Netlist/physical reports; macro assumptions; bill of materials; model calibration.

Method
Independent physical-design review
Cadence
Release candidate; repeat after relevant changes
Owner
k lane (a3c9601a6d4686fe1)
Run
adversary-20261009-placed-32lane
Design status
NOT RUN
Standard page
28
Plan pages
8, 10, 12, 22, 23
ADV-06Separate process advantage from specialisationPriority GATEProfile P04, P12NOT RUNEvidence recordLast run 8 Oct 2026, 22:09 UK

Setup

Evaluate same-node, one-node-ahead and two-node-ahead scenarios with explicit technology definitions.

Steps

  1. Use independently justified process factors, voltages, memory and packaging assumptions for each design.
  2. Allow reusable IP and modular revisions; credit GPU improvement consistently.
  3. Evaluate measurement confidence and model-parameter sensitivity separately.

Accept

P04 primary limits hold for all competitive-reference cells; two-node futures are reported and pass the predeclared economic stress envelope. A model range is never labelled a statistical confidence interval without justification.

Evidence the case requires

Node-specific reports; factor provenance; uncertainty and sensitivity tables.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
k lane (a3c9601a6d4686fe1)
Run
floor-k-20261008-rows-repeat
Design status
NOT RUN
Standard page
28
Plan pages
8, 10, 12, 22, 23
ADV-07Evaluate lifetime without forced obsolescencePriority GATEProfile P04, P12NOT RUNEvidence none yetLast run 9 Oct 2026, 08:32 UK

Setup

Assume multi-year productive survival and known schedule support before testing optional retirement penalties.

Steps

  1. Price firmware, emulation, memory expansion, companion hardware and incremental redesign.
  2. Include 1-, 3- and 5-year productive lifetimes plus idle/resale possibilities.
  3. Grant a retirement credit only if all feasible cheaper adaptations lose competitiveness.

Accept

The primary case does not require chip death or a fresh full development bill per family. Every retirement credit has a documented adaptation comparison; incompatible and unprofitable are reported separately.

Evidence the case requires

Lifetime/adaptation ledger; revision costs; feasible-alternative analysis.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261009-placed-32lane
Design status
NOT RUN
Standard page
29
Plan pages
8, 10, 12, 22, 23
ADV-08Independently challenge the best-cost envelopePriority GATEProfile P04NOT RUNEvidence recordLast run 9 Oct 2026, 08:32 UK

Setup

Publish the non-sensitive model and negative results; commission an unaffiliated second hardware reviewer.

Steps

  1. Reward cheaper valid designs and reproduced shortcuts, not confirmation of the preferred number.
  2. Re-run P04 with the strongest submitted feasible design, including a low-cost funded-development case.
  3. Record unresolved modelling disagreements and future technology exclusions.

Accept

Both reviews accept the scoped envelope or all material disagreements are resolved transparently. Passing supports only evaluated designs and conditions, never a universal bound on all future silicon.

Evidence the case requires

Two review reports; challenge log; final envelope; unresolved-limit statement.

Method
Independent challenge/review
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261009-placed-32lane
Design status
NOT RUN
Standard page
29
Plan pages
8, 10, 12, 22, 23
05ROT

Epochs, seeds and memory transitions

Transitions must agree across nodes and remain usable during failures; crossing a boundary is not a chip-retirement test.

NOT RUN
Owner
Consensus + GPU leads
Gate
G5 / G2 G5 G2
Fixtures
F0 activation rules; F4 fault network; F5 historical and boundary vectors
Plan pages
7, 11, 19, 21
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
ROT-01Agree across every hourly boundaryPriority BLOCKERProfile P01, P08NOT RUNEvidence recordLast run 8 Oct 2026, 21:07 UK

Setup

Use real nodes, CPU/GPU miners and independent clocks around successive program boundaries.

Steps

  1. Submit valid work immediately before, at and after the activation boundary under clock skew and delayed delivery.
  2. Restart nodes from both sides and replay the same headers.
  3. Compare selected seed, program, validity, rewards and local wall-clock dependence.

Accept

All honest nodes derive identical consensus outcomes from the frozen rule. Late work is handled exactly as specified; no wall-clock ambiguity or cross-backend split occurs.

Evidence the case requires

Boundary vectors; node/miner traces; acceptance and reward matrix.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fast-time lane (a8be71a0db962911c)
Run
f10-worker-20261008
Design status
NOT RUN
Standard page
30
Plan pages
7, 11, 19, 21
ROT-02Cross weekly and family boundaries togetherPriority BLOCKERProfile P01, P03, P08NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Use the retained schedule in F0, including coincident program, parameter and family changes.

Steps

  1. Run every known family transition and all coincident-boundary combinations on production code.
  2. Interrupt downloads, compilation and restart during activation; include mixed old/new clients.
  3. Repeat selected cases under real elapsed time and the remainder under disclosed accelerated time.

Accept

Deterministic activation, documented old-client behaviour and no unsafe fallback. Compilation/setup costs satisfy P03; accelerated runs are not reported as years of operating history.

Evidence the case requires

Transition matrix; code-path evidence; compile timing; old-client logs.

Evidence record of the run

What was run
the class v6 object crossing at its floor on 617cb441
Run by
fast-time lane (a8be71a0db962911c)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fast-time lane (a8be71a0db962911c)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
30
Plan pages
7, 11, 19, 21
ROT-03Test miner-voted bring-forward governancePriority BLOCKERProfile P00, P01, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Freeze eligibility, threshold, windows and activation semantics before testing; do not invent a no-veto rule.

Steps

  1. Attempt threshold-minus-one, threshold, conflicting proposals, duplicate votes and coalition withholding.
  2. Partition voters, restore them and test vote-key substitution through pools.
  3. Verify adoption and refusal behaviour of already running nodes.

Accept

The actual mechanism enforces F0, with authenticated voting and no conflicting activation. Any coalition capable of blocking or manipulating changes is disclosed; labels such as no veto do not override arithmetic.

Evidence the case requires

Executable governance model; signed-vote corpus; coalition/partition results.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
30
Plan pages
7, 11, 19, 21
ROT-04Resist seed selection and faster evaluatorsPriority BLOCKERProfile P00, P01, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Provide the specified seed pipeline and delay proof implementation plus independently parameterised fast-adversary models.

Steps

  1. Try withholding candidate seeds, grinding alternatives, replaying delay proofs and biased checkpoint selection.
  2. Vary adversarial speed advantage and outage duration; trace influence on program choice.
  3. Validate inputs, parameters and proofs against independent vectors.

Accept

No invalid seed or proof is accepted; selection advantage stays within the approved threat-model bound. Missing bounds block this gate. A delay mechanism is not credited as generic ASIC resistance.

Evidence the case requires

Seed/grinding simulations; speed sensitivity; proof vectors; threat-model signoff.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Design status
NOT RUN
Standard page
31
Plan pages
7, 11, 19, 21
ROT-05Continue or pause correctly when finality stopsPriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Stop checkpoint signing while mining continues, then cross seed and family boundaries.

Steps

  1. Remove the required signing weight and observe the documented fallback or safe pause.
  2. Prevent access to any founder seed service; restart from persisted state.
  3. Restore the stated fault assumptions and verify deterministic recovery.

Accept

Mining/seed behaviour matches F0 without manufacturing certificates or reinterpreting finality. Safety holds during the outage; liveness is required only after its stated assumptions return.

Evidence the case requires

Fault timeline; seed/certificate history; node-state comparison; recovery log.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
31
Plan pages
7, 11, 19, 21
ROT-06Activate datasets without hidden exclusionsPriority BLOCKERProfile P01, P06NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Freeze memory sizes, support horizon and sync/update procedure; test all advertised roles.

Steps

  1. Construct the next dataset while current work remains active; test slow disks, low free memory and interruption.
  2. Try stale-state/dataset submissions and maliciously expensive state growth where coupling exists.
  3. Measure data transfer, restart and excluded-card costs before approving progression.

Accept

No invalid stale work is accepted, no supported card silently fails, and P06 is met. Hardware retirement and sync burden are included in the economic decision, not treated as automatic chip protection.

Evidence the case requires

Dataset hashes; memory/update traces; stale-work tests; exclusion decision.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
31
Plan pages
7, 11, 19, 21
ROT-07Ablate redundant rotation layersPriority GATEProfile P03, P04NOT RUNEvidence recordLast run 8 Oct 2026, 22:49 UK

Setup

Use matched baseline and ablated variants in the lab; do not change a running public network.

Steps

  1. Remove each weekly/family component independently and measure adversarial cost, GPU setup and verifier complexity.
  2. Include favourable-period specialists and all retained known families.
  3. Keep a layer only with a distinct, independently supported benefit or a documented non-resistance purpose.

Accept

Every retained layer has explicit justification and full boundary coverage. Redundant complexity is removed or its rationale recorded; the security model does not double-count the same versatility cost.

Evidence the case requires

Ablation report; decision log; complexity/cost comparison.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
lane D family gate (a07a99a3788566af2)
Run
family-gate-20261008c
Design status
NOT RUN
Standard page
32
Plan pages
7, 11, 19, 21
ROT-08Pass the no-new-rules counterfactualPriority GATEProfile P04, P12NOT RUNEvidence recordLast run 8 Oct 2026, 22:49 UK

Setup

Freeze the complete published rule bank and known schedule for the five-year evaluation.

Steps

  1. Allow a programmable adversary to know and survive all planned changes.
  2. Remove assumed future emergency instructions and manual retirement actions from the model.
  3. Run the required ECO scenarios and link them to independent network-transition tests.

Accept

Competitiveness survives the approved envelope without future rescue assumptions. Any result that needs unannounced changes fails this claim; ordinary bug maintenance is distinguished from anti-chip intervention.

Evidence the case requires

Frozen-rule model; scenario results; excluded-rescue audit; G5 evidence.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Run
family-gate-20261008c
Design status
NOT RUN
Standard page
32
Plan pages
7, 11, 19, 21
06ECO

Five-year coexistence economics

Test the world after specialised hardware exists, including new entrants and an already-funded competitor.

FAIL
Owner
Economics lead + independent reviewer
Gate
G4 G4
Fixtures
F6 adversarial costs; F7 scenario model; F2 operator costs
Plan pages
8, 13, 18, 24, 26
8 cases: 0 passed under the standard, 0 running with team evidence, 1 failed, 7 not run, 0 deferred
ECO-01Reconcile complete cost per accepted workPriority GATEProfile P12NOT RUNEvidence recordLast run 8 Oct 2026, 21:07 UK

Setup

Use benchmark outputs, current-source cost inputs recorded at execution time and separate reference scenarios.

Steps

  1. Calculate hardware annualisation, electricity, host, cooling/hosting, failures, fees, downtime and residual value.
  2. Use actual accepted work and independently verify units and period conversions.
  3. Cross-check formulas using hand-worked fixtures, edge cases and a second implementation.

Accept

All material costs and rejected-work effects appear once; model totals reconcile to raw inputs. No GPU upgrade is free, development cost is not double-counted, and burn is not mislabelled operator income.

Evidence the case requires

Versioned model; unit fixtures; independent reconciliation; input sources.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco05-20261008-02
Design status
NOT RUN
Standard page
33
Plan pages
8, 13, 18, 24, 26
ECO-02Separate existing-owner and new-entrant viabilityPriority GATEProfile P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use both installed hardware and purchasable replacement hardware in every mandatory cohort.

Steps

  1. Evaluate marginal operation separately from recovery of a new purchase.
  2. Stress resale at zero, hardware failures, financing and replacement cycles.
  3. Report break-even power price and total cost relative to the strongest feasible specialist.

Accept

P12 competitiveness conditions hold for the predeclared cohorts in required sustainable worlds. Existing-owner profitability cannot substitute for viable new entry; cards outside the envelope remain visible.

Evidence the case requires

Owner/entrant curves; price-date records; break-even tables; cohort outcomes.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
33
Plan pages
8, 13, 18, 24, 26
ECO-03Let the specialist keep its sunk developmentPriority GATEProfile P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use three development cases: fully funded elsewhere, source-range low and source-range high.

Steps

  1. Evaluate private mining, public hardware sales and a hybrid business model.
  2. Allow shared IP, incremental revisions, multi-year survival and resale where justified.
  3. Re-evaluate GPU entry after the specialist fleet is already installed.

Accept

The coexistence claim does not depend on recovering the original chip research bill. Required P12 cases meet the approved envelope even at zero incremental development cost; failures cannot be hidden by the $23M/$340M source thresholds.

Evidence the case requires

Business-model variants; sunk-cost case; full cash-flow and adaptation records.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
33
Plan pages
8, 13, 18, 24, 26
ECO-04Model entry, exit and difficulty responsePriority GATEProfile P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use independently reviewed dynamic operator policies, not fixed market shares.

Steps

  1. Let agents buy, sell, switch off, re-enter and choose tasks based on declared costs and expected income.
  2. Apply the actual difficulty/reward rules and test optimistic and adversarial liquidity/capital availability.
  3. Compare equilibrium and transient outcomes across independent starting conditions.

Accept

Mandatory worlds satisfy P12 without an imposed GPU share or artificial specialist capacity limit. Concentration, oscillations and excluded regions are reported; model behaviour matches unit and conservation checks.

Evidence the case requires

Agent policies; sensitivity seeds; market-share paths; independent model review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
34
Plan pages
8, 13, 18, 24, 26
ECO-05Stress success, contraction and cheap electricityPriority GATEProfile P12FAILEvidence recordLast run 8 Oct 2026, 21:07 UK

Setup

Freeze mandatory scenarios before results: revenue bands, tariff range, lifetimes and demand states.

Steps

  1. Run the P12 factorial grid plus adversarial combinations selected by the independent reviewer.
  2. Test a large successful network as well as weak-revenue and heterogeneous-tariff cases.
  3. Distinguish feasible sustained-entry worlds from collapse scenarios with no rational profitable operator.

Accept

No small-network or token-appreciation assumption props up the primary claim. Required viable worlds pass the envelope; collapse worlds show honest contraction and safety, not fabricated profits. Failure regions are explicit.

Evidence the case requires

Scenario register; full result cube; boundary plots; failed-world explanations.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco05-20261008-02
Design status
NOT RUN
Standard page
34
Plan pages
8, 13, 18, 24, 26
ECO-06Fund security and proving as issuance fallsPriority GATEProfile P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use the frozen supply, halving, fee, burn and reward rules rather than source prose assumptions.

Steps

  1. Reconcile revenue reaching miners, internal provers, developers and burns over the full horizon.
  2. Test flat/declining fees and no external proving income; separately introduce external demand.
  3. Calculate capacity and security-provider coverage after each reward transition.

Accept

Recurring compensation is explicit and internally consistent; mandatory sustainable scenarios meet P12. Burned amounts are never counted as payments, and external operator income is not assumed to fund internal work automatically.

Evidence the case requires

Issuance/fee ledger; scenario cash flows; funding-shortfall report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
34
Plan pages
8, 13, 18, 24, 26
ECO-07Price memory growth and honest-card displacementPriority GATEProfile P06, P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use GPU-05 and ROT-06 costs with the cheapest specialist adaptation.

Steps

  1. For each dataset increment, compare specialist cost increases with excluded cards and lost proving capacity.
  2. Include ordinary-owner replacement, resale and reloading expenses.
  3. Run alternate bounded schedules without assigning automatic chip death.

Accept

The retained schedule meets P06/P12 and has an evidence-backed net competitiveness benefit. A schedule that mainly harms accessible GPUs fails; excluded tiers and mitigations are documented before activation.

Evidence the case requires

Per-step cost/retention table; alternative schedules; approval record.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
35
Plan pages
8, 13, 18, 24, 26
ECO-08Reproduce and adversarially audit the modelPriority GATEProfile P12NOT RUNEvidence recordLast run 8 Oct 2026, 21:07 UK

Setup

Give an independent economist or qualified analyst the code, inputs and frozen success criteria.

Steps

  1. Recalculate required worlds and perturb favourable assumptions against the team.
  2. Check dependence on discounts, utilisation, capital limits, artificial prices and future upgrades.
  3. Publish the sensitivity range and state which conclusions are conditional.

Accept

Material results reproduce, required scenarios pass and no unacknowledged assumption dominates the claim. The model supports a bounded coexistence conclusion, not a percentage probability that no chip will appear.

Evidence the case requires

Independent report; rerun outputs; model limitations; approved claim envelope.

Method
Independent economic review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco05-20261008-02
Design status
NOT RUN
Standard page
35
Plan pages
8, 13, 18, 24, 26
07EVM

Execution and developer compatibility

Keep familiar applications while making every difference and metering rule explicit and reproducible.

NOT RUN
Owner
Execution lead + independent implementer
Gate
Technical readiness
Fixtures
F0 execution-fork semantics; F5 transactions/contracts; F4 multi-node network
Plan pages
15, 25, 34, 35, 36, 37
8 cases: 1 passed under the standard, 0 running with team evidence, 7 not run, 0 deferred
EVM-01Match the selected EVM semanticsPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 21:10 UK

Setup

Pin the intended execution fork, revm version and all Igneum deviations in F0.

Steps

  1. Run the applicable upstream execution/state fixtures plus independently written deviation tests.
  2. Execute identical blocks on multiple nodes and compare roots, receipts, logs, gas and failure outcomes.
  3. Minimise mismatches and distinguish intended differences from implementation defects.

Accept

All applicable vectors match; every deviation has a documented test and developer consequence. No claim of universal Ethereum equivalence or Ethereum settlement security is inferred.

Evidence the case requires

Fixture/version inventory; root/receipt diffs; deviation matrix.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
36
Plan pages
15, 25, 34, 35, 36, 37
EVM-02Preserve transaction binding and replay protectionPriority BLOCKERProfile P01NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Use signed transfers, contract calls and deployment transactions with boundary field values.

Steps

  1. Alter chain identity, nonce, signature, fee caps and recipient after signing.
  2. Replay across nodes, forks and distinct test networks; resubmit around reorganisation.
  3. Check mempool admission and final consensus execution independently.

Accept

Unauthorised, wrong-network or duplicate spends are rejected according to F0. Valid replacements follow the declared rule; mempool filtering alone is not evidence of consensus enforcement.

Evidence the case requires

Signed corpus; admission/execution outcomes; account-state reconciliation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
36
Plan pages
15, 25, 34, 35, 36, 37
EVM-03Test two-dimensional fees and proving limitsPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:13 UK

Setup

Freeze fee dimensions, estimator rules, abort behaviour and refund policy.

Steps

  1. Run workloads near and beyond execution and proving budgets, including state-heavy pathological cases.
  2. Compare estimated fees with charged fees and validate rollback/receipt status on abort.
  3. Mutate a block producer to omit or undercharge expensive work.

Accept

Deterministic metering, charged amounts and aborted state agree across nodes and proofs. Resource bounds hold; fee estimates meet P09 for accepted supported cases. Undercharged invalid blocks cannot bypass consensus.

Evidence the case requires

Metering traces; fee fixtures; estimator errors; invalid-block rejection.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1744-evm
Design status
NOT RUN
Standard page
36
Plan pages
15, 25, 34, 35, 36, 37
EVM-04Exercise block context and randomness assumptionsPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:13 UK

Setup

Use contracts sensitive to timestamp, height/context, randomness and ordering.

Steps

  1. Compare the declared Igneum semantics with developers' documented expectations.
  2. Test boundary transitions, miner-influenced inputs and adversarial ordering in the isolated network.
  3. Run dependency reviews for applications using these values for economic decisions.

Accept

Semantics match F0 and differences are surfaced in compatibility documentation. No source of miner influence is marketed as unbiased randomness; incompatible applications are not included in the compatibility claim.

Evidence the case requires

Context-contract results; threat notes; compatibility exclusions.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1744-evm
Design status
NOT RUN
Standard page
37
Plan pages
15, 25, 34, 35, 36, 37
EVM-05Run representative contract integration journeysPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:13 UK

Setup

Use versioned transfer/token, NFT, multisignature, exchange and upgrade-pattern fixtures where supported.

Steps

  1. Deploy, initialise, transact, revert and upgrade each contract using ordinary tooling.
  2. Exercise events, logs, balances, storage and call traces across node restart/reorganisation.
  3. Compare expected application invariants with native execution and proved results.

Accept

Supported journeys preserve their stated invariants; all deviations are documented. Example deployment success alone cannot stand in for application-level correctness or financial audit.

Evidence the case requires

Contract fixture hashes; transaction journeys; invariant and state comparisons.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1744-evm
Design status
NOT RUN
Standard page
37
Plan pages
15, 25, 34, 35, 36, 37
EVM-06Validate wallets, RPC and indexersPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:13 UK

Setup

Pin supported RPC methods and response semantics; use normal developer clients and an independent indexer.

Steps

  1. Test fee estimation, pending/final states, subscriptions, pagination and reconnects.
  2. Reindex from genesis or the documented trust anchor after pruning and restart.
  3. Compare logs, receipts and balances with independently validated chain state.

Accept

No missing/duplicate canonical records; unsupported methods are explicit. UI states distinguish included, executed, proven and finalised. Malformed RPC input cannot crash validators or leak secrets.

Evidence the case requires

RPC conformance report; reindex comparison; reconnect/edge-case logs.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1744-evm
Design status
NOT RUN
Standard page
37
Plan pages
15, 25, 34, 35, 36, 37
EVM-07Handle execution denial-of-service workloadsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Create bounded pathological bytecode, calls, state growth, storage and precompile inputs.

Steps

  1. Measure CPU, memory, disk and proving cost against charged budgets.
  2. Saturate admission with invalid/expensive requests while valid workloads continue.
  3. Restart mid-execution and verify atomic state recovery.

Accept

P09 limits hold with no unbounded free work or divergent rollback. State remains consistent after crash; availability under overload follows the declared admission policy, not silent dropping of accepted transactions.

Evidence the case requires

Resource profiles; adversarial corpus; state recovery comparisons.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Design status
NOT RUN
Standard page
38
Plan pages
15, 25, 34, 35, 36, 37
EVM-08Verify controlled execution and verifier upgradesPriority BLOCKERProfile P01, P08, P09PASSEvidence recordLast run 8 Oct 2026, 23:24 UK

Setup

Prepare two authorised versions and malicious, stale or unknown versions.

Steps

  1. Cross activation with mixed clients, queued transactions and proofs from both versions.
  2. Bind each accepted proof to the correct execution semantics and program identity.
  3. Exercise a failed software distribution without altering consensus activation.

Accept

No unknown or wrong-version execution is accepted. Pre/post-boundary handling is deterministic and documented; software delivery cannot silently redefine transaction semantics or proof acceptance.

Evidence the case requires

Upgrade vectors; mixed-version traces; manifest/version bindings.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
enforced-proving-20261008-03
Design status
NOT RUN
Standard page
38
Plan pages
15, 25, 34, 35, 36, 37
08ZKP

Consensus-enforced proof validity

The validator, not merely the official producer, must reject unauthorised or invalid proof records and rewards.

NOT RUN
Owner
Proving + protocol leads; independent cryptography review
Gate
Technical readiness / G5 G5
Fixtures
F0 pinned programs/verifiers; F5 valid and hostile proof corpus; unmodified validators
Plan pages
16, 20, 24, 25, 36, 37
8 cases: 4 passed under the standard, 0 running with team evidence, 4 not run, 0 deferred
ZKP-01Reject missing and invalid proofsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Start from a native-correct statement and an independently verified valid proof.

Steps

  1. Submit the statement with no proof, truncated bytes, random bytes and targeted proof mutations using a modified producer.
  2. Submit the genuine proof as a positive control through ordinary network paths.
  3. Inspect block acceptance and resulting reward/state on unmodified validators.

Accept

Every invalid proof record is rejected and earns no reward; valid controls succeed. A producer-side filter is not sufficient. Record rejection semantics exactly as defined by F0.

Evidence the case requires

Hostile record corpus; validator decisions; before/after balances; positive controls.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
39
Plan pages
16, 20, 24, 25, 36, 37
ZKP-02Bind program, verifier and security parametersPriority BLOCKERProfile P01, P09PASSEvidence recordLast run 8 Oct 2026, 23:24 UK

Setup

Use valid proofs from authorised and unauthorised programs and parameter sets.

Steps

  1. Swap program digest, verifier version, security settings and verification key where applicable.
  2. Attempt downgrade through configuration, serialized metadata or an old node path.
  3. Test authorised boundary transitions and unsupported future identities.

Accept

Only explicitly authorised combinations are accepted in the correct epoch. No implicit trust in producer-supplied metadata or lower-security fallback; all accepted settings have scoped soundness review.

Evidence the case requires

Identity/parameter matrix; rejection traces; cryptographic review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
enforced-proving-20261008-03
Design status
NOT RUN
Standard page
39
Plan pages
16, 20, 24, 25, 36, 37
ZKP-03Bind network, epoch, job and state rootsPriority BLOCKERProfile P01NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Prepare valid proofs for distinct chains, epochs, jobs and initial/final states.

Steps

  1. Replay each proof under another network, job, epoch, shard range or state commitment.
  2. Alter public inputs while retaining the proof and test valid-but-wrong-context statements.
  3. Check duplicated and reordered records across forks and replayed sync data.

Accept

Every misbound proof is rejected; valid authorised replays follow only explicitly allowed semantics and never create extra rewards. Native reexecution cannot conceal missing proof-context binding.

Evidence the case requires

Binding matrix; public-input hashes; replay traces; reward reconciliation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
39
Plan pages
16, 20, 24, 25, 36, 37
ZKP-04Prevent reward and payout substitutionPriority BLOCKERProfile P01PASSEvidence recordLast run 8 Oct 2026, 23:24 UK

Setup

Use proofs that commit to authorisation and all reward-relevant fields required by F0.

Steps

  1. Alter payout key, amount, beneficiary, source work or fee allocation independently.
  2. Supply correct execution over malicious producer-provided consensus/reward inputs.
  3. Compare consensus-derived rewards with the proved/publicly authenticated derivation.

Accept

Unauthorised payout changes and incorrect consensus inputs are rejected; no statement accepted merely because execution over supplied inputs is internally correct. Legitimate authorisations are preserved.

Evidence the case requires

Mutation cases; reward derivation trace; signature/proof binding review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
enforced-proving-20261008-03
Design status
NOT RUN
Standard page
40
Plan pages
16, 20, 24, 25, 36, 37
ZKP-05Make proof payment idempotent across racesPriority BLOCKERProfile P01PASSEvidence recordLast run 8 Oct 2026, 23:24 UK

Setup

Use competing provers submitting valid results for the same work and simulate retries/reorganisations.

Steps

  1. Submit simultaneous duplicates, reordered receipts and repeated messages after disconnects.
  2. Crash validators between validation and reward application, then recover.
  3. Reconcile canonical payouts against the exact F0 duplicate policy.

Accept

Only the authorised total payment is made; no double payout, lost accepted entitlement or fork-retained balance. Transactions and payout records recover atomically.

Evidence the case requires

Concurrency schedule; canonical payment ledger; crash/recovery evidence.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
enforced-proving-20261008-03
Design status
NOT RUN
Standard page
40
Plan pages
16, 20, 24, 25, 36, 37
ZKP-06Verify aggregation coverage and completenessPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Build valid multi-shard workloads plus omitted, duplicated, overlapping and misordered shard sets.

Steps

  1. Attempt an aggregate with a correct outer proof but wrong coverage/public-input construction.
  2. Alter shard ranges, roots and aggregation-program identity.
  3. Verify native execution, aggregate validity and coverage commitments independently.

Accept

Only complete, correctly ordered authorised coverage is accepted. No valid proof of the wrong computation becomes an accepted chain result; aggregation failures do not fabricate successful delivery.

Evidence the case requires

Coverage corpus; aggregate/public-input verification; rejection ledger.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
40
Plan pages
16, 20, 24, 25, 36, 37
ZKP-07Review soundness and verifier resource limitsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Provide proof-system code, parameters, patches and the pinned verification path to an independent specialist.

Steps

  1. Review soundness assumptions, parameter margins and consequences of performance patches.
  2. Fuzz deserialization and adversarial proofs; measure verification CPU and memory under load.
  3. Cross-check an independent verifier or reference path and test crash containment.

Accept

P09 review and resource requirements pass with no unresolved critical/high finding. Random proof rejection counts are not described as evidence of a particular cryptographic security level.

Evidence the case requires

Scoped soundness review; parameter sheet; fuzzer corpus; verifier profiles.

Method
Independent cryptographic review + testing
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Standard page
41
Plan pages
16, 20, 24, 25, 36, 37
ZKP-08Preserve authority and audit all acceptance pathsPriority BLOCKERProfile P01, P07, P08PASSEvidence recordLast run 8 Oct 2026, 23:24 UK

Setup

Inspect block import, sync, RPC, light verification, database restoration and fast paths.

Steps

  1. Try bypassing validation via each path with a proof rejected by the normal path.
  2. Remove the dominant prover/aggregator and have independent replacements process available inputs.
  3. Attempt to use proof-production status as ordering, voting or finality authority.

Accept

No bypass accepts invalid work; proofs alone confer no unauthorised consensus control. Replacement and pause behaviour meet F0/P07/P08 without privileged keys or a trusted aggregator shortcut.

Evidence the case requires

Path coverage report; bypass corpus; replacement run; authority checks.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
enforced-proving-20261008-03
Design status
NOT RUN
Standard page
41
Plan pages
16, 20, 24, 25, 36, 37
09CAP

Sustained proving and delivery

A correct fast shard is only one stage; capacity, latency, payment and retries must work together.

NOT RUN
Owner
Proving lead + independent operators
Gate
Technical readiness / commercial track
Fixtures
F3 meaningful workload catalogue; F4 network; F8 external job harness
Plan pages
17, 18, 24, 25
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
CAP-01Reproduce the historical consumer-shard resultPriority GATEProfile P02, P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Recover the exact source-era workload/build if available; keep it separate from the release-candidate workload.

Steps

  1. Attempt independent reproduction of the 4,717,439-cycle workload and reported 3060/4060/4070 results.
  2. Record proof format, memory, energy, host and whether aggregation/compression are included.
  3. Repeat on the final release and label all configuration changes.

Accept

Historical figures are either reproduced within P02 tolerance or corrected/labelled non-reproduced. Release acceptance uses the current complete workload, never an unmatched historical time or a smaller substituted shard.

Evidence the case requires

Historical/current manifests; proof verification; timing and memory records.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
42
Plan pages
17, 18, 24, 25
CAP-02Prove on the actual mining configurationPriority BLOCKERProfile P01, P06, P07NOT RUNEvidence recordLast run 8 Oct 2026, 23:22 UK

Setup

Use final dataset sizes, registers, clocks, drivers and proof pipeline on every advertised proving tier.

Steps

  1. Run mining alone, proving alone, concurrent execution and supported time-sharing.
  2. Measure wall energy, memory headroom, reloads, proof latency and forgone accepted mining work.
  3. Induce memory pressure and GPU task failure without losing wallet control.

Accept

Every advertised mode completes correctly and meets P06/P07. Net output includes opportunity cost; unsupported concurrency is not claimed. Mining-only vendor support remains separately labelled.

Evidence the case requires

Four-mode results; OOM/failure logs; memory and opportunity-cost ledger.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Run
v607-floor-memory-20261008T2059Z
Design status
NOT RUN
Standard page
42
Plan pages
17, 18, 24, 25
CAP-03Measure the entire request-to-payment pathPriority GATEProfile P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Assign a unique job ID and immutable timestamps to every stage of F3/F8 jobs.

Steps

  1. Record request, input availability, assignment, execution, shard proof, aggregation, verification, delivery and payment.
  2. Compare monotonic elapsed time with any protocol/DAA clock and document their relationship.
  3. Reconcile failed, censored, retried and abandoned jobs with the original request denominator.

Accept

No hidden stage or missing job; latency distributions and cost cover the complete path. Delivery, finality and payment are reported separately; protocol seconds are not silently relabelled wall-clock seconds.

Evidence the case requires

Stage event ledger; clock calibration; end-to-end latency/cost report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
42
Plan pages
17, 18, 24, 25
CAP-04Sustain meaningful load without queue growthPriority GATEProfile P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Freeze W: payload mix, input sizes, execution work and per-hour demand; prohibit tiny-workload substitution.

Steps

  1. Run 72 hours at W and a separate 24 hours at 1.2W on the declared fleet.
  2. Measure arrival/completion counts, backlog trend, oldest-job age, deadlines and all retries.
  3. Use held-out workloads and an independent observer to detect discarded or delayed requests.

Accept

P07 completion, tail-latency and bounded-backlog criteria hold. Capacity is stated for the tested W/fleet, not as universal TPS. A queue that grows indefinitely or shrinks through silent loss fails.

Evidence the case requires

Request/completion reconciliation; backlog series; held-out results; observer report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
43
Plan pages
17, 18, 24, 25
CAP-05Overload and recover without false acceptancePriority BLOCKERProfile P01, P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Start at W and inject 2W for 15 minutes with valid and invalid jobs, then return to W.

Steps

  1. Observe admission, explicit backpressure, reservations and deadline estimates.
  2. Track accepted jobs to valid completion or the pre-agreed failure/refund outcome.
  3. Measure recovery time and ensure ordinary users are not silently starved.

Accept

P07 overload policy and recovery limits hold; no accepted job vanishes or earns an invalid reward. Rejected demand is reported separately from delivery success, preventing denominator manipulation.

Evidence the case requires

Overload timeline; admission/refund logs; backlog-drain proof.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
43
Plan pages
17, 18, 24, 25
CAP-06Calibrate assignment windows to paid completionPriority GATEProfile P07, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use a heterogeneous proving fleet, including the slowest advertised consumer tier.

Steps

  1. Measure actual completion distributions with network delay, competing load and failed attempts.
  2. Test the chosen exclusive window, open claiming and faster challengers after expiry.
  3. Compare assignment frequency, paid completions and wasted work by tier.

Accept

P07 fairness and wasted-work limits hold for advertised tiers. A provisional 10-DAA-second window is not treated as approved. Fair assignment counts alone cannot pass; payment outcomes and operator margins matter.

Evidence the case requires

Window sweep; paid-completion distribution; wasted-work and margin report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
43
Plan pages
17, 18, 24, 25
CAP-07Reassign work when inputs or providers disappearPriority BLOCKERProfile P01, P07, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Remove input providers, assigned provers and the dominant aggregator independently and together.

Steps

  1. Have replacement operators retrieve authenticated inputs without founder files.
  2. Retry expired assignments while preserving idempotent reward and customer outcomes.
  3. Restore providers and test late submissions racing with replacements.

Accept

P07/P08 replacement deadlines hold when availability assumptions permit. Otherwise a truthful bounded pause/refund occurs; no fake proof, double payment or hidden privileged input source is used.

Evidence the case requires

Failure schedule; input hashes; reassignment and payout ledger; recovery trace.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
44
Plan pages
17, 18, 24, 25
CAP-08Deliver customer-verifiable output at scalePriority BLOCKERProfile P01, P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Run the external workload using a customer-controlled verifier and independently operated workers.

Steps

  1. Verify every delivered proof against the contracted program and input commitment.
  2. Reject wrong-format, stale and partial deliveries; test customer retry and delivery failure.
  3. Reconcile delivery, acceptance, payment and refund records without exposing private inputs publicly.

Accept

P07 delivery performance and exact validity hold. Payment depends on the contracted correct result; a valid proof for the wrong job is not a successful delivery.

Evidence the case requires

Customer verification log; proof-format contract; settlement reconciliation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
44
Plan pages
17, 18, 24, 25
10INC

Rewards, incentives and selfish operators

Assume operators optimise their own returns. Do not depend on the official client choosing a less profitable task.

NOT RUN
Owner
Protocol economics + proving leads
Gate
G4 / G5 G4 G5
Fixtures
F0 fee/reward rules; F4 adversarial operators; F7 incentive models
Plan pages
13, 16, 17, 18, 24, 26
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
INC-01Reconcile issuance, fees, burns and recipientsPriority BLOCKERProfile P01, P12NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Use a deterministic short chain containing all reward types, fee paths and rounding cases.

Steps

  1. Calculate balances, total supply changes, burns and distributions independently.
  2. Execute identical blocks natively and through the proving path.
  3. Test zero, minimum, maximum and transition-boundary values plus malformed producer accounting.

Accept

Conservation and recipient rules match F0 exactly; no inflation, rounding leakage or duplicate reward. Fee-table and prose discrepancies are resolved before the run, not guessed by the tester.

Evidence the case requires

Independent accounting ledger; balance/supply diffs; boundary vectors.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
45
Plan pages
13, 16, 17, 18, 24, 26
INC-02Keep revenue streams and claims separatePriority BLOCKERProfile P01, P12, P14NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Prepare jobs and blocks producing mining income, internal proof rewards and external payments.

Steps

  1. Trace money from source to operator, protocol, developer and any burn.
  2. Compare node records, settlement records and Ember displays.
  3. Attempt to classify testnet rewards, reimbursed purchases or token appreciation as external customer revenue.

Accept

Every stream reconciles and is labelled correctly. No double-counted revenue or fabricated protocol demand; mining subsidy and external service income remain distinct in dashboards and ECO.

Evidence the case requires

Money-flow register; UI reconciliation; rejected classifications.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
45
Plan pages
13, 16, 17, 18, 24, 26
INC-03Let a modified client choose the most profitable taskPriority GATEProfile P07, P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Permit independent schedulers to mine, prove internally, prove externally or switch off.

Steps

  1. Publish common costs and vary relative task rewards, memory pressure and switching costs.
  2. Run clients that ignore the official scheduling recommendation.
  3. Measure realised operator margin, internal capacity and network progress.

Accept

Required P12 sustainable worlds maintain paid essential capacity without compelled altruism. Profitability and availability are based on realised outcomes, including switching and wasted work.

Evidence the case requires

Scheduler source/policies; switching traces; capacity and margin series.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
45
Plan pages
13, 16, 17, 18, 24, 26
INC-04Survive external-demand spikes and token declinesPriority GATEProfile P07, P08, P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use F7 scenarios with 10x external job offers and token-denominated mining-income shocks.

Steps

  1. Allow miners/provers to switch freely under the declared reward and difficulty rules.
  2. Observe hash participation, proof backlog, fees and recovery without an administrator.
  3. Repeat with external demand dropping to zero and with a dominant operator withdrawn.

Accept

Mandatory viable worlds meet P07/P12; stressed nonviable worlds fail or pause safely with truthful status. No emergency rule, fabricated demand or unofficial subsidy is inserted to force a pass.

Evidence the case requires

Shock timeline; fee/hash/capacity paths; failure-region report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
46
Plan pages
13, 16, 17, 18, 24, 26
INC-05Contain job reservation and identity-splitting abusePriority BLOCKERProfile P01, P07, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Freeze the actual assignment/payment mechanism; do not assume unimplemented collateral or identity controls.

Steps

  1. Create many worker identities, reserve jobs, withhold proofs and submit late results.
  2. Attempt free option-taking, duplicate work rewards and displacement of honest assignments.
  3. Price attacker costs and observe honest completion under the approved abuse load.

Accept

F0 rules and P07 service limits hold under the declared adversary. Identity splitting does not create unauthorised rewards or control; any unmitigated starvation path blocks the permissionless-service claim.

Evidence the case requires

Attack clients; assignment trace; cost-to-disrupt analysis; honest-user outcomes.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Standard page
46
Plan pages
13, 16, 17, 18, 24, 26
INC-06Test difficulty and timestamp manipulationPriority BLOCKERProfile P01, P08, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use the actual adjustment algorithm and consensus timestamp rule with independent miners.

Steps

  1. Inject large hashrate arrivals/departures, periodic selective mining and boundary-timed bursts.
  2. Try allowed and invalid timestamp skew, withheld blocks and replayed work.
  3. Observe block intervals, reward allocation and recovery after hashrate stabilises.

Accept

Invalid inputs are rejected; valid adversarial strategies remain within F0/P08 bounds and are priced in ECO. No unexplained reward amplification, permanent stall or conflicting accepted work.

Evidence the case requires

Difficulty trace; timestamp corpus; revenue analysis; independent rule review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Design status
NOT RUN
Standard page
46
Plan pages
13, 16, 17, 18, 24, 26
INC-07Resist self-dealing fees and fake proving demandPriority BLOCKERProfile P01, P12, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use self-funded operators and related customer identities in the isolated economic model/network.

Steps

  1. Cycle funds through jobs, tips, developer shares and rebates to seek net reward extraction.
  2. Attempt to inflate external-demand metrics without genuine unrelated customer expenditure.
  3. Reconcile all counterparties and net cash contribution rather than gross transaction volume.

Accept

No unauthorised subsidy extraction or metric inflation passes. Related-party volume is disclosed/excluded from P14; net external cash and legitimate protocol incentives are reported separately.

Evidence the case requires

Circular-flow tests; ownership/conflict review; net-cash reconciliation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Standard page
47
Plan pages
13, 16, 17, 18, 24, 26
INC-08Quantify provider and supplier failure concentrationPriority GATEProfile P08, P11, P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Model control of hashing, signing, proving, aggregation and hardware supply separately.

Steps

  1. Remove each largest operational dependency and combine correlated failures.
  2. Measure replacement cost/time and whether essential roles share hidden ownership.
  3. Compare results with the approved fault model and no-rescue exercise.

Accept

No hidden single dependency defeats the claimed independence; within-tolerance withdrawals recover under P08/P11. Hardware supply concentration is disclosed without equating vendor sales to operator voting control.

Evidence the case requires

Role/ownership map; dependency removals; recovery and concentration report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
47
Plan pages
13, 16, 17, 18, 24, 26
11FIN

Consensus safety and recovery

Test safety under the stated fault bounds. Demand liveness only when synchrony and participation assumptions actually hold.

NOT RUN
Owner
Consensus lead + independent formal/security review
Gate
G5 / technical readiness G5
Fixtures
F0 exact fault model; F4 real-node partitions; F5 certificates and historical failures
Plan pages
19, 21, 24, 25
8 cases: 1 passed under the standard, 0 running with team evidence, 7 not run, 0 deferred
FIN-01Agree on ordering, work and executed statePriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Use real fork-choice/DAG handling and independent miners, not only a simplified simulator.

Steps

  1. Generate concurrent branches, delayed blocks, duplicates and invalid work with deterministic seeds.
  2. Compare selected ordering, accumulated work, transaction execution and state roots after delivery converges.
  3. Replay from independent checkpoints and from genesis where practical.

Accept

Honest nodes converge under F0 assumptions with exact roots and rewards. No duplicated work accounting or undocumented ordering dependence; simulator-only success cannot substitute.

Evidence the case requires

Block/ordering corpus; root/work diffs; real-node replay logs.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fast-time lane (a8be71a0db962911c)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
48
Plan pages
19, 21, 24, 25
FIN-02Attack finality with split honest populationsPriority BLOCKERProfile P01, P08PASSEvidence recordLast run 9 Oct 2026, 02:02 UK

Setup

Use the source-discussed 40/40/20 weight split, plus threshold-boundary splits under F0.

Steps

  1. Let the 20% adversarial group sign conflicting histories while honest groups are partitioned.
  2. Delay messages and eligibility updates independently; keep total historical weights auditable.
  3. Try to form two certificates and reconnect nodes to observe accepted final history.

Accept

No conflicting final certificates are accepted within the declared fault bound. A safe pause is valid when quorum is unavailable; making progress on both sides is not required.

Evidence the case requires

Signed votes; certificate attempts; voter-table snapshots; safety checker output.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
fin-203-20261009T0127Z
Design status
NOT RUN
Standard page
48
Plan pages
19, 21, 24, 25
FIN-03Cross authority expiry in a long partitionPriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Recover historical expiry failures where available; use the actual current authority-transition rules.

Steps

  1. Partition for 31, 35, 60 and 90 logical days and around every retention/expiry boundary.
  2. Attempt independently renewed authority sets and conflicting checkpoint locks.
  3. Repeat selected boundary cases on real nodes with accelerated timers explicitly labelled.

Accept

Authority continuity remains authenticated and no conflicting final history appears within F0 assumptions. A timeout is not accepted as proof absent voters ceased to exist. Compressed time is not multi-month field evidence.

Evidence the case requires

Expiry timeline; table/certificate history; historical regression tests.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
48
Plan pages
19, 21, 24, 25
FIN-04Stop signing while mining continuesPriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Remove enough signing participation to invalidate the liveness assumption without forging votes.

Steps

  1. Continue mining and execution, cross seed boundaries and monitor proof queues.
  2. Check which user-visible states advance and which remain unfinalised.
  3. Restore eligible weight and bounded message delay, then verify recovery.

Accept

No false finality or fabricated authority. Behaviour matches F0 during the pause and P08 after assumptions return; unfinished transactions are not displayed as irreversible.

Evidence the case requires

Signing/mining trace; UI/RPC states; recovery roots and timing.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
49
Plan pages
19, 21, 24, 25
FIN-05Authenticate voter-set changes and pooled keysPriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Use normal transitions, pool members retaining keys and malicious substitution attempts.

Steps

  1. Alter voter weights, membership proofs, miner/pool identity bindings and prior-certificate links.
  2. Race updates across boundaries and replay old signed changes.
  3. Have a new node verify the authority chain from its declared trust anchor.

Accept

Only correctly authenticated changes are accepted; weights cannot be double-counted or redirected by a pool. All honest nodes agree on the active authority set for each certified point.

Evidence the case requires

Authority-chain fixtures; substitution attacks; new-node verification log.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
49
Plan pages
19, 21, 24, 25
FIN-06Analyse old-key compromise and long-range historiesPriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Freeze assumptions about key erasure, retained weights, trust anchors and offline recovery.

Steps

  1. Use previously eligible keys to build alternative histories after their operators disappear.
  2. Present these histories to recently offline and newly joining clients.
  3. Test replayed certificates, stale anchors and compromised signer subsets.

Accept

Acceptance matches the explicit security model with no hidden trusted recovery step. Any reliance on a recent trusted anchor is disclosed and tested; hashpower assumptions cannot replace old-key analysis.

Evidence the case requires

Long-range corpus; trust-anchor policy; key-compromise review; client results.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
49
Plan pages
19, 21, 24, 25
FIN-07Recover deterministically after reconnection and crashPriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 9 Oct 2026, 02:02 UK

Setup

Combine partitions with node crash, partial writes, restarts and proof backlog.

Steps

  1. Reconnect networks under bounded latency and restore required honest participation.
  2. Verify fork choice, unfinalised reorganisation, finality, reward rollback and proof reassignments.
  3. Compare all honest nodes and customer-visible receipts after recovery.

Accept

P08 recovery holds without reversing a previously valid final guarantee. Only permitted unfinalised state is reorganised; no duplicate rewards or inconsistent receipt statuses survive.

Evidence the case requires

Recovery timelines; roots/certificates; payout rollback; customer-state reconciliation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
fin-203-20261009T0127Z
Design status
NOT RUN
Standard page
50
Plan pages
19, 21, 24, 25
FIN-08Combine boundaries, faults and adversarial schedulingPriority BLOCKERProfile P01, P08NOT RUNEvidence recordLast run 9 Oct 2026, 02:02 UK

Setup

Use an independent model checker/scheduler and production-node scenarios from F4.

Steps

  1. Combine epoch changes, authority transitions, mining churn, data delays and prover/aggregator loss.
  2. Explore bounded adversarial message schedules and minimise any counterexample.
  3. Replay model findings on real code and have an independent reviewer assess uncovered states.

Accept

No unresolved safety failure; liveness claims hold only within declared assumptions and P08. Model bounds and untested schedules are published, not described as proof over every possible execution.

Evidence the case requires

Model/spec artifacts; schedule corpus; replay evidence; independent assessment.

Method
Model checking + real-node testing
Cadence
Release candidate; repeat after relevant changes
Owner
fast-time lane (a8be71a0db962911c)
Run
fin-203-20261009T0127Z
Design status
NOT RUN
Standard page
50
Plan pages
19, 21, 24, 25
12VER

Wallets, receipts and data availability

Verify the exact property shown to the user. An inclusion proof, execution proof and finality certificate are not interchangeable.

FAIL
Owner
Wallet + light-client lead; independent security review
Gate
Technical readiness / claimed options
Fixtures
F0 trust/availability model; F5 malformed roots, receipts and authority chains
Plan pages
20, 25, 35, 37
8 cases: 0 passed under the standard, 0 running with team evidence, 3 failed, 5 not run, 0 deferred
VER-01Authenticate light-client bootstrapPriority BLOCKERProfile P01, P09FAILEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Give a clean client malicious RPC responses, fabricated voter tables and valid-looking signatures.

Steps

  1. Start from the approved trust anchor and verify every required link to the advertised state.
  2. Substitute otherwise well-formed but unauthorised keys, weights and checkpoints.
  3. Remove the bootstrap service and use another independently operated source.

Accept

The client rejects unauthorised authority and discloses any trust anchor. Signatures over a node-supplied table do not by themselves pass; missing authentication never silently degrades to trusted RPC.

Evidence the case requires

Bootstrap corpus; trust-chain trace; fail-closed tests.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
51
Plan pages
20, 25, 35, 37
VER-02Verify evolving authority and execution statementsPriority BLOCKERProfile P01, P09FAILEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Use valid state proofs paired with wrong execution statements or stale authority histories.

Steps

  1. Cross voter and verifier changes with offline clients returning after long intervals.
  2. Alter roots, aggregate identity and proof/public-input bindings independently.
  3. Check local verification rather than merely a server-reported verified flag.

Accept

All advertised proof checks occur locally or the remaining trust is explicitly disclosed. Wrong roots and unauthenticated authority are rejected; unsupported verification paths are not claimed.

Evidence the case requires

Client verification trace; corrupted inputs; offline/upgrade results.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
51
Plan pages
20, 25, 35, 37
VER-03Prove successful payment rather than inclusionPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Create successful, reverted, wrong-asset, wrong-recipient and wrong-amount transfers.

Steps

  1. Generate receipts for included transactions, including failures and replaced/unfinalised transactions.
  2. Verify execution status plus asset, recipient, amount and canonical-state/receipt commitment.
  3. Replay the receipt on another chain and after an allowed unfinalised reorganisation.

Accept

Only the actual successful, correctly bound transfer is labelled payment proof. Inclusion-only receipts are labelled as such; no node-reported success flag substitutes for authenticated outcome.

Evidence the case requires

Payment fixture corpus; receipt verification; merchant-facing status checks.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
51
Plan pages
20, 25, 35, 37
VER-04Bound cross-chain oracle trust and replayPriority BLOCKERProfile P00, P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

For a claimed oracle, freeze destination verifier, authority updates, accepted proof types and replay policy.

Steps

  1. Try deployer-substituted keys, stale certificates, unchecked signatures and wrong source/destination identities.
  2. Exercise legitimate authority updates and source reorganisations under the approved model.
  3. Measure gas/cost with realistic header sets and test disabled/unavailable verification.

Accept

The oracle enforces its declared trust model and fails closed. Deployer privileges and unavailable guarantees are explicit; no trustless-bridge claim exceeds the checks performed. Excluded oracle scope earns no pass credit.

Evidence the case requires

Oracle code/parameters; attack cases; cost report; privilege disclosure.

Method
Claimed-option verification
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
52
Plan pages
20, 25, 35, 37
VER-05Reconstruct required state without founder storagePriority BLOCKERProfile P01, P08, P09FAILEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Remove founder archival/input services and start an independent operator from the documented entry point.

Steps

  1. Fetch authenticated blocks, state/proof inputs and any required witnesses from permitted peers.
  2. Rebuild the expected state and continue validation/proving.
  3. Measure bandwidth, disk, time and retention requirements against advertised operator budgets.

Accept

Required data can be obtained and verified within the declared availability model. Hidden archives or unpublished files block independence. A valid execution proof alone does not satisfy this test.

Evidence the case requires

Download/reconstruction logs; data hashes; resource costs; dependency inventory.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
52
Plan pages
20, 25, 35, 37
VER-06Detect withholding, corruption and stale dataPriority BLOCKERProfile P01, P08, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Serve valid commitments with missing data, corrupted chunks, stale witnesses and conflicting peer replies.

Steps

  1. Attempt to make a validator or light client accept an unavailable or incorrect state under F0.
  2. Test retrieval from independent peers and expiry/retry policy.
  3. Restore data and check that recovery cannot alter an already verified commitment.

Accept

No unjustified available/verified status; safety and admission rules match F0. Recovery is bounded where assumptions permit, and unavailable-data states remain visible instead of hidden behind proofs.

Evidence the case requires

Withholding corpus; peer retrieval traces; availability/status checks.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
52
Plan pages
20, 25, 35, 37
VER-07Protect wallet keys, signing and recoveryPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use test-only keys, encrypted backups and clean replacement devices; no real user funds.

Steps

  1. Attempt secret access from proving jobs, logs, crash dumps, clipboard and telemetry paths.
  2. Verify transaction destination/amount before signing; test backup/restore and wrong-password handling.
  3. Upgrade and recover without silently changing signing authority or exposing seed material.

Accept

No unintended secret disclosure or unauthorised signature. Supported recovery restores the correct keys and accounts; users receive explicit risk/backup information. Logs are sanitised without hiding security evidence.

Evidence the case requires

Security review; canary-secret tests; signing fixtures; restore journey.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Design status
NOT RUN
Standard page
53
Plan pages
20, 25, 35, 37
VER-08Keep every user-facing state truthfulPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Create included-only, executed, proven, finalised, reverted, stale and paused examples.

Steps

  1. Compare explorer, wallet, receipt, RPC and customer API labels against authenticated evidence.
  2. Interrupt finality and proof services and observe refresh/reconnect behaviour.
  3. Check statements about privacy, Ethereum security and device support.

Accept

No stronger state is implied than verified; stale data is marked and failures are actionable. EVM compatibility is not labelled Ethereum security, and ZK technology is not automatically labelled transaction privacy.

Evidence the case requires

Cross-surface screenshots/logs; state mapping; claim review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
53
Plan pages
20, 25, 35, 37
13OPS

Independent operation and release security

A permissionless specification must remain operational without privileged infrastructure or unsafe automatic updates.

NOT RUN
Owner
Operations + release leads; independent operators
Gate
G5 G5
Fixtures
F4 isolated multi-operator network; F0 signed releases; F9 telemetry
Plan pages
21, 24, 25, 26
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
OPS-01Run the complete no-founder exercisePriority BLOCKERProfile P07, P08, P11NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use the P11 independent network, adequate honest participation and enough non-founder capacity for W.

Steps

  1. Remove founder miners, provers, aggregators, RPC, DNS/bootstrap dependencies and private support access.
  2. Run the full P11 period while crossing real and separately labelled accelerated boundaries.
  3. Introduce scheduled faults and have independent operators recover using published instructions.

Accept

No founder action, secret file, privileged key or emergency anti-chip rule is needed. P07/P08 outcomes hold within assumptions; any intervention is recorded as a failed no-rescue run, not erased.

Evidence the case requires

Operator roster/conflict checks; dependency removals; full activity/intervention log.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Design status
NOT RUN
Standard page
54
Plan pages
21, 24, 25, 26
OPS-02Diversify bootstrap and resist peer isolationPriority BLOCKERProfile P01, P08, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Start nodes without the default bootstrap host and give others adversarial peer lists.

Steps

  1. Attempt eclipse through peer concentration, stale discovery, poisoned DNS and repeated identities in an isolated lab.
  2. Use independent documented discovery paths and validate returned chain data.
  3. Measure synchronisation, peer diversity and recovery after benign connectivity returns.

Accept

No unauthenticated history is trusted; bootstrap has no hidden single-provider requirement. Isolation is detected/contained according to F0 and recovery meets P08 when assumptions return.

Evidence the case requires

Peer/discovery traces; eclipse scenarios; startup and recovery evidence.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Design status
NOT RUN
Standard page
54
Plan pages
21, 24, 25, 26
OPS-03Separate update distribution from consensus authorityPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Use test signing keys and clean desktop/node installations with valid, stale and malicious packages.

Steps

  1. Offer signed updates with unexpected consensus rules, downgraded binaries and corrupted payloads.
  2. Test explicit operator acceptance and the published signing-key incident procedure.
  3. Confirm that distribution-key possession cannot independently activate new consensus rules.

Accept

Tampering/unauthorised rollback is rejected; updates do not silently transfer authority. Approved acceptance and activation are separate. No test touches production signing material.

Evidence the case requires

Package corpus; approval/activation traces; compromised-key rehearsal.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Run
site-manifest-20261009-02
Design status
NOT RUN
Standard page
54
Plan pages
21, 24, 25, 26
OPS-04Recover nodes from crash and storage damagePriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Use production database/snapshot paths with controlled interrupted writes and corrupted test storage.

Steps

  1. Crash during import, proof acceptance, reward application and snapshot generation.
  2. Restore from independently verified snapshots or re-sync through documented procedures.
  3. Compare roots, certificates, balances and processed-job IDs with an unaffected node.

Accept

No corrupt snapshot is trusted, no duplicate payout and no loss of authenticated final state. Recovery meets P08 where data is available; ambiguous corruption fails closed and is actionable.

Evidence the case requires

Crash schedule; snapshot hashes; root/balance diffs; recovery timing.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
55
Plan pages
21, 24, 25, 26
OPS-05Isolate untrusted proving workloadsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Run hostile test jobs with secret canaries and restrictive worker permissions.

Steps

  1. Attempt filesystem escape, process spawning, resource exhaustion, network access and key-store reads.
  2. Crash workers and inspect host, wallet and node availability plus dump/log contents.
  3. Retry on every supported isolation backend and check dependency vulnerability handling.

Accept

No secret leakage or unauthorised host action; P09 resource containment holds. Worker failure does not compromise validator/wallet authority; unsupported isolation is not marketed as safe execution.

Evidence the case requires

Sandbox penetration report; canary logs; resource limits; host-integrity checks.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Design status
NOT RUN
Standard page
55
Plan pages
21, 24, 25, 26
OPS-06Contain malicious network and API trafficPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Use an authorised isolated load environment with declared resource and request-rate budgets.

Steps

  1. Send malformed headers, proofs, oversized messages, floods and invalid peer sequences.
  2. Measure legitimate traffic, memory/disk growth and validator CPU use.
  3. Test limit resets, peer reconnect and graceful degradation without disabling validation.

Accept

P09 abuse budgets hold; no unbounded allocation, persistent crash or invalid acceptance. Backpressure is visible and honest users retain the specified service at admitted load.

Evidence the case requires

Load/corpus manifests; resource series; valid-traffic metrics; incident traces.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
55
Plan pages
21, 24, 25, 26
OPS-07Detect failures with usable evidence and runbooksPriority GATEProfile P09, P10NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Define alerts for invalid acceptance, conflicting finality, backlog, data loss, payout mismatch and stale status.

Steps

  1. Inject one instance of each monitored failure in the lab.
  2. Have an unaffiliated operator diagnose it using only emitted evidence and published instructions.
  3. Test redaction, metric freshness and duplicate-alert suppression without suppressing serious failures.

Accept

P10 alert/detection limits hold; every blocker produces actionable evidence. Monitoring does not leak secrets or mislabel intentional safe pauses as successful finality.

Evidence the case requires

Alert matrix; detection timelines; independent runbook exercise.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Design status
NOT RUN
Standard page
56
Plan pages
21, 24, 25, 26
OPS-08Repeat independent operation across releasesPriority BLOCKERProfile P00, P08, P11NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use a clean previous supported version and the final candidate with independent operators.

Steps

  1. Perform documented rolling upgrade, rollback of non-consensus software where allowed and resynchronisation.
  2. Cross activation with mixed versions and unavailable founder distribution hosts.
  3. Re-run affected gates after changes and preserve prior failures and incident lessons.

Accept

No undocumented privileged migration or automatic consensus rewrite. All affected evidence is refreshed; P11 no-rescue results remain tied to the final release, not an earlier build.

Evidence the case requires

Upgrade/replay logs; invalidation map; repeated gate signatures.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Design status
NOT RUN
Standard page
56
Plan pages
21, 24, 25, 26
14UX

Ember, payouts and operator control

Successful participation must be practical for ordinary owners without hidden custody or loss of consensus authority.

NOT RUN
Owner
Desktop product + pool leads; independent usability study
Gate
Operator readiness / G5 G5
Fixtures
F2 supported desktops; F8 user study; F4 honest/malicious pools
Plan pages
14, 21, 25, 26
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
UX-01Onboard ordinary owners on native desktop appsPriority GATEProfile P10NOT RUNEvidence recordLast run 8 Oct 2026, 21:42 UK

Setup

Recruit the P10 first-time user cohort across Windows and macOS using supported physical hardware.

Steps

  1. Observe install, hardware detection, safety explanation and first accepted work without staff intervention.
  2. Record download/data preparation separately as well as complete end-to-end time.
  3. Test unsupported hardware and insufficient memory messaging rather than forcing a failed start.

Accept

P10 completion/time targets hold with no unsafe default or concealed prerequisite. The product is tested as the actual desktop app, not only a browser preview.

Evidence the case requires

Consent-based study records; task timings; failure reasons; compatibility outcomes.

Method
Independent observed user study
Cadence
Release candidate; repeat after relevant changes
Owner
update-return lane (a22d765a2e0355a9f)
Run
ux-01-20261008-win-2.0.0
Design status
NOT RUN
Standard page
57
Plan pages
14, 21, 25, 26
UX-02Make pause, stop and safe tuning reliablePriority BLOCKERProfile P01, P10NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Run mining/proving on active desktops under contention and safe thermal stress.

Steps

  1. Use pause, stop, power limit, task selection and emergency local shutdown controls.
  2. Crash or restart the UI while workers run and verify ownership of background processes.
  3. Restore the original hardware settings and test power-saving/low-battery behaviour where supported.

Accept

P10 control latency and safe-state requirements hold. Stopping does not strand an uncontrolled process; tuning never depends on unsafe settings or silent privilege escalation.

Evidence the case requires

Control timings; process/settings audit; restart and safety traces.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
57
Plan pages
14, 21, 25, 26
UX-03Show net earnings and compatibility honestlyPriority BLOCKERProfile P01, P10, P12NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Use known rewards, fees, energy readings, retries and operator-entered tariffs.

Steps

  1. Compare mining, internal proof and external proof income with authoritative ledgers.
  2. Show gross/net estimates, measurement boundaries, tariff assumptions and payout status.
  3. Test stale data, losses, negative margins and mining-only versus proving-compatible devices.

Accept

P10 reconciliation limits hold and uncertainty is visible. No guaranteed profits, fabricated fiat price or inferred proving support; provisional earnings are not shown as settled payments.

Evidence the case requires

UI/ledger comparisons; tariff fixtures; stale/negative examples.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
57
Plan pages
14, 21, 25, 26
UX-04Pay small operators without hidden custodyPriority BLOCKERProfile P01, P10NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Use ordinary single-card balances and the actual pooling/payment path.

Steps

  1. Earn, request/receive payment, disconnect and reconnect; include low balances, fees and a pool outage.
  2. Attempt redirection, delayed accounting and withdrawal of another user's entitlement.
  3. Reconcile displayed balances with canonical entitlement and actual settlement.

Accept

P10 payout limits hold for the declared small-operator case. No unauthorised custody, redirection or unexplained loss; thresholds and fees are disclosed rather than masked by larger test balances.

Evidence the case requires

Single-card payout ledger; pool failure record; custody/authorisation review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
pool design seat (a3832b1c3b274b310)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
58
Plan pages
14, 21, 25, 26
UX-05Keep voting keys with the miner through poolingPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 21:48 UK

Setup

Use an honest pool and a modified pool that replaces worker identity or voting credentials.

Steps

  1. Verify the consensus binding from performed work to the miner's retained key.
  2. Attempt substitution, replay and reassignment without the miner's authorisation.
  3. Leave the pool and verify retained voting/finality rights under F0.

Accept

No silent transfer of governance/finality authority. If the protocol cannot establish retained keys, this requirement fails; a pool-protocol name or user-interface promise does not pass.

Evidence the case requires

Work/key binding vectors; malicious-pool attempts; leave-pool authority check.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
pool design seat (a3832b1c3b274b310)
Run
pool-2.0-20261008-03
Design status
NOT RUN
Standard page
58
Plan pages
14, 21, 25, 26
UX-06Verify actual miner-selected work templatesPriority BLOCKERProfile P01, P10NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Provide a pool interface with declared job-declaration support and independent miner templates.

Steps

  1. Submit miner-selected valid transaction templates and verify what is actually hashed and accepted.
  2. Have a pool substitute or censor templates and test local verification/fallback.
  3. Measure payout and acceptance consequences without moving authority to the pool.

Accept

The advertised selection control exists in accepted work, not only configuration. Undisclosed substitution is detected; supported independent operation remains practical under P10.

Evidence the case requires

Template commitments; accepted-block evidence; malicious-pool/fallback report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
58
Plan pages
14, 21, 25, 26
UX-07Expose actionable failures and safe updatesPriority BLOCKERProfile P09, P10NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Create failed proofs, memory pressure, expired jobs, missing payouts and available software updates.

Steps

  1. Ask independent users to identify the issue, stop safely and follow the recommended action.
  2. Test explicit update approval, version visibility and a failed/corrupt update.
  3. Confirm diagnostic exports remove keys and private inputs while retaining useful evidence.

Accept

P10 task-success requirements hold; no silent update or false success state. Recovery instructions work on supported desktops and secret canaries never enter exported logs.

Evidence the case requires

Observed tasks; update traces; sanitised export tests.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
59
Plan pages
14, 21, 25, 26
UX-08Publish competitive accessible softwarePriority GATEProfile P02, P10NOT RUNEvidence none yetLast run 9 Oct 2026, 08:36 UK

Setup

Provide open documented builds, tuning parameters and known fee conditions for all supported platforms.

Steps

  1. Compare Ember against independently optimised permissible implementations on identical work.
  2. Measure efficiency, fees, false rejection, installation and update transparency.
  3. Scan for hidden developer fees, hardware whitelists, per-address privilege or undisclosed remote controls.

Accept

P10 relative-efficiency limits hold and all fees/privileges are explicit. No self-reported device tier earns consensus advantage. A superior external implementation triggers investigation, not selective exclusion.

Evidence the case requires

Matched software comparison; code/config review; fee/privilege inventory.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
site-gate-20261009-01
Design status
NOT RUN
Standard page
59
Plan pages
14, 21, 25, 26
15COM

Paid demand and sustainable delivery

Devnet payouts and subsidised pilots demonstrate mechanics, not independent willingness to pay.

NOT RUN
Owner
Commercial lead + independent financial/customer reviewer
Gate
Commercial evidence
Fixtures
F8 real consenting customers; F7 full service costs; private identity proofs
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
COM-01Deliver a genuine contracted proof pilotPriority GATEProfile P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Select one real external customer with a meaningful fixed workload and no required migration to Igneum.

Steps

  1. Agree program, inputs, proof format, deadline, price, failure/refund policy and verification method.
  2. Run paid jobs through ordinary independently operated infrastructure.
  3. Have the customer verify usefulness, correctness and its reason for choosing the service.

Accept

The pilot satisfies its actual contract and settles genuine external payment. Trial subsidies are disclosed and cannot satisfy the repeat-demand gate; no invented customer or testimonial.

Evidence the case requires

Redacted contract; verified jobs; settlement proof; consented customer confirmation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
60
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-02Establish independent repeat purchasingPriority GATEProfile P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use the P14 multi-customer observation period and ownership/conflict checks.

Steps

  1. Track paid purchases on distinct occasions, including refunds and stopped customers.
  2. Audit related parties, project reimbursements, token grants and circular funding.
  3. Reconcile external cash received with correctly delivered meaningful work.

Accept

P14 buyer, duration and volume minima are met without reimbursement or related-party substitution. Repeat orders are separate buying decisions, not a single payment split into many jobs.

Evidence the case requires

Anonymised buyer ledger; repeat-order dates; conflict review; net receipts.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
60
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-03Demonstrate service and operator marginsPriority GATEProfile P12, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Allocate all delivery costs, including aggregation, retries, hardware, power, host, network and support.

Steps

  1. Calculate gross contribution and fully loaded unit costs for each contracted workload.
  2. Reconcile a representative operator's realised earnings against metered costs and opportunity cost.
  3. Repeat under the declared demand and price sensitivities.

Accept

P14 contribution targets hold and at least the required operator cohort has positive realised contribution. Excluded overhead is visible; token appreciation or unpriced founder labour cannot silently create profitability.

Evidence the case requires

Unit-economics ledger; metered operator sample; allocation rules; sensitivity report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
60
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-04Meet the customer service guaranteePriority BLOCKERProfile P01, P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Observe actual delivery deadlines, validity, failure handling and support over the contracted period.

Steps

  1. Count all accepted jobs, including failed, retried and abandoned cases.
  2. Have the customer independently verify results and invoke one authorised refund/failure exercise.
  3. Compare offered capacity and quoted price with what was actually delivered.

Accept

P07 and contracted obligations hold; validity has zero accepted exceptions. Failure terms are honoured, and demand beyond capacity is explicitly refused rather than quietly omitted from metrics.

Evidence the case requires

Customer-verifier records; SLO report; refunds; promised-versus-delivered comparison.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
61
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-05Compare against the buyer's real alternativePriority GATEProfile P14, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Identify a credible alternative supplier or in-house option for the same workload, proof format and security.

Steps

  1. Obtain comparable quotes or consented measured trials at the evaluation date.
  2. Include integration, verification, deadlines and all operational costs, not only proof-generation time.
  3. Document the customer's actual trade-off without inventing unavailable comparator evidence.

Accept

P15 commercial comparison is satisfied with like-for-like scope and a evidenced purchase reason. Missing alternative data remains MISSING; it is not scored as an Igneum win.

Evidence the case requires

Dated comparison; workload/security match; customer decision record.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
61
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-06Retain buyers after the pilot and subsidy periodPriority GATEProfile P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Follow all recruited customers through the P14 observation period, including churn.

Steps

  1. Remove disclosed trial incentives before measuring repeat demand.
  2. Track renewal, expansion, cancellation reasons, unresolved incidents and buyer concentration.
  3. Review whether one affiliated or subsidised buyer dominates the apparent market.

Accept

P14 repeat/concentration conditions hold with honest denominator and churn reporting. Paying demand survives beyond a demonstration; unsatisfied or departed buyers are not removed retrospectively.

Evidence the case requires

Cohort/renewal ledger; churn notes; concentration and incentive report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
61
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-07Fund maintenance without assumed appreciationPriority GATEProfile P13NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Prepare a costed plan for development, review, infrastructure, support and incident response.

Steps

  1. Separate committed resources from revenue dependent on adoption or token price.
  2. Stress lower income and an unexpected security/operations expense.
  3. Verify responsible owners and continuity arrangements without changing fair-launch promises.

Accept

P13 committed-runway requirement holds and downside responses are documented. No uncommitted financing, rising token price or burn accounting is presented as available maintenance funding.

Evidence the case requires

Budget and commitment evidence; downside plan; owner/continuity roster.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
62
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-08Let independent developers build useful integrationsPriority GATEProfile P09, P14NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Recruit unaffiliated developers unfamiliar with unpublished implementation details.

Steps

  1. Use public docs to deploy a supported application or integrate an external proof request and verification flow.
  2. Record time, undocumented dependencies, workarounds and correctness issues.
  3. Retest after documentation fixes without founder-written hidden integration code.

Accept

P14 developer-task minimum passes on the final release; all required public instructions exist. Successful bytecode deployment alone does not count as a working application or service integration.

Evidence the case requires

Consented developer logs; public examples; issue closure; verified end-to-end journeys.

Method
Independent integration study
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
62
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
16LEAD

Comparative leadership evidence

A serious contention claim requires comparative outcomes and real adoption evidence, not just an internally green test dashboard.

NOT RUN
Owner
Independent assessment panel + product/economics reviewers
Gate
Leadership-contender decision
Fixtures
F8 peer/customer studies; full signed technical evidence; 90-day observation
Plan pages
4, 22, 25, 27, 31, 32, 33
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
LEAD-01Register a fair contemporary comparisonPriority GATEProfile P15NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Choose at least the P15 peer coverage and an evaluation date before collecting confirmatory results.

Steps

  1. Include the plan's Ravencoin, Ergo and Firo reference set where comparable, then check for other relevant current options.
  2. Freeze versions, supported hardware, methods, noninferiority margins and commercial alternatives.
  3. Publish exclusions and prohibit cross-algorithm raw-hashrate comparisons.

Accept

The protocol covers material alternatives fairly and is signed independently. A missing or non-comparable feature is not scored zero; no arbitrary universal rank is inferred from selected metrics.

Evidence the case requires

Timestamped peer protocol; source/version records; comparison/exclusion rationale.

Method
Pre-registered comparative study
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
63
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-02Demonstrate comparable operator advantagesPriority GATEProfile P02, P10, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use matched user tasks and operating conditions on the selected GPU-first networks.

Steps

  1. Measure install-to-first-accepted-work, software overhead versus each network's tuned baseline, payout friction and retained control.
  2. Measure rejection/availability under the same network conditions; report fees separately.
  3. Use blinded analysis where possible and independent runs for decisive differences.

Accept

P15 noninferiority and superiority requirements hold on meaningful comparable dimensions. No raw hashes from different algorithms are compared, and transient token price is not labelled engineering superiority.

Evidence the case requires

Matched task data; uncertainty/effect sizes; independent comparison report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
site lane (a846fd66b5403e35a)
Design status
NOT RUN
Standard page
63
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-03Substantiate the specialist-coexistence claimPriority GATEProfile P04, P12, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Assemble G1-G4 plus frozen rules and all surviving-adversary assumptions.

Steps

  1. Have independent reviewers trace each public competitiveness statement to its narrowest evidence.
  2. Separate measured GPUs, modelled silicon and economic scenarios in all summaries.
  3. Evaluate residual uncertainty, excluded technologies and the no-new-rules counterfactual.

Accept

All claimed envelopes meet P04/P12 without unsupported universal bounds. Reviewers agree the evidence supports scoped commodity competitiveness even when chips remain compatible; an exact chip-arrival probability is not inferred.

Evidence the case requires

Claim-to-evidence map; signed envelope review; limitations statement.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
63
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-04Observe ordinary-operator retention and marginsPriority GATEProfile P12, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Recruit the P16 independent cohort before observing results; use privacy-preserving evidence.

Steps

  1. Follow participation, realised margin, hardware changes, failures and reasons for leaving for 90 days.
  2. Report trial incentives separately and include every initial participant in retention denominators.
  3. Compare behaviour with matched alternatives where feasible; disclose absence of an actual downturn.

Accept

P16 retention/margin minima hold with verified independence and no removal of churned users. Simulated downturns cannot be called observed bear-market retention; historical claims stay limited to the period measured.

Evidence the case requires

Pseudonymous cohort ledger; margin/retention calculations; departure reasons.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
64
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-05Measure control and dependency concentrationPriority GATEProfile P11, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Audit operational control of mining, voting, proving, aggregation, hosting and software distribution separately.

Steps

  1. Use opt-in attestations, observed dependencies and independent corroboration; disclose uncertain common ownership.
  2. Compare concentration and provider-removal outcomes to the approved security and availability assumptions.
  3. Check that pooled payments do not hide authority concentration and hardware vendors are not equated with operators.

Accept

P11/P16 concentration requirements hold within disclosed uncertainty; unidentified control cannot be counted as independent. No single removable dependency is falsely marketed as decentralised operation.

Evidence the case requires

Control/failure-domain map; uncertainty notes; concentration/removal results.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
64
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-06Complete the reliability observation windowPriority BLOCKERProfile P01, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Observe the final candidate and approved compatible updates for the full P16 real-time period.

Steps

  1. Measure promised service availability, invalid acceptance, finality safety, payouts and incident impact.
  2. Reconcile external probes, customer records and operator logs, including maintenance and exclusions.
  3. Repeat affected critical tests after every material change; reset observation where comparability breaks.

Accept

P16 availability and safety criteria hold on live observation; no hidden downtime or compressed-time substitution. This supports the recorded window only, not multi-year operational maturity.

Evidence the case requires

90-day SLO ledger; independent probes; incident reports; change/retest history.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
64
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-07Issue an independent contender assessmentPriority GATEProfile P00, P15, P16NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Provide the full evidence packet, commercial results, comparative study and unresolved-limit register to the panel.

Steps

  1. Check every mandatory and claimed-option test, source requirement and approved threshold.
  2. Require separate signoffs for hardware/economics, security/operations and customer/operator evidence.
  3. Document dissent and challenge any inference that passing an internal checklist proves number-one rank.

Accept

Every required gate is PASS with no unresolved material challenge, critical/high defect or missing comparator/customer evidence. The panel supports a credible leadership-contender conclusion within scope, not a guaranteed rank.

Evidence the case requires

Signed assessment; full status index; dissent/limitations; approved claim wording.

Method
Independent final assessment
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
65
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-08Keep leadership claims valid after releasePriority GATEProfile P00, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Define material-change triggers and scheduled reviews before publishing the assessment.

Steps

  1. Refresh competitor, hardware-cost, demand and security evidence at the P16 cadence.
  2. Test a newly credible specialist, lost customer, major outage and verifier change against invalidation rules.
  3. Withdraw or narrow stale claims promptly while publishing the new evidence status.

Accept

Claims remain dated, scoped and revisable; material contrary evidence reopens the appropriate gate. The network may remain usable while a leadership claim is suspended. No permanent self-awarded certification.

Evidence the case requires

Review calendar; invalidation drills; versioned public claim register.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
65
Plan pages
4, 22, 25, 27, 31, 32, 33
17REV

REV: the external review's required regressions

44 regressions from 14 findings; each reads NOT RUN until its owner lane records a run

NOT RUN
Owner
the owner lanes per the dispatch table
Gate
Review findings closed
Fixtures
F0,F5
Plan pages
docs/analysis/review-2026-10-08-b/findings.json and docs/analysis/review-2026-10-08-b/dispatch.md; ids from the master traceability register
44 cases: 1 passed under the standard, 0 running with team evidence, 43 not run, 0 deferred
R2-F01-R01Valid proof A, warm cache, carried statement B: refuse exactly as a cold node does.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F01 requires (review R2 finding F01: Proof-verdict cache omits the statement being verified).

Steps

  1. Valid proof A, warm cache, carried statement B: refuse exactly as a cold node does.

Accept

Valid proof A, warm cache, carried statement B: refuse exactly as a cold node does.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, node lane
Design status
NOT RUN
Plan pages
R2-F01
R2-F01-R02Run valid/invalid contexts in both orders, concurrently and across cache eviction/restart.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F01 requires (review R2 finding F01: Proof-verdict cache omits the statement being verified).

Steps

  1. Run valid/invalid contexts in both orders, concurrently and across cache eviction/restart.

Accept

Run valid/invalid contexts in both orders, concurrently and across cache eviction/restart.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, node lane
Design status
NOT RUN
Plan pages
R2-F01
R2-F01-R03Change payout, network, kind, program ID and activation context; no accepted misbinding.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F01 requires (review R2 finding F01: Proof-verdict cache omits the statement being verified).

Steps

  1. Change payout, network, kind, program ID and activation context; no accepted misbinding.

Accept

Change payout, network, kind, program ID and activation context; no accepted misbinding.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, node lane
Design status
NOT RUN
Plan pages
R2-F01
R2-F01-R04A native two-node test must agree on block validity and payouts despite different cache histories.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F01 requires (review R2 finding F01: Proof-verdict cache omits the statement being verified).

Steps

  1. A native two-node test must agree on block validity and payouts despite different cache histories.

Accept

A native two-node test must agree on block validity and payouts despite different cache histories.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, node lane
Design status
NOT RUN
Plan pages
R2-F01
R2-F02-R01Release build cannot activate test bypass.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F02 requires (review R2 finding F02: Proof-rule infrastructure can fail open).

Steps

  1. Release build cannot activate test bypass.

Accept

Release build cannot activate test bypass.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, CI steward
Design status
NOT RUN
Plan pages
R2-F02
R2-F02-R02Missing oracle or pinned keys prevents service readiness after enforcement activation.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F02 requires (review R2 finding F02: Proof-rule infrastructure can fail open).

Steps

  1. Missing oracle or pinned keys prevents service readiness after enforcement activation.

Accept

Missing oracle or pinned keys prevents service readiness after enforcement activation.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, CI steward
Design status
NOT RUN
Plan pages
R2-F02
R2-F02-R03Missing proof bytes retry without incorrectly marking a valid block permanently invalid.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F02 requires (review R2 finding F02: Proof-rule infrastructure can fail open).

Steps

  1. Missing proof bytes retry without incorrectly marking a valid block permanently invalid.

Accept

Missing proof bytes retry without incorrectly marking a valid block permanently invalid.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, CI steward
Design status
NOT RUN
Plan pages
R2-F02
R2-F03-R01Clean build from one manifest, including the pool and workers, with no unpublished vendor tree.Priority P0Profile P00PASSEvidence none yetLast run 8 Oct 2026, 22:11 UK

Setup

The regression R2-F03 requires (review R2 finding F03: The bundle contains a v6 candidate, not a demonstrated integrated v6 release).

Steps

  1. Clean build from one manifest, including the pool and workers, with no unpublished vendor tree.

Accept

Clean build from one manifest, including the pool and workers, with no unpublished vendor tree.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward, hash lane (ProgramClass::V6 on freeze), pool lane
Run
f03-manifest-20261008-01
Design status
NOT RUN
Plan pages
R2-F03
R2-F03-R02Same job context produces identical accepted work in node, CPU reference, CUDA, Metal, OpenCL and pool.Priority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 06:08 UK

Setup

The regression R2-F03 requires (review R2 finding F03: The bundle contains a v6 candidate, not a demonstrated integrated v6 release).

Steps

  1. Same job context produces identical accepted work in node, CPU reference, CUDA, Metal, OpenCL and pool.

Accept

Same job context produces identical accepted work in node, CPU reference, CUDA, Metal, OpenCL and pool.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward, hash lane (ProgramClass::V6 on freeze), pool lane
Run
same-work-20261008-03
Design status
NOT RUN
Plan pages
R2-F03
R2-F03-R03Cross every scheduled transition with old/new client behavior documented and identical rule identities.Priority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 06:08 UK

Setup

The regression R2-F03 requires (review R2 finding F03: The bundle contains a v6 candidate, not a demonstrated integrated v6 release).

Steps

  1. Cross every scheduled transition with old/new client behavior documented and identical rule identities.

Accept

Cross every scheduled transition with old/new client behavior documented and identical rule identities.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward, hash lane (ProgramClass::V6 on freeze), pool lane
Run
same-work-20261008-03
Design status
NOT RUN
Plan pages
R2-F03
R2-F04-R01Native multi-node 40/40/20 partition, equivocation and dust-valid mining on both sides past the window.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F04 requires (review R2 finding F04: Finality v4 recovery deliberately has a weaker safety boundary).

Steps

  1. Native multi-node 40/40/20 partition, equivocation and dust-valid mining on both sides past the window.

Accept

Native multi-node 40/40/20 partition, equivocation and dust-valid mining on both sides past the window.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane, reference apps, site (explorer)
Design status
NOT RUN
Plan pages
R2-F04
R2-F04-R02Proof that the chosen recovery guarantee matches the public finality claim; two valid contradictory certificates are a hard failure for strong finality.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F04 requires (review R2 finding F04: Finality v4 recovery deliberately has a weaker safety boundary).

Steps

  1. Proof that the chosen recovery guarantee matches the public finality claim; two valid contradictory certificates are a hard failure for strong finality.

Accept

Proof that the chosen recovery guarantee matches the public finality claim; two valid contradictory certificates are a hard failure for strong finality.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane, reference apps, site (explorer)
Design status
NOT RUN
Plan pages
R2-F04
R2-F04-R03Pause-only resume with historical backfill, missing historical data and all old keys returning.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F04 requires (review R2 finding F04: Finality v4 recovery deliberately has a weaker safety boundary).

Steps

  1. Pause-only resume with historical backfill, missing historical data and all old keys returning.

Accept

Pause-only resume with historical backfill, missing historical data and all old keys returning.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane, reference apps, site (explorer)
Design status
NOT RUN
Plan pages
R2-F04
R2-F04-R04Wallet, receipt and oracle consumers distinguish any weaker recovery state.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F04 requires (review R2 finding F04: Finality v4 recovery deliberately has a weaker safety boundary).

Steps

  1. Wallet, receipt and oracle consumers distinguish any weaker recovery state.

Accept

Wallet, receipt and oracle consumers distinguish any weaker recovery state.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane, reference apps, site (explorer)
Design status
NOT RUN
Plan pages
R2-F04
R2-F05-R01Native reference-vs-incremental expression equivalence across all source registers and real instruction updates.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F05 requires (review R2 finding F05: reg64 address coupling has an exact incremental alternative).

Steps

  1. Native reference-vs-incremental expression equivalence across all source registers and real instruction updates.

Accept

Native reference-vs-incremental expression equivalence across all source registers and real instruction updates.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, adversary lane, floor lane 3
Design status
NOT RUN
Plan pages
R2-F05
R2-F05-R02Full-kernel output equivalence, registers, spills, wall power and accepted throughput across target GPUs.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F05 requires (review R2 finding F05: reg64 address coupling has an exact incremental alternative).

Steps

  1. Full-kernel output equivalence, registers, spills, wall power and accepted throughput across target GPUs.

Accept

Full-kernel output equivalence, registers, spills, wall power and accepted throughput across target GPUs.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, adversary lane, floor lane 3
Design status
NOT RUN
Plan pages
R2-F05
R2-F05-R03Adversary physical design includes prefix caching/recomputation cost; no assumed full 63-read cost on every load.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F05 requires (review R2 finding F05: reg64 address coupling has an exact incremental alternative).

Steps

  1. Adversary physical design includes prefix caching/recomputation cost; no assumed full 63-read cost on every load.

Accept

Adversary physical design includes prefix caching/recomputation cost; no assumed full 63-read cost on every load.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, adversary lane, floor lane 3
Design status
NOT RUN
Plan pages
R2-F05
R2-F06-R01Acceptance/reference/emitter evaluate the same activated schedule.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F06 requires (review R2 finding F06: The v6 acceptance and census gates are not complete for the final execution).

Steps

  1. Acceptance/reference/emitter evaluate the same activated schedule.

Accept

Acceptance/reference/emitter evaluate the same activated schedule.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, research lane D
Design status
NOT RUN
Plan pages
R2-F06
R2-F06-R02Full live-dataset census on unseen seeds and the complete v6 pack.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F06 requires (review R2 finding F06: The v6 acceptance and census gates are not complete for the final execution).

Steps

  1. Full live-dataset census on unseen seeds and the complete v6 pack.

Accept

Full live-dataset census on unseen seeds and the complete v6 pack.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, research lane D
Design status
NOT RUN
Plan pages
R2-F06
R2-F06-R03A failed experimental rule does not silently exhaust generation or bypass the intended resource requirement.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F06 requires (review R2 finding F06: The v6 acceptance and census gates are not complete for the final execution).

Steps

  1. A failed experimental rule does not silently exhaust generation or bypass the intended resource requirement.

Accept

A failed experimental rule does not silently exhaust generation or bypass the intended resource requirement.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, research lane D
Design status
NOT RUN
Plan pages
R2-F06
R2-F07-R01Same final v6 configuration: mine -> evict -> prove -> aggregate -> submit -> rebuild -> resume; no leaked reservations.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F07 requires (review R2 finding F07: VRAM admission and proving deadlines need one operator-level scheduler).

Steps

  1. Same final v6 configuration: mine -> evict -> prove -> aggregate -> submit -> rebuild -> resume; no leaked reservations.

Accept

Same final v6 configuration: mine -> evict -> prove -> aggregate -> submit -> rebuild -> resume; no leaked reservations.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, fleet lane
Design status
NOT RUN
Plan pages
R2-F07
R2-F07-R02OOM, process crash and stale work recover without losing wallet state or silently consuming power.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F07 requires (review R2 finding F07: VRAM admission and proving deadlines need one operator-level scheduler).

Steps

  1. OOM, process crash and stale work recover without losing wallet state or silently consuming power.

Accept

OOM, process crash and stale work recover without losing wallet state or silently consuming power.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, fleet lane
Design status
NOT RUN
Plan pages
R2-F07
R2-F07-R0316 GB+ simultaneous mode only after measured peak plus next-epoch headroom; smaller-card modes labelled separately.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F07 requires (review R2 finding F07: VRAM admission and proving deadlines need one operator-level scheduler).

Steps

  1. 16 GB+ simultaneous mode only after measured peak plus next-epoch headroom; smaller-card modes labelled separately.

Accept

16 GB+ simultaneous mode only after measured peak plus next-epoch headroom; smaller-card modes labelled separately.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, fleet lane
Design status
NOT RUN
Plan pages
R2-F07
R2-F08-R01Report every eligible job outcome, including expired work; a bounded list cannot hide losses.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F08 requires (review R2 finding F08: The proving pipeline reports waste and deadline censoring, not sustained capacity).

Steps

  1. Report every eligible job outcome, including expired work; a bounded list cannot hide losses.

Accept

Report every eligible job outcome, including expired work; a bounded list cannot hide losses.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, fleet lane, site (ops page)
Design status
NOT RUN
Plan pages
R2-F08
R2-F08-R02Consumer tiers complete and receive payment for declared jobs before claims about income.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F08 requires (review R2 finding F08: The proving pipeline reports waste and deadline censoring, not sustained capacity).

Steps

  1. Consumer tiers complete and receive payment for declared jobs before claims about income.

Accept

Consumer tiers complete and receive payment for declared jobs before claims about income.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, fleet lane, site (ops page)
Design status
NOT RUN
Plan pages
R2-F08
R2-F08-R03Sustained real workload across class transitions, with restart/retry and no publisher intervention.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F08 requires (review R2 finding F08: The proving pipeline reports waste and deadline censoring, not sustained capacity).

Steps

  1. Sustained real workload across class transitions, with restart/retry and no publisher intervention.

Accept

Sustained real workload across class transitions, with restart/retry and no publisher intervention.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, fleet lane, site (ops page)
Design status
NOT RUN
Plan pages
R2-F08
R2-F09-R01Generate all pass/fail cells directly from the declared inequalities and inputs.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F09 requires (review R2 finding F09: The economic model explicitly retains a failed specialist case).

Steps

  1. Generate all pass/fail cells directly from the declared inequalities and inputs.

Accept

Generate all pass/fail cells directly from the declared inequalities and inputs.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
research lane, floor lane 3, coordinator
Design status
NOT RUN
Plan pages
R2-F09
R2-F09-R02Independent feasibility and cost evaluation of the strongest modeled SRAM/hybrid opponent.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F09 requires (review R2 finding F09: The economic model explicitly retains a failed specialist case).

Steps

  1. Independent feasibility and cost evaluation of the strongest modeled SRAM/hybrid opponent.

Accept

Independent feasibility and cost evaluation of the strongest modeled SRAM/hybrid opponent.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
research lane, floor lane 3, coordinator
Design status
NOT RUN
Plan pages
R2-F09
R2-F09-R03GPU owners and entrants remain viable under the approved scenario envelope without assuming chip absence or death.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F09 requires (review R2 finding F09: The economic model explicitly retains a failed specialist case).

Steps

  1. GPU owners and entrants remain viable under the approved scenario envelope without assuming chip absence or death.

Accept

GPU owners and entrants remain viable under the approved scenario envelope without assuming chip absence or death.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
research lane, floor lane 3, coordinator
Design status
NOT RUN
Plan pages
R2-F09
R2-F10-R01Compare exact found nonce/hash sets with full-read mode, including all-hit overflow and zero-hit cases.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F10 requires (review R2 finding F10: CUDA production readback has an existing OpenCL optimization to borrow).

Steps

  1. Compare exact found nonce/hash sets with full-read mode, including all-hit overflow and zero-hit cases.

Accept

Compare exact found nonce/hash sets with full-read mode, including all-hit overflow and zero-hit cases.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
worker lane (new)
Design status
NOT RUN
Plan pages
R2-F10
R2-F10-R02Test stale jobs, high-32 rollover, tail batches and asynchronous buffer reuse.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F10 requires (review R2 finding F10: CUDA production readback has an existing OpenCL optimization to borrow).

Steps

  1. Test stale jobs, high-32 rollover, tail batches and asynchronous buffer reuse.

Accept

Test stale jobs, high-32 rollover, tail batches and asynchronous buffer reuse.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
worker lane (new)
Design status
NOT RUN
Plan pages
R2-F10
R2-F10-R03Compare production throughput and wall energy, not only the isolated kernel timer.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F10 requires (review R2 finding F10: CUDA production readback has an existing OpenCL optimization to borrow).

Steps

  1. Compare production throughput and wall energy, not only the isolated kernel timer.

Accept

Compare production throughput and wall energy, not only the isolated kernel timer.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
worker lane (new)
Design status
NOT RUN
Plan pages
R2-F10
R2-F11-R01Goal switch from an efficiency prior can explore higher core/power when policy allows.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F11 requires (review R2 finding F11: Ember needs workload-aware identity and objective-aware search).

Steps

  1. Goal switch from an efficiency prior can explore higher core/power when policy allows.

Accept

Goal switch from an efficiency prior can explore higher core/power when policy allows.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ember lane (new)
Design status
NOT RUN
Plan pages
R2-F11
R2-F11-R02Driver, workload, dataset, compiler and device changes invalidate certification while retaining optional hints.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F11 requires (review R2 finding F11: Ember needs workload-aware identity and objective-aware search).

Steps

  1. Driver, workload, dataset, compiler and device changes invalidate certification while retaining optional hints.

Accept

Driver, workload, dataset, compiler and device changes invalidate certification while retaining optional hints.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ember lane (new)
Design status
NOT RUN
Plan pages
R2-F11
R2-F11-R03Thermal/error/late-share events revert safely, including process or machine crash.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F11 requires (review R2 finding F11: Ember needs workload-aware identity and objective-aware search).

Steps

  1. Thermal/error/late-share events revert safely, including process or machine crash.

Accept

Thermal/error/late-share events revert safely, including process or machine crash.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ember lane (new)
Design status
NOT RUN
Plan pages
R2-F11
R2-F12-R01Crash before/after broadcast, response timeout, restart before snapshot: no duplicate payment or silent debt loss.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F12 requires (review R2 finding F12: Pool payouts have a broadcast-before-durable-intent window).

Steps

  1. Crash before/after broadcast, response timeout, restart before snapshot: no duplicate payment or silent debt loss.

Accept

Crash before/after broadcast, response timeout, restart before snapshot: no duplicate payment or silent debt loss.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
R2-F12
R2-F12-R02Same signed transaction retried, fee replacement reconciled by intent, not a new payment.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F12 requires (review R2 finding F12: Pool payouts have a broadcast-before-durable-intent window).

Steps

  1. Same signed transaction retried, fee replacement reconciled by intent, not a new payment.

Accept

Same signed transaction retried, fee replacement reconciled by intent, not a new payment.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
R2-F12
R2-F12-R03Receipt reorg and finality pause leave correct pending obligations.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F12 requires (review R2 finding F12: Pool payouts have a broadcast-before-durable-intent window).

Steps

  1. Receipt reorg and finality pause leave correct pending obligations.

Accept

Receipt reorg and finality pause leave correct pending obligations.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
R2-F12
R2-F13-R01Repeated authorization rejected or atomically replaces and cleans prior state.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F13 requires (review R2 finding F13: Pool admission and membership need bounded resources).

Steps

  1. Repeated authorization rejected or atomically replaces and cleans prior state.

Accept

Repeated authorization rejected or atomically replaces and cleans prior state.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
R2-F13
R2-F13-R02Oversized unterminated frame rejected within fixed memory/time budget.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F13 requires (review R2 finding F13: Pool admission and membership need bounded resources).

Steps

  1. Oversized unterminated frame rejected within fixed memory/time budget.

Accept

Oversized unterminated frame rejected within fixed memory/time budget.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
R2-F13
R2-F13-R03Slow clients and invalid share floods cannot grow unbounded member, nonce or outgoing state.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F13 requires (review R2 finding F13: Pool admission and membership need bounded resources).

Steps

  1. Slow clients and invalid share floods cannot grow unbounded member, nonce or outgoing state.

Accept

Slow clients and invalid share floods cannot grow unbounded member, nonce or outgoing state.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
R2-F13
R2-F14-R01Public build has no default arbitrary remote execution and a documented least-privilege boundary.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F14 requires (review R2 finding F14: Developer fleet control must not silently become the public client trust model).

Steps

  1. Public build has no default arbitrary remote execution and a documented least-privilege boundary.

Accept

Public build has no default arbitrary remote execution and a documented least-privilege boundary.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, relay lane
Design status
NOT RUN
Plan pages
R2-F14
R2-F14-R02Automatic updates off remains off for urgent manifests until explicit action.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F14 requires (review R2 finding F14: Developer fleet control must not silently become the public client trust model).

Steps

  1. Automatic updates off remains off for urgent manifests until explicit action.

Accept

Automatic updates off remains off for urgent manifests until explicit action.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, relay lane
Design status
NOT RUN
Plan pages
R2-F14
R2-F14-R03A compromised fleet/update signing key cannot silently acquire wallet access or activate a consensus change.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F14 requires (review R2 finding F14: Developer fleet control must not silently become the public client trust model).

Steps

  1. A compromised fleet/update signing key cannot silently acquire wallet access or activate a consensus change.

Accept

A compromised fleet/update signing key cannot silently acquire wallet access or activate a consensus change.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, relay lane
Design status
NOT RUN
Plan pages
R2-F14
18INT

INT: the master edition's integration gates (R1, the full-system review)

18 integration gates; each reads NOT RUN until its owner lane records a run

FAIL
Owner
the owner lanes per the coordinator's crosswalk
Gate
Integration gates closed
Fixtures
F0,F5
Plan pages
docs/plans/igneum-2.0-master/traceability.json integration_gates
18 cases: 0 passed under the standard, 0 running with team evidence, 1 failed, 17 not run, 0 deferred
INT-01Real proof H cannot authenticate a different statement under a warm cache.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-01 of the master edition (R1 / Additional regression gates).

Steps

  1. Real proof H cannot authenticate a different statement under a warm cache.

Accept

Real proof H cannot authenticate a different statement under a warm cache.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Plan pages
R1
INT-02Warm/cold/relay/restart/concurrent cache order does not change block or payout decisions; negative cache isolated.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-02 of the master edition (R1 / Additional regression gates).

Steps

  1. Warm/cold/relay/restart/concurrent cache order does not change block or payout decisions; negative cache isolated.

Accept

Warm/cold/relay/restart/concurrent cache order does not change block or payout decisions; negative cache isolated.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Plan pages
R1
INT-03Durable payout outbox survives every crash/RPC boundary without duplicate or lost liabilities.Priority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 00:47 UK

Setup

Integration gate INT-03 of the master edition (R1 / Additional regression gates).

Steps

  1. Durable payout outbox survives every crash/RPC boundary without duplicate or lost liabilities.

Accept

Durable payout outbox survives every crash/RPC boundary without duplicate or lost liabilities.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (a1c484c48a62948c2)
Run
pool-int-20261009-01
Design status
NOT RUN
Plan pages
R1
INT-04Corrupt existing pool state, disk-full and reorg cause safe recovery, not silent empty balances.Priority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 00:47 UK

Setup

Integration gate INT-04 of the master edition (R1 / Additional regression gates).

Steps

  1. Corrupt existing pool state, disk-full and reorg cause safe recovery, not silent empty balances.

Accept

Corrupt existing pool state, disk-full and reorg cause safe recovery, not silent empty balances.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (a1c484c48a62948c2)
Run
pool-int-20261009-01
Design status
NOT RUN
Plan pages
R1
INT-05The supplied finality implementation matches the approved anchor rule after >window healing.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-05 of the master edition (R1 / Additional regression gates).

Steps

  1. The supplied finality implementation matches the approved anchor rule after >window healing.

Accept

The supplied finality implementation matches the approved anchor rule after >window healing.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane (a283f5f0d364ceef0)
Design status
NOT RUN
Plan pages
R1
INT-06Recovery tests state and preserve their weaker fault bound; interfaces never label it as a stronger guarantee.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-06 of the master edition (R1 / Additional regression gates).

Steps

  1. Recovery tests state and preserve their weaker fault bound; interfaces never label it as a stronger guarantee.

Accept

Recovery tests state and preserve their weaker fault bound; interfaces never label it as a stronger guarantee.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane (a283f5f0d364ceef0)
Design status
NOT RUN
Plan pages
R1
INT-07One v6 object agrees in node, pool, CPU verifier and each supported GPU host across activation.Priority P0Profile P00FAILEvidence none yetLast run 9 Oct 2026, 08:43 UK

Setup

Integration gate INT-07 of the master edition (R1 / Additional regression gates).

Steps

  1. One v6 object agrees in node, pool, CPU verifier and each supported GPU host across activation.

Accept

One v6 object agrees in node, pool, CPU verifier and each supported GPU host across activation.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)
Run
canary-202-20261009-01
Design status
NOT RUN
Plan pages
R1
INT-08Census, production acceptance, schedule counters and live-dataset tests use the identical frozen contract.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-08 of the master edition (R1 / Additional regression gates).

Steps

  1. Census, production acceptance, schedule counters and live-dataset tests use the identical frozen contract.

Accept

Census, production acceptance, schedule counters and live-dataset tests use the identical frozen contract.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)
Design status
NOT RUN
Plan pages
R1
INT-09Eight- and twelve-GiB epoch transitions recover deliberately without relying on repeated OOM/watchdog cycles.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-09 of the master edition (R1 / Additional regression gates).

Steps

  1. Eight- and twelve-GiB epoch transitions recover deliberately without relying on repeated OOM/watchdog cycles.

Accept

Eight- and twelve-GiB epoch transitions recover deliberately without relying on repeated OOM/watchdog cycles.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane
Design status
NOT RUN
Plan pages
R1
INT-10Metal/CUDA/OpenCL exact dataset geometry agrees; unsupported packs reject before launch.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-10 of the master edition (R1 / Additional regression gates).

Steps

  1. Metal/CUDA/OpenCL exact dataset geometry agrees; unsupported packs reject before launch.

Accept

Metal/CUDA/OpenCL exact dataset geometry agrees; unsupported packs reject before launch.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)
Design status
NOT RUN
Plan pages
R1
INT-11Only a memory-reserved proving job launches; mining buffers really release when required.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-11 of the master edition (R1 / Additional regression gates).

Steps

  1. Only a memory-reserved proving job launches; mining buffers really release when required.

Accept

Only a memory-reserved proving job launches; mining buffers really release when required.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane
Design status
NOT RUN
Plan pages
R1
INT-12Transient shard errors can retry safely; expiration, loss and paid work remain distinct durable outcomes.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-12 of the master edition (R1 / Additional regression gates).

Steps

  1. Transient shard errors can retry safely; expiration, loss and paid work remain distinct durable outcomes.

Accept

Transient shard errors can retry safely; expiration, loss and paid work remain distinct durable outcomes.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane (a6e8f84588b809d62) and fleet lane (ac055d60427caab99)
Design status
NOT RUN
Plan pages
R1
INT-13Ember cannot retain a rate-ineligible prior; material workload changes invalidate incompatible profiles.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-13 of the master edition (R1 / Additional regression gates).

Steps

  1. Ember cannot retain a rate-ineligible prior; material workload changes invalidate incompatible profiles.

Accept

Ember cannot retain a rate-ineligible prior; material workload changes invalidate incompatible profiles.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ember lane (a04fe3451877e2ff0) with the app lane
Design status
NOT RUN
Plan pages
R1
INT-14Protected helper and per-device leases restore owned settings on normal/abnormal exit; real ACL/security tests.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-14 of the master edition (R1 / Additional regression gates).

Steps

  1. Protected helper and per-device leases restore owned settings on normal/abnormal exit; real ACL/security tests.

Accept

Protected helper and per-device leases restore owned settings on normal/abnormal exit; real ACL/security tests.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ember lane (a04fe3451877e2ff0) with the app lane
Design status
NOT RUN
Plan pages
R1
INT-15Public PoP replay is not session authorization; payout/server/network binding enforced.Priority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 00:47 UK

Setup

Integration gate INT-15 of the master edition (R1 / Additional regression gates).

Steps

  1. Public PoP replay is not session authorization; payout/server/network binding enforced.

Accept

Public PoP replay is not session authorization; payout/server/network binding enforced.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (a1c484c48a62948c2)
Run
pool-int-20261009-01
Design status
NOT RUN
Plan pages
R1
INT-16Pool parsing/queues/connection and crypto budgets remain bounded under controlled adversarial traffic.Priority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 00:47 UK

Setup

Integration gate INT-16 of the master edition (R1 / Additional regression gates).

Steps

  1. Pool parsing/queues/connection and crypto budgets remain bounded under controlled adversarial traffic.

Accept

Pool parsing/queues/connection and crypto budgets remain bounded under controlled adversarial traffic.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (a1c484c48a62948c2)
Run
pool-int-20261009-01
Design status
NOT RUN
Plan pages
R1
INT-17Missing oracle/keys/mandatory real-proof fixture blocks the applicable production acceptance gate.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-17 of the master edition (R1 / Additional regression gates).

Steps

  1. Missing oracle/keys/mandatory real-proof fixture blocks the applicable production acceptance gate.

Accept

Missing oracle/keys/mandatory real-proof fixture blocks the applicable production acceptance gate.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Plan pages
R1
INT-18Whole-system economics pass the strongest feasible adversary, including sunk development and multi-epoch survival.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-18 of the master edition (R1 / Additional regression gates).

Steps

  1. Whole-system economics pass the strongest feasible adversary, including sunk development and multi-epoch survival.

Accept

Whole-system economics pass the strongest feasible adversary, including sunk development and multi-epoch survival.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
research lane (ad6a2bd47d4a46105)
Design status
NOT RUN
Plan pages
R1
19VR

VR: the token value and network leadership rules (normative, proposed, requiring ratification)

40 normative rules from Igneum 2.0, Token Value & Network Leadership 1.0-proposed (snapshot 2026-10-08); Supplement to original master and 128-case test standard; not a price/rank guarantee

NOT RUN
Owner
founder (ratification); the owner role per rule
Gate
Ratification by the founder and each rule's owner role
Fixtures
F0
Plan pages
docs/plans/igneum-2.0-master/token-value/rules-and-gates.json rules
40 cases: 0 passed under the standard, 0 running with team evidence, 40 not run, 0 deferred
VR-01One monetary contractPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Ratify one maximum-supply, subsidy and change-policy contract. No unexplained tail escape, automatic emergency mint or price-triggered issuance.

Accept

Ratify one maximum-supply, subsidy and change-policy contract. No unexplained tail escape, automatic emergency mint or price-triggered issuance.

Evidence the case requires

D01 decision, normative spec, executable supply tests and consistent public text.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Protocol + governance
Plan pages
TV
VR-02Independent supply accountingPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Make circulating, issued, burned, locked and maximum supply independently reproducible. Count bridges and wrappers without creating fictitious native supply.

Accept

Make circulating, issued, burned, locked and maximum supply independently reproducible. Count bridges and wrappers without creating fictitious native supply.

Evidence the case requires

Two independent supply calculations with exact integer reconciliation.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Protocol + measurement
Plan pages
TV
VR-03Equal opportunity at launchPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. No premine or privileged devnet conversion under the stated fair-launch policy. Publish efficient software and launch conditions before activation.

Accept

No premine or privileged devnet conversion under the stated fair-launch policy. Publish efficient software and launch conditions before activation.

Evidence the case requires

Genesis audit, launch rehearsal, insider disclosures and public release history.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Release + ecosystem
Plan pages
TV
VR-04No artificial return promisePriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Do not advertise guaranteed appreciation, passive returns without necessary work, a redemption floor or electricity-backed value.

Accept

Do not advertise guaranteed appreciation, passive returns without necessary work, a redemption floor or electricity-backed value.

Evidence the case requires

Product terms, source of rewards and public-claim review.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Governance + counsel
Plan pages
TV
VR-05Fund necessary securityPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Model miners, internal provers, minimum validators and maintenance separately through declining issuance. No assumption that an external sale automatically funds all roles.

Accept

Model miners, internal provers, minimum validators and maintenance separately through declining issuance. No assumption that an external sale automatically funds all roles.

Evidence the case requires

Role-by-role cash flow, adverse scenarios and committed initial resources.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Economics + protocol
Plan pages
TV
VR-06Honest rule changePriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Publish rationale, impact, adoption path and compatibility limits before a material monetary change. Do not pretend software can prevent all future voluntary forks.

Accept

Publish rationale, impact, adoption path and compatibility limits before a material monetary change. Do not pretend software can prevent all future voluntary forks.

Evidence the case requires

Versioned proposals, reviewer comments, adoption and dissent documentation.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Protocol + governance
Plan pages
TV
VR-07Transparent fee routingPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Every fee, burn, operator payment and optional Labs charge has an explicit source and recipient. No new team tax hidden in a commercial label.

Accept

Every fee, burn, operator payment and optional Labs charge has an explicit source and recipient. No new team tax hidden in a commercial label.

Evidence the case requires

Executable fee tests and reconciliation to invoices/receipts.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Economics + protocol
Plan pages
TV
VR-08Separate value and money flowsPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Distinguish job turnover, fees, operator income, Labs income, token holdings and market value. Do not count the same payment or saving twice.

Accept

Distinguish job turnover, fees, operator income, Labs income, token holdings and market value. Do not count the same payment or saving twice.

Evidence the case requires

Reconciled flow diagram and reproducible metric definitions.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Economics + measurement
Plan pages
TV
VR-09Accessible hardware economicsPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Fix the reference cohort and scenarios in advance. Allow the strongest feasible programmable multi-epoch specialist, including sunk development and alternative memory.

Accept

Fix the reference cohort and scenarios in advance. Allow the strongest feasible programmable multi-epoch specialist, including sunk development and alternative memory.

Evidence the case requires

Approved original GPU/ADV/ROT/ECO profiles and independent review.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
GPU + hardware reviewer
Plan pages
TV
VR-10Mandatory correct proofsPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. All activated proof decisions must bind their actual statement, kind and verifier independent of cache history. Missing trusted infrastructure must not disable enforcement.

Accept

All activated proof decisions must bind their actual statement, kind and verifier independent of cache history. Missing trusted infrastructure must not disable enforcement.

Evidence the case requires

Native warm/cold/order/restart tests and positive/negative proof fixtures.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Protocol + proving
Plan pages
TV
VR-11Literal finalityPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Define fault assumptions, authority continuity and recovery. Never present a weaker recovery certificate as the stronger irreversible guarantee.

Accept

Define fault assumptions, authority continuity and recovery. Never present a weaker recovery certificate as the stronger irreversible guarantee.

Evidence the case requires

Native multi-node boundary tests and consumer label checks.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Consensus + security
Plan pages
TV
VR-12Retained operator authorityPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Pooling variance or buying a service does not silently transfer keys, transaction selection or finality/governance control.

Accept

Pooling variance or buying a service does not silently transfer keys, transaction selection or finality/governance control.

Evidence the case requires

Key/template substitution tests and explicit delegation contracts.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Protocol + pool
Plan pages
TV
VR-13Safe custody and consentPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Private keys, spending limits, signing displays and recovery choices remain under explicit user authority. Defaults must not conceal broad powers.

Accept

Private keys, spending limits, signing displays and recovery choices remain under explicit user authority. Defaults must not conceal broad powers.

Evidence the case requires

Wallet security review and independent user/recovery exercises.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Wallet + security
Plan pages
TV
VR-14Portable verificationPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Balances and receipts authenticate their roots, successful outcome and trust anchors. Necessary reconstruction data has a documented availability path.

Accept

Balances and receipts authenticate their roots, successful outcome and trust anchors. Necessary reconstruction data has a documented availability path.

Evidence the case requires

Independent receipt/client verification with hostile inputs.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Wallet + protocol
Plan pages
TV
VR-15Price real resourcesPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Bound execution, verification and storage costs. Sponsored transactions have limits. No deliberate congestion solely to increase a token metric.

Accept

Bound execution, verification and storage costs. Sponsored transactions have limits. No deliberate congestion solely to increase a token metric.

Evidence the case requires

Minimum-node tests and fee/sponsor-abuse scenarios.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Protocol + economics
Plan pages
TV
VR-16No fragile stable-value promisePriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Any stable-value product has explicit issuer, reserve/redemption rights, permissions and risks. No native-backed peg used merely to manufacture demand.

Accept

Any stable-value product has explicit issuer, reserve/redemption rights, permissions and risks. No native-backed peg used merely to manufacture demand.

Evidence the case requires

Independent diligence, risk limits and legal assessment before release.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Application + counsel
Plan pages
TV
VR-17Optional bounded bridgesPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Bridge exposure is separate from core security. No bridge is mandatory for genesis or allowed to redefine base-chain finality after a loss.

Accept

Bridge exposure is separate from core security. No bridge is mandatory for genesis or allowed to redefine base-chain finality after a loss.

Evidence the case requires

External security review, loss limits and failure/isolation tests.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Application + security
Plan pages
TV
VR-18Open work settlementPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Jobs bind program, inputs, result, verifier, deadline and payment. Gateways are replaceable and Labs approval is not required for ordinary work.

Accept

Jobs bind program, inputs, result, verifier, deadline and payment. Gateways are replaceable and Labs approval is not required for ordinary work.

Evidence the case requires

Independent request-to-paid-result test and state reconciliation.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Protocol + ecosystem
Plan pages
TV
VR-19Obligation-based service bondsPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Deposits secure a specific obligation, not consensus influence. Size and failure conditions must preserve small-operator paths and handle collateral decline.

Accept

Deposits secure a specific obligation, not consensus influence. Size and failure conditions must preserve small-operator paths and handle collateral decline.

Evidence the case requires

Economic and adversarial reservation/default tests.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Economics + application
Plan pages
TV
VR-20Independent developer accessPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Publish complete standards, fixtures and tooling. Grants reward useful maintained deliverables rather than deployments or price effects.

Accept

Publish complete standards, fixtures and tooling. Grants reward useful maintained deliverables rather than deployments or price effects.

Evidence the case requires

Unaffiliated integration and maintenance evidence.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Ecosystem
Plan pages
TV
VR-21Committed maintenancePriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Essential maintenance and audits need a funded runway with stress accounting, distinct from hoped-for appreciation or fundraising.

Accept

Essential maintenance and audits need a funded runway with stress accounting, distinct from hoped-for appreciation or fundraising.

Evidence the case requires

At least approved P13 runway, commitments and role costs.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Maintainers + finance
Plan pages
TV
VR-22Founder independencePriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Routine block, job, payment and recovery paths must not require a founder credential or undocumented manual action.

Accept

Routine block, job, payment and recovery paths must not require a founder credential or undocumented manual action.

Evidence the case requires

Real founder-absence exercises and intervention ledger.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Operations + independent reviewer
Plan pages
TV
VR-23Measure effective controlPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Report operator, pool, hosting, service and client dependencies with attribution limits. Keys and addresses are not people.

Accept

Report operator, pool, hosting, service and client dependencies with attribution limits. Keys and addresses are not people.

Evidence the case requires

Dependency/control map with uncertainty and removal experiments.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Measurement + operations
Plan pages
TV
VR-24Reproducible secure releasePriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Pin source, binaries, rules, guests/keys and activation. Provenance is necessary but not sufficient for correctness.

Accept

Pin source, binaries, rules, guests/keys and activation. Provenance is necessary but not sufficient for correctness.

Evidence the case requires

Independent builds, artifact verification and scoped review.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Release + security
Plan pages
TV
VR-25Consent-preserving incident responsePriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Separate public/developer authority. Urgency must not silently override installation or grant arbitrary execution. Disclose material incidents and retest.

Accept

Separate public/developer authority. Urgency must not silently override installation or grant arbitrary execution. Disclose material incidents and retest.

Evidence the case requires

Compromised-key, unsafe-update and recovery drills.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Release + operations
Plan pages
TV
VR-26Honest access and liquidityPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Use functional deposits/withdrawals and executable depth, not ticker count or fabricated volume. Never restrict exit to simulate value.

Accept

Use functional deposits/withdrawals and executable depth, not ticker count or fabricated volume. Never restrict exit to simulate value.

Evidence the case requires

Independent access-route and two-sided liquidity observations.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Ecosystem + measurement
Plan pages
TV
VR-27Transparent treasury relationshipsPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Disclose material grants, insider holdings, inventory and market-making mandates. No wash trades or hidden price-support promises.

Accept

Disclose material grants, insider holdings, inventory and market-making mandates. No wash trades or hidden price-support promises.

Evidence the case requires

Mandate register, reconciled accounts and conflict policy.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Treasury + counsel
Plan pages
TV
VR-28Auditable metricsPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Publish definitions, raw/adjusted views, sampling, attribution uncertainty and missing data. No subsidy-hidden demand or censored failed jobs.

Accept

Publish definitions, raw/adjusted views, sampling, attribution uncertainty and missing data. No subsidy-hidden demand or censored failed jobs.

Evidence the case requires

Data lineage, conservation checks and independent replay.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Measurement
Plan pages
TV
VR-29Fair comparison universePriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Define eligible peers and exclusions before observing rankings. Include qualifying new entrants and preserve unknown values.

Accept

Define eligible peers and exclusions before observing rankings. Include qualifying new entrants and preserve unknown values.

Evidence the case requires

Independent peer census and versioned comparison protocol.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Measurement + external panel
Plan pages
TV
VR-30Scoped claims onlyPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Every leadership claim names its metric, universe, period and limits. A measured price rank does not certify overall safety or future leadership.

Accept

Every leadership claim names its metric, universe, period and limits. A measured price rank does not certify overall safety or future leadership.

Evidence the case requires

Claim register with evidence, expiry and legal signoff.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Governance + counsel
Plan pages
TV
VR-31Evidence before passPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Pre-register thresholds; missing inputs block gates; corrections preserve failed results. No aggregate score can waive core safety or economic failure.

Accept

Pre-register thresholds; missing inputs block gates; corrections preserve failed results. No aggregate score can waive core safety or economic failure.

Evidence the case requires

Frozen test charter and versioned evidence packets.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Independent acceptance panel
Plan pages
TV
VR-32Real adoptionPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Measure unaffiliated retained users and useful repeat activity with incentives identified. Do not require buying IGN to participate in a study.

Accept

Measure unaffiliated retained users and useful repeat activity with incentives identified. Do not require buying IGN to participate in a study.

Evidence the case requires

Cohort definitions, attrition, usage and subsidy audit.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Product + ecosystem
Plan pages
TV
VR-33AI earns admissionPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. AI is an optional workload category, not a guaranteed-margin network identity. Price full costs and adverse demand before expansion.

Accept

AI is an optional workload category, not a guaranteed-margin network identity. Price full costs and adverse demand before expansion.

Evidence the case requires

Workload-specific benchmark, repeat demand and verification policy.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Compute + economics
Plan pages
TV
VR-34Bound agent spendingPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Automated buyers have scoped budgets, permissions, expiry, revocation and logs. Untrusted prompts never alter base permissions.

Accept

Automated buyers have scoped budgets, permissions, expiry, revocation and logs. Untrusted prompts never alter base permissions.

Evidence the case requires

Prompt/input adversarial tests and payment-loss caps.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Application + security
Plan pages
TV
VR-35Cryptographic migration readinessPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Maintain a full algorithm inventory and reviewed transition plan. No quantum-proof claim from one component or speculative attack date.

Accept

Maintain a full algorithm inventory and reviewed transition plan. No quantum-proof claim from one component or speculative attack date.

Evidence the case requires

Expert review, downgrade/migration tests and annual refresh.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Cryptography + protocol
Plan pages
TV
VR-36Separate proof, truth and privacyPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Execution validity does not establish real-world input truth, AI answer quality or confidentiality. State trust and data exposure for each service.

Accept

Execution validity does not establish real-world input truth, AI answer quality or confidentiality. State trust and data exposure for each service.

Evidence the case requires

Threat model and user-facing guarantee audit.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Security + product
Plan pages
TV
VR-37Scale within verification budgetsPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Throughput, data and state growth must preserve the declared minimum-node and reconstruction capabilities. Reprice security after fee compression.

Accept

Throughput, data and state growth must preserve the declared minimum-node and reconstruction capabilities. Reprice security after fee compression.

Evidence the case requires

Cold-path capacity, bootstrap, pruning and provider-removal tests.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Protocol + operations
Plan pages
TV
VR-38Honest energy accountingPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Report complete-system energy and role allocation. Avoid double-counting joint work or making unsupported carbon/marginal-transaction claims.

Accept

Report complete-system energy and role allocation. Avoid double-counting joint work or making unsupported carbon/marginal-transaction claims.

Evidence the case requires

Calibrated wall tests and documented environmental methodology.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
GPU + measurement
Plan pages
TV
VR-39Activity-specific legal approvalPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Obtain counsel review for actual audiences and activities. No-presale, fair-launch or decentralised labels are not blanket legal exemptions.

Accept

Obtain counsel review for actual audiences and activities. No-presale, fair-launch or decentralised labels are not blanket legal exemptions.

Evidence the case requires

Jurisdiction/activity matrix and approved external communications.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Counsel
Plan pages
TV
VR-40No indispensable administratorPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. A useful company, token holder, pool, AI agent or funding body receives no hidden power over balances, issuance or canonical history.

Accept

A useful company, token holder, pool, AI agent or funding body receives no hidden power over balances, issuance or canonical history.

Evidence the case requires

Authority inventory, isolation tests and independent operation.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Protocol + governance
Plan pages
TV
20TV

TV: the token value and network leadership gates (proposed; no gate executed)

32 gates from Igneum 2.0, Token Value & Network Leadership 1.0-proposed (snapshot 2026-10-08); scope CORE, CAPABILITY IF ENABLED or LEADERSHIP CLAIM as the file gives it; Supplement to original master and 128-case test standard; not a price/rank guarantee

NOT RUN
Owner
the owner role per gate
Gate
Token value gates closed
Fixtures
F0
Plan pages
docs/plans/igneum-2.0-master/token-value/rules-and-gates.json gates
32 cases: 0 passed under the standard, 0 running with team evidence, 32 not run, 0 deferred
TV-01Resolve and freeze the monetary contractPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Supply, tail, fee and recovery documents plus exact proposed release.

Steps

  1. Reconcile D01-D06 with protocol/economic/counsel review. Freeze thresholds and all interfaces before confirmatory tests.

Accept

No conflicting normative policy; every material choice has a signed rationale, version, adoption path and tests. Unresolved core choice is BLOCKED.

Evidence the case requires

Decision log, signed specification, release manifest, test charter.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Protocol + independent panel
Plan pages
TV
TV-02Reproduce complete supply accountingPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Two independent implementations; genesis and representative boundary/reorg fixtures.

Steps

  1. Recompute issued, paid, burned, locked and outstanding amounts through subsidy transitions, rollback/replay and duplicate records.

Accept

Exact integer agreement; no unaccounted creation, duplicate supply or cap breach under the ratified policy. Restricted wrappers are not extra native supply.

Evidence the case requires

Machine-readable ledgers, vectors, independent signoff.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Protocol + measurement
Plan pages
TV
TV-03Fair launch and early distributionPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Public binaries, source, mining modes, launch notice and insider inventory.

Steps

  1. Rehearse from clean outsider machines; audit genesis allocations and devnet balances; simulate arrival times under alternative emission schedules.

Accept

Zero undisclosed allocation or privileged conversion; approved notice/support window and cohort pass; distribution analysis includes delayed entrants without guaranteeing equal ownership.

Evidence the case requires

Genesis report, dated releases, disclosure register, simulation inputs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Release + ecosystem
Plan pages
TV
TV-04Security budget without price rescuePriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Ratified reward/fee rules; role costs; horizons 1, 5, 10 and 20 years.

Steps

  1. Model falling issuance, fee volatility and .25x/1x/4x/10x revenue, zero external jobs and -90% price. Separate role receipts and funding.

Accept

Approved viable scenarios fund minimum required roles without hidden issuance or assumed appreciation; failure regions stated. Collapse scenarios need safe behaviour, not universal profit.

Evidence the case requires

Reproducible cash-flow model, assumptions, independent review.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Economics + protocol
Plan pages
TV
TV-05Strongest surviving specialistPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Pinned candidate/cohort; cheapest supported physical designs including SRAM/hybrid.

Steps

  1. Apply original ADV/GPU/ECO profiles with multi-epoch survival and development sunk. Reprice alternative state and memory implementations.

Accept

All approved core energy and total-cost bounds pass with uncertainty; no unresolved feasible dominating design. Unknown feasibility blocks the broad claim.

Evidence the case requires

Design files, wall results, sensitivity model, two independent hardware opinions.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Hardware reviewer + economics
Plan pages
TV
TV-06Every fee and payment reconcilesPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Native rules, payer contract and optional Labs/service invoices.

Steps

  1. Execute gas, proof, developer, pool, burn, sponsor and refund paths, including rounding, abort, retry and zero-demand cases.

Accept

No unexplained recipient or double count; statements/invoices match exact contract outcomes. Network turnover never labelled Labs revenue or permanent holding demand.

Evidence the case requires

Flow ledger, fixtures, invoice examples, reviewed public fee table.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Economics + application
Plan pages
TV
TV-07Ownership-critical engineering closurePriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Original master findings mapped to current release with genuine proof fixtures.

Steps

  1. Run native cache-order, fail-closed activation, payout crash and finality tests; reproduce fixed cases in independent environments.

Accept

No unresolved critical/high finding or counterexample within the approved guarantee; all applicable original safety gates pass. Reproducing a defect is not closure.

Evidence the case requires

Native outputs, manifests, scoped audit, issue-by-issue closure.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Protocol + independent security
Plan pages
TV
TV-08Custody and recovery usabilityPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Declared wallet/hardware combinations; 30 new participants, at least 15 non-miners.

Steps

  1. Perform receive, preview/sign, limit, recovery and revocation tasks with valueless funds; inject wrong network/address and malicious prompts.

Accept

Zero unauthorised transfer or secret disclosure; at least 90% complete the approved safe task without private help. Report confidence limitations and all failures.

Evidence the case requires

Task protocol, anonymised results, security review, recovery vectors.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Wallet + independent users
Plan pages
TV
TV-09Independently verifiable settlementPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Proof/receipt client without Labs RPC; normal and recovery certificates.

Steps

  1. Verify successful/failed transfers, wrong asset/amount, stale roots, fake voter lists, invalid proofs and withheld data.

Accept

All invalid claims refused; valid ordinary transfers verify within approved resource limits; weaker recovery and unavailable data never shown as stronger finality.

Evidence the case requires

Offline fixtures, consumer traces and independent implementation.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Wallet + consensus
Plan pages
TV
TV-10Minimum-node and sponsored-use limitsPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Approved minimum validator and sponsor budgets under final workload.

Steps

  1. Run cold proof verification, expensive invalid inputs, state growth, paymaster drain attempts and overloaded bursts.

Accept

Original capacity/security profiles pass; budgets remain bounded; no proof skipped to catch up and no sponsor can spend outside authorised scope.

Evidence the case requires

Cold-path profiles, stress traces, sponsor negative tests.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Protocol + application
Plan pages
TV
TV-11Pooled payments without authority lossPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Independent pool/member clients and durable payment state.

Steps

  1. Inject key/template substitution, reauthorisation, crash/RPC ambiguity, receipt reorg and hostile bounded inputs.

Accept

No duplicate/lost liability or unauthorised authority change; member can verify delegated powers and change pools. Session resource limits hold.

Evidence the case requires

Ledger replay, signed work fixtures and pool removal test.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Pool + independent operators
Plan pages
TV
TV-12Reproducible and consented softwarePriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Release manifest, build dependencies, update keys and public installer.

Steps

  1. Two independent parties build/verify; simulate compromised key, stale package, rollback, urgency and missing fixtures.

Accept

No hidden consensus variation or arbitrary default remote control; update-off remains respected; mandatory unavailable fixtures block acceptance.

Evidence the case requires

Attestations, independent hashes, key drill, installer/ACL review.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Release + independent security
Plan pages
TV
TV-13Committed maintenance coveragePriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Costed roles, commitments and monthly cash dates.

Steps

  1. Audit at least 12 months of approved maintenance coverage; stress IGN-denominated resources and provider withdrawal.

Accept

Original P13 satisfied without counting future appreciation or unsigned pledges; essential functions have funded substitutes and explicit shortfall response.

Evidence the case requires

Contracts/grants or funding proof, stress cash flow, responsibility register.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Maintainers + independent finance
Plan pages
TV
TV-14Founder-absent operating exercisePriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Independent builds/operators; founder services, keys and manual help removed.

Steps

  1. Run 30 real days, then satisfy the original 90-day observation programme; cross boundaries, remove major providers and record all interventions.

Accept

Approved original independence/reliability gates pass; no unpublished founder action or privileged override. Simulated long partitions are labelled separately.

Evidence the case requires

Dependency map, availability logs, intervention and payer ledger.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Independent operations panel
Plan pages
TV
TV-15Governance and authority boundariesPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Every control/activation threshold, treasury power and application admin interface.

Steps

  1. Exercise hostile coalitions, absent voters, old clients and compromised non-consensus keys; test refusal and recovery.

Accept

No actor gains undeclared issuance/balance/history authority. Every activation follows the ratified safe procedure; ambiguous threshold or recovery remains BLOCKED.

Evidence the case requires

Authority model, scenarios, native outcomes and independent review.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Protocol + governance
Plan pages
TV
TV-16Two functional independent access routesPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

At least two unaffiliated custody/exchange/payment routes with disclosed shared infrastructure.

Steps

  1. Complete small controlled deposits, withdrawals, outage and reconciliation tests; identify actual custody and settlement dependencies.

Accept

Both settle correctly; neither is merely a front end to the same indispensable provider. Gaps and jurisdiction limits visible; no listing assumed from a logo.

Evidence the case requires

Settlement records, dependency map and third-party confirmation.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ecosystem + independent reviewer
Plan pages
TV
TV-17Supply-price-liquidity measurementPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Frozen sources, price filters, circulating/free-float definitions and order-size bands.

Steps

  1. Collect 90 real days; independently replay supply and prices; measure both buy/sell execution costs and withdrawal availability.

Accept

At least 95% daily coverage; exact supply reconciliation; no fabricated missing data. Sparse liquidity invalidates broad liquidity claims, not automatically the arithmetic cap.

Evidence the case requires

Raw snapshots, methodology/code, gap ledger, audit.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Measurement steward
Plan pages
TV
TV-18Real versus incentivised demandPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Customer/job/transaction definitions with privacy-respecting attribution and subsidy data.

Steps

  1. Reconcile raw/adjusted activity, self-dealing controls and incentives; test whether circular activity earns more than its irrecoverable cost.

Accept

All subsidies and known related activity separated; useful demand not inferred from gross volume alone; abusive incentive loop closed before scaling rewards.

Evidence the case requires

Accounting model, filter logic, sensitivity and independent replay.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Economics + measurement
Plan pages
TV
TV-19Independent developer adoptionPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Public kit and at least five unaffiliated developers with declared tasks.

Steps

  1. Build useful integrations without private dependencies; have two independent maintainers update the kit; record obstacles and adoption reason.

Accept

All declared core integration paths work; at least five usable integrations and two maintainer reproductions. Empty subsidised deployments do not qualify.

Evidence the case requires

Repos, task traces, user evidence and maintenance records.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ecosystem + external developers
Plan pages
TV
TV-20Programmable payment acceptancePriority P1Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Versioned library, independent application, user/sponsor limits and receipt path.

Steps

  1. Execute simple/conditional/recurring payments, revocations, expiry, failed outcome and duplicate invoice cases.

Accept

No unauthorised spend or double settlement; successful transfer independently evidenced; subjective conditions disclose adjudicator/trust.

Evidence the case requires

Contracts, negative vectors, user task record, security review.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Application + wallet
Plan pages
TV
TV-21Useful paid proof demandPriority P1Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Exact workload and final hardware path; three unrelated buyers and approved COM profile.

Steps

  1. Observe repeat purchases under original P14/P16 conditions, full job outcomes and operator/service costs.

Accept

All applicable COM targets met without hidden reimbursement. Queue expiry not counted as success. A monetary-only scope cannot claim this gate passed by exclusion.

Evidence the case requires

Buyer evidence, cost ledger, all-job traces and independent review.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Proving + independent customers
Plan pages
TV
TV-22Replaceable work-market gatewayPriority P1Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Two independent gateway implementations and job/settlement specification.

Steps

  1. Create jobs, switch providers/gateways, fail one service and deliver the same objective result using public inputs.

Accept

Correct payment/result without Labs approval; no concealed central dispatcher or irreversible dependency. External-chain receipts labelled separately.

Evidence the case requires

Gateway traces, escrow reconciliation, dependency-removal run.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Application + independent operators
Plan pages
TV
TV-23Obligation-based depositsPriority P1Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Proposed bond/default contract and volatile-collateral scenarios.

Steps

  1. Test reservation abandonment, invalid inputs, network pause, -90% collateral value and malicious claims.

Accept

No consensus influence bought; default reason objective; compensation limits explicit; viable small-operator participation and approved risk bounds.

Evidence the case requires

Adversarial model, state tests, risk/legal review.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Economics + security
Plan pages
TV
TV-24AI earns a separate commercial casePriority P1Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

One bounded model/job, provider hardware, verification tier and licences.

Steps

  1. Benchmark full delivery vs actual alternatives; test 90% lower unit prices, demand collapse, private-data exposure and substituted models.

Accept

Approved service economics and buyer gates pass; correctness/truth/privacy distinguished. No native price or perpetual yield assumption.

Evidence the case requires

End-to-end costs, repeat demand, licence/threat review.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Compute + independent reviewer
Plan pages
TV
TV-25Bounded machine purchasingPriority P1Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Approved account/paymaster permissions and chosen x402/agent interfaces.

Steps

  1. Inject hostile outputs/prompts, replayed requests, recursive spending, revoked permissions and gateway failure.

Accept

Spend never exceeds authorised destination/time/amount scope; no instruction changes authority. Draft standard support is described accurately.

Evidence the case requires

Property tests, loss-cap proof, revocation/audit logs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Application + security
Plan pages
TV
TV-26Cryptographic migration readinessPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Complete key/proof/transport/update inventory and external cryptographic review.

Steps

  1. Rehearse versioned signature/proof migration, downgrade/replay, mixed clients, inactive owners and minimum-node overhead.

Accept

No unreviewed assumption or automatic confiscation; migration can be explained and tested. No absolute quantum-proof claim or attack date inferred.

Evidence the case requires

Inventory, expert report, migration vectors, annual schedule.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Cryptography + protocol
Plan pages
TV
TV-27Private data and oracle assurancePriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Per-product claims, input trust sources, data-retention and execution model.

Steps

  1. Use forged data, hostile providers, telemetry leakage, unsupported attestation and false-but-correctly-executed AI outputs.

Accept

No claim exceeds tested guarantee; secrets/data protected to stated model; unauthenticated inputs not represented as objective truth.

Evidence the case requires

Threat model, exposure tests, labelled user flows.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Security + product
Plan pages
TV
TV-28Stable assets and bridge isolationPriority P1Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Only if enabled: issuer/bridge design, redemption rights, trust anchors and approved value caps.

Steps

  1. Test reserve/redemption failure, stale oracle, invalid/recovery certificates, contract compromise and emergency shutdown.

Accept

No hidden base-chain guarantee or forced reversal of final history; independent audit, conservative exposure and counsel approval.

Evidence the case requires

Risk dossier, scenarios, disclosure, independent tests.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Application + security + counsel
Plan pages
TV
TV-29Growth without inaccessible verificationPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Declared minimum node, projected data growth and alternative scaling design.

Steps

  1. Run cold/worst-case validation, state/pruning/bootstrap, censorship and aggregation withdrawal; model 10x/100x growth and fee compression.

Accept

Original minimum-node/security bounds hold; required data remains obtainable; security funding restated for changed fee routes.

Evidence the case requires

Capacity/availability results and revised economics.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Protocol + operations
Plan pages
TV
TV-30Energy and claims disciplinePriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Calibrated whole-system metering and workload allocation protocol.

Steps

  1. Measure mining, proving, mixed/time-shared operation, setup/recovery and unsuccessful work; review environmental text.

Accept

No double-counted savings; original meter tolerances satisfied; no marginal-energy/carbon claim beyond method.

Evidence the case requires

Raw meter traces, job ledger, method and external review.

Method
Automated + independent review
Cadence
Every release candidate
Owner
GPU + measurement
Plan pages
TV
TV-31Public-claim and activity reviewPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Actual jurisdiction, audience, service, token-distribution and promotion plans.

Steps

  1. Counsel assesses applicable routes and reviews each value/rank/return/security assertion against evidence.

Accept

Written activity-specific clearance and approved wording; no future-value assertion in a covered MiCA white paper; no blanket exemption inferred from mining.

Evidence the case requires

Legal decision matrix, claim register, review dates.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Qualified counsel
Plan pages
TV
TV-32Observed leadership, not a roadmap certificatePriority P1Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:39 UK

Setup

Approved peer universe; all applicable mandatory gates; stable release and 90-day observation.

Steps

  1. Run original P15/P16 comparisons and independently replay scoped rank data. Test changing peer/exclusion assumptions and missing data.

Accept

Contender requires original criteria; market-cap first requires highest 90-day median, 95% coverage; sustained daily-first convention also needs 80% of covered days. Never certify overall best from price alone.

Evidence the case requires

Independent panel report, full methods/data, scope and expiry of claim.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Independent acceptance panel
Plan pages
TV
Profiles

The numbers each case is held to.

17 profiles, P00 to P16. A profile is frozen before the confirmatory run; weakening a target after a failure creates a different claim.

P00Approved as proposed

Frozen scope and approval

  1. Approve the release manifest, supported roles, numerical profiles, mandatory scenarios, trust/fault model, workload W, adapters and claims before confirmatory tests. Unknown values are BLOCKED, not defaults.
  2. Core safety and authentication invariants admit no waiver. Proposed performance or commercial targets may be replaced only before the confirmatory run, with an independent rationale and a versioned public scope.
  3. After a failure, weakening a target creates a different claim and requires a new assessment. Preserve all failed runs; do not average a blocker away.

Cited by 148 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P01Approved as proposed

Correctness and negative-test depth

  1. Zero observed invalid acceptance, unauthorised signature, conflicting finality within assumptions, duplicated reward or unexplained cross-backend state/hash disagreement.
  2. Minimum proposed campaign: 1,000,000 full-hash vectors per supported backend across all families, plus at least 10,000 malformed/boundary cases per relevant parser or binding class. Include exhaustive small-domain cases and historical regressions.
  3. All prescribed critical mutants must be detected. This sampling target is not a bound on cryptographic failure probability and does not replace independent reasoning about soundness or safety.

Cited by 69 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P02Approved as proposed

Hardware coverage and reproducibility

  1. At least 12 physical retail configurations: at least 3 NVIDIA, 3 AMD and 2 Apple configurations, at least two discrete-GPU generations, an advertised 8 GB mining tier and 12 GB proving tiers where claimed. Record usable, not nominal, memory.
  2. Declare a competitive core of at least 6 configurations spanning every advertised vendor and at least two discrete generations before optimisation. The wider cohort remains mandatory for access and economic tests; it cannot be silently dropped.
  3. Use 5 paired 30-minute steady-state runs per primary cell after at least 15 minutes of warm-up and a stable temperature trend. Calibrated wall meter uncertainty must be at most 2%. Run a 7-day soak on representative low/mid/high tiers.
  4. Three unaffiliated operators participate; every competitive-core cell is reproduced by at least two. Identical-SKU energy/accepted-work results must agree within 5% after declared environment corrections; unexplained variance blocks the headline.

Cited by 12 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P03Approved as proposed

Candidate improvement and honest-card budget

  1. For production candidate changes, per mandatory GPU cell: no more than 5% increase in joules per accepted work and no more than 2% decrease in accepted throughput versus the paired tuned baseline. Absolute safety limits always apply.
  2. G2 requires at least a 10% reduction in the strongest evaluated specialist advantage after redesign, outside the declared measurement/model uncertainty, while meeting those budgets. A failed experiment is not a successful upgrade.
  3. Existing clock-lock savings belong in the baseline. Long programs cannot pass by adding enough equally costly work to both devices to improve a ratio while materially worsening honest operation.

Cited by 8 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P04Approved as proposed

Scoped specialist-competition target

  1. Define R_E as GPU wall joules per accepted work divided by the lowest credible complete-system specialist joules for that same work. The proposed target is R_E at most 1.5 for every competitive-core cell at the same node and one node ahead.
  2. Evaluate at least three materially distinct specialist architectures, with one programmable multi-family design, and a second independent reviewer. Include shared/reduced memory, hybrid execution, selective participation and realistic power/host costs.
  3. Publish two-node-ahead and modular/reused-IP stress cases; they must satisfy the predeclared P12 economic envelope. No universal ceiling for unknown future hardware is claimed. Report model bounds separately from statistical confidence.
  4. A lower-bound specialist estimate, not a convenient average or a deliberately constrained reference architecture, drives the conservative comparison. Undefined or unbounded decision-critical assumptions make the result BLOCKED.

FAIL R_E target at most 1.5 at the same node and one node ahead; today's placed bracket 1.5x to 2.1x: FAIL

Cited by 14 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P05Approved as proposed

Measurement and inference protocol

  1. Pre-register primary metrics, cohorts, holdout seeds, run order, exclusions and analysis before confirmation. Keep tuning/training runs separate from holdout runs.
  2. Use independent runs/operators as measurement units. Report point estimates, two-sided 95% measurement intervals and absolute sample counts; handle time-series dependence with a declared block or run-level method.
  3. Apply conservative uncertainty to pass decisions. A confidence interval around measured GPU energy does not capture unknown ASIC architectures; model parameter ranges and expert judgement must be reported as such.
  4. Never compare raw hashes per second across different algorithms. Do not transform a five-year scenario sweep into a probability of chip arrival or a guarantee of future profitability.

Cited by 0 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P06Approved as proposed

Memory and support policy

  1. All advertised role/configuration combinations must finish without OOM, corruption or unsafe fallback. Publish a component memory budget, including display/OS, driver, miner, prover, aggregation and epoch construction.
  2. Proposed support horizon: at least 24 months of known schedule compatibility for the advertised entry tier, unless a narrower horizon is prominently approved before sale or launch. Removal changes the claim and must pass ECO-07.
  3. Treat 5.5 / 8.5 / 11.5 GiB as source candidates, not imposed final rules. Simultaneous operation, eviction and time-sharing are distinct advertised modes with separately measured cost.

Cited by 4 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P07Approved as proposed

Proof service capacity and fairness

  1. Freeze W as a meaningful workload mix, input sizes, proof format, fleet and requests/hour. Primary proposed target: 72 hours at W, plus 24 hours at 1.2W; at least 99.5% accepted jobs delivered valid within the contracted deadline.
  2. Default delivery targets for the declared internal reference workload: p95 at most 60 seconds and p99 at most 120 seconds from input-ready assignment through verified delivery. Also publish request-to-delivery including input wait; no claim may omit that delay.
  3. Request-to-delivery p99 must meet the separately approved customer deadline. Payment p99 must be at most 10 minutes after verified payable eligibility, with chain finality time reported separately. These defaults do not override a stricter contract.
  4. No statistically supported positive backlog drift at steady load, no silent drops; after 2W for 15 minutes, drain excess backlog within 30 minutes of return to W. Report rejected demand and accepted-job success separately.
  5. Proposed advertised-tier fairness: at least 90% timely valid assigned completions are paid under the approved rules; avoidable duplicate/retry work is at most 10% of total work. Reassignment policy must bound abandonment without promising every assignment a reward.

Cited by 15 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P08Approved as proposed

Fault assumptions and recovery

  1. F0 must state the exact safety threshold, quorum and authority-transition rule; the synchrony/participation assumptions for liveness; trusted inputs; and clock/expiry semantics. This manual supplies no substitute consensus rule.
  2. Exercise threshold-minus/at/plus cases, the 40/40/20 partition fixture, signing outages and 31/35/60/90 logical-day expiry cases. Preserve safety when liveness assumptions fail; do not demand finality from an unavailable quorum.
  3. After assumptions and input availability are restored: service replacement within 10 minutes and deterministic network convergence within 30 minutes on the reference topology. Different certified bounds must be approved beforehand.
  4. Accelerated-time simulation and real elapsed operation are separate evidence classes. Recovery may not reverse a guarantee previously represented as final.

Cited by 25 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P09Approved as proposed

Security and bounded resource requirements

  1. Zero unresolved critical or high-severity security findings on the claimed release. Independent scopes must cover consensus, proof soundness/parameters, implementation bypasses, wallet/isolation and relevant operational controls.
  2. Review the intended proof-system security level and assumptions explicitly; do not infer a security-bit claim from random rejection tests. Version every verifier, program and parameter set.
  3. Freeze maximum valid/invalid verification time, memory, disk and admission rates for ordinary validator hardware. At rated valid load plus the approved hostile load, no unbounded growth, invalid acceptance or unrecoverable process failure.
  4. For supported wallet fee-estimation cases, proposed absolute error at most 5% versus the specified charge when inputs are unchanged; deterministic fee-cap handling and explicit uncertainty otherwise. Customer contracts remain separately binding.

Cited by 30 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P10Approved as proposed

Ordinary-operator product targets

  1. At least 30 unaffiliated first-time study participants across supported Windows/macOS combinations. At least 90% install, configure safely and submit accepted work without staff help; p90 active setup at most 15 minutes. Publish complete download/dataset time separately.
  2. Pause/stop acknowledgement within 2 seconds, safe worker stop within 5 seconds where no documented atomic operation prevents it, and reliable restoration of original tuning settings. No hidden custody or silent update.
  3. Net-energy/fee displays reconcile within 5% under the declared measurement boundary. Incremental rejected-work loss on the normal home-link profile is at most 2 percentage points over the matched datacentre profile.
  4. Open miner efficiency is within 5% of the best independently tuned permitted implementation on identical work. For the declared single-card payout case, p95 payable-to-payment at most 24 hours and total payout friction at most 2% of earned value.
  5. Critical alerts are emitted within 60 seconds of detectable evidence. At least 90% of study users can identify the injected failure and follow the published safe action. No control target excuses a security failure.

Cited by 11 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P11Approved as proposed

No-founder exercise and independence

  1. At least 10 verified unaffiliated operators, three independently administered network/hosting domains and sufficient honest weight/capacity to satisfy F0 and W after founders are removed.
  2. Run at least 30 real elapsed days without founder mining, proving, aggregation, bootstrap, required RPC, private files or privileged interventions. Cross all known logical transitions separately without calling accelerated time real history.
  3. Document control by role and common dependencies; uncertain identities are not counted as independent. Within-assumption withdrawals must satisfy P08; losing more than the assumed quorum may cause a visible safe pause.

Cited by 4 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P12Approved as proposed

Five-year coexistence envelope

  1. Freeze a sourced revenue reference R and mandatory worlds before results. Sweep 0.25R, R, 4R and 10R; electricity at $0.03/$0.10/$0.25/$0.40 per kWh; 1/3/5-year productive life; zero/$20M/$75M development; private mining and hardware sales; no/normal/spiking external demand.
  2. Those values are proposed stress inputs, not current prices or forecasts. Declare which worlds have enough funded demand for rational ongoing service before running; retain collapse worlds as explicit safety/exit tests, not profitable successes.
  3. Proposed matched-tariff new-entry target in every mandatory sustainable world: median GPU/specialist total cost per accepted work at most 1.5, 90th percentile at most 1.75, and no advertised competitive-core cell above 2.0. Publish every cell, including heterogeneous tariffs.
  4. At least three purchasable GPU configurations across at least two advertised vendors must have positive modelled new-entry economics; at least 75% of the entry cohort must have positive marginal operating economics in those worlds. Report model uncertainty and failure regions.
  5. Do not impose GPU market share, specialist production limits, token appreciation, full research-cost recovery or automatic chip death to force the result. Any such condition must become an explicit limitation rather than a hidden assumption.

Cited by 24 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P13Deferred by the founder

Maintenance continuity

  1. Before a readiness claim, document at least 12 months of committed maintenance resources at the approved operating scope. Include engineering, security review, infrastructure, support and incident response.
  2. Use independently reviewable commitments and downside budgets. Uncommitted future sales, rising token prices, burned fees or assumed fundraising are not available resources.
  3. This is a proposed governance test, not a directive to change the supply cap, issuance allocation or fair-launch design.

Cited by 1 case. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P14Approved as proposed

Genuine commercial and developer proof

  1. At least three unrelated paying buyer organisations, each making at least three separate purchase decisions across at least 30 days; at least 1,000 meaningful verified external jobs in aggregate. Split invoices do not create independent demand.
  2. No project reimbursement, circular funding or undisclosed related party counts. Report customer concentration and churn; proposed maximum largest-buyer share is 70% of qualifying revenue.
  3. At least 20% aggregate contribution margin after directly attributable delivery costs, retries, refunds and support; publish fully loaded economics separately. At least 75% of sampled eligible operators have positive realised contribution on the declared workload.
  4. At least five unaffiliated developers complete a useful supported application or proof-service integration using public documentation. Customer confirmation and raw commercial evidence may remain confidential to the reviewer.

Cited by 10 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P15Approved as proposed

Comparative contention threshold

  1. Pre-register at least three relevant operating GPU-first peers, plus a real proving alternative for customer comparisons. Verify current versions at execution time. The source reference set is a starting point, not a claim about current rankings.
  2. Require at least three meaningful comparable dimensions with no material inferiority beyond a pre-agreed 10% margin against the best valid comparator, and at least two independently evidenced advantages against at least two peers.
  3. Advantages must be either a greater-than-10% measured improvement outside uncertainty or a directly tested control/capability difference with demonstrated user value. Non-comparable or missing data is not a win.
  4. A panel with hardware/economics, security/operations and customer/operator expertise must support the scoped contender conclusion. Passing these judgement-based thresholds does not certify a universal number-one ranking.

Cited by 5 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P16Approved as proposed

Observed durability and claim freshness

  1. At least 90 real elapsed days on the final compatible release family, at least 30 independently verified operators, and transparent eligibility/churn denominators. Material uncomparable changes reset affected observations.
  2. Proposed outcomes: at least 60% day-90 operator retention and at least 75% of eligible observed operators with positive measured marginal operation over the period. Report incentives and electricity assumptions; do not claim a downturn was observed if it was not.
  3. At least 99.9% availability for the declared customer service during eligible operating conditions, with all-in availability also reported; zero accepted invalid proofs or conflicting finality within F0 assumptions. Do not remove real incidents as maintenance to force a pass.
  4. Run fault injection on isolated infrastructure, not unsuspecting customers. Publish planned test windows separately. Reassess claims at least quarterly and immediately after material hardware, protocol, economics or security changes.

Cited by 5 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

Fixtures

What every run is built on.

F0

Release and assurance manifest

Exact commits, binaries, genesis/network ID, mining class, dataset schedule, EVM fork/deviations, program/verifier IDs, fees, supply, quorum/fault rules, trust anchors, activation and supported roles.

F1

Clean build environments

Pinned toolchains, dependency locks, clean OS images and documented signing/notarisation boundaries. No production secrets or private founder files.

F2

Hardware and measurement lab

Approved physical GPU cohort, calibrated wall meters, stable thermal conditions, driver/OS images and realistic home/datacentre link conditions.

F3

Workload and oracle catalogue

Fixed full-hash and EVM/proving jobs, independent reference implementations, real customer-sized payloads, held-out seeds and complete expected results.

F4

Authorised fault network

Independent nodes/operators; controllable latency, loss, clocks, partitions, storage faults and role withdrawals. Actual consensus paths plus separately labelled simulators.

F5

Negative and regression corpus

Malformed transactions/proofs, wrong roots/IDs, duplicate payments, bad authority tables, historical failures and deliberately faulty code mutants.

F6

Specialist implementation pack

Functionally checked architectures, RTL/physical estimates where feasible, memory and board assumptions, cost inputs, adaptation paths and uncertainty ranges.

F7

Economic and incentive models

Independently reproducible costs, entry/exit/difficulty policies, scenario grid, operator opportunity costs and money-flow conservation fixtures.

F8

User/customer/peer studies

Consenting unaffiliated users, contracted meaningful workloads, private ownership checks, dated competitor methods and independent analysis.

F9

Evidence and status vault

Immutable run IDs, raw logs, hashes, analysis code, exclusions, defects, reviewers, signatures, privacy controls and public redacted summaries.

What a full pass means

Independent passage of all mandatory and claimed-option gates, including commercial and comparative observation, can support a scoped leadership-contender assessment. It does not prove a universal rank or eliminate unknown future hardware risks.

Test design, not executed evidence. All numeric additions are proposed, not source-approved protocol rules. Optional claimed features require their tests; excluded features earn no pass credit.

Rules in force

  • P03: a candidate change pays at most 5 percent of joules per accepted work and loses at most 2 percent of accepted throughput against the paired tuned baseline (replaces the 10 percent budget from 18:2x UK)
  • P04: R_E at most 1.5 for every competitive-core cell at the same node and one node ahead against the lowest credible complete-system specialist; today's placed bracket (1.5x to 2.1x same-node) is a FAIL to work against and is served as such
  • P12: the matched-tariff median at most 1.5, p90 at most 1.75, no core cell above 2.0
  • P02: twelve retail configurations, three unaffiliated operators, the seven-day soak define D1's reproduction

Never served: guaranteed chip death, a universal ASIC-efficiency ceiling, chip-arrival probabilities, guaranteed profits, Ethereum security by compatibility, privacy from ZK, a numerical rank.

Source: docs/plans/igneum-2.0-test-registry.json, version 1.0, dated 8 October 2026, plan sha256 418b3b9f68f96a41. This copy was written when the page was built; the page checks the registry on the public git host every 60 seconds.

- +
Igneum 2.0 acceptance

Test and Acceptance Standard 1.0

Every case of the standard, shown as it is run, in the standard’s own words. A checklist, never a completion score: a gate passes only when every case it depends on has passed.

Basis IGNEUM_2.0_Plan.pdf, 37 pages, 8 October 2026. The standard runs to 73 pages. Registry dated 8 October 2026.

APPROVED AS PROPOSED 8 OCTOBER 2026P13 DEFERRED

Test and Acceptance Standard 1.0: APPROVED AS PROPOSED by the founder, 8 October 2026; P13 (maintenance continuity) DEFERRED; 272 cases: 10 passed under the standard, 0 running with team evidence, 7 failed, 255 not run, 0 deferred

  • 10 pass
  • 7 fail
  • 0 blocked
  • 0 running
  • 255 not run
  • 0 deferred
The gates

Five gates, and the freeze before them.

A gate reads NOT RUN until every case it depends on has run, RUNNING while any is running, BLOCKED if any is blocked, FAIL if any fails, and PASS only when every case passes. No gate is weighted into an average.

G0NOT RUN

Freeze

Release identity

No formal run or public pass before approval.

8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred

  • GOV8 casesNOT RUN
G1NOT RUN

Baseline

D1

No validated hardware claim without reproduction.

16 cases: 2 passed under the standard, 0 running with team evidence, 14 not run, 0 deferred

  • GOV8 casesNOT RUN
  • GPU8 casesNOT RUN
G2FAIL

Experiments

D2

No improvement claim from a negative hypothesis.

32 cases: 2 passed under the standard, 0 running with team evidence, 2 failed, 28 not run, 0 deferred

  • GOV8 casesNOT RUN
  • GPU8 casesNOT RUN
  • POW8 casesFAIL
  • ROT8 casesNOT RUN
G3NOT RUN

Adversary

D3

No broad resistance claim from one weak design.

16 cases: 0 passed under the standard, 0 running with team evidence, 16 not run, 0 deferred

  • GOV8 casesNOT RUN
  • ADV8 casesNOT RUN
G4FAIL

Coexistence

D4

No durability claim based on assumed chip expiry.

24 cases: 0 passed under the standard, 0 running with team evidence, 1 failed, 23 not run, 0 deferred

  • GOV8 casesNOT RUN
  • ECO8 casesFAIL
  • INC8 casesNOT RUN
G5NOT RUN

No rescue

D5

No no-rescue claim from a founder-supported demo.

56 cases: 5 passed under the standard, 0 running with team evidence, 51 not run, 0 deferred

  • GOV8 casesNOT RUN
  • ROT8 casesNOT RUN
  • ZKP8 casesNOT RUN
  • INC8 casesNOT RUN
  • FIN8 casesNOT RUN
  • OPS8 casesNOT RUN
  • UX8 casesNOT RUN

The three named gates

FAIL

Technical readiness

Execution control

No mainnet-ready claim with missing enforcement or safety.

64 cases: 6 passed under the standard, 0 running with team evidence, 5 failed, 53 not run, 0 deferred

  • GOV8 casesNOT RUN
  • POW8 casesFAIL
  • EVM8 casesNOT RUN
  • ZKP8 casesNOT RUN
  • CAP8 casesNOT RUN
  • FIN8 casesNOT RUN
  • VER8 casesFAIL
  • UX8 casesNOT RUN
NOT RUN

Commercial evidence

Execution control

Devnet activity is insufficient.

24 cases: 0 passed under the standard, 0 running with team evidence, 24 not run, 0 deferred

  • GOV8 casesNOT RUN
  • CAP8 casesNOT RUN
  • COM8 casesNOT RUN
FAIL

Leadership-contender decision

Execution control

Supports a scoped contention assessment, not a guaranteed rank.

272 cases: 10 passed under the standard, 0 running with team evidence, 7 failed, 255 not run, 0 deferred

  • GOV8 casesNOT RUN
  • GPU8 casesNOT RUN
  • POW8 casesFAIL
  • ADV8 casesNOT RUN
  • ROT8 casesNOT RUN
  • ECO8 casesFAIL
  • EVM8 casesNOT RUN
  • ZKP8 casesNOT RUN
  • CAP8 casesNOT RUN
  • INC8 casesNOT RUN
  • FIN8 casesNOT RUN
  • VER8 casesFAIL
  • OPS8 casesNOT RUN
  • UX8 casesNOT RUN
  • COM8 casesNOT RUN
  • LEAD8 casesNOT RUN
  • REV44 casesNOT RUN
  • INT18 casesFAIL
  • VR40 casesNOT RUN
  • TV32 casesNOT RUN
  • R1510 casesNOT RUN
01GOV

Release identity and evidence

Prevent a favourable result from being attached to the wrong code, assumptions or public claim.

NOT RUN
Owner
Release lead + independent assurance
Gate
G0 / all gates G0 G1 G2 G3 G4 G5
Fixtures
F0 manifest; F1 source/build archives; F9 evidence vault
Plan pages
5, 21, 23, 25, 26, 27
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
GOV-01Freeze the release and its claimsPriority BLOCKERProfile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 08:43 UK

Setup

Candidate source, binaries, public documentation and the 2.0 plan are available; no run is yet accepted.

Steps

  1. Record exact commits, binary hashes, dependencies, genesis/network identity, mining class, datasets, execution fork, verifier IDs and fee rules in F0.
  2. Map every promised capability and plan requirement to a test ID; distinguish supported mining, proving and wallet combinations.
  3. Sign the manifest with protocol, product and independent review owners before confirmatory runs.

Accept

Every material rule and claim has an unambiguous version and test. Conflicts or unknown activation rules produce BLOCKED, not an inferred default. Changes create a new manifest and invalidate affected results.

Evidence the case requires

Signed F0; source-to-test map; claim inventory; unresolved-field register.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Run
f0-signing-20261008-2330
Design status
NOT RUN
Standard page
18
Plan pages
5, 21, 23, 25, 26, 27
GOV-02Approve thresholds before resultsPriority BLOCKERProfile P00NOT RUNEvidence recordLast run 8 Oct 2026, 21:10 UK

Setup

This manual supplies proposed test thresholds, not source-approved protocol parameters.

Steps

  1. Approve or replace every P-profile before confirmatory testing; give each change a rationale and independent approver.
  2. Register hardware cohorts, mandatory economic worlds, customer workloads, peer dimensions and exclusion rules.
  3. Lock the profile hash and hold out seeds/workloads from the developers doing optimisation.

Accept

No decision-critical field is TBD. Numeric limits are frozen, commercially meaningful and not chosen from observed results. A weakened limit after failure requires a new protocol, full affected rerun and explicit claim downgrade review.

Evidence the case requires

Approved profile register; timestamped holdout commitments; change log.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
CI steward (a2ecfa95d3206016c)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
18
Plan pages
5, 21, 23, 25, 26, 27
GOV-03Reproduce builds outside the founding teamPriority BLOCKERProfile P00, P02NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Provide public source and documented build instructions to three unaffiliated operators.

Steps

  1. Build on clean declared environments without private files, tokens or founder assistance.
  2. Compare reproducible payload hashes; isolate signatures, notarisation and permitted non-deterministic wrappers.
  3. Run reference vectors and restart a node using only documented artifacts.

Accept

All independent builds reproduce the same consensus payload or an independently explained, pre-approved wrapper difference; reference outputs match exactly. Missing private prerequisites block release.

Evidence the case requires

Build logs; dependency lockfiles; binary comparison; operator attestations.

Method
Independent reproduction
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Design status
NOT RUN
Standard page
18
Plan pages
5, 21, 23, 25, 26, 27
GOV-04Preserve raw and negative evidencePriority BLOCKERProfile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Enable append-only storage for run outputs and a separate analysis workspace.

Steps

  1. Capture failed, aborted and successful runs with timestamps, seeds and environment hashes.
  2. Recompute one published figure from raw records on a clean machine.
  3. Modify a retained artifact deliberately and test integrity verification.

Accept

Every headline can be regenerated; tampering is detected; exclusions have pre-registered reasons. Failed or missing runs remain visible and are never replaced silently by a successful retry.

Evidence the case requires

Artifact manifest; hashes; reproduction script; exclusion ledger; negative-run archive.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
CI steward (a2ecfa95d3206016c)
Design status
NOT RUN
Standard page
19
Plan pages
5, 21, 23, 25, 26, 27
GOV-05Prove the test oracle detects broken behaviourPriority BLOCKERProfile P01NOT RUNEvidence none yetLast run 8 Oct 2026, 19:28 UK

Setup

Create controlled defective variants on an isolated network only.

Steps

  1. Disable proof verification, change one reward, accept an expired authority set and alter one hash output in separate mutants.
  2. Run the corresponding ZKP, INC, FIN and POW tests without telling the runner which mutant is active.
  3. Confirm the baseline still accepts authorised valid cases.

Accept

Every deliberately introduced fault is caught by its mapped test; valid controls pass. Any undetected critical mutant blocks acceptance of that test family until the oracle is repaired.

Evidence the case requires

Mutation catalogue; blinded run results; baseline controls; oracle review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fast-time lane (a8be71a0db962911c)
Run
200-417c4a57-b2
Design status
NOT RUN
Standard page
19
Plan pages
5, 21, 23, 25, 26, 27
GOV-06Enforce scope and optional-feature disciplinePriority BLOCKERProfile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 08:36 UK

Setup

Inventory FP32 experiments, receipts/oracles and all retained or excluded mining levers.

Steps

  1. Mark each capability CORE, CLAIMED-OPTIONAL or EXCLUDED before release testing.
  2. For excluded code, check binaries, protocol activation and product copy for accidental enablement or implied availability.
  3. For each claimed option, require the complete associated test set rather than a demonstration.

Accept

Every core and claimed-option obligation passes. Excluded items are shown as EXCLUDED, never PASS and never counted as achievements. Removing a failed core requirement prevents an all-2.0-pass claim.

Evidence the case requires

Scope manifest; activation scan; product-copy comparison; exclusions register.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
CI steward (a2ecfa95d3206016c)
Run
site-gate-20261009-01
Design status
NOT RUN
Standard page
19
Plan pages
5, 21, 23, 25, 26, 27
GOV-07Independent review and finding closurePriority BLOCKERProfile P09NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Nominate reviewers with declared conflicts and scopes covering cryptography, consensus and hardware.

Steps

  1. Provide pinned code, raw data, adversarial models and prior failures, including negative results.
  2. Track each finding to remediation and an independent retest; do not use the author as sole approver.
  3. Have reviewers state unreviewed surfaces and model limitations in their signed conclusions.

Accept

No unresolved critical or high-severity finding affects the claimed release. A finite review is described by scope, not as proof of universal security. Independent reproduction and review are both evidenced.

Evidence the case requires

Signed scoped reports; conflict declarations; finding/retest ledger.

Method
Independent specialist review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
20
Plan pages
5, 21, 23, 25, 26, 27
GOV-08Invalidate stale evidence and control public statusPriority BLOCKERProfile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Create a simulated post-test change to a verifier, mining class, dataset and fee rule.

Steps

  1. Calculate affected test dependencies and invalidate their former PASS statuses.
  2. Regenerate public status pages from F0 and the evidence register.
  3. Attempt to publish a rank-one, guaranteed-profit or automatic-chip-death claim without the required evidence.

Accept

Affected gates return to NOT RUN or BLOCKED. Public claims retain version, limits and date; unsupported claims are withheld. No stale result remains attached to a different release.

Evidence the case requires

Dependency impact report; regenerated status page; rejected claim examples.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
CI steward (a2ecfa95d3206016c)
Design status
NOT RUN
Standard page
20
Plan pages
5, 21, 23, 25, 26, 27
02GPU

Whole-system GPU measurements

Close the pending measurements and evaluate the actual configuration, including costs hidden by kernel-only results.

NOT RUN
Owner
GPU lead + three independent operators
Gate
G1 / G2 G1 G2
Fixtures
F2 retail-hardware cohort; F3 paired benchmark workloads; F9 calibrated evidence
Plan pages
6, 7, 8, 14, 18, 23
8 cases: 2 passed under the standard, 0 running with team evidence, 6 not run, 0 deferred
GPU-01Cover the declared commodity populationPriority GATEProfile P02PASSEvidence none yetLast run 9 Oct 2026, 10:08 UK

Setup

Freeze the P02 cohort, supported role matrix and the final v6 configuration.

Steps

  1. Inventory physical SKU, usable memory, driver, operating system, firmware, cooling and acquisition channel.
  2. Run mining on every supported cohort cell and proving on every separately advertised prover cell.
  3. Include lower-memory, used-generation and all advertised vendor cases; retain unsupported results separately.

Accept

All declared cells are tested, with no after-the-fact removal of weak cards. At least the P02 minimum coverage is met. Mining-only support is never reported as proof-generation support.

Evidence the case requires

Cohort manifest; compatibility matrix; raw results by SKU and role.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
hash-lane-20261009-batch5
Design status
NOT RUN
Standard page
21
Plan pages
6, 7, 8, 14, 18, 23
GPU-02Reproduce Ember clock-lock savingsPriority GATEProfile P02, P03PASSEvidence recordLast run 9 Oct 2026, 04:58 UK

Setup

Use paired stock and tuned runs on the same board, host, workload and ambient conditions.

Steps

  1. Warm to stability; randomise stock/tuned order and run P02 repeated sessions.
  2. Measure accepted work, calibrated wall energy, device telemetry and rejected work.
  3. Calculate paired energy and rate changes with run-level uncertainty, retaining failed tuning attempts.

Accept

Tuning preserves correctness and meets approved P03 operating limits. The historical 34-41% saving and under-2% rate-loss statement is reproduced only for qualifying configurations; otherwise that claim is corrected. Existing savings are not counted twice.

Evidence the case requires

Raw power/time series; paired analysis; tuning settings; claim-by-SKU table.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
hash-lane-20261009-batch4
Design status
NOT RUN
Standard page
21
Plan pages
6, 7, 8, 14, 18, 23
GPU-03Measure the real 64-register GPU costPriority GATEProfile P02, P03NOT RUNEvidence none yetLast run 9 Oct 2026, 10:08 UK

Setup

Build the baseline and window variant with identical dataset, reads and semantic workload.

Steps

  1. Inspect compiled register allocation, spills, occupancy and memory traffic on each supported backend.
  2. Measure paired complete-system energy and accepted throughput, including host work.
  3. Repeat during proving coexistence and expose any memory or scheduling cliff.

Accept

Any production window meets P03 budgets for every mandatory SKU; no hidden spills or correctness changes. Zero GPU cost is claimed only where measurement supports it within uncertainty. Results feed the redesigned adversary, not an old core estimate.

Evidence the case requires

Compiler reports; allocation traces; paired energy/rate data; coexistence runs.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
hash-lane-20261009-batch5
Design status
NOT RUN
Standard page
21
Plan pages
6, 7, 8, 14, 18, 23
GPU-04Find the memory-clock operating ladderPriority BLOCKERProfile P01, P02NOT RUNEvidence recordLast run 8 Oct 2026, 22:00 UK

Setup

Use safe vendor-supported settings only; record operator permission and original settings.

Steps

  1. Sweep approved core and memory operating points while holding workload constant.
  2. Measure error rate, accepted throughput, wall energy and thermal equilibrium.
  3. Repeat the selected knee after reboot and restore defaults after a failed or interrupted tuning session.

Accept

Selected profiles are stable, reproducible and not dependent on unsafe clocks. Every accepted hash remains correct; saved settings restore predictably. Tuning failure leaves a working safe configuration.

Evidence the case requires

Clock ladder; safe bounds; thermal/error logs; reboot and rollback record.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
22
Plan pages
6, 7, 8, 14, 18, 23
GPU-05Test dataset fit and support-horizon costsPriority BLOCKERProfile P01, P02, P06NOT RUNEvidence none yetLast run 9 Oct 2026, 04:58 UK

Setup

Test 5.5, 8.5 and 11.5 GiB only as source-proposed candidates; F0 determines activated sizes.

Steps

  1. Measure allocation plus driver, display, prover and OS headroom on the 8 GB and other cohort tiers.
  2. Run near-full-memory, fragmentation, restart and next-epoch construction scenarios.
  3. Compare time-sharing/eviction with concurrent mining/proving, including reload cost.

Accept

Every advertised combination completes without OOM or silent corruption. Unsupported future sizes are identified before activation. GPU exclusions and lost proving capacity appear in ECO evaluation; retirement of a tier is not a success metric.

Evidence the case requires

Memory budget per SKU; OOM traces; support horizon; concurrency cost table.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
hash-lane-20261009-batch4
Design status
NOT RUN
Standard page
22
Plan pages
6, 7, 8, 14, 18, 23
GPU-06Measure accepted work under ordinary connectivityPriority GATEProfile P02, P10NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use the same hardware against clean, delayed, lossy and intermittent links in F4.

Steps

  1. Measure kernel rate and accepted work separately under home and datacentre link profiles.
  2. Include reconnects, template changes, expired submissions and pool failover.
  3. Attribute loss to network, local software, validation and protocol causes.

Accept

Results use accepted work, never kernel rate alone. Ordinary-link incremental rejection stays within P10; all losses remain priced in ECO. Unreachable links may pause but must not claim paid work.

Evidence the case requires

Per-submission ledger; network trace; rejection reasons; accepted-work comparison.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
22
Plan pages
6, 7, 8, 14, 18, 23
GPU-07Survive sustained thermal and power operationPriority BLOCKERProfile P01, P02, P10NOT RUNEvidence recordLast run 8 Oct 2026, 22:00 UK

Setup

Run the selected profile on actual reference machines for the P02 soak period.

Steps

  1. Track wall power, temperatures, clocks, memory and accepted work continuously.
  2. Inject safe power interruptions, process restarts and normal competing desktop load.
  3. Check restored settings and compare late-run efficiency with the first stable period.

Accept

No invalid work or unsafe persistent settings; P02/P10 stability limits hold. Thermal throttling, crashes and recovery time remain in throughput and energy denominators. A crash-free short benchmark cannot substitute for the soak.

Evidence the case requires

Seven-day time series; crash reports; settings-restoration checks; drift analysis.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
23
Plan pages
6, 7, 8, 14, 18, 23
GPU-08Reproduce the full baseline independentlyPriority GATEProfile P02NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Three unaffiliated operators receive F0, F2 and F3, including the final miner/prover build.

Steps

  1. Repeat identical-SKU paired runs with documented meter calibration and environment differences.
  2. Recompute joules and total cost per accepted work from the shared raw schema.
  3. Investigate divergence before accepting a pooled headline or uncertainty band.

Accept

Reproductions meet P02 tolerance and exact correctness. No unexplained divergence or selectively missing low-end cell remains. Report manufactured GPU measurements separately from modelled specialist estimates.

Evidence the case requires

Three signed reproduction packs; reconciliation report; final baseline table.

Method
Independent reproduction
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
23
Plan pages
6, 7, 8, 14, 18, 23
03POW

Proof-of-work correctness and coupling

Find semantic disagreements and structural shortcuts before treating a harder-looking program as a stronger defence.

FAIL
Owner
Cryptography + GPU lead
Gate
G2 / technical readiness G2
Fixtures
F0 rule set; F3 independent CPU/GPU oracles; F5 mutation corpus
Plan pages
7, 9, 10, 23
8 cases: 0 passed under the standard, 0 running with team evidence, 2 failed, 6 not run, 0 deferred
POW-01Match independent execution across every backendPriority BLOCKERProfile P01NOT RUNEvidence none yetLast run 9 Oct 2026, 11:15 UK

Setup

Implement an independently written reference evaluator, not a wrapper around the production GPU path.

Steps

  1. Execute the P01 corpus across every family, boundary seed and supported backend.
  2. Exercise zero, maximum, sign, shift, rotate, overflow and unaligned-address cases allowed by the spec.
  3. Minimise every mismatch and rerun it on clean builds.

Accept

Bit-for-bit agreement for all valid cases and identical rejection for invalid cases. One unexplained mismatch is a blocker. Large sample counts are evidence of testing, not proof that unseen disagreements cannot exist.

Evidence the case requires

Reference implementation review; seeds/vectors; backend matrix; mismatch archive.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
mhpow-b3-20261009-01
Design status
NOT RUN
Standard page
24
Plan pages
7, 9, 10, 23
POW-02Validate generated programs and index foldingPriority BLOCKERProfile P01NOT RUNEvidence none yetLast run 9 Oct 2026, 11:20 UK

Setup

Use the frozen grammar, opcode semantics and index-fold rule; include boundary and malformed programs.

Steps

  1. Enumerate small constrained programs and fuzz the full generator at P01 depth.
  2. Check bounds, valid dependencies, address distribution and forbidden encodings.
  3. Compare source-level operations with optimised compiled code for removed or altered work.

Accept

No accepted program violates semantics, termination or memory bounds. Distribution claims have predeclared tests and effect-size limits; passing randomness checks is not treated as a cryptographic proof.

Evidence the case requires

Generator/fuzzer logs; reduced counterexamples; disassembly comparison; index tests.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
1p5x-int8-20261009-01
Design status
NOT RUN
Standard page
24
Plan pages
7, 9, 10, 23
POW-03Test whether live state is unavoidablePriority GATEProfile P03, P04FAILEvidence none yetLast run 9 Oct 2026, 10:25 UK

Setup

Take the 64-register candidate and the cheapest independently proposed storage organisations.

Steps

  1. Trace value liveness across dependent reads and final output, distinguishing distinct information from duplicated values.
  2. Try banking, compression, recomputation, fewer ports and time-multiplexed contexts.
  3. Quantify the best complete-system cost/throughput trade-off rather than the reference register count.

Accept

Production selection is supported by measured or physically modelled penalties after these alternatives. G2 requires the P03 improvement; an attractive source-level register count alone does not pass.

Evidence the case requires

Liveness traces; alternative implementations; Pareto table; reviewer analysis.

Method
Experiment + independent hardware review
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261009-placed-32lane
Design status
NOT RUN
Standard page
24
Plan pages
7, 9, 10, 23
POW-04Evaluate connected-resource restructuringPriority GATEProfile P03, P04NOT RUNEvidence none yetLast run 9 Oct 2026, 10:43 UK

Setup

Use a candidate initially matched to baseline instruction count, read count and dataset size.

Steps

  1. Connect state, addresses, arithmetic and lane communication according to the written hypothesis.
  2. Measure GPU cost and allow the specialist reviewer to redesign the entire core.
  3. Repeat on held-out program seeds and compare the worst supported adversary, not only the original design.

Accept

The selected upgrade meets P03 and improves the adversarial result outside declared uncertainty. A negative experiment remains a negative outcome; adopting a different design requires a new frozen comparison.

Evidence the case requires

Matched workloads; GPU runs; redesigned core estimates; held-out results.

Method
Controlled experiment
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
1p5x-x1-20261009-01
Design status
NOT RUN
Standard page
25
Plan pages
7, 9, 10, 23
POW-05Prevent amortised cheap winning attemptsPriority BLOCKERProfile P01, P04NOT RUNEvidence none yetLast run 9 Oct 2026, 11:10 UK

Setup

Prepare valid templates, nonces, intermediate-state captures and independent acceptance checks.

Steps

  1. Vary nonce, payout identity, transactions, roots and other committed fields after expensive work.
  2. Try replay, precomputation, shared prefixes, partial evaluation and many cheap suffix candidates.
  3. Price any valid strategy against fresh evaluation; independently review all bindings.

Accept

Invalid modifications are rejected. Any valid cost-saving strategy is incorporated into ADV and must still meet P04/ECO gates. No unresolved shortcut is hidden behind passing reference vectors.

Evidence the case requires

Attack implementations; valid/invalid controls; work-cost analysis; binding review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
pool design seat (a3832b1c3b274b310)
Run
mhpow-b2-20261009-01
Design status
NOT RUN
Standard page
25
Plan pages
7, 9, 10, 23
POW-06Bound verifier work and malformed-input costPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 9 Oct 2026, 11:15 UK

Setup

Use ordinary CPU validators with a manifest-defined resource budget and untrusted submissions.

Steps

  1. Submit shortest/longest programs, malformed encodings and adversarial memory references.
  2. Measure verification time, peak memory and work amplification across valid and invalid inputs.
  3. Sustain the approved hostile request rate while ordinary valid traffic continues.

Accept

All semantics remain correct and P09 resource budgets hold. Invalid traffic cannot cause unbounded allocation, crashes or disproportionate free work. Rate limits must not replace consensus validation.

Evidence the case requires

CPU profiles; adversarial corpus; allocation traces; valid-traffic latency.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
mhpow-b3-20261009-01
Design status
NOT RUN
Standard page
25
Plan pages
7, 9, 10, 23
POW-07Constrain any mixed-resource or FP32 branchPriority BLOCKERProfile P00, P01, P03FAILEvidence none yetLast run 8 Oct 2026, 22:00 UK

Setup

If this branch is excluded, verify that it is unreachable and not claimed; if included, use a separate frozen candidate.

Steps

  1. Specify exact rounding, fusion, special values and backend behaviour before compiling.
  2. Differentially test all supported architectures and allow numerical-domain simplification in the specialist model.
  3. Include verifier cost and candidate energy in P03/P04, not just arithmetic-unit area.

Accept

Included branches achieve exact agreed semantics and all hardware budgets. An excluded branch earns no performance credit. No approximate operation or unspecified compiler choice enters consensus.

Evidence the case requires

Scope decision; semantic specification; vectors; simplified datapath model.

Method
Conditional implementation test
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
kills-20261008
Design status
NOT RUN
Standard page
26
Plan pages
7, 9, 10, 23
POW-08Keep rejected mechanisms out of the shipped claimPriority GATEProfile P00, P03NOT RUNEvidence none yetLast run 9 Oct 2026, 10:08 UK

Setup

Inventory long programs, select trees, SM gating, wider reads, sealed classes, random epoch lengths, per-tier scoring and VRF draws.

Steps

  1. Retain their historic negative tests and realistic SRAM instruction-memory control.
  2. Inspect the release for reintroduction through renamed settings or hidden paths.
  3. Require a new written hypothesis and complete adversarial retest for any proposed return.

Accept

Excluded levers remain excluded unless separately approved and retested. Flip-flop instruction-memory area is never presented as the cost of a realistic SRAM implementation.

Evidence the case requires

Decision register; binary/config scan; negative-control results.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
hash-lane-20261009-batch5
Design status
NOT RUN
Standard page
26
Plan pages
7, 9, 10, 23
04ADV

Programmable specialist adversaries

Give the opponent permission to adapt, share resources and remain operational; test cost rather than imagined chip death.

NOT RUN
Owner
Independent hardware team
Gate
G3 G3
Fixtures
F2 reference GPUs; F6 RTL/physical models; all published families
Plan pages
8, 10, 12, 22, 23
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
ADV-01Build a multi-family programmable opponentPriority GATEProfile P01, P04NOT RUNEvidence recordLast run 9 Oct 2026, 10:25 UK

Setup

Provide the complete published family bank and future known parameter schedule to the reviewer.

Steps

  1. Design one programmable architecture that supports all retained families, including firmware and emulation paths.
  2. Optimise clocks, lanes, ports and pipelines without requiring a graphics-card layout.
  3. Verify its outputs against POW vectors before measuring any advantage.

Accept

At least the P04 design diversity is evaluated; every estimated competitive design is functionally validated. Inability of one narrow design to adapt is not evidence that all chips expire.

Evidence the case requires

Architecture reports; functional simulations; adaptation matrix; reviewer signature.

Method
Independent hardware study
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261009-placed-32lane
Design status
NOT RUN
Standard page
27
Plan pages
8, 10, 12, 22, 23
ADV-02Price shared, reduced and reconstructed memoryPriority GATEProfile P04NOT RUNEvidence none yetLast run 9 Oct 2026, 10:44 UK

Setup

Allow multiple engines to share a dataset and to store selected fractions rather than a complete per-engine copy.

Steps

  1. Sweep sharing factors, memory fractions, caches and recomputation depth across many simultaneous hashes.
  2. Include construction/update amortisation, bandwidth contention and retained state.
  3. Take the most favourable feasible point for the specialist into the complete-board model.

Accept

No omitted feasible trade-off materially lowers the accepted cost estimate. Any winning alternative is included in P04 and ECO; capacity alone is not accepted as an energy bound.

Evidence the case requires

Sweep definitions; energy/bandwidth data; best-feasible envelope; excluded-design reasons.

Method
Model + adversarial implementation
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261009-x7
Design status
NOT RUN
Standard page
27
Plan pages
8, 10, 12, 22, 23
ADV-03Attack with data-local and hybrid executionPriority GATEProfile P04NOT RUNEvidence recordLast run 9 Oct 2026, 10:25 UK

Setup

Permit distributed memories, state migration and companion CPU/GPU/FPGA components.

Steps

  1. Compare moving computation, intermediate state or fetched data to each read location.
  2. Test specialised mining alongside outsourced proof generation rather than assuming one physical GPU does both.
  3. Include interconnect, host, synchronisation, idle and conversion costs.

Accept

The cheapest feasible combined system is included in the adversarial envelope and economic model. A worker identity or account is never treated as proof of a single physical device.

Evidence the case requires

Hybrid architecture diagrams; traffic traces; system cost and energy ledger.

Method
Independent system modelling
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261009-placed-32lane
Design status
NOT RUN
Standard page
27
Plan pages
8, 10, 12, 22, 23
ADV-04Measure profitable selective participationPriority GATEProfile P04, P12NOT RUNEvidence recordLast run 8 Oct 2026, 21:41 UK

Setup

Use all declared families plus held-out generated programs and the protocol difficulty rule.

Steps

  1. Identify favourable execution paths and add cheap fallbacks for other periods.
  2. Simulate entry/exit around profitable periods, including idle time, compilation and re-entry costs.
  3. Evaluate revenue and costs across the full schedule, not just average program energy.

Accept

Intermittent specialists meet P04/ECO limits when evaluated on full-period economics. A weak tail cannot be concealed by a favourable mean; known valid shortcuts must be priced.

Evidence the case requires

Per-program advantage distribution; policy simulator; full-period returns.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261008-placed-8lane
Design status
NOT RUN
Standard page
28
Plan pages
8, 10, 12, 22, 23
ADV-05Validate physical and complete-board costsPriority GATEProfile P04NOT RUNEvidence none yetLast run 9 Oct 2026, 10:44 UK

Setup

Use feasible process/library assumptions and documented component boundaries; no fabricated foundry access.

Steps

  1. Model SRAM macros, ports, wiring, clocking, memory PHYs, external memory, host and power conversion.
  2. Run place-and-route where available; mark unmodelled items as uncertainty rather than zero.
  3. Compare against a calibrated existing hardware block or equivalent validation case.

Accept

No decision-critical cost is omitted. Physically unvalidated or proprietary estimates are labelled and independently bounded; synthesis alone cannot earn a manufactured-chip claim.

Evidence the case requires

Netlist/physical reports; macro assumptions; bill of materials; model calibration.

Method
Independent physical-design review
Cadence
Release candidate; repeat after relevant changes
Owner
k lane (a3c9601a6d4686fe1)
Run
adversary-20261009-x7
Design status
NOT RUN
Standard page
28
Plan pages
8, 10, 12, 22, 23
ADV-06Separate process advantage from specialisationPriority GATEProfile P04, P12NOT RUNEvidence recordLast run 8 Oct 2026, 22:09 UK

Setup

Evaluate same-node, one-node-ahead and two-node-ahead scenarios with explicit technology definitions.

Steps

  1. Use independently justified process factors, voltages, memory and packaging assumptions for each design.
  2. Allow reusable IP and modular revisions; credit GPU improvement consistently.
  3. Evaluate measurement confidence and model-parameter sensitivity separately.

Accept

P04 primary limits hold for all competitive-reference cells; two-node futures are reported and pass the predeclared economic stress envelope. A model range is never labelled a statistical confidence interval without justification.

Evidence the case requires

Node-specific reports; factor provenance; uncertainty and sensitivity tables.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
k lane (a3c9601a6d4686fe1)
Run
floor-k-20261008-rows-repeat
Design status
NOT RUN
Standard page
28
Plan pages
8, 10, 12, 22, 23
ADV-07Evaluate lifetime without forced obsolescencePriority GATEProfile P04, P12NOT RUNEvidence none yetLast run 9 Oct 2026, 10:25 UK

Setup

Assume multi-year productive survival and known schedule support before testing optional retirement penalties.

Steps

  1. Price firmware, emulation, memory expansion, companion hardware and incremental redesign.
  2. Include 1-, 3- and 5-year productive lifetimes plus idle/resale possibilities.
  3. Grant a retirement credit only if all feasible cheaper adaptations lose competitiveness.

Accept

The primary case does not require chip death or a fresh full development bill per family. Every retirement credit has a documented adaptation comparison; incompatible and unprofitable are reported separately.

Evidence the case requires

Lifetime/adaptation ledger; revision costs; feasible-alternative analysis.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261009-placed-32lane
Design status
NOT RUN
Standard page
29
Plan pages
8, 10, 12, 22, 23
ADV-08Independently challenge the best-cost envelopePriority GATEProfile P04NOT RUNEvidence none yetLast run 9 Oct 2026, 10:44 UK

Setup

Publish the non-sensitive model and negative results; commission an unaffiliated second hardware reviewer.

Steps

  1. Reward cheaper valid designs and reproduced shortcuts, not confirmation of the preferred number.
  2. Re-run P04 with the strongest submitted feasible design, including a low-cost funded-development case.
  3. Record unresolved modelling disagreements and future technology exclusions.

Accept

Both reviews accept the scoped envelope or all material disagreements are resolved transparently. Passing supports only evaluated designs and conditions, never a universal bound on all future silicon.

Evidence the case requires

Two review reports; challenge log; final envelope; unresolved-limit statement.

Method
Independent challenge/review
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261009-x7
Design status
NOT RUN
Standard page
29
Plan pages
8, 10, 12, 22, 23
05ROT

Epochs, seeds and memory transitions

Transitions must agree across nodes and remain usable during failures; crossing a boundary is not a chip-retirement test.

NOT RUN
Owner
Consensus + GPU leads
Gate
G5 / G2 G5 G2
Fixtures
F0 activation rules; F4 fault network; F5 historical and boundary vectors
Plan pages
7, 11, 19, 21
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
ROT-01Agree across every hourly boundaryPriority BLOCKERProfile P01, P08NOT RUNEvidence recordLast run 8 Oct 2026, 21:07 UK

Setup

Use real nodes, CPU/GPU miners and independent clocks around successive program boundaries.

Steps

  1. Submit valid work immediately before, at and after the activation boundary under clock skew and delayed delivery.
  2. Restart nodes from both sides and replay the same headers.
  3. Compare selected seed, program, validity, rewards and local wall-clock dependence.

Accept

All honest nodes derive identical consensus outcomes from the frozen rule. Late work is handled exactly as specified; no wall-clock ambiguity or cross-backend split occurs.

Evidence the case requires

Boundary vectors; node/miner traces; acceptance and reward matrix.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fast-time lane (a8be71a0db962911c)
Run
f10-worker-20261008
Design status
NOT RUN
Standard page
30
Plan pages
7, 11, 19, 21
ROT-02Cross weekly and family boundaries togetherPriority BLOCKERProfile P01, P03, P08NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Use the retained schedule in F0, including coincident program, parameter and family changes.

Steps

  1. Run every known family transition and all coincident-boundary combinations on production code.
  2. Interrupt downloads, compilation and restart during activation; include mixed old/new clients.
  3. Repeat selected cases under real elapsed time and the remainder under disclosed accelerated time.

Accept

Deterministic activation, documented old-client behaviour and no unsafe fallback. Compilation/setup costs satisfy P03; accelerated runs are not reported as years of operating history.

Evidence the case requires

Transition matrix; code-path evidence; compile timing; old-client logs.

Evidence record of the run

What was run
the class v6 object crossing at its floor on 617cb441
Run by
fast-time lane (a8be71a0db962911c)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fast-time lane (a8be71a0db962911c)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
30
Plan pages
7, 11, 19, 21
ROT-03Test miner-voted bring-forward governancePriority BLOCKERProfile P00, P01, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Freeze eligibility, threshold, windows and activation semantics before testing; do not invent a no-veto rule.

Steps

  1. Attempt threshold-minus-one, threshold, conflicting proposals, duplicate votes and coalition withholding.
  2. Partition voters, restore them and test vote-key substitution through pools.
  3. Verify adoption and refusal behaviour of already running nodes.

Accept

The actual mechanism enforces F0, with authenticated voting and no conflicting activation. Any coalition capable of blocking or manipulating changes is disclosed; labels such as no veto do not override arithmetic.

Evidence the case requires

Executable governance model; signed-vote corpus; coalition/partition results.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
30
Plan pages
7, 11, 19, 21
ROT-04Resist seed selection and faster evaluatorsPriority BLOCKERProfile P00, P01, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Provide the specified seed pipeline and delay proof implementation plus independently parameterised fast-adversary models.

Steps

  1. Try withholding candidate seeds, grinding alternatives, replaying delay proofs and biased checkpoint selection.
  2. Vary adversarial speed advantage and outage duration; trace influence on program choice.
  3. Validate inputs, parameters and proofs against independent vectors.

Accept

No invalid seed or proof is accepted; selection advantage stays within the approved threat-model bound. Missing bounds block this gate. A delay mechanism is not credited as generic ASIC resistance.

Evidence the case requires

Seed/grinding simulations; speed sensitivity; proof vectors; threat-model signoff.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Design status
NOT RUN
Standard page
31
Plan pages
7, 11, 19, 21
ROT-05Continue or pause correctly when finality stopsPriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Stop checkpoint signing while mining continues, then cross seed and family boundaries.

Steps

  1. Remove the required signing weight and observe the documented fallback or safe pause.
  2. Prevent access to any founder seed service; restart from persisted state.
  3. Restore the stated fault assumptions and verify deterministic recovery.

Accept

Mining/seed behaviour matches F0 without manufacturing certificates or reinterpreting finality. Safety holds during the outage; liveness is required only after its stated assumptions return.

Evidence the case requires

Fault timeline; seed/certificate history; node-state comparison; recovery log.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
31
Plan pages
7, 11, 19, 21
ROT-06Activate datasets without hidden exclusionsPriority BLOCKERProfile P01, P06NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Freeze memory sizes, support horizon and sync/update procedure; test all advertised roles.

Steps

  1. Construct the next dataset while current work remains active; test slow disks, low free memory and interruption.
  2. Try stale-state/dataset submissions and maliciously expensive state growth where coupling exists.
  3. Measure data transfer, restart and excluded-card costs before approving progression.

Accept

No invalid stale work is accepted, no supported card silently fails, and P06 is met. Hardware retirement and sync burden are included in the economic decision, not treated as automatic chip protection.

Evidence the case requires

Dataset hashes; memory/update traces; stale-work tests; exclusion decision.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
31
Plan pages
7, 11, 19, 21
ROT-07Ablate redundant rotation layersPriority GATEProfile P03, P04NOT RUNEvidence recordLast run 8 Oct 2026, 22:49 UK

Setup

Use matched baseline and ablated variants in the lab; do not change a running public network.

Steps

  1. Remove each weekly/family component independently and measure adversarial cost, GPU setup and verifier complexity.
  2. Include favourable-period specialists and all retained known families.
  3. Keep a layer only with a distinct, independently supported benefit or a documented non-resistance purpose.

Accept

Every retained layer has explicit justification and full boundary coverage. Redundant complexity is removed or its rationale recorded; the security model does not double-count the same versatility cost.

Evidence the case requires

Ablation report; decision log; complexity/cost comparison.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
lane D family gate (a07a99a3788566af2)
Run
family-gate-20261008c
Design status
NOT RUN
Standard page
32
Plan pages
7, 11, 19, 21
ROT-08Pass the no-new-rules counterfactualPriority GATEProfile P04, P12NOT RUNEvidence recordLast run 8 Oct 2026, 22:49 UK

Setup

Freeze the complete published rule bank and known schedule for the five-year evaluation.

Steps

  1. Allow a programmable adversary to know and survive all planned changes.
  2. Remove assumed future emergency instructions and manual retirement actions from the model.
  3. Run the required ECO scenarios and link them to independent network-transition tests.

Accept

Competitiveness survives the approved envelope without future rescue assumptions. Any result that needs unannounced changes fails this claim; ordinary bug maintenance is distinguished from anti-chip intervention.

Evidence the case requires

Frozen-rule model; scenario results; excluded-rescue audit; G5 evidence.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Run
family-gate-20261008c
Design status
NOT RUN
Standard page
32
Plan pages
7, 11, 19, 21
06ECO

Five-year coexistence economics

Test the world after specialised hardware exists, including new entrants and an already-funded competitor.

FAIL
Owner
Economics lead + independent reviewer
Gate
G4 G4
Fixtures
F6 adversarial costs; F7 scenario model; F2 operator costs
Plan pages
8, 13, 18, 24, 26
8 cases: 0 passed under the standard, 0 running with team evidence, 1 failed, 7 not run, 0 deferred
ECO-01Reconcile complete cost per accepted workPriority GATEProfile P12NOT RUNEvidence recordLast run 8 Oct 2026, 21:07 UK

Setup

Use benchmark outputs, current-source cost inputs recorded at execution time and separate reference scenarios.

Steps

  1. Calculate hardware annualisation, electricity, host, cooling/hosting, failures, fees, downtime and residual value.
  2. Use actual accepted work and independently verify units and period conversions.
  3. Cross-check formulas using hand-worked fixtures, edge cases and a second implementation.

Accept

All material costs and rejected-work effects appear once; model totals reconcile to raw inputs. No GPU upgrade is free, development cost is not double-counted, and burn is not mislabelled operator income.

Evidence the case requires

Versioned model; unit fixtures; independent reconciliation; input sources.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco05-20261008-02
Design status
NOT RUN
Standard page
33
Plan pages
8, 13, 18, 24, 26
ECO-02Separate existing-owner and new-entrant viabilityPriority GATEProfile P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use both installed hardware and purchasable replacement hardware in every mandatory cohort.

Steps

  1. Evaluate marginal operation separately from recovery of a new purchase.
  2. Stress resale at zero, hardware failures, financing and replacement cycles.
  3. Report break-even power price and total cost relative to the strongest feasible specialist.

Accept

P12 competitiveness conditions hold for the predeclared cohorts in required sustainable worlds. Existing-owner profitability cannot substitute for viable new entry; cards outside the envelope remain visible.

Evidence the case requires

Owner/entrant curves; price-date records; break-even tables; cohort outcomes.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
33
Plan pages
8, 13, 18, 24, 26
ECO-03Let the specialist keep its sunk developmentPriority GATEProfile P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use three development cases: fully funded elsewhere, source-range low and source-range high.

Steps

  1. Evaluate private mining, public hardware sales and a hybrid business model.
  2. Allow shared IP, incremental revisions, multi-year survival and resale where justified.
  3. Re-evaluate GPU entry after the specialist fleet is already installed.

Accept

The coexistence claim does not depend on recovering the original chip research bill. Required P12 cases meet the approved envelope even at zero incremental development cost; failures cannot be hidden by the $23M/$340M source thresholds.

Evidence the case requires

Business-model variants; sunk-cost case; full cash-flow and adaptation records.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
33
Plan pages
8, 13, 18, 24, 26
ECO-04Model entry, exit and difficulty responsePriority GATEProfile P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use independently reviewed dynamic operator policies, not fixed market shares.

Steps

  1. Let agents buy, sell, switch off, re-enter and choose tasks based on declared costs and expected income.
  2. Apply the actual difficulty/reward rules and test optimistic and adversarial liquidity/capital availability.
  3. Compare equilibrium and transient outcomes across independent starting conditions.

Accept

Mandatory worlds satisfy P12 without an imposed GPU share or artificial specialist capacity limit. Concentration, oscillations and excluded regions are reported; model behaviour matches unit and conservation checks.

Evidence the case requires

Agent policies; sensitivity seeds; market-share paths; independent model review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
34
Plan pages
8, 13, 18, 24, 26
ECO-05Stress success, contraction and cheap electricityPriority GATEProfile P12FAILEvidence recordLast run 8 Oct 2026, 21:07 UK

Setup

Freeze mandatory scenarios before results: revenue bands, tariff range, lifetimes and demand states.

Steps

  1. Run the P12 factorial grid plus adversarial combinations selected by the independent reviewer.
  2. Test a large successful network as well as weak-revenue and heterogeneous-tariff cases.
  3. Distinguish feasible sustained-entry worlds from collapse scenarios with no rational profitable operator.

Accept

No small-network or token-appreciation assumption props up the primary claim. Required viable worlds pass the envelope; collapse worlds show honest contraction and safety, not fabricated profits. Failure regions are explicit.

Evidence the case requires

Scenario register; full result cube; boundary plots; failed-world explanations.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco05-20261008-02
Design status
NOT RUN
Standard page
34
Plan pages
8, 13, 18, 24, 26
ECO-06Fund security and proving as issuance fallsPriority GATEProfile P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use the frozen supply, halving, fee, burn and reward rules rather than source prose assumptions.

Steps

  1. Reconcile revenue reaching miners, internal provers, developers and burns over the full horizon.
  2. Test flat/declining fees and no external proving income; separately introduce external demand.
  3. Calculate capacity and security-provider coverage after each reward transition.

Accept

Recurring compensation is explicit and internally consistent; mandatory sustainable scenarios meet P12. Burned amounts are never counted as payments, and external operator income is not assumed to fund internal work automatically.

Evidence the case requires

Issuance/fee ledger; scenario cash flows; funding-shortfall report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
34
Plan pages
8, 13, 18, 24, 26
ECO-07Price memory growth and honest-card displacementPriority GATEProfile P06, P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use GPU-05 and ROT-06 costs with the cheapest specialist adaptation.

Steps

  1. For each dataset increment, compare specialist cost increases with excluded cards and lost proving capacity.
  2. Include ordinary-owner replacement, resale and reloading expenses.
  3. Run alternate bounded schedules without assigning automatic chip death.

Accept

The retained schedule meets P06/P12 and has an evidence-backed net competitiveness benefit. A schedule that mainly harms accessible GPUs fails; excluded tiers and mitigations are documented before activation.

Evidence the case requires

Per-step cost/retention table; alternative schedules; approval record.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
35
Plan pages
8, 13, 18, 24, 26
ECO-08Reproduce and adversarially audit the modelPriority GATEProfile P12NOT RUNEvidence recordLast run 8 Oct 2026, 21:07 UK

Setup

Give an independent economist or qualified analyst the code, inputs and frozen success criteria.

Steps

  1. Recalculate required worlds and perturb favourable assumptions against the team.
  2. Check dependence on discounts, utilisation, capital limits, artificial prices and future upgrades.
  3. Publish the sensitivity range and state which conclusions are conditional.

Accept

Material results reproduce, required scenarios pass and no unacknowledged assumption dominates the claim. The model supports a bounded coexistence conclusion, not a percentage probability that no chip will appear.

Evidence the case requires

Independent report; rerun outputs; model limitations; approved claim envelope.

Method
Independent economic review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco05-20261008-02
Design status
NOT RUN
Standard page
35
Plan pages
8, 13, 18, 24, 26
07EVM

Execution and developer compatibility

Keep familiar applications while making every difference and metering rule explicit and reproducible.

NOT RUN
Owner
Execution lead + independent implementer
Gate
Technical readiness
Fixtures
F0 execution-fork semantics; F5 transactions/contracts; F4 multi-node network
Plan pages
15, 25, 34, 35, 36, 37
8 cases: 1 passed under the standard, 0 running with team evidence, 7 not run, 0 deferred
EVM-01Match the selected EVM semanticsPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 21:10 UK

Setup

Pin the intended execution fork, revm version and all Igneum deviations in F0.

Steps

  1. Run the applicable upstream execution/state fixtures plus independently written deviation tests.
  2. Execute identical blocks on multiple nodes and compare roots, receipts, logs, gas and failure outcomes.
  3. Minimise mismatches and distinguish intended differences from implementation defects.

Accept

All applicable vectors match; every deviation has a documented test and developer consequence. No claim of universal Ethereum equivalence or Ethereum settlement security is inferred.

Evidence the case requires

Fixture/version inventory; root/receipt diffs; deviation matrix.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
36
Plan pages
15, 25, 34, 35, 36, 37
EVM-02Preserve transaction binding and replay protectionPriority BLOCKERProfile P01NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Use signed transfers, contract calls and deployment transactions with boundary field values.

Steps

  1. Alter chain identity, nonce, signature, fee caps and recipient after signing.
  2. Replay across nodes, forks and distinct test networks; resubmit around reorganisation.
  3. Check mempool admission and final consensus execution independently.

Accept

Unauthorised, wrong-network or duplicate spends are rejected according to F0. Valid replacements follow the declared rule; mempool filtering alone is not evidence of consensus enforcement.

Evidence the case requires

Signed corpus; admission/execution outcomes; account-state reconciliation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
36
Plan pages
15, 25, 34, 35, 36, 37
EVM-03Test two-dimensional fees and proving limitsPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:13 UK

Setup

Freeze fee dimensions, estimator rules, abort behaviour and refund policy.

Steps

  1. Run workloads near and beyond execution and proving budgets, including state-heavy pathological cases.
  2. Compare estimated fees with charged fees and validate rollback/receipt status on abort.
  3. Mutate a block producer to omit or undercharge expensive work.

Accept

Deterministic metering, charged amounts and aborted state agree across nodes and proofs. Resource bounds hold; fee estimates meet P09 for accepted supported cases. Undercharged invalid blocks cannot bypass consensus.

Evidence the case requires

Metering traces; fee fixtures; estimator errors; invalid-block rejection.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1744-evm
Design status
NOT RUN
Standard page
36
Plan pages
15, 25, 34, 35, 36, 37
EVM-04Exercise block context and randomness assumptionsPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:13 UK

Setup

Use contracts sensitive to timestamp, height/context, randomness and ordering.

Steps

  1. Compare the declared Igneum semantics with developers' documented expectations.
  2. Test boundary transitions, miner-influenced inputs and adversarial ordering in the isolated network.
  3. Run dependency reviews for applications using these values for economic decisions.

Accept

Semantics match F0 and differences are surfaced in compatibility documentation. No source of miner influence is marketed as unbiased randomness; incompatible applications are not included in the compatibility claim.

Evidence the case requires

Context-contract results; threat notes; compatibility exclusions.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1744-evm
Design status
NOT RUN
Standard page
37
Plan pages
15, 25, 34, 35, 36, 37
EVM-05Run representative contract integration journeysPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:13 UK

Setup

Use versioned transfer/token, NFT, multisignature, exchange and upgrade-pattern fixtures where supported.

Steps

  1. Deploy, initialise, transact, revert and upgrade each contract using ordinary tooling.
  2. Exercise events, logs, balances, storage and call traces across node restart/reorganisation.
  3. Compare expected application invariants with native execution and proved results.

Accept

Supported journeys preserve their stated invariants; all deviations are documented. Example deployment success alone cannot stand in for application-level correctness or financial audit.

Evidence the case requires

Contract fixture hashes; transaction journeys; invariant and state comparisons.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1744-evm
Design status
NOT RUN
Standard page
37
Plan pages
15, 25, 34, 35, 36, 37
EVM-06Validate wallets, RPC and indexersPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:13 UK

Setup

Pin supported RPC methods and response semantics; use normal developer clients and an independent indexer.

Steps

  1. Test fee estimation, pending/final states, subscriptions, pagination and reconnects.
  2. Reindex from genesis or the documented trust anchor after pruning and restart.
  3. Compare logs, receipts and balances with independently validated chain state.

Accept

No missing/duplicate canonical records; unsupported methods are explicit. UI states distinguish included, executed, proven and finalised. Malformed RPC input cannot crash validators or leak secrets.

Evidence the case requires

RPC conformance report; reindex comparison; reconnect/edge-case logs.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1744-evm
Design status
NOT RUN
Standard page
37
Plan pages
15, 25, 34, 35, 36, 37
EVM-07Handle execution denial-of-service workloadsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Create bounded pathological bytecode, calls, state growth, storage and precompile inputs.

Steps

  1. Measure CPU, memory, disk and proving cost against charged budgets.
  2. Saturate admission with invalid/expensive requests while valid workloads continue.
  3. Restart mid-execution and verify atomic state recovery.

Accept

P09 limits hold with no unbounded free work or divergent rollback. State remains consistent after crash; availability under overload follows the declared admission policy, not silent dropping of accepted transactions.

Evidence the case requires

Resource profiles; adversarial corpus; state recovery comparisons.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Design status
NOT RUN
Standard page
38
Plan pages
15, 25, 34, 35, 36, 37
EVM-08Verify controlled execution and verifier upgradesPriority BLOCKERProfile P01, P08, P09PASSEvidence recordLast run 8 Oct 2026, 23:24 UK

Setup

Prepare two authorised versions and malicious, stale or unknown versions.

Steps

  1. Cross activation with mixed clients, queued transactions and proofs from both versions.
  2. Bind each accepted proof to the correct execution semantics and program identity.
  3. Exercise a failed software distribution without altering consensus activation.

Accept

No unknown or wrong-version execution is accepted. Pre/post-boundary handling is deterministic and documented; software delivery cannot silently redefine transaction semantics or proof acceptance.

Evidence the case requires

Upgrade vectors; mixed-version traces; manifest/version bindings.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
enforced-proving-20261008-03
Design status
NOT RUN
Standard page
38
Plan pages
15, 25, 34, 35, 36, 37
08ZKP

Consensus-enforced proof validity

The validator, not merely the official producer, must reject unauthorised or invalid proof records and rewards.

NOT RUN
Owner
Proving + protocol leads; independent cryptography review
Gate
Technical readiness / G5 G5
Fixtures
F0 pinned programs/verifiers; F5 valid and hostile proof corpus; unmodified validators
Plan pages
16, 20, 24, 25, 36, 37
8 cases: 4 passed under the standard, 0 running with team evidence, 4 not run, 0 deferred
ZKP-01Reject missing and invalid proofsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Start from a native-correct statement and an independently verified valid proof.

Steps

  1. Submit the statement with no proof, truncated bytes, random bytes and targeted proof mutations using a modified producer.
  2. Submit the genuine proof as a positive control through ordinary network paths.
  3. Inspect block acceptance and resulting reward/state on unmodified validators.

Accept

Every invalid proof record is rejected and earns no reward; valid controls succeed. A producer-side filter is not sufficient. Record rejection semantics exactly as defined by F0.

Evidence the case requires

Hostile record corpus; validator decisions; before/after balances; positive controls.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
39
Plan pages
16, 20, 24, 25, 36, 37
ZKP-02Bind program, verifier and security parametersPriority BLOCKERProfile P01, P09PASSEvidence recordLast run 8 Oct 2026, 23:24 UK

Setup

Use valid proofs from authorised and unauthorised programs and parameter sets.

Steps

  1. Swap program digest, verifier version, security settings and verification key where applicable.
  2. Attempt downgrade through configuration, serialized metadata or an old node path.
  3. Test authorised boundary transitions and unsupported future identities.

Accept

Only explicitly authorised combinations are accepted in the correct epoch. No implicit trust in producer-supplied metadata or lower-security fallback; all accepted settings have scoped soundness review.

Evidence the case requires

Identity/parameter matrix; rejection traces; cryptographic review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
enforced-proving-20261008-03
Design status
NOT RUN
Standard page
39
Plan pages
16, 20, 24, 25, 36, 37
ZKP-03Bind network, epoch, job and state rootsPriority BLOCKERProfile P01NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Prepare valid proofs for distinct chains, epochs, jobs and initial/final states.

Steps

  1. Replay each proof under another network, job, epoch, shard range or state commitment.
  2. Alter public inputs while retaining the proof and test valid-but-wrong-context statements.
  3. Check duplicated and reordered records across forks and replayed sync data.

Accept

Every misbound proof is rejected; valid authorised replays follow only explicitly allowed semantics and never create extra rewards. Native reexecution cannot conceal missing proof-context binding.

Evidence the case requires

Binding matrix; public-input hashes; replay traces; reward reconciliation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
39
Plan pages
16, 20, 24, 25, 36, 37
ZKP-04Prevent reward and payout substitutionPriority BLOCKERProfile P01PASSEvidence recordLast run 8 Oct 2026, 23:24 UK

Setup

Use proofs that commit to authorisation and all reward-relevant fields required by F0.

Steps

  1. Alter payout key, amount, beneficiary, source work or fee allocation independently.
  2. Supply correct execution over malicious producer-provided consensus/reward inputs.
  3. Compare consensus-derived rewards with the proved/publicly authenticated derivation.

Accept

Unauthorised payout changes and incorrect consensus inputs are rejected; no statement accepted merely because execution over supplied inputs is internally correct. Legitimate authorisations are preserved.

Evidence the case requires

Mutation cases; reward derivation trace; signature/proof binding review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
enforced-proving-20261008-03
Design status
NOT RUN
Standard page
40
Plan pages
16, 20, 24, 25, 36, 37
ZKP-05Make proof payment idempotent across racesPriority BLOCKERProfile P01PASSEvidence recordLast run 8 Oct 2026, 23:24 UK

Setup

Use competing provers submitting valid results for the same work and simulate retries/reorganisations.

Steps

  1. Submit simultaneous duplicates, reordered receipts and repeated messages after disconnects.
  2. Crash validators between validation and reward application, then recover.
  3. Reconcile canonical payouts against the exact F0 duplicate policy.

Accept

Only the authorised total payment is made; no double payout, lost accepted entitlement or fork-retained balance. Transactions and payout records recover atomically.

Evidence the case requires

Concurrency schedule; canonical payment ledger; crash/recovery evidence.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
enforced-proving-20261008-03
Design status
NOT RUN
Standard page
40
Plan pages
16, 20, 24, 25, 36, 37
ZKP-06Verify aggregation coverage and completenessPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Build valid multi-shard workloads plus omitted, duplicated, overlapping and misordered shard sets.

Steps

  1. Attempt an aggregate with a correct outer proof but wrong coverage/public-input construction.
  2. Alter shard ranges, roots and aggregation-program identity.
  3. Verify native execution, aggregate validity and coverage commitments independently.

Accept

Only complete, correctly ordered authorised coverage is accepted. No valid proof of the wrong computation becomes an accepted chain result; aggregation failures do not fabricate successful delivery.

Evidence the case requires

Coverage corpus; aggregate/public-input verification; rejection ledger.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
40
Plan pages
16, 20, 24, 25, 36, 37
ZKP-07Review soundness and verifier resource limitsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Provide proof-system code, parameters, patches and the pinned verification path to an independent specialist.

Steps

  1. Review soundness assumptions, parameter margins and consequences of performance patches.
  2. Fuzz deserialization and adversarial proofs; measure verification CPU and memory under load.
  3. Cross-check an independent verifier or reference path and test crash containment.

Accept

P09 review and resource requirements pass with no unresolved critical/high finding. Random proof rejection counts are not described as evidence of a particular cryptographic security level.

Evidence the case requires

Scoped soundness review; parameter sheet; fuzzer corpus; verifier profiles.

Method
Independent cryptographic review + testing
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Standard page
41
Plan pages
16, 20, 24, 25, 36, 37
ZKP-08Preserve authority and audit all acceptance pathsPriority BLOCKERProfile P01, P07, P08PASSEvidence recordLast run 8 Oct 2026, 23:24 UK

Setup

Inspect block import, sync, RPC, light verification, database restoration and fast paths.

Steps

  1. Try bypassing validation via each path with a proof rejected by the normal path.
  2. Remove the dominant prover/aggregator and have independent replacements process available inputs.
  3. Attempt to use proof-production status as ordering, voting or finality authority.

Accept

No bypass accepts invalid work; proofs alone confer no unauthorised consensus control. Replacement and pause behaviour meet F0/P07/P08 without privileged keys or a trusted aggregator shortcut.

Evidence the case requires

Path coverage report; bypass corpus; replacement run; authority checks.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
enforced-proving-20261008-03
Design status
NOT RUN
Standard page
41
Plan pages
16, 20, 24, 25, 36, 37
09CAP

Sustained proving and delivery

A correct fast shard is only one stage; capacity, latency, payment and retries must work together.

NOT RUN
Owner
Proving lead + independent operators
Gate
Technical readiness / commercial track
Fixtures
F3 meaningful workload catalogue; F4 network; F8 external job harness
Plan pages
17, 18, 24, 25
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
CAP-01Reproduce the historical consumer-shard resultPriority GATEProfile P02, P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Recover the exact source-era workload/build if available; keep it separate from the release-candidate workload.

Steps

  1. Attempt independent reproduction of the 4,717,439-cycle workload and reported 3060/4060/4070 results.
  2. Record proof format, memory, energy, host and whether aggregation/compression are included.
  3. Repeat on the final release and label all configuration changes.

Accept

Historical figures are either reproduced within P02 tolerance or corrected/labelled non-reproduced. Release acceptance uses the current complete workload, never an unmatched historical time or a smaller substituted shard.

Evidence the case requires

Historical/current manifests; proof verification; timing and memory records.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
42
Plan pages
17, 18, 24, 25
CAP-02Prove on the actual mining configurationPriority BLOCKERProfile P01, P06, P07NOT RUNEvidence recordLast run 8 Oct 2026, 23:22 UK

Setup

Use final dataset sizes, registers, clocks, drivers and proof pipeline on every advertised proving tier.

Steps

  1. Run mining alone, proving alone, concurrent execution and supported time-sharing.
  2. Measure wall energy, memory headroom, reloads, proof latency and forgone accepted mining work.
  3. Induce memory pressure and GPU task failure without losing wallet control.

Accept

Every advertised mode completes correctly and meets P06/P07. Net output includes opportunity cost; unsupported concurrency is not claimed. Mining-only vendor support remains separately labelled.

Evidence the case requires

Four-mode results; OOM/failure logs; memory and opportunity-cost ledger.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Run
v607-floor-memory-20261008T2059Z
Design status
NOT RUN
Standard page
42
Plan pages
17, 18, 24, 25
CAP-03Measure the entire request-to-payment pathPriority GATEProfile P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Assign a unique job ID and immutable timestamps to every stage of F3/F8 jobs.

Steps

  1. Record request, input availability, assignment, execution, shard proof, aggregation, verification, delivery and payment.
  2. Compare monotonic elapsed time with any protocol/DAA clock and document their relationship.
  3. Reconcile failed, censored, retried and abandoned jobs with the original request denominator.

Accept

No hidden stage or missing job; latency distributions and cost cover the complete path. Delivery, finality and payment are reported separately; protocol seconds are not silently relabelled wall-clock seconds.

Evidence the case requires

Stage event ledger; clock calibration; end-to-end latency/cost report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
42
Plan pages
17, 18, 24, 25
CAP-04Sustain meaningful load without queue growthPriority GATEProfile P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Freeze W: payload mix, input sizes, execution work and per-hour demand; prohibit tiny-workload substitution.

Steps

  1. Run 72 hours at W and a separate 24 hours at 1.2W on the declared fleet.
  2. Measure arrival/completion counts, backlog trend, oldest-job age, deadlines and all retries.
  3. Use held-out workloads and an independent observer to detect discarded or delayed requests.

Accept

P07 completion, tail-latency and bounded-backlog criteria hold. Capacity is stated for the tested W/fleet, not as universal TPS. A queue that grows indefinitely or shrinks through silent loss fails.

Evidence the case requires

Request/completion reconciliation; backlog series; held-out results; observer report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
43
Plan pages
17, 18, 24, 25
CAP-05Overload and recover without false acceptancePriority BLOCKERProfile P01, P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Start at W and inject 2W for 15 minutes with valid and invalid jobs, then return to W.

Steps

  1. Observe admission, explicit backpressure, reservations and deadline estimates.
  2. Track accepted jobs to valid completion or the pre-agreed failure/refund outcome.
  3. Measure recovery time and ensure ordinary users are not silently starved.

Accept

P07 overload policy and recovery limits hold; no accepted job vanishes or earns an invalid reward. Rejected demand is reported separately from delivery success, preventing denominator manipulation.

Evidence the case requires

Overload timeline; admission/refund logs; backlog-drain proof.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
43
Plan pages
17, 18, 24, 25
CAP-06Calibrate assignment windows to paid completionPriority GATEProfile P07, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use a heterogeneous proving fleet, including the slowest advertised consumer tier.

Steps

  1. Measure actual completion distributions with network delay, competing load and failed attempts.
  2. Test the chosen exclusive window, open claiming and faster challengers after expiry.
  3. Compare assignment frequency, paid completions and wasted work by tier.

Accept

P07 fairness and wasted-work limits hold for advertised tiers. A provisional 10-DAA-second window is not treated as approved. Fair assignment counts alone cannot pass; payment outcomes and operator margins matter.

Evidence the case requires

Window sweep; paid-completion distribution; wasted-work and margin report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
43
Plan pages
17, 18, 24, 25
CAP-07Reassign work when inputs or providers disappearPriority BLOCKERProfile P01, P07, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Remove input providers, assigned provers and the dominant aggregator independently and together.

Steps

  1. Have replacement operators retrieve authenticated inputs without founder files.
  2. Retry expired assignments while preserving idempotent reward and customer outcomes.
  3. Restore providers and test late submissions racing with replacements.

Accept

P07/P08 replacement deadlines hold when availability assumptions permit. Otherwise a truthful bounded pause/refund occurs; no fake proof, double payment or hidden privileged input source is used.

Evidence the case requires

Failure schedule; input hashes; reassignment and payout ledger; recovery trace.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
44
Plan pages
17, 18, 24, 25
CAP-08Deliver customer-verifiable output at scalePriority BLOCKERProfile P01, P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Run the external workload using a customer-controlled verifier and independently operated workers.

Steps

  1. Verify every delivered proof against the contracted program and input commitment.
  2. Reject wrong-format, stale and partial deliveries; test customer retry and delivery failure.
  3. Reconcile delivery, acceptance, payment and refund records without exposing private inputs publicly.

Accept

P07 delivery performance and exact validity hold. Payment depends on the contracted correct result; a valid proof for the wrong job is not a successful delivery.

Evidence the case requires

Customer verification log; proof-format contract; settlement reconciliation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
44
Plan pages
17, 18, 24, 25
10INC

Rewards, incentives and selfish operators

Assume operators optimise their own returns. Do not depend on the official client choosing a less profitable task.

NOT RUN
Owner
Protocol economics + proving leads
Gate
G4 / G5 G4 G5
Fixtures
F0 fee/reward rules; F4 adversarial operators; F7 incentive models
Plan pages
13, 16, 17, 18, 24, 26
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
INC-01Reconcile issuance, fees, burns and recipientsPriority BLOCKERProfile P01, P12NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Use a deterministic short chain containing all reward types, fee paths and rounding cases.

Steps

  1. Calculate balances, total supply changes, burns and distributions independently.
  2. Execute identical blocks natively and through the proving path.
  3. Test zero, minimum, maximum and transition-boundary values plus malformed producer accounting.

Accept

Conservation and recipient rules match F0 exactly; no inflation, rounding leakage or duplicate reward. Fee-table and prose discrepancies are resolved before the run, not guessed by the tester.

Evidence the case requires

Independent accounting ledger; balance/supply diffs; boundary vectors.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
45
Plan pages
13, 16, 17, 18, 24, 26
INC-02Keep revenue streams and claims separatePriority BLOCKERProfile P01, P12, P14NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Prepare jobs and blocks producing mining income, internal proof rewards and external payments.

Steps

  1. Trace money from source to operator, protocol, developer and any burn.
  2. Compare node records, settlement records and Ember displays.
  3. Attempt to classify testnet rewards, reimbursed purchases or token appreciation as external customer revenue.

Accept

Every stream reconciles and is labelled correctly. No double-counted revenue or fabricated protocol demand; mining subsidy and external service income remain distinct in dashboards and ECO.

Evidence the case requires

Money-flow register; UI reconciliation; rejected classifications.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
45
Plan pages
13, 16, 17, 18, 24, 26
INC-03Let a modified client choose the most profitable taskPriority GATEProfile P07, P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Permit independent schedulers to mine, prove internally, prove externally or switch off.

Steps

  1. Publish common costs and vary relative task rewards, memory pressure and switching costs.
  2. Run clients that ignore the official scheduling recommendation.
  3. Measure realised operator margin, internal capacity and network progress.

Accept

Required P12 sustainable worlds maintain paid essential capacity without compelled altruism. Profitability and availability are based on realised outcomes, including switching and wasted work.

Evidence the case requires

Scheduler source/policies; switching traces; capacity and margin series.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
45
Plan pages
13, 16, 17, 18, 24, 26
INC-04Survive external-demand spikes and token declinesPriority GATEProfile P07, P08, P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use F7 scenarios with 10x external job offers and token-denominated mining-income shocks.

Steps

  1. Allow miners/provers to switch freely under the declared reward and difficulty rules.
  2. Observe hash participation, proof backlog, fees and recovery without an administrator.
  3. Repeat with external demand dropping to zero and with a dominant operator withdrawn.

Accept

Mandatory viable worlds meet P07/P12; stressed nonviable worlds fail or pause safely with truthful status. No emergency rule, fabricated demand or unofficial subsidy is inserted to force a pass.

Evidence the case requires

Shock timeline; fee/hash/capacity paths; failure-region report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
46
Plan pages
13, 16, 17, 18, 24, 26
INC-05Contain job reservation and identity-splitting abusePriority BLOCKERProfile P01, P07, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Freeze the actual assignment/payment mechanism; do not assume unimplemented collateral or identity controls.

Steps

  1. Create many worker identities, reserve jobs, withhold proofs and submit late results.
  2. Attempt free option-taking, duplicate work rewards and displacement of honest assignments.
  3. Price attacker costs and observe honest completion under the approved abuse load.

Accept

F0 rules and P07 service limits hold under the declared adversary. Identity splitting does not create unauthorised rewards or control; any unmitigated starvation path blocks the permissionless-service claim.

Evidence the case requires

Attack clients; assignment trace; cost-to-disrupt analysis; honest-user outcomes.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Standard page
46
Plan pages
13, 16, 17, 18, 24, 26
INC-06Test difficulty and timestamp manipulationPriority BLOCKERProfile P01, P08, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use the actual adjustment algorithm and consensus timestamp rule with independent miners.

Steps

  1. Inject large hashrate arrivals/departures, periodic selective mining and boundary-timed bursts.
  2. Try allowed and invalid timestamp skew, withheld blocks and replayed work.
  3. Observe block intervals, reward allocation and recovery after hashrate stabilises.

Accept

Invalid inputs are rejected; valid adversarial strategies remain within F0/P08 bounds and are priced in ECO. No unexplained reward amplification, permanent stall or conflicting accepted work.

Evidence the case requires

Difficulty trace; timestamp corpus; revenue analysis; independent rule review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Design status
NOT RUN
Standard page
46
Plan pages
13, 16, 17, 18, 24, 26
INC-07Resist self-dealing fees and fake proving demandPriority BLOCKERProfile P01, P12, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use self-funded operators and related customer identities in the isolated economic model/network.

Steps

  1. Cycle funds through jobs, tips, developer shares and rebates to seek net reward extraction.
  2. Attempt to inflate external-demand metrics without genuine unrelated customer expenditure.
  3. Reconcile all counterparties and net cash contribution rather than gross transaction volume.

Accept

No unauthorised subsidy extraction or metric inflation passes. Related-party volume is disclosed/excluded from P14; net external cash and legitimate protocol incentives are reported separately.

Evidence the case requires

Circular-flow tests; ownership/conflict review; net-cash reconciliation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Standard page
47
Plan pages
13, 16, 17, 18, 24, 26
INC-08Quantify provider and supplier failure concentrationPriority GATEProfile P08, P11, P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Model control of hashing, signing, proving, aggregation and hardware supply separately.

Steps

  1. Remove each largest operational dependency and combine correlated failures.
  2. Measure replacement cost/time and whether essential roles share hidden ownership.
  3. Compare results with the approved fault model and no-rescue exercise.

Accept

No hidden single dependency defeats the claimed independence; within-tolerance withdrawals recover under P08/P11. Hardware supply concentration is disclosed without equating vendor sales to operator voting control.

Evidence the case requires

Role/ownership map; dependency removals; recovery and concentration report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
47
Plan pages
13, 16, 17, 18, 24, 26
11FIN

Consensus safety and recovery

Test safety under the stated fault bounds. Demand liveness only when synchrony and participation assumptions actually hold.

NOT RUN
Owner
Consensus lead + independent formal/security review
Gate
G5 / technical readiness G5
Fixtures
F0 exact fault model; F4 real-node partitions; F5 certificates and historical failures
Plan pages
19, 21, 24, 25
8 cases: 1 passed under the standard, 0 running with team evidence, 7 not run, 0 deferred
FIN-01Agree on ordering, work and executed statePriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Use real fork-choice/DAG handling and independent miners, not only a simplified simulator.

Steps

  1. Generate concurrent branches, delayed blocks, duplicates and invalid work with deterministic seeds.
  2. Compare selected ordering, accumulated work, transaction execution and state roots after delivery converges.
  3. Replay from independent checkpoints and from genesis where practical.

Accept

Honest nodes converge under F0 assumptions with exact roots and rewards. No duplicated work accounting or undocumented ordering dependence; simulator-only success cannot substitute.

Evidence the case requires

Block/ordering corpus; root/work diffs; real-node replay logs.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fast-time lane (a8be71a0db962911c)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
48
Plan pages
19, 21, 24, 25
FIN-02Attack finality with split honest populationsPriority BLOCKERProfile P01, P08PASSEvidence recordLast run 9 Oct 2026, 02:02 UK

Setup

Use the source-discussed 40/40/20 weight split, plus threshold-boundary splits under F0.

Steps

  1. Let the 20% adversarial group sign conflicting histories while honest groups are partitioned.
  2. Delay messages and eligibility updates independently; keep total historical weights auditable.
  3. Try to form two certificates and reconnect nodes to observe accepted final history.

Accept

No conflicting final certificates are accepted within the declared fault bound. A safe pause is valid when quorum is unavailable; making progress on both sides is not required.

Evidence the case requires

Signed votes; certificate attempts; voter-table snapshots; safety checker output.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
fin-203-20261009T0127Z
Design status
NOT RUN
Standard page
48
Plan pages
19, 21, 24, 25
FIN-03Cross authority expiry in a long partitionPriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Recover historical expiry failures where available; use the actual current authority-transition rules.

Steps

  1. Partition for 31, 35, 60 and 90 logical days and around every retention/expiry boundary.
  2. Attempt independently renewed authority sets and conflicting checkpoint locks.
  3. Repeat selected boundary cases on real nodes with accelerated timers explicitly labelled.

Accept

Authority continuity remains authenticated and no conflicting final history appears within F0 assumptions. A timeout is not accepted as proof absent voters ceased to exist. Compressed time is not multi-month field evidence.

Evidence the case requires

Expiry timeline; table/certificate history; historical regression tests.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
48
Plan pages
19, 21, 24, 25
FIN-04Stop signing while mining continuesPriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Remove enough signing participation to invalidate the liveness assumption without forging votes.

Steps

  1. Continue mining and execution, cross seed boundaries and monitor proof queues.
  2. Check which user-visible states advance and which remain unfinalised.
  3. Restore eligible weight and bounded message delay, then verify recovery.

Accept

No false finality or fabricated authority. Behaviour matches F0 during the pause and P08 after assumptions return; unfinished transactions are not displayed as irreversible.

Evidence the case requires

Signing/mining trace; UI/RPC states; recovery roots and timing.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
49
Plan pages
19, 21, 24, 25
FIN-05Authenticate voter-set changes and pooled keysPriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Use normal transitions, pool members retaining keys and malicious substitution attempts.

Steps

  1. Alter voter weights, membership proofs, miner/pool identity bindings and prior-certificate links.
  2. Race updates across boundaries and replay old signed changes.
  3. Have a new node verify the authority chain from its declared trust anchor.

Accept

Only correctly authenticated changes are accepted; weights cannot be double-counted or redirected by a pool. All honest nodes agree on the active authority set for each certified point.

Evidence the case requires

Authority-chain fixtures; substitution attacks; new-node verification log.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
49
Plan pages
19, 21, 24, 25
FIN-06Analyse old-key compromise and long-range historiesPriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Freeze assumptions about key erasure, retained weights, trust anchors and offline recovery.

Steps

  1. Use previously eligible keys to build alternative histories after their operators disappear.
  2. Present these histories to recently offline and newly joining clients.
  3. Test replayed certificates, stale anchors and compromised signer subsets.

Accept

Acceptance matches the explicit security model with no hidden trusted recovery step. Any reliance on a recent trusted anchor is disclosed and tested; hashpower assumptions cannot replace old-key analysis.

Evidence the case requires

Long-range corpus; trust-anchor policy; key-compromise review; client results.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
49
Plan pages
19, 21, 24, 25
FIN-07Recover deterministically after reconnection and crashPriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 9 Oct 2026, 02:02 UK

Setup

Combine partitions with node crash, partial writes, restarts and proof backlog.

Steps

  1. Reconnect networks under bounded latency and restore required honest participation.
  2. Verify fork choice, unfinalised reorganisation, finality, reward rollback and proof reassignments.
  3. Compare all honest nodes and customer-visible receipts after recovery.

Accept

P08 recovery holds without reversing a previously valid final guarantee. Only permitted unfinalised state is reorganised; no duplicate rewards or inconsistent receipt statuses survive.

Evidence the case requires

Recovery timelines; roots/certificates; payout rollback; customer-state reconciliation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
fin-203-20261009T0127Z
Design status
NOT RUN
Standard page
50
Plan pages
19, 21, 24, 25
FIN-08Combine boundaries, faults and adversarial schedulingPriority BLOCKERProfile P01, P08NOT RUNEvidence recordLast run 9 Oct 2026, 02:02 UK

Setup

Use an independent model checker/scheduler and production-node scenarios from F4.

Steps

  1. Combine epoch changes, authority transitions, mining churn, data delays and prover/aggregator loss.
  2. Explore bounded adversarial message schedules and minimise any counterexample.
  3. Replay model findings on real code and have an independent reviewer assess uncovered states.

Accept

No unresolved safety failure; liveness claims hold only within declared assumptions and P08. Model bounds and untested schedules are published, not described as proof over every possible execution.

Evidence the case requires

Model/spec artifacts; schedule corpus; replay evidence; independent assessment.

Method
Model checking + real-node testing
Cadence
Release candidate; repeat after relevant changes
Owner
fast-time lane (a8be71a0db962911c)
Run
fin-203-20261009T0127Z
Design status
NOT RUN
Standard page
50
Plan pages
19, 21, 24, 25
12VER

Wallets, receipts and data availability

Verify the exact property shown to the user. An inclusion proof, execution proof and finality certificate are not interchangeable.

FAIL
Owner
Wallet + light-client lead; independent security review
Gate
Technical readiness / claimed options
Fixtures
F0 trust/availability model; F5 malformed roots, receipts and authority chains
Plan pages
20, 25, 35, 37
8 cases: 0 passed under the standard, 0 running with team evidence, 3 failed, 5 not run, 0 deferred
VER-01Authenticate light-client bootstrapPriority BLOCKERProfile P01, P09FAILEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Give a clean client malicious RPC responses, fabricated voter tables and valid-looking signatures.

Steps

  1. Start from the approved trust anchor and verify every required link to the advertised state.
  2. Substitute otherwise well-formed but unauthorised keys, weights and checkpoints.
  3. Remove the bootstrap service and use another independently operated source.

Accept

The client rejects unauthorised authority and discloses any trust anchor. Signatures over a node-supplied table do not by themselves pass; missing authentication never silently degrades to trusted RPC.

Evidence the case requires

Bootstrap corpus; trust-chain trace; fail-closed tests.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
51
Plan pages
20, 25, 35, 37
VER-02Verify evolving authority and execution statementsPriority BLOCKERProfile P01, P09FAILEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Use valid state proofs paired with wrong execution statements or stale authority histories.

Steps

  1. Cross voter and verifier changes with offline clients returning after long intervals.
  2. Alter roots, aggregate identity and proof/public-input bindings independently.
  3. Check local verification rather than merely a server-reported verified flag.

Accept

All advertised proof checks occur locally or the remaining trust is explicitly disclosed. Wrong roots and unauthenticated authority are rejected; unsupported verification paths are not claimed.

Evidence the case requires

Client verification trace; corrupted inputs; offline/upgrade results.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
51
Plan pages
20, 25, 35, 37
VER-03Prove successful payment rather than inclusionPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Create successful, reverted, wrong-asset, wrong-recipient and wrong-amount transfers.

Steps

  1. Generate receipts for included transactions, including failures and replaced/unfinalised transactions.
  2. Verify execution status plus asset, recipient, amount and canonical-state/receipt commitment.
  3. Replay the receipt on another chain and after an allowed unfinalised reorganisation.

Accept

Only the actual successful, correctly bound transfer is labelled payment proof. Inclusion-only receipts are labelled as such; no node-reported success flag substitutes for authenticated outcome.

Evidence the case requires

Payment fixture corpus; receipt verification; merchant-facing status checks.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
51
Plan pages
20, 25, 35, 37
VER-04Bound cross-chain oracle trust and replayPriority BLOCKERProfile P00, P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

For a claimed oracle, freeze destination verifier, authority updates, accepted proof types and replay policy.

Steps

  1. Try deployer-substituted keys, stale certificates, unchecked signatures and wrong source/destination identities.
  2. Exercise legitimate authority updates and source reorganisations under the approved model.
  3. Measure gas/cost with realistic header sets and test disabled/unavailable verification.

Accept

The oracle enforces its declared trust model and fails closed. Deployer privileges and unavailable guarantees are explicit; no trustless-bridge claim exceeds the checks performed. Excluded oracle scope earns no pass credit.

Evidence the case requires

Oracle code/parameters; attack cases; cost report; privilege disclosure.

Method
Claimed-option verification
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
52
Plan pages
20, 25, 35, 37
VER-05Reconstruct required state without founder storagePriority BLOCKERProfile P01, P08, P09FAILEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Remove founder archival/input services and start an independent operator from the documented entry point.

Steps

  1. Fetch authenticated blocks, state/proof inputs and any required witnesses from permitted peers.
  2. Rebuild the expected state and continue validation/proving.
  3. Measure bandwidth, disk, time and retention requirements against advertised operator budgets.

Accept

Required data can be obtained and verified within the declared availability model. Hidden archives or unpublished files block independence. A valid execution proof alone does not satisfy this test.

Evidence the case requires

Download/reconstruction logs; data hashes; resource costs; dependency inventory.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
52
Plan pages
20, 25, 35, 37
VER-06Detect withholding, corruption and stale dataPriority BLOCKERProfile P01, P08, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Serve valid commitments with missing data, corrupted chunks, stale witnesses and conflicting peer replies.

Steps

  1. Attempt to make a validator or light client accept an unavailable or incorrect state under F0.
  2. Test retrieval from independent peers and expiry/retry policy.
  3. Restore data and check that recovery cannot alter an already verified commitment.

Accept

No unjustified available/verified status; safety and admission rules match F0. Recovery is bounded where assumptions permit, and unavailable-data states remain visible instead of hidden behind proofs.

Evidence the case requires

Withholding corpus; peer retrieval traces; availability/status checks.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
52
Plan pages
20, 25, 35, 37
VER-07Protect wallet keys, signing and recoveryPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use test-only keys, encrypted backups and clean replacement devices; no real user funds.

Steps

  1. Attempt secret access from proving jobs, logs, crash dumps, clipboard and telemetry paths.
  2. Verify transaction destination/amount before signing; test backup/restore and wrong-password handling.
  3. Upgrade and recover without silently changing signing authority or exposing seed material.

Accept

No unintended secret disclosure or unauthorised signature. Supported recovery restores the correct keys and accounts; users receive explicit risk/backup information. Logs are sanitised without hiding security evidence.

Evidence the case requires

Security review; canary-secret tests; signing fixtures; restore journey.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Design status
NOT RUN
Standard page
53
Plan pages
20, 25, 35, 37
VER-08Keep every user-facing state truthfulPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Create included-only, executed, proven, finalised, reverted, stale and paused examples.

Steps

  1. Compare explorer, wallet, receipt, RPC and customer API labels against authenticated evidence.
  2. Interrupt finality and proof services and observe refresh/reconnect behaviour.
  3. Check statements about privacy, Ethereum security and device support.

Accept

No stronger state is implied than verified; stale data is marked and failures are actionable. EVM compatibility is not labelled Ethereum security, and ZK technology is not automatically labelled transaction privacy.

Evidence the case requires

Cross-surface screenshots/logs; state mapping; claim review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
53
Plan pages
20, 25, 35, 37
13OPS

Independent operation and release security

A permissionless specification must remain operational without privileged infrastructure or unsafe automatic updates.

NOT RUN
Owner
Operations + release leads; independent operators
Gate
G5 G5
Fixtures
F4 isolated multi-operator network; F0 signed releases; F9 telemetry
Plan pages
21, 24, 25, 26
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
OPS-01Run the complete no-founder exercisePriority BLOCKERProfile P07, P08, P11NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use the P11 independent network, adequate honest participation and enough non-founder capacity for W.

Steps

  1. Remove founder miners, provers, aggregators, RPC, DNS/bootstrap dependencies and private support access.
  2. Run the full P11 period while crossing real and separately labelled accelerated boundaries.
  3. Introduce scheduled faults and have independent operators recover using published instructions.

Accept

No founder action, secret file, privileged key or emergency anti-chip rule is needed. P07/P08 outcomes hold within assumptions; any intervention is recorded as a failed no-rescue run, not erased.

Evidence the case requires

Operator roster/conflict checks; dependency removals; full activity/intervention log.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Design status
NOT RUN
Standard page
54
Plan pages
21, 24, 25, 26
OPS-02Diversify bootstrap and resist peer isolationPriority BLOCKERProfile P01, P08, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Start nodes without the default bootstrap host and give others adversarial peer lists.

Steps

  1. Attempt eclipse through peer concentration, stale discovery, poisoned DNS and repeated identities in an isolated lab.
  2. Use independent documented discovery paths and validate returned chain data.
  3. Measure synchronisation, peer diversity and recovery after benign connectivity returns.

Accept

No unauthenticated history is trusted; bootstrap has no hidden single-provider requirement. Isolation is detected/contained according to F0 and recovery meets P08 when assumptions return.

Evidence the case requires

Peer/discovery traces; eclipse scenarios; startup and recovery evidence.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Design status
NOT RUN
Standard page
54
Plan pages
21, 24, 25, 26
OPS-03Separate update distribution from consensus authorityPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 9 Oct 2026, 11:17 UK

Setup

Use test signing keys and clean desktop/node installations with valid, stale and malicious packages.

Steps

  1. Offer signed updates with unexpected consensus rules, downgraded binaries and corrupted payloads.
  2. Test explicit operator acceptance and the published signing-key incident procedure.
  3. Confirm that distribution-key possession cannot independently activate new consensus rules.

Accept

Tampering/unauthorised rollback is rejected; updates do not silently transfer authority. Approved acceptance and activation are separate. No test touches production signing material.

Evidence the case requires

Package corpus; approval/activation traces; compromised-key rehearsal.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Run
site-manifest-20261009-02
Design status
NOT RUN
Standard page
54
Plan pages
21, 24, 25, 26
OPS-04Recover nodes from crash and storage damagePriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Use production database/snapshot paths with controlled interrupted writes and corrupted test storage.

Steps

  1. Crash during import, proof acceptance, reward application and snapshot generation.
  2. Restore from independently verified snapshots or re-sync through documented procedures.
  3. Compare roots, certificates, balances and processed-job IDs with an unaffected node.

Accept

No corrupt snapshot is trusted, no duplicate payout and no loss of authenticated final state. Recovery meets P08 where data is available; ambiguous corruption fails closed and is actionable.

Evidence the case requires

Crash schedule; snapshot hashes; root/balance diffs; recovery timing.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
55
Plan pages
21, 24, 25, 26
OPS-05Isolate untrusted proving workloadsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Run hostile test jobs with secret canaries and restrictive worker permissions.

Steps

  1. Attempt filesystem escape, process spawning, resource exhaustion, network access and key-store reads.
  2. Crash workers and inspect host, wallet and node availability plus dump/log contents.
  3. Retry on every supported isolation backend and check dependency vulnerability handling.

Accept

No secret leakage or unauthorised host action; P09 resource containment holds. Worker failure does not compromise validator/wallet authority; unsupported isolation is not marketed as safe execution.

Evidence the case requires

Sandbox penetration report; canary logs; resource limits; host-integrity checks.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Design status
NOT RUN
Standard page
55
Plan pages
21, 24, 25, 26
OPS-06Contain malicious network and API trafficPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Use an authorised isolated load environment with declared resource and request-rate budgets.

Steps

  1. Send malformed headers, proofs, oversized messages, floods and invalid peer sequences.
  2. Measure legitimate traffic, memory/disk growth and validator CPU use.
  3. Test limit resets, peer reconnect and graceful degradation without disabling validation.

Accept

P09 abuse budgets hold; no unbounded allocation, persistent crash or invalid acceptance. Backpressure is visible and honest users retain the specified service at admitted load.

Evidence the case requires

Load/corpus manifests; resource series; valid-traffic metrics; incident traces.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
55
Plan pages
21, 24, 25, 26
OPS-07Detect failures with usable evidence and runbooksPriority GATEProfile P09, P10NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Define alerts for invalid acceptance, conflicting finality, backlog, data loss, payout mismatch and stale status.

Steps

  1. Inject one instance of each monitored failure in the lab.
  2. Have an unaffiliated operator diagnose it using only emitted evidence and published instructions.
  3. Test redaction, metric freshness and duplicate-alert suppression without suppressing serious failures.

Accept

P10 alert/detection limits hold; every blocker produces actionable evidence. Monitoring does not leak secrets or mislabel intentional safe pauses as successful finality.

Evidence the case requires

Alert matrix; detection timelines; independent runbook exercise.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Design status
NOT RUN
Standard page
56
Plan pages
21, 24, 25, 26
OPS-08Repeat independent operation across releasesPriority BLOCKERProfile P00, P08, P11NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use a clean previous supported version and the final candidate with independent operators.

Steps

  1. Perform documented rolling upgrade, rollback of non-consensus software where allowed and resynchronisation.
  2. Cross activation with mixed versions and unavailable founder distribution hosts.
  3. Re-run affected gates after changes and preserve prior failures and incident lessons.

Accept

No undocumented privileged migration or automatic consensus rewrite. All affected evidence is refreshed; P11 no-rescue results remain tied to the final release, not an earlier build.

Evidence the case requires

Upgrade/replay logs; invalidation map; repeated gate signatures.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Design status
NOT RUN
Standard page
56
Plan pages
21, 24, 25, 26
14UX

Ember, payouts and operator control

Successful participation must be practical for ordinary owners without hidden custody or loss of consensus authority.

NOT RUN
Owner
Desktop product + pool leads; independent usability study
Gate
Operator readiness / G5 G5
Fixtures
F2 supported desktops; F8 user study; F4 honest/malicious pools
Plan pages
14, 21, 25, 26
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
UX-01Onboard ordinary owners on native desktop appsPriority GATEProfile P10NOT RUNEvidence recordLast run 8 Oct 2026, 21:42 UK

Setup

Recruit the P10 first-time user cohort across Windows and macOS using supported physical hardware.

Steps

  1. Observe install, hardware detection, safety explanation and first accepted work without staff intervention.
  2. Record download/data preparation separately as well as complete end-to-end time.
  3. Test unsupported hardware and insufficient memory messaging rather than forcing a failed start.

Accept

P10 completion/time targets hold with no unsafe default or concealed prerequisite. The product is tested as the actual desktop app, not only a browser preview.

Evidence the case requires

Consent-based study records; task timings; failure reasons; compatibility outcomes.

Method
Independent observed user study
Cadence
Release candidate; repeat after relevant changes
Owner
update-return lane (a22d765a2e0355a9f)
Run
ux-01-20261008-win-2.0.0
Design status
NOT RUN
Standard page
57
Plan pages
14, 21, 25, 26
UX-02Make pause, stop and safe tuning reliablePriority BLOCKERProfile P01, P10NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Run mining/proving on active desktops under contention and safe thermal stress.

Steps

  1. Use pause, stop, power limit, task selection and emergency local shutdown controls.
  2. Crash or restart the UI while workers run and verify ownership of background processes.
  3. Restore the original hardware settings and test power-saving/low-battery behaviour where supported.

Accept

P10 control latency and safe-state requirements hold. Stopping does not strand an uncontrolled process; tuning never depends on unsafe settings or silent privilege escalation.

Evidence the case requires

Control timings; process/settings audit; restart and safety traces.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
57
Plan pages
14, 21, 25, 26
UX-03Show net earnings and compatibility honestlyPriority BLOCKERProfile P01, P10, P12NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Use known rewards, fees, energy readings, retries and operator-entered tariffs.

Steps

  1. Compare mining, internal proof and external proof income with authoritative ledgers.
  2. Show gross/net estimates, measurement boundaries, tariff assumptions and payout status.
  3. Test stale data, losses, negative margins and mining-only versus proving-compatible devices.

Accept

P10 reconciliation limits hold and uncertainty is visible. No guaranteed profits, fabricated fiat price or inferred proving support; provisional earnings are not shown as settled payments.

Evidence the case requires

UI/ledger comparisons; tariff fixtures; stale/negative examples.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
57
Plan pages
14, 21, 25, 26
UX-04Pay small operators without hidden custodyPriority BLOCKERProfile P01, P10NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Use ordinary single-card balances and the actual pooling/payment path.

Steps

  1. Earn, request/receive payment, disconnect and reconnect; include low balances, fees and a pool outage.
  2. Attempt redirection, delayed accounting and withdrawal of another user's entitlement.
  3. Reconcile displayed balances with canonical entitlement and actual settlement.

Accept

P10 payout limits hold for the declared small-operator case. No unauthorised custody, redirection or unexplained loss; thresholds and fees are disclosed rather than masked by larger test balances.

Evidence the case requires

Single-card payout ledger; pool failure record; custody/authorisation review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
pool design seat (a3832b1c3b274b310)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
58
Plan pages
14, 21, 25, 26
UX-05Keep voting keys with the miner through poolingPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 21:48 UK

Setup

Use an honest pool and a modified pool that replaces worker identity or voting credentials.

Steps

  1. Verify the consensus binding from performed work to the miner's retained key.
  2. Attempt substitution, replay and reassignment without the miner's authorisation.
  3. Leave the pool and verify retained voting/finality rights under F0.

Accept

No silent transfer of governance/finality authority. If the protocol cannot establish retained keys, this requirement fails; a pool-protocol name or user-interface promise does not pass.

Evidence the case requires

Work/key binding vectors; malicious-pool attempts; leave-pool authority check.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
pool design seat (a3832b1c3b274b310)
Run
pool-2.0-20261008-03
Design status
NOT RUN
Standard page
58
Plan pages
14, 21, 25, 26
UX-06Verify actual miner-selected work templatesPriority BLOCKERProfile P01, P10NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Provide a pool interface with declared job-declaration support and independent miner templates.

Steps

  1. Submit miner-selected valid transaction templates and verify what is actually hashed and accepted.
  2. Have a pool substitute or censor templates and test local verification/fallback.
  3. Measure payout and acceptance consequences without moving authority to the pool.

Accept

The advertised selection control exists in accepted work, not only configuration. Undisclosed substitution is detected; supported independent operation remains practical under P10.

Evidence the case requires

Template commitments; accepted-block evidence; malicious-pool/fallback report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
58
Plan pages
14, 21, 25, 26
UX-07Expose actionable failures and safe updatesPriority BLOCKERProfile P09, P10NOT RUNEvidence none yetLast run 9 Oct 2026, 01:33 UK

Setup

Create failed proofs, memory pressure, expired jobs, missing payouts and available software updates.

Steps

  1. Ask independent users to identify the issue, stop safely and follow the recommended action.
  2. Test explicit update approval, version visibility and a failed/corrupt update.
  3. Confirm diagnostic exports remove keys and private inputs while retaining useful evidence.

Accept

P10 task-success requirements hold; no silent update or false success state. Recovery instructions work on supported desktops and secret canaries never enter exported logs.

Evidence the case requires

Observed tasks; update traces; sanitised export tests.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Run
202-5d53a591-1176efb9
Design status
NOT RUN
Standard page
59
Plan pages
14, 21, 25, 26
UX-08Publish competitive accessible softwarePriority GATEProfile P02, P10NOT RUNEvidence none yetLast run 9 Oct 2026, 08:36 UK

Setup

Provide open documented builds, tuning parameters and known fee conditions for all supported platforms.

Steps

  1. Compare Ember against independently optimised permissible implementations on identical work.
  2. Measure efficiency, fees, false rejection, installation and update transparency.
  3. Scan for hidden developer fees, hardware whitelists, per-address privilege or undisclosed remote controls.

Accept

P10 relative-efficiency limits hold and all fees/privileges are explicit. No self-reported device tier earns consensus advantage. A superior external implementation triggers investigation, not selective exclusion.

Evidence the case requires

Matched software comparison; code/config review; fee/privilege inventory.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
site-gate-20261009-01
Design status
NOT RUN
Standard page
59
Plan pages
14, 21, 25, 26
15COM

Paid demand and sustainable delivery

Devnet payouts and subsidised pilots demonstrate mechanics, not independent willingness to pay.

NOT RUN
Owner
Commercial lead + independent financial/customer reviewer
Gate
Commercial evidence
Fixtures
F8 real consenting customers; F7 full service costs; private identity proofs
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
COM-01Deliver a genuine contracted proof pilotPriority GATEProfile P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Select one real external customer with a meaningful fixed workload and no required migration to Igneum.

Steps

  1. Agree program, inputs, proof format, deadline, price, failure/refund policy and verification method.
  2. Run paid jobs through ordinary independently operated infrastructure.
  3. Have the customer verify usefulness, correctness and its reason for choosing the service.

Accept

The pilot satisfies its actual contract and settles genuine external payment. Trial subsidies are disclosed and cannot satisfy the repeat-demand gate; no invented customer or testimonial.

Evidence the case requires

Redacted contract; verified jobs; settlement proof; consented customer confirmation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
60
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-02Establish independent repeat purchasingPriority GATEProfile P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use the P14 multi-customer observation period and ownership/conflict checks.

Steps

  1. Track paid purchases on distinct occasions, including refunds and stopped customers.
  2. Audit related parties, project reimbursements, token grants and circular funding.
  3. Reconcile external cash received with correctly delivered meaningful work.

Accept

P14 buyer, duration and volume minima are met without reimbursement or related-party substitution. Repeat orders are separate buying decisions, not a single payment split into many jobs.

Evidence the case requires

Anonymised buyer ledger; repeat-order dates; conflict review; net receipts.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
60
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-03Demonstrate service and operator marginsPriority GATEProfile P12, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Allocate all delivery costs, including aggregation, retries, hardware, power, host, network and support.

Steps

  1. Calculate gross contribution and fully loaded unit costs for each contracted workload.
  2. Reconcile a representative operator's realised earnings against metered costs and opportunity cost.
  3. Repeat under the declared demand and price sensitivities.

Accept

P14 contribution targets hold and at least the required operator cohort has positive realised contribution. Excluded overhead is visible; token appreciation or unpriced founder labour cannot silently create profitability.

Evidence the case requires

Unit-economics ledger; metered operator sample; allocation rules; sensitivity report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
60
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-04Meet the customer service guaranteePriority BLOCKERProfile P01, P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Observe actual delivery deadlines, validity, failure handling and support over the contracted period.

Steps

  1. Count all accepted jobs, including failed, retried and abandoned cases.
  2. Have the customer independently verify results and invoke one authorised refund/failure exercise.
  3. Compare offered capacity and quoted price with what was actually delivered.

Accept

P07 and contracted obligations hold; validity has zero accepted exceptions. Failure terms are honoured, and demand beyond capacity is explicitly refused rather than quietly omitted from metrics.

Evidence the case requires

Customer-verifier records; SLO report; refunds; promised-versus-delivered comparison.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
61
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-05Compare against the buyer's real alternativePriority GATEProfile P14, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Identify a credible alternative supplier or in-house option for the same workload, proof format and security.

Steps

  1. Obtain comparable quotes or consented measured trials at the evaluation date.
  2. Include integration, verification, deadlines and all operational costs, not only proof-generation time.
  3. Document the customer's actual trade-off without inventing unavailable comparator evidence.

Accept

P15 commercial comparison is satisfied with like-for-like scope and a evidenced purchase reason. Missing alternative data remains MISSING; it is not scored as an Igneum win.

Evidence the case requires

Dated comparison; workload/security match; customer decision record.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
61
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-06Retain buyers after the pilot and subsidy periodPriority GATEProfile P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Follow all recruited customers through the P14 observation period, including churn.

Steps

  1. Remove disclosed trial incentives before measuring repeat demand.
  2. Track renewal, expansion, cancellation reasons, unresolved incidents and buyer concentration.
  3. Review whether one affiliated or subsidised buyer dominates the apparent market.

Accept

P14 repeat/concentration conditions hold with honest denominator and churn reporting. Paying demand survives beyond a demonstration; unsatisfied or departed buyers are not removed retrospectively.

Evidence the case requires

Cohort/renewal ledger; churn notes; concentration and incentive report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
61
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-07Fund maintenance without assumed appreciationPriority GATEProfile P13NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Prepare a costed plan for development, review, infrastructure, support and incident response.

Steps

  1. Separate committed resources from revenue dependent on adoption or token price.
  2. Stress lower income and an unexpected security/operations expense.
  3. Verify responsible owners and continuity arrangements without changing fair-launch promises.

Accept

P13 committed-runway requirement holds and downside responses are documented. No uncommitted financing, rising token price or burn accounting is presented as available maintenance funding.

Evidence the case requires

Budget and commitment evidence; downside plan; owner/continuity roster.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
62
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-08Let independent developers build useful integrationsPriority GATEProfile P09, P14NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Recruit unaffiliated developers unfamiliar with unpublished implementation details.

Steps

  1. Use public docs to deploy a supported application or integrate an external proof request and verification flow.
  2. Record time, undocumented dependencies, workarounds and correctness issues.
  3. Retest after documentation fixes without founder-written hidden integration code.

Accept

P14 developer-task minimum passes on the final release; all required public instructions exist. Successful bytecode deployment alone does not count as a working application or service integration.

Evidence the case requires

Consented developer logs; public examples; issue closure; verified end-to-end journeys.

Method
Independent integration study
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
62
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
16LEAD

Comparative leadership evidence

A serious contention claim requires comparative outcomes and real adoption evidence, not just an internally green test dashboard.

NOT RUN
Owner
Independent assessment panel + product/economics reviewers
Gate
Leadership-contender decision
Fixtures
F8 peer/customer studies; full signed technical evidence; 90-day observation
Plan pages
4, 22, 25, 27, 31, 32, 33
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
LEAD-01Register a fair contemporary comparisonPriority GATEProfile P15NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Choose at least the P15 peer coverage and an evaluation date before collecting confirmatory results.

Steps

  1. Include the plan's Ravencoin, Ergo and Firo reference set where comparable, then check for other relevant current options.
  2. Freeze versions, supported hardware, methods, noninferiority margins and commercial alternatives.
  3. Publish exclusions and prohibit cross-algorithm raw-hashrate comparisons.

Accept

The protocol covers material alternatives fairly and is signed independently. A missing or non-comparable feature is not scored zero; no arbitrary universal rank is inferred from selected metrics.

Evidence the case requires

Timestamped peer protocol; source/version records; comparison/exclusion rationale.

Method
Pre-registered comparative study
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
63
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-02Demonstrate comparable operator advantagesPriority GATEProfile P02, P10, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use matched user tasks and operating conditions on the selected GPU-first networks.

Steps

  1. Measure install-to-first-accepted-work, software overhead versus each network's tuned baseline, payout friction and retained control.
  2. Measure rejection/availability under the same network conditions; report fees separately.
  3. Use blinded analysis where possible and independent runs for decisive differences.

Accept

P15 noninferiority and superiority requirements hold on meaningful comparable dimensions. No raw hashes from different algorithms are compared, and transient token price is not labelled engineering superiority.

Evidence the case requires

Matched task data; uncertainty/effect sizes; independent comparison report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
site lane (a846fd66b5403e35a)
Design status
NOT RUN
Standard page
63
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-03Substantiate the specialist-coexistence claimPriority GATEProfile P04, P12, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Assemble G1-G4 plus frozen rules and all surviving-adversary assumptions.

Steps

  1. Have independent reviewers trace each public competitiveness statement to its narrowest evidence.
  2. Separate measured GPUs, modelled silicon and economic scenarios in all summaries.
  3. Evaluate residual uncertainty, excluded technologies and the no-new-rules counterfactual.

Accept

All claimed envelopes meet P04/P12 without unsupported universal bounds. Reviewers agree the evidence supports scoped commodity competitiveness even when chips remain compatible; an exact chip-arrival probability is not inferred.

Evidence the case requires

Claim-to-evidence map; signed envelope review; limitations statement.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
63
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-04Observe ordinary-operator retention and marginsPriority GATEProfile P12, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Recruit the P16 independent cohort before observing results; use privacy-preserving evidence.

Steps

  1. Follow participation, realised margin, hardware changes, failures and reasons for leaving for 90 days.
  2. Report trial incentives separately and include every initial participant in retention denominators.
  3. Compare behaviour with matched alternatives where feasible; disclose absence of an actual downturn.

Accept

P16 retention/margin minima hold with verified independence and no removal of churned users. Simulated downturns cannot be called observed bear-market retention; historical claims stay limited to the period measured.

Evidence the case requires

Pseudonymous cohort ledger; margin/retention calculations; departure reasons.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
64
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-05Measure control and dependency concentrationPriority GATEProfile P11, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Audit operational control of mining, voting, proving, aggregation, hosting and software distribution separately.

Steps

  1. Use opt-in attestations, observed dependencies and independent corroboration; disclose uncertain common ownership.
  2. Compare concentration and provider-removal outcomes to the approved security and availability assumptions.
  3. Check that pooled payments do not hide authority concentration and hardware vendors are not equated with operators.

Accept

P11/P16 concentration requirements hold within disclosed uncertainty; unidentified control cannot be counted as independent. No single removable dependency is falsely marketed as decentralised operation.

Evidence the case requires

Control/failure-domain map; uncertainty notes; concentration/removal results.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
64
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-06Complete the reliability observation windowPriority BLOCKERProfile P01, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Observe the final candidate and approved compatible updates for the full P16 real-time period.

Steps

  1. Measure promised service availability, invalid acceptance, finality safety, payouts and incident impact.
  2. Reconcile external probes, customer records and operator logs, including maintenance and exclusions.
  3. Repeat affected critical tests after every material change; reset observation where comparability breaks.

Accept

P16 availability and safety criteria hold on live observation; no hidden downtime or compressed-time substitution. This supports the recorded window only, not multi-year operational maturity.

Evidence the case requires

90-day SLO ledger; independent probes; incident reports; change/retest history.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
64
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-07Issue an independent contender assessmentPriority GATEProfile P00, P15, P16NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Provide the full evidence packet, commercial results, comparative study and unresolved-limit register to the panel.

Steps

  1. Check every mandatory and claimed-option test, source requirement and approved threshold.
  2. Require separate signoffs for hardware/economics, security/operations and customer/operator evidence.
  3. Document dissent and challenge any inference that passing an internal checklist proves number-one rank.

Accept

Every required gate is PASS with no unresolved material challenge, critical/high defect or missing comparator/customer evidence. The panel supports a credible leadership-contender conclusion within scope, not a guaranteed rank.

Evidence the case requires

Signed assessment; full status index; dissent/limitations; approved claim wording.

Method
Independent final assessment
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
65
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-08Keep leadership claims valid after releasePriority GATEProfile P00, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Define material-change triggers and scheduled reviews before publishing the assessment.

Steps

  1. Refresh competitor, hardware-cost, demand and security evidence at the P16 cadence.
  2. Test a newly credible specialist, lost customer, major outage and verifier change against invalidation rules.
  3. Withdraw or narrow stale claims promptly while publishing the new evidence status.

Accept

Claims remain dated, scoped and revisable; material contrary evidence reopens the appropriate gate. The network may remain usable while a leadership claim is suspended. No permanent self-awarded certification.

Evidence the case requires

Review calendar; invalidation drills; versioned public claim register.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
65
Plan pages
4, 22, 25, 27, 31, 32, 33
17REV

REV: the external review's required regressions

44 regressions from 14 findings; each reads NOT RUN until its owner lane records a run

NOT RUN
Owner
the owner lanes per the dispatch table
Gate
Review findings closed
Fixtures
F0,F5
Plan pages
docs/analysis/review-2026-10-08-b/findings.json and docs/analysis/review-2026-10-08-b/dispatch.md; ids from the master traceability register
44 cases: 2 passed under the standard, 0 running with team evidence, 42 not run, 0 deferred
R2-F01-R01Valid proof A, warm cache, carried statement B: refuse exactly as a cold node does.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F01 requires (review R2 finding F01: Proof-verdict cache omits the statement being verified).

Steps

  1. Valid proof A, warm cache, carried statement B: refuse exactly as a cold node does.

Accept

Valid proof A, warm cache, carried statement B: refuse exactly as a cold node does.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, node lane
Design status
NOT RUN
Plan pages
R2-F01
R2-F01-R02Run valid/invalid contexts in both orders, concurrently and across cache eviction/restart.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F01 requires (review R2 finding F01: Proof-verdict cache omits the statement being verified).

Steps

  1. Run valid/invalid contexts in both orders, concurrently and across cache eviction/restart.

Accept

Run valid/invalid contexts in both orders, concurrently and across cache eviction/restart.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, node lane
Design status
NOT RUN
Plan pages
R2-F01
R2-F01-R03Change payout, network, kind, program ID and activation context; no accepted misbinding.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F01 requires (review R2 finding F01: Proof-verdict cache omits the statement being verified).

Steps

  1. Change payout, network, kind, program ID and activation context; no accepted misbinding.

Accept

Change payout, network, kind, program ID and activation context; no accepted misbinding.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, node lane
Design status
NOT RUN
Plan pages
R2-F01
R2-F01-R04A native two-node test must agree on block validity and payouts despite different cache histories.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F01 requires (review R2 finding F01: Proof-verdict cache omits the statement being verified).

Steps

  1. A native two-node test must agree on block validity and payouts despite different cache histories.

Accept

A native two-node test must agree on block validity and payouts despite different cache histories.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, node lane
Design status
NOT RUN
Plan pages
R2-F01
R2-F02-R01Release build cannot activate test bypass.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F02 requires (review R2 finding F02: Proof-rule infrastructure can fail open).

Steps

  1. Release build cannot activate test bypass.

Accept

Release build cannot activate test bypass.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, CI steward
Design status
NOT RUN
Plan pages
R2-F02
R2-F02-R02Missing oracle or pinned keys prevents service readiness after enforcement activation.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F02 requires (review R2 finding F02: Proof-rule infrastructure can fail open).

Steps

  1. Missing oracle or pinned keys prevents service readiness after enforcement activation.

Accept

Missing oracle or pinned keys prevents service readiness after enforcement activation.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, CI steward
Design status
NOT RUN
Plan pages
R2-F02
R2-F02-R03Missing proof bytes retry without incorrectly marking a valid block permanently invalid.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F02 requires (review R2 finding F02: Proof-rule infrastructure can fail open).

Steps

  1. Missing proof bytes retry without incorrectly marking a valid block permanently invalid.

Accept

Missing proof bytes retry without incorrectly marking a valid block permanently invalid.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, CI steward
Design status
NOT RUN
Plan pages
R2-F02
R2-F03-R01Clean build from one manifest, including the pool and workers, with no unpublished vendor tree.Priority P0Profile P00PASSEvidence none yetLast run 8 Oct 2026, 22:11 UK

Setup

The regression R2-F03 requires (review R2 finding F03: The bundle contains a v6 candidate, not a demonstrated integrated v6 release).

Steps

  1. Clean build from one manifest, including the pool and workers, with no unpublished vendor tree.

Accept

Clean build from one manifest, including the pool and workers, with no unpublished vendor tree.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward, hash lane (ProgramClass::V6 on freeze), pool lane
Run
f03-manifest-20261008-01
Design status
NOT RUN
Plan pages
R2-F03
R2-F03-R02Same job context produces identical accepted work in node, CPU reference, CUDA, Metal, OpenCL and pool.Priority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:57 UK

Setup

The regression R2-F03 requires (review R2 finding F03: The bundle contains a v6 candidate, not a demonstrated integrated v6 release).

Steps

  1. Same job context produces identical accepted work in node, CPU reference, CUDA, Metal, OpenCL and pool.

Accept

Same job context produces identical accepted work in node, CPU reference, CUDA, Metal, OpenCL and pool.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward, hash lane (ProgramClass::V6 on freeze), pool lane
Run
same-work-20261008-03
Design status
NOT RUN
Plan pages
R2-F03
R2-F03-R03Cross every scheduled transition with old/new client behavior documented and identical rule identities.Priority P0Profile P00PASSEvidence none yetLast run 9 Oct 2026, 09:57 UK

Setup

The regression R2-F03 requires (review R2 finding F03: The bundle contains a v6 candidate, not a demonstrated integrated v6 release).

Steps

  1. Cross every scheduled transition with old/new client behavior documented and identical rule identities.

Accept

Cross every scheduled transition with old/new client behavior documented and identical rule identities.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward, hash lane (ProgramClass::V6 on freeze), pool lane
Run
same-work-20261008-03
Design status
NOT RUN
Plan pages
R2-F03
R2-F04-R01Native multi-node 40/40/20 partition, equivocation and dust-valid mining on both sides past the window.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F04 requires (review R2 finding F04: Finality v4 recovery deliberately has a weaker safety boundary).

Steps

  1. Native multi-node 40/40/20 partition, equivocation and dust-valid mining on both sides past the window.

Accept

Native multi-node 40/40/20 partition, equivocation and dust-valid mining on both sides past the window.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane, reference apps, site (explorer)
Design status
NOT RUN
Plan pages
R2-F04
R2-F04-R02Proof that the chosen recovery guarantee matches the public finality claim; two valid contradictory certificates are a hard failure for strong finality.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F04 requires (review R2 finding F04: Finality v4 recovery deliberately has a weaker safety boundary).

Steps

  1. Proof that the chosen recovery guarantee matches the public finality claim; two valid contradictory certificates are a hard failure for strong finality.

Accept

Proof that the chosen recovery guarantee matches the public finality claim; two valid contradictory certificates are a hard failure for strong finality.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane, reference apps, site (explorer)
Design status
NOT RUN
Plan pages
R2-F04
R2-F04-R03Pause-only resume with historical backfill, missing historical data and all old keys returning.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F04 requires (review R2 finding F04: Finality v4 recovery deliberately has a weaker safety boundary).

Steps

  1. Pause-only resume with historical backfill, missing historical data and all old keys returning.

Accept

Pause-only resume with historical backfill, missing historical data and all old keys returning.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane, reference apps, site (explorer)
Design status
NOT RUN
Plan pages
R2-F04
R2-F04-R04Wallet, receipt and oracle consumers distinguish any weaker recovery state.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F04 requires (review R2 finding F04: Finality v4 recovery deliberately has a weaker safety boundary).

Steps

  1. Wallet, receipt and oracle consumers distinguish any weaker recovery state.

Accept

Wallet, receipt and oracle consumers distinguish any weaker recovery state.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane, reference apps, site (explorer)
Design status
NOT RUN
Plan pages
R2-F04
R2-F05-R01Native reference-vs-incremental expression equivalence across all source registers and real instruction updates.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F05 requires (review R2 finding F05: reg64 address coupling has an exact incremental alternative).

Steps

  1. Native reference-vs-incremental expression equivalence across all source registers and real instruction updates.

Accept

Native reference-vs-incremental expression equivalence across all source registers and real instruction updates.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, adversary lane, floor lane 3
Design status
NOT RUN
Plan pages
R2-F05
R2-F05-R02Full-kernel output equivalence, registers, spills, wall power and accepted throughput across target GPUs.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F05 requires (review R2 finding F05: reg64 address coupling has an exact incremental alternative).

Steps

  1. Full-kernel output equivalence, registers, spills, wall power and accepted throughput across target GPUs.

Accept

Full-kernel output equivalence, registers, spills, wall power and accepted throughput across target GPUs.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, adversary lane, floor lane 3
Design status
NOT RUN
Plan pages
R2-F05
R2-F05-R03Adversary physical design includes prefix caching/recomputation cost; no assumed full 63-read cost on every load.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F05 requires (review R2 finding F05: reg64 address coupling has an exact incremental alternative).

Steps

  1. Adversary physical design includes prefix caching/recomputation cost; no assumed full 63-read cost on every load.

Accept

Adversary physical design includes prefix caching/recomputation cost; no assumed full 63-read cost on every load.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, adversary lane, floor lane 3
Design status
NOT RUN
Plan pages
R2-F05
R2-F06-R01Acceptance/reference/emitter evaluate the same activated schedule.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F06 requires (review R2 finding F06: The v6 acceptance and census gates are not complete for the final execution).

Steps

  1. Acceptance/reference/emitter evaluate the same activated schedule.

Accept

Acceptance/reference/emitter evaluate the same activated schedule.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, research lane D
Design status
NOT RUN
Plan pages
R2-F06
R2-F06-R02Full live-dataset census on unseen seeds and the complete v6 pack.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F06 requires (review R2 finding F06: The v6 acceptance and census gates are not complete for the final execution).

Steps

  1. Full live-dataset census on unseen seeds and the complete v6 pack.

Accept

Full live-dataset census on unseen seeds and the complete v6 pack.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, research lane D
Design status
NOT RUN
Plan pages
R2-F06
R2-F06-R03A failed experimental rule does not silently exhaust generation or bypass the intended resource requirement.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F06 requires (review R2 finding F06: The v6 acceptance and census gates are not complete for the final execution).

Steps

  1. A failed experimental rule does not silently exhaust generation or bypass the intended resource requirement.

Accept

A failed experimental rule does not silently exhaust generation or bypass the intended resource requirement.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, research lane D
Design status
NOT RUN
Plan pages
R2-F06
R2-F07-R01Same final v6 configuration: mine -> evict -> prove -> aggregate -> submit -> rebuild -> resume; no leaked reservations.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F07 requires (review R2 finding F07: VRAM admission and proving deadlines need one operator-level scheduler).

Steps

  1. Same final v6 configuration: mine -> evict -> prove -> aggregate -> submit -> rebuild -> resume; no leaked reservations.

Accept

Same final v6 configuration: mine -> evict -> prove -> aggregate -> submit -> rebuild -> resume; no leaked reservations.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, fleet lane
Design status
NOT RUN
Plan pages
R2-F07
R2-F07-R02OOM, process crash and stale work recover without losing wallet state or silently consuming power.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F07 requires (review R2 finding F07: VRAM admission and proving deadlines need one operator-level scheduler).

Steps

  1. OOM, process crash and stale work recover without losing wallet state or silently consuming power.

Accept

OOM, process crash and stale work recover without losing wallet state or silently consuming power.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, fleet lane
Design status
NOT RUN
Plan pages
R2-F07
R2-F07-R0316 GB+ simultaneous mode only after measured peak plus next-epoch headroom; smaller-card modes labelled separately.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F07 requires (review R2 finding F07: VRAM admission and proving deadlines need one operator-level scheduler).

Steps

  1. 16 GB+ simultaneous mode only after measured peak plus next-epoch headroom; smaller-card modes labelled separately.

Accept

16 GB+ simultaneous mode only after measured peak plus next-epoch headroom; smaller-card modes labelled separately.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, fleet lane
Design status
NOT RUN
Plan pages
R2-F07
R2-F08-R01Report every eligible job outcome, including expired work; a bounded list cannot hide losses.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F08 requires (review R2 finding F08: The proving pipeline reports waste and deadline censoring, not sustained capacity).

Steps

  1. Report every eligible job outcome, including expired work; a bounded list cannot hide losses.

Accept

Report every eligible job outcome, including expired work; a bounded list cannot hide losses.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, fleet lane, site (ops page)
Design status
NOT RUN
Plan pages
R2-F08
R2-F08-R02Consumer tiers complete and receive payment for declared jobs before claims about income.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F08 requires (review R2 finding F08: The proving pipeline reports waste and deadline censoring, not sustained capacity).

Steps

  1. Consumer tiers complete and receive payment for declared jobs before claims about income.

Accept

Consumer tiers complete and receive payment for declared jobs before claims about income.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, fleet lane, site (ops page)
Design status
NOT RUN
Plan pages
R2-F08
R2-F08-R03Sustained real workload across class transitions, with restart/retry and no publisher intervention.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F08 requires (review R2 finding F08: The proving pipeline reports waste and deadline censoring, not sustained capacity).

Steps

  1. Sustained real workload across class transitions, with restart/retry and no publisher intervention.

Accept

Sustained real workload across class transitions, with restart/retry and no publisher intervention.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, fleet lane, site (ops page)
Design status
NOT RUN
Plan pages
R2-F08
R2-F09-R01Generate all pass/fail cells directly from the declared inequalities and inputs.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F09 requires (review R2 finding F09: The economic model explicitly retains a failed specialist case).

Steps

  1. Generate all pass/fail cells directly from the declared inequalities and inputs.

Accept

Generate all pass/fail cells directly from the declared inequalities and inputs.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
research lane, floor lane 3, coordinator
Design status
NOT RUN
Plan pages
R2-F09
R2-F09-R02Independent feasibility and cost evaluation of the strongest modeled SRAM/hybrid opponent.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F09 requires (review R2 finding F09: The economic model explicitly retains a failed specialist case).

Steps

  1. Independent feasibility and cost evaluation of the strongest modeled SRAM/hybrid opponent.

Accept

Independent feasibility and cost evaluation of the strongest modeled SRAM/hybrid opponent.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
research lane, floor lane 3, coordinator
Design status
NOT RUN
Plan pages
R2-F09
R2-F09-R03GPU owners and entrants remain viable under the approved scenario envelope without assuming chip absence or death.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F09 requires (review R2 finding F09: The economic model explicitly retains a failed specialist case).

Steps

  1. GPU owners and entrants remain viable under the approved scenario envelope without assuming chip absence or death.

Accept

GPU owners and entrants remain viable under the approved scenario envelope without assuming chip absence or death.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
research lane, floor lane 3, coordinator
Design status
NOT RUN
Plan pages
R2-F09
R2-F10-R01Compare exact found nonce/hash sets with full-read mode, including all-hit overflow and zero-hit cases.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F10 requires (review R2 finding F10: CUDA production readback has an existing OpenCL optimization to borrow).

Steps

  1. Compare exact found nonce/hash sets with full-read mode, including all-hit overflow and zero-hit cases.

Accept

Compare exact found nonce/hash sets with full-read mode, including all-hit overflow and zero-hit cases.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
worker lane (new)
Design status
NOT RUN
Plan pages
R2-F10
R2-F10-R02Test stale jobs, high-32 rollover, tail batches and asynchronous buffer reuse.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F10 requires (review R2 finding F10: CUDA production readback has an existing OpenCL optimization to borrow).

Steps

  1. Test stale jobs, high-32 rollover, tail batches and asynchronous buffer reuse.

Accept

Test stale jobs, high-32 rollover, tail batches and asynchronous buffer reuse.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
worker lane (new)
Design status
NOT RUN
Plan pages
R2-F10
R2-F10-R03Compare production throughput and wall energy, not only the isolated kernel timer.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F10 requires (review R2 finding F10: CUDA production readback has an existing OpenCL optimization to borrow).

Steps

  1. Compare production throughput and wall energy, not only the isolated kernel timer.

Accept

Compare production throughput and wall energy, not only the isolated kernel timer.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
worker lane (new)
Design status
NOT RUN
Plan pages
R2-F10
R2-F11-R01Goal switch from an efficiency prior can explore higher core/power when policy allows.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F11 requires (review R2 finding F11: Ember needs workload-aware identity and objective-aware search).

Steps

  1. Goal switch from an efficiency prior can explore higher core/power when policy allows.

Accept

Goal switch from an efficiency prior can explore higher core/power when policy allows.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ember lane (new)
Design status
NOT RUN
Plan pages
R2-F11
R2-F11-R02Driver, workload, dataset, compiler and device changes invalidate certification while retaining optional hints.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F11 requires (review R2 finding F11: Ember needs workload-aware identity and objective-aware search).

Steps

  1. Driver, workload, dataset, compiler and device changes invalidate certification while retaining optional hints.

Accept

Driver, workload, dataset, compiler and device changes invalidate certification while retaining optional hints.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ember lane (new)
Design status
NOT RUN
Plan pages
R2-F11
R2-F11-R03Thermal/error/late-share events revert safely, including process or machine crash.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F11 requires (review R2 finding F11: Ember needs workload-aware identity and objective-aware search).

Steps

  1. Thermal/error/late-share events revert safely, including process or machine crash.

Accept

Thermal/error/late-share events revert safely, including process or machine crash.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ember lane (new)
Design status
NOT RUN
Plan pages
R2-F11
R2-F12-R01Crash before/after broadcast, response timeout, restart before snapshot: no duplicate payment or silent debt loss.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F12 requires (review R2 finding F12: Pool payouts have a broadcast-before-durable-intent window).

Steps

  1. Crash before/after broadcast, response timeout, restart before snapshot: no duplicate payment or silent debt loss.

Accept

Crash before/after broadcast, response timeout, restart before snapshot: no duplicate payment or silent debt loss.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
R2-F12
R2-F12-R02Same signed transaction retried, fee replacement reconciled by intent, not a new payment.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F12 requires (review R2 finding F12: Pool payouts have a broadcast-before-durable-intent window).

Steps

  1. Same signed transaction retried, fee replacement reconciled by intent, not a new payment.

Accept

Same signed transaction retried, fee replacement reconciled by intent, not a new payment.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
R2-F12
R2-F12-R03Receipt reorg and finality pause leave correct pending obligations.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F12 requires (review R2 finding F12: Pool payouts have a broadcast-before-durable-intent window).

Steps

  1. Receipt reorg and finality pause leave correct pending obligations.

Accept

Receipt reorg and finality pause leave correct pending obligations.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
R2-F12
R2-F13-R01Repeated authorization rejected or atomically replaces and cleans prior state.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F13 requires (review R2 finding F13: Pool admission and membership need bounded resources).

Steps

  1. Repeated authorization rejected or atomically replaces and cleans prior state.

Accept

Repeated authorization rejected or atomically replaces and cleans prior state.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
R2-F13
R2-F13-R02Oversized unterminated frame rejected within fixed memory/time budget.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F13 requires (review R2 finding F13: Pool admission and membership need bounded resources).

Steps

  1. Oversized unterminated frame rejected within fixed memory/time budget.

Accept

Oversized unterminated frame rejected within fixed memory/time budget.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
R2-F13
R2-F13-R03Slow clients and invalid share floods cannot grow unbounded member, nonce or outgoing state.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F13 requires (review R2 finding F13: Pool admission and membership need bounded resources).

Steps

  1. Slow clients and invalid share floods cannot grow unbounded member, nonce or outgoing state.

Accept

Slow clients and invalid share floods cannot grow unbounded member, nonce or outgoing state.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
R2-F13
R2-F14-R01Public build has no default arbitrary remote execution and a documented least-privilege boundary.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F14 requires (review R2 finding F14: Developer fleet control must not silently become the public client trust model).

Steps

  1. Public build has no default arbitrary remote execution and a documented least-privilege boundary.

Accept

Public build has no default arbitrary remote execution and a documented least-privilege boundary.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, relay lane
Design status
NOT RUN
Plan pages
R2-F14
R2-F14-R02Automatic updates off remains off for urgent manifests until explicit action.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F14 requires (review R2 finding F14: Developer fleet control must not silently become the public client trust model).

Steps

  1. Automatic updates off remains off for urgent manifests until explicit action.

Accept

Automatic updates off remains off for urgent manifests until explicit action.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, relay lane
Design status
NOT RUN
Plan pages
R2-F14
R2-F14-R03A compromised fleet/update signing key cannot silently acquire wallet access or activate a consensus change.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F14 requires (review R2 finding F14: Developer fleet control must not silently become the public client trust model).

Steps

  1. A compromised fleet/update signing key cannot silently acquire wallet access or activate a consensus change.

Accept

A compromised fleet/update signing key cannot silently acquire wallet access or activate a consensus change.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, relay lane
Design status
NOT RUN
Plan pages
R2-F14
18INT

INT: the master edition's integration gates (R1, the full-system review)

18 integration gates; each reads NOT RUN until its owner lane records a run

FAIL
Owner
the owner lanes per the coordinator's crosswalk
Gate
Integration gates closed
Fixtures
F0,F5
Plan pages
docs/plans/igneum-2.0-master/traceability.json integration_gates
18 cases: 0 passed under the standard, 0 running with team evidence, 1 failed, 17 not run, 0 deferred
INT-01Real proof H cannot authenticate a different statement under a warm cache.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-01 of the master edition (R1 / Additional regression gates).

Steps

  1. Real proof H cannot authenticate a different statement under a warm cache.

Accept

Real proof H cannot authenticate a different statement under a warm cache.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Plan pages
R1
INT-02Warm/cold/relay/restart/concurrent cache order does not change block or payout decisions; negative cache isolated.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-02 of the master edition (R1 / Additional regression gates).

Steps

  1. Warm/cold/relay/restart/concurrent cache order does not change block or payout decisions; negative cache isolated.

Accept

Warm/cold/relay/restart/concurrent cache order does not change block or payout decisions; negative cache isolated.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Plan pages
R1
INT-03Durable payout outbox survives every crash/RPC boundary without duplicate or lost liabilities.Priority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 00:47 UK

Setup

Integration gate INT-03 of the master edition (R1 / Additional regression gates).

Steps

  1. Durable payout outbox survives every crash/RPC boundary without duplicate or lost liabilities.

Accept

Durable payout outbox survives every crash/RPC boundary without duplicate or lost liabilities.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (a1c484c48a62948c2)
Run
pool-int-20261009-01
Design status
NOT RUN
Plan pages
R1
INT-04Corrupt existing pool state, disk-full and reorg cause safe recovery, not silent empty balances.Priority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 00:47 UK

Setup

Integration gate INT-04 of the master edition (R1 / Additional regression gates).

Steps

  1. Corrupt existing pool state, disk-full and reorg cause safe recovery, not silent empty balances.

Accept

Corrupt existing pool state, disk-full and reorg cause safe recovery, not silent empty balances.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (a1c484c48a62948c2)
Run
pool-int-20261009-01
Design status
NOT RUN
Plan pages
R1
INT-05The supplied finality implementation matches the approved anchor rule after >window healing.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-05 of the master edition (R1 / Additional regression gates).

Steps

  1. The supplied finality implementation matches the approved anchor rule after >window healing.

Accept

The supplied finality implementation matches the approved anchor rule after >window healing.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane (a283f5f0d364ceef0)
Design status
NOT RUN
Plan pages
R1
INT-06Recovery tests state and preserve their weaker fault bound; interfaces never label it as a stronger guarantee.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-06 of the master edition (R1 / Additional regression gates).

Steps

  1. Recovery tests state and preserve their weaker fault bound; interfaces never label it as a stronger guarantee.

Accept

Recovery tests state and preserve their weaker fault bound; interfaces never label it as a stronger guarantee.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane (a283f5f0d364ceef0)
Design status
NOT RUN
Plan pages
R1
INT-07One v6 object agrees in node, pool, CPU verifier and each supported GPU host across activation.Priority P0Profile P00FAILEvidence none yetLast run 9 Oct 2026, 09:59 UK

Setup

Integration gate INT-07 of the master edition (R1 / Additional regression gates).

Steps

  1. One v6 object agrees in node, pool, CPU verifier and each supported GPU host across activation.

Accept

One v6 object agrees in node, pool, CPU verifier and each supported GPU host across activation.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)
Run
canary-202-20261009-01
Design status
NOT RUN
Plan pages
R1
INT-08Census, production acceptance, schedule counters and live-dataset tests use the identical frozen contract.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-08 of the master edition (R1 / Additional regression gates).

Steps

  1. Census, production acceptance, schedule counters and live-dataset tests use the identical frozen contract.

Accept

Census, production acceptance, schedule counters and live-dataset tests use the identical frozen contract.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)
Design status
NOT RUN
Plan pages
R1
INT-09Eight- and twelve-GiB epoch transitions recover deliberately without relying on repeated OOM/watchdog cycles.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-09 of the master edition (R1 / Additional regression gates).

Steps

  1. Eight- and twelve-GiB epoch transitions recover deliberately without relying on repeated OOM/watchdog cycles.

Accept

Eight- and twelve-GiB epoch transitions recover deliberately without relying on repeated OOM/watchdog cycles.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane
Design status
NOT RUN
Plan pages
R1
INT-10Metal/CUDA/OpenCL exact dataset geometry agrees; unsupported packs reject before launch.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-10 of the master edition (R1 / Additional regression gates).

Steps

  1. Metal/CUDA/OpenCL exact dataset geometry agrees; unsupported packs reject before launch.

Accept

Metal/CUDA/OpenCL exact dataset geometry agrees; unsupported packs reject before launch.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)
Design status
NOT RUN
Plan pages
R1
INT-11Only a memory-reserved proving job launches; mining buffers really release when required.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-11 of the master edition (R1 / Additional regression gates).

Steps

  1. Only a memory-reserved proving job launches; mining buffers really release when required.

Accept

Only a memory-reserved proving job launches; mining buffers really release when required.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane
Design status
NOT RUN
Plan pages
R1
INT-12Transient shard errors can retry safely; expiration, loss and paid work remain distinct durable outcomes.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-12 of the master edition (R1 / Additional regression gates).

Steps

  1. Transient shard errors can retry safely; expiration, loss and paid work remain distinct durable outcomes.

Accept

Transient shard errors can retry safely; expiration, loss and paid work remain distinct durable outcomes.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane (a6e8f84588b809d62) and fleet lane (ac055d60427caab99)
Design status
NOT RUN
Plan pages
R1
INT-13Ember cannot retain a rate-ineligible prior; material workload changes invalidate incompatible profiles.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-13 of the master edition (R1 / Additional regression gates).

Steps

  1. Ember cannot retain a rate-ineligible prior; material workload changes invalidate incompatible profiles.

Accept

Ember cannot retain a rate-ineligible prior; material workload changes invalidate incompatible profiles.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ember lane (a04fe3451877e2ff0) with the app lane
Design status
NOT RUN
Plan pages
R1
INT-14Protected helper and per-device leases restore owned settings on normal/abnormal exit; real ACL/security tests.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-14 of the master edition (R1 / Additional regression gates).

Steps

  1. Protected helper and per-device leases restore owned settings on normal/abnormal exit; real ACL/security tests.

Accept

Protected helper and per-device leases restore owned settings on normal/abnormal exit; real ACL/security tests.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ember lane (a04fe3451877e2ff0) with the app lane
Design status
NOT RUN
Plan pages
R1
INT-15Public PoP replay is not session authorization; payout/server/network binding enforced.Priority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 00:47 UK

Setup

Integration gate INT-15 of the master edition (R1 / Additional regression gates).

Steps

  1. Public PoP replay is not session authorization; payout/server/network binding enforced.

Accept

Public PoP replay is not session authorization; payout/server/network binding enforced.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (a1c484c48a62948c2)
Run
pool-int-20261009-01
Design status
NOT RUN
Plan pages
R1
INT-16Pool parsing/queues/connection and crypto budgets remain bounded under controlled adversarial traffic.Priority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 00:47 UK

Setup

Integration gate INT-16 of the master edition (R1 / Additional regression gates).

Steps

  1. Pool parsing/queues/connection and crypto budgets remain bounded under controlled adversarial traffic.

Accept

Pool parsing/queues/connection and crypto budgets remain bounded under controlled adversarial traffic.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (a1c484c48a62948c2)
Run
pool-int-20261009-01
Design status
NOT RUN
Plan pages
R1
INT-17Missing oracle/keys/mandatory real-proof fixture blocks the applicable production acceptance gate.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-17 of the master edition (R1 / Additional regression gates).

Steps

  1. Missing oracle/keys/mandatory real-proof fixture blocks the applicable production acceptance gate.

Accept

Missing oracle/keys/mandatory real-proof fixture blocks the applicable production acceptance gate.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Plan pages
R1
INT-18Whole-system economics pass the strongest feasible adversary, including sunk development and multi-epoch survival.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-18 of the master edition (R1 / Additional regression gates).

Steps

  1. Whole-system economics pass the strongest feasible adversary, including sunk development and multi-epoch survival.

Accept

Whole-system economics pass the strongest feasible adversary, including sunk development and multi-epoch survival.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
research lane (ad6a2bd47d4a46105)
Design status
NOT RUN
Plan pages
R1
19VR

VR: the token value and network leadership rules (normative, proposed, requiring ratification)

40 normative rules from Igneum 2.0, Token Value & Network Leadership 1.0-proposed (snapshot 2026-10-08); Supplement to original master and 128-case test standard; not a price/rank guarantee

NOT RUN
Owner
founder (ratification); the owner role per rule
Gate
Ratification by the founder and each rule's owner role
Fixtures
F0
Plan pages
docs/plans/igneum-2.0-master/token-value/rules-and-gates.json rules
40 cases: 0 passed under the standard, 0 running with team evidence, 40 not run, 0 deferred
VR-01One monetary contractPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Ratify one maximum-supply, subsidy and change-policy contract. No unexplained tail escape, automatic emergency mint or price-triggered issuance.

Accept

Ratify one maximum-supply, subsidy and change-policy contract. No unexplained tail escape, automatic emergency mint or price-triggered issuance.

Evidence the case requires

D01 decision, normative spec, executable supply tests and consistent public text.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Protocol + governance
Plan pages
TV
VR-02Independent supply accountingPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Make circulating, issued, burned, locked and maximum supply independently reproducible. Count bridges and wrappers without creating fictitious native supply.

Accept

Make circulating, issued, burned, locked and maximum supply independently reproducible. Count bridges and wrappers without creating fictitious native supply.

Evidence the case requires

Two independent supply calculations with exact integer reconciliation.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Protocol + measurement
Plan pages
TV
VR-03Equal opportunity at launchPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. No premine or privileged devnet conversion under the stated fair-launch policy. Publish efficient software and launch conditions before activation.

Accept

No premine or privileged devnet conversion under the stated fair-launch policy. Publish efficient software and launch conditions before activation.

Evidence the case requires

Genesis audit, launch rehearsal, insider disclosures and public release history.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Release + ecosystem
Plan pages
TV
VR-04No artificial return promisePriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Do not advertise guaranteed appreciation, passive returns without necessary work, a redemption floor or electricity-backed value.

Accept

Do not advertise guaranteed appreciation, passive returns without necessary work, a redemption floor or electricity-backed value.

Evidence the case requires

Product terms, source of rewards and public-claim review.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Governance + counsel
Plan pages
TV
VR-05Fund necessary securityPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Model miners, internal provers, minimum validators and maintenance separately through declining issuance. No assumption that an external sale automatically funds all roles.

Accept

Model miners, internal provers, minimum validators and maintenance separately through declining issuance. No assumption that an external sale automatically funds all roles.

Evidence the case requires

Role-by-role cash flow, adverse scenarios and committed initial resources.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Economics + protocol
Plan pages
TV
VR-06Honest rule changePriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Publish rationale, impact, adoption path and compatibility limits before a material monetary change. Do not pretend software can prevent all future voluntary forks.

Accept

Publish rationale, impact, adoption path and compatibility limits before a material monetary change. Do not pretend software can prevent all future voluntary forks.

Evidence the case requires

Versioned proposals, reviewer comments, adoption and dissent documentation.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Protocol + governance
Plan pages
TV
VR-07Transparent fee routingPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Every fee, burn, operator payment and optional Labs charge has an explicit source and recipient. No new team tax hidden in a commercial label.

Accept

Every fee, burn, operator payment and optional Labs charge has an explicit source and recipient. No new team tax hidden in a commercial label.

Evidence the case requires

Executable fee tests and reconciliation to invoices/receipts.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Economics + protocol
Plan pages
TV
VR-08Separate value and money flowsPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Distinguish job turnover, fees, operator income, Labs income, token holdings and market value. Do not count the same payment or saving twice.

Accept

Distinguish job turnover, fees, operator income, Labs income, token holdings and market value. Do not count the same payment or saving twice.

Evidence the case requires

Reconciled flow diagram and reproducible metric definitions.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Economics + measurement
Plan pages
TV
VR-09Accessible hardware economicsPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Fix the reference cohort and scenarios in advance. Allow the strongest feasible programmable multi-epoch specialist, including sunk development and alternative memory.

Accept

Fix the reference cohort and scenarios in advance. Allow the strongest feasible programmable multi-epoch specialist, including sunk development and alternative memory.

Evidence the case requires

Approved original GPU/ADV/ROT/ECO profiles and independent review.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
GPU + hardware reviewer
Plan pages
TV
VR-10Mandatory correct proofsPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. All activated proof decisions must bind their actual statement, kind and verifier independent of cache history. Missing trusted infrastructure must not disable enforcement.

Accept

All activated proof decisions must bind their actual statement, kind and verifier independent of cache history. Missing trusted infrastructure must not disable enforcement.

Evidence the case requires

Native warm/cold/order/restart tests and positive/negative proof fixtures.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Protocol + proving
Plan pages
TV
VR-11Literal finalityPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Define fault assumptions, authority continuity and recovery. Never present a weaker recovery certificate as the stronger irreversible guarantee.

Accept

Define fault assumptions, authority continuity and recovery. Never present a weaker recovery certificate as the stronger irreversible guarantee.

Evidence the case requires

Native multi-node boundary tests and consumer label checks.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Consensus + security
Plan pages
TV
VR-12Retained operator authorityPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Pooling variance or buying a service does not silently transfer keys, transaction selection or finality/governance control.

Accept

Pooling variance or buying a service does not silently transfer keys, transaction selection or finality/governance control.

Evidence the case requires

Key/template substitution tests and explicit delegation contracts.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Protocol + pool
Plan pages
TV
VR-13Safe custody and consentPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Private keys, spending limits, signing displays and recovery choices remain under explicit user authority. Defaults must not conceal broad powers.

Accept

Private keys, spending limits, signing displays and recovery choices remain under explicit user authority. Defaults must not conceal broad powers.

Evidence the case requires

Wallet security review and independent user/recovery exercises.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Wallet + security
Plan pages
TV
VR-14Portable verificationPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Balances and receipts authenticate their roots, successful outcome and trust anchors. Necessary reconstruction data has a documented availability path.

Accept

Balances and receipts authenticate their roots, successful outcome and trust anchors. Necessary reconstruction data has a documented availability path.

Evidence the case requires

Independent receipt/client verification with hostile inputs.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Wallet + protocol
Plan pages
TV
VR-15Price real resourcesPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Bound execution, verification and storage costs. Sponsored transactions have limits. No deliberate congestion solely to increase a token metric.

Accept

Bound execution, verification and storage costs. Sponsored transactions have limits. No deliberate congestion solely to increase a token metric.

Evidence the case requires

Minimum-node tests and fee/sponsor-abuse scenarios.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Protocol + economics
Plan pages
TV
VR-16No fragile stable-value promisePriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Any stable-value product has explicit issuer, reserve/redemption rights, permissions and risks. No native-backed peg used merely to manufacture demand.

Accept

Any stable-value product has explicit issuer, reserve/redemption rights, permissions and risks. No native-backed peg used merely to manufacture demand.

Evidence the case requires

Independent diligence, risk limits and legal assessment before release.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Application + counsel
Plan pages
TV
VR-17Optional bounded bridgesPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Bridge exposure is separate from core security. No bridge is mandatory for genesis or allowed to redefine base-chain finality after a loss.

Accept

Bridge exposure is separate from core security. No bridge is mandatory for genesis or allowed to redefine base-chain finality after a loss.

Evidence the case requires

External security review, loss limits and failure/isolation tests.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Application + security
Plan pages
TV
VR-18Open work settlementPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Jobs bind program, inputs, result, verifier, deadline and payment. Gateways are replaceable and Labs approval is not required for ordinary work.

Accept

Jobs bind program, inputs, result, verifier, deadline and payment. Gateways are replaceable and Labs approval is not required for ordinary work.

Evidence the case requires

Independent request-to-paid-result test and state reconciliation.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Protocol + ecosystem
Plan pages
TV
VR-19Obligation-based service bondsPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Deposits secure a specific obligation, not consensus influence. Size and failure conditions must preserve small-operator paths and handle collateral decline.

Accept

Deposits secure a specific obligation, not consensus influence. Size and failure conditions must preserve small-operator paths and handle collateral decline.

Evidence the case requires

Economic and adversarial reservation/default tests.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Economics + application
Plan pages
TV
VR-20Independent developer accessPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Publish complete standards, fixtures and tooling. Grants reward useful maintained deliverables rather than deployments or price effects.

Accept

Publish complete standards, fixtures and tooling. Grants reward useful maintained deliverables rather than deployments or price effects.

Evidence the case requires

Unaffiliated integration and maintenance evidence.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Ecosystem
Plan pages
TV
VR-21Committed maintenancePriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Essential maintenance and audits need a funded runway with stress accounting, distinct from hoped-for appreciation or fundraising.

Accept

Essential maintenance and audits need a funded runway with stress accounting, distinct from hoped-for appreciation or fundraising.

Evidence the case requires

At least approved P13 runway, commitments and role costs.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Maintainers + finance
Plan pages
TV
VR-22Founder independencePriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Routine block, job, payment and recovery paths must not require a founder credential or undocumented manual action.

Accept

Routine block, job, payment and recovery paths must not require a founder credential or undocumented manual action.

Evidence the case requires

Real founder-absence exercises and intervention ledger.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Operations + independent reviewer
Plan pages
TV
VR-23Measure effective controlPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Report operator, pool, hosting, service and client dependencies with attribution limits. Keys and addresses are not people.

Accept

Report operator, pool, hosting, service and client dependencies with attribution limits. Keys and addresses are not people.

Evidence the case requires

Dependency/control map with uncertainty and removal experiments.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Measurement + operations
Plan pages
TV
VR-24Reproducible secure releasePriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Pin source, binaries, rules, guests/keys and activation. Provenance is necessary but not sufficient for correctness.

Accept

Pin source, binaries, rules, guests/keys and activation. Provenance is necessary but not sufficient for correctness.

Evidence the case requires

Independent builds, artifact verification and scoped review.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Release + security
Plan pages
TV
VR-25Consent-preserving incident responsePriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Separate public/developer authority. Urgency must not silently override installation or grant arbitrary execution. Disclose material incidents and retest.

Accept

Separate public/developer authority. Urgency must not silently override installation or grant arbitrary execution. Disclose material incidents and retest.

Evidence the case requires

Compromised-key, unsafe-update and recovery drills.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Release + operations
Plan pages
TV
VR-26Honest access and liquidityPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Use functional deposits/withdrawals and executable depth, not ticker count or fabricated volume. Never restrict exit to simulate value.

Accept

Use functional deposits/withdrawals and executable depth, not ticker count or fabricated volume. Never restrict exit to simulate value.

Evidence the case requires

Independent access-route and two-sided liquidity observations.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Ecosystem + measurement
Plan pages
TV
VR-27Transparent treasury relationshipsPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Disclose material grants, insider holdings, inventory and market-making mandates. No wash trades or hidden price-support promises.

Accept

Disclose material grants, insider holdings, inventory and market-making mandates. No wash trades or hidden price-support promises.

Evidence the case requires

Mandate register, reconciled accounts and conflict policy.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Treasury + counsel
Plan pages
TV
VR-28Auditable metricsPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Publish definitions, raw/adjusted views, sampling, attribution uncertainty and missing data. No subsidy-hidden demand or censored failed jobs.

Accept

Publish definitions, raw/adjusted views, sampling, attribution uncertainty and missing data. No subsidy-hidden demand or censored failed jobs.

Evidence the case requires

Data lineage, conservation checks and independent replay.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Measurement
Plan pages
TV
VR-29Fair comparison universePriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Define eligible peers and exclusions before observing rankings. Include qualifying new entrants and preserve unknown values.

Accept

Define eligible peers and exclusions before observing rankings. Include qualifying new entrants and preserve unknown values.

Evidence the case requires

Independent peer census and versioned comparison protocol.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Measurement + external panel
Plan pages
TV
VR-30Scoped claims onlyPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Every leadership claim names its metric, universe, period and limits. A measured price rank does not certify overall safety or future leadership.

Accept

Every leadership claim names its metric, universe, period and limits. A measured price rank does not certify overall safety or future leadership.

Evidence the case requires

Claim register with evidence, expiry and legal signoff.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Governance + counsel
Plan pages
TV
VR-31Evidence before passPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Pre-register thresholds; missing inputs block gates; corrections preserve failed results. No aggregate score can waive core safety or economic failure.

Accept

Pre-register thresholds; missing inputs block gates; corrections preserve failed results. No aggregate score can waive core safety or economic failure.

Evidence the case requires

Frozen test charter and versioned evidence packets.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Independent acceptance panel
Plan pages
TV
VR-32Real adoptionPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Measure unaffiliated retained users and useful repeat activity with incentives identified. Do not require buying IGN to participate in a study.

Accept

Measure unaffiliated retained users and useful repeat activity with incentives identified. Do not require buying IGN to participate in a study.

Evidence the case requires

Cohort definitions, attrition, usage and subsidy audit.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Product + ecosystem
Plan pages
TV
VR-33AI earns admissionPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. AI is an optional workload category, not a guaranteed-margin network identity. Price full costs and adverse demand before expansion.

Accept

AI is an optional workload category, not a guaranteed-margin network identity. Price full costs and adverse demand before expansion.

Evidence the case requires

Workload-specific benchmark, repeat demand and verification policy.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Compute + economics
Plan pages
TV
VR-34Bound agent spendingPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Automated buyers have scoped budgets, permissions, expiry, revocation and logs. Untrusted prompts never alter base permissions.

Accept

Automated buyers have scoped budgets, permissions, expiry, revocation and logs. Untrusted prompts never alter base permissions.

Evidence the case requires

Prompt/input adversarial tests and payment-loss caps.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Application + security
Plan pages
TV
VR-35Cryptographic migration readinessPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Maintain a full algorithm inventory and reviewed transition plan. No quantum-proof claim from one component or speculative attack date.

Accept

Maintain a full algorithm inventory and reviewed transition plan. No quantum-proof claim from one component or speculative attack date.

Evidence the case requires

Expert review, downgrade/migration tests and annual refresh.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Cryptography + protocol
Plan pages
TV
VR-36Separate proof, truth and privacyPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Execution validity does not establish real-world input truth, AI answer quality or confidentiality. State trust and data exposure for each service.

Accept

Execution validity does not establish real-world input truth, AI answer quality or confidentiality. State trust and data exposure for each service.

Evidence the case requires

Threat model and user-facing guarantee audit.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Security + product
Plan pages
TV
VR-37Scale within verification budgetsPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Throughput, data and state growth must preserve the declared minimum-node and reconstruction capabilities. Reprice security after fee compression.

Accept

Throughput, data and state growth must preserve the declared minimum-node and reconstruction capabilities. Reprice security after fee compression.

Evidence the case requires

Cold-path capacity, bootstrap, pruning and provider-removal tests.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Protocol + operations
Plan pages
TV
VR-38Honest energy accountingPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Report complete-system energy and role allocation. Avoid double-counting joint work or making unsupported carbon/marginal-transaction claims.

Accept

Report complete-system energy and role allocation. Avoid double-counting joint work or making unsupported carbon/marginal-transaction claims.

Evidence the case requires

Calibrated wall tests and documented environmental methodology.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
GPU + measurement
Plan pages
TV
VR-39Activity-specific legal approvalPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. Obtain counsel review for actual audiences and activities. No-presale, fair-launch or decentralised labels are not blanket legal exemptions.

Accept

Obtain counsel review for actual audiences and activities. No-presale, fair-launch or decentralised labels are not blanket legal exemptions.

Evidence the case requires

Jurisdiction/activity matrix and approved external communications.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Counsel
Plan pages
TV
VR-40No indispensable administratorPriority P0Profile P00NOT RUNEvidence none yetLast run none yet

Setup

Steps

  1. A useful company, token holder, pool, AI agent or funding body receives no hidden power over balances, issuance or canonical history.

Accept

A useful company, token holder, pool, AI agent or funding body receives no hidden power over balances, issuance or canonical history.

Evidence the case requires

Authority inventory, isolation tests and independent operation.

Method
Ratification
Cadence
Once, at ratification; again on any change of the rule
Owner
Protocol + governance
Plan pages
TV
20TV

TV: the token value and network leadership gates (proposed; no gate executed)

32 gates from Igneum 2.0, Token Value & Network Leadership 1.0-proposed (snapshot 2026-10-08); scope CORE, CAPABILITY IF ENABLED or LEADERSHIP CLAIM as the file gives it; Supplement to original master and 128-case test standard; not a price/rank guarantee

NOT RUN
Owner
the owner role per gate
Gate
Token value gates closed
Fixtures
F0
Plan pages
docs/plans/igneum-2.0-master/token-value/rules-and-gates.json gates
32 cases: 0 passed under the standard, 0 running with team evidence, 32 not run, 0 deferred
TV-01Resolve and freeze the monetary contractPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 10:54 UK

Setup

Supply, tail, fee and recovery documents plus exact proposed release.

Steps

  1. Reconcile D01-D06 with protocol/economic/counsel review. Freeze thresholds and all interfaces before confirmatory tests.

Accept

No conflicting normative policy; every material choice has a signed rationale, version, adoption path and tests. Unresolved core choice is BLOCKED.

Evidence the case requires

Decision log, signed specification, release manifest, test charter.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Protocol + independent panel
Run
tv-d02-20261009-03
Plan pages
TV
TV-02Reproduce complete supply accountingPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 10:51 UK

Setup

Two independent implementations; genesis and representative boundary/reorg fixtures.

Steps

  1. Recompute issued, paid, burned, locked and outstanding amounts through subsidy transitions, rollback/replay and duplicate records.

Accept

Exact integer agreement; no unaccounted creation, duplicate supply or cap breach under the ratified policy. Restricted wrappers are not extra native supply.

Evidence the case requires

Machine-readable ledgers, vectors, independent signoff.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Protocol + measurement
Run
tv-02-20261009-01
Plan pages
TV
TV-03Fair launch and early distributionPriority P0Profile P00NOT RUNEvidence recordLast run 9 Oct 2026, 10:54 UK

Setup

Public binaries, source, mining modes, launch notice and insider inventory.

Steps

  1. Rehearse from clean outsider machines; audit genesis allocations and devnet balances; simulate arrival times under alternative emission schedules.

Accept

Zero undisclosed allocation or privileged conversion; approved notice/support window and cohort pass; distribution analysis includes delayed entrants without guaranteeing equal ownership.

Evidence the case requires

Genesis report, dated releases, disclosure register, simulation inputs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Release + ecosystem
Run
tv-d02-20261009-03
Plan pages
TV
TV-04Security budget without price rescuePriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 10:54 UK

Setup

Ratified reward/fee rules; role costs; horizons 1, 5, 10 and 20 years.

Steps

  1. Model falling issuance, fee volatility and .25x/1x/4x/10x revenue, zero external jobs and -90% price. Separate role receipts and funding.

Accept

Approved viable scenarios fund minimum required roles without hidden issuance or assumed appreciation; failure regions stated. Collapse scenarios need safe behaviour, not universal profit.

Evidence the case requires

Reproducible cash-flow model, assumptions, independent review.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Economics + protocol
Run
tv-d02-20261009-03
Plan pages
TV
TV-05Strongest surviving specialistPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Pinned candidate/cohort; cheapest supported physical designs including SRAM/hybrid.

Steps

  1. Apply original ADV/GPU/ECO profiles with multi-epoch survival and development sunk. Reprice alternative state and memory implementations.

Accept

All approved core energy and total-cost bounds pass with uncertainty; no unresolved feasible dominating design. Unknown feasibility blocks the broad claim.

Evidence the case requires

Design files, wall results, sensitivity model, two independent hardware opinions.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Hardware reviewer + economics
Plan pages
TV
TV-06Every fee and payment reconcilesPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Native rules, payer contract and optional Labs/service invoices.

Steps

  1. Execute gas, proof, developer, pool, burn, sponsor and refund paths, including rounding, abort, retry and zero-demand cases.

Accept

No unexplained recipient or double count; statements/invoices match exact contract outcomes. Network turnover never labelled Labs revenue or permanent holding demand.

Evidence the case requires

Flow ledger, fixtures, invoice examples, reviewed public fee table.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Economics + application
Plan pages
TV
TV-07Ownership-critical engineering closurePriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Original master findings mapped to current release with genuine proof fixtures.

Steps

  1. Run native cache-order, fail-closed activation, payout crash and finality tests; reproduce fixed cases in independent environments.

Accept

No unresolved critical/high finding or counterexample within the approved guarantee; all applicable original safety gates pass. Reproducing a defect is not closure.

Evidence the case requires

Native outputs, manifests, scoped audit, issue-by-issue closure.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Protocol + independent security
Plan pages
TV
TV-08Custody and recovery usabilityPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Declared wallet/hardware combinations; 30 new participants, at least 15 non-miners.

Steps

  1. Perform receive, preview/sign, limit, recovery and revocation tasks with valueless funds; inject wrong network/address and malicious prompts.

Accept

Zero unauthorised transfer or secret disclosure; at least 90% complete the approved safe task without private help. Report confidence limitations and all failures.

Evidence the case requires

Task protocol, anonymised results, security review, recovery vectors.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Wallet + independent users
Plan pages
TV
TV-09Independently verifiable settlementPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Proof/receipt client without Labs RPC; normal and recovery certificates.

Steps

  1. Verify successful/failed transfers, wrong asset/amount, stale roots, fake voter lists, invalid proofs and withheld data.

Accept

All invalid claims refused; valid ordinary transfers verify within approved resource limits; weaker recovery and unavailable data never shown as stronger finality.

Evidence the case requires

Offline fixtures, consumer traces and independent implementation.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Wallet + consensus
Plan pages
TV
TV-10Minimum-node and sponsored-use limitsPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Approved minimum validator and sponsor budgets under final workload.

Steps

  1. Run cold proof verification, expensive invalid inputs, state growth, paymaster drain attempts and overloaded bursts.

Accept

Original capacity/security profiles pass; budgets remain bounded; no proof skipped to catch up and no sponsor can spend outside authorised scope.

Evidence the case requires

Cold-path profiles, stress traces, sponsor negative tests.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Protocol + application
Plan pages
TV
TV-11Pooled payments without authority lossPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Independent pool/member clients and durable payment state.

Steps

  1. Inject key/template substitution, reauthorisation, crash/RPC ambiguity, receipt reorg and hostile bounded inputs.

Accept

No duplicate/lost liability or unauthorised authority change; member can verify delegated powers and change pools. Session resource limits hold.

Evidence the case requires

Ledger replay, signed work fixtures and pool removal test.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Pool + independent operators
Plan pages
TV
TV-12Reproducible and consented softwarePriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Release manifest, build dependencies, update keys and public installer.

Steps

  1. Two independent parties build/verify; simulate compromised key, stale package, rollback, urgency and missing fixtures.

Accept

No hidden consensus variation or arbitrary default remote control; update-off remains respected; mandatory unavailable fixtures block acceptance.

Evidence the case requires

Attestations, independent hashes, key drill, installer/ACL review.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Release + independent security
Plan pages
TV
TV-13Committed maintenance coveragePriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Costed roles, commitments and monthly cash dates.

Steps

  1. Audit at least 12 months of approved maintenance coverage; stress IGN-denominated resources and provider withdrawal.

Accept

Original P13 satisfied without counting future appreciation or unsigned pledges; essential functions have funded substitutes and explicit shortfall response.

Evidence the case requires

Contracts/grants or funding proof, stress cash flow, responsibility register.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Maintainers + independent finance
Plan pages
TV
TV-14Founder-absent operating exercisePriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Independent builds/operators; founder services, keys and manual help removed.

Steps

  1. Run 30 real days, then satisfy the original 90-day observation programme; cross boundaries, remove major providers and record all interventions.

Accept

Approved original independence/reliability gates pass; no unpublished founder action or privileged override. Simulated long partitions are labelled separately.

Evidence the case requires

Dependency map, availability logs, intervention and payer ledger.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Independent operations panel
Plan pages
TV
TV-15Governance and authority boundariesPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Every control/activation threshold, treasury power and application admin interface.

Steps

  1. Exercise hostile coalitions, absent voters, old clients and compromised non-consensus keys; test refusal and recovery.

Accept

No actor gains undeclared issuance/balance/history authority. Every activation follows the ratified safe procedure; ambiguous threshold or recovery remains BLOCKED.

Evidence the case requires

Authority model, scenarios, native outcomes and independent review.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Protocol + governance
Plan pages
TV
TV-16Two functional independent access routesPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

At least two unaffiliated custody/exchange/payment routes with disclosed shared infrastructure.

Steps

  1. Complete small controlled deposits, withdrawals, outage and reconciliation tests; identify actual custody and settlement dependencies.

Accept

Both settle correctly; neither is merely a front end to the same indispensable provider. Gaps and jurisdiction limits visible; no listing assumed from a logo.

Evidence the case requires

Settlement records, dependency map and third-party confirmation.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ecosystem + independent reviewer
Plan pages
TV
TV-17Supply-price-liquidity measurementPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Frozen sources, price filters, circulating/free-float definitions and order-size bands.

Steps

  1. Collect 90 real days; independently replay supply and prices; measure both buy/sell execution costs and withdrawal availability.

Accept

At least 95% daily coverage; exact supply reconciliation; no fabricated missing data. Sparse liquidity invalidates broad liquidity claims, not automatically the arithmetic cap.

Evidence the case requires

Raw snapshots, methodology/code, gap ledger, audit.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Measurement steward
Plan pages
TV
TV-18Real versus incentivised demandPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Customer/job/transaction definitions with privacy-respecting attribution and subsidy data.

Steps

  1. Reconcile raw/adjusted activity, self-dealing controls and incentives; test whether circular activity earns more than its irrecoverable cost.

Accept

All subsidies and known related activity separated; useful demand not inferred from gross volume alone; abusive incentive loop closed before scaling rewards.

Evidence the case requires

Accounting model, filter logic, sensitivity and independent replay.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Economics + measurement
Plan pages
TV
TV-19Independent developer adoptionPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Public kit and at least five unaffiliated developers with declared tasks.

Steps

  1. Build useful integrations without private dependencies; have two independent maintainers update the kit; record obstacles and adoption reason.

Accept

All declared core integration paths work; at least five usable integrations and two maintainer reproductions. Empty subsidised deployments do not qualify.

Evidence the case requires

Repos, task traces, user evidence and maintenance records.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ecosystem + external developers
Plan pages
TV
TV-20Programmable payment acceptancePriority P1Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Versioned library, independent application, user/sponsor limits and receipt path.

Steps

  1. Execute simple/conditional/recurring payments, revocations, expiry, failed outcome and duplicate invoice cases.

Accept

No unauthorised spend or double settlement; successful transfer independently evidenced; subjective conditions disclose adjudicator/trust.

Evidence the case requires

Contracts, negative vectors, user task record, security review.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Application + wallet
Plan pages
TV
TV-21Useful paid proof demandPriority P1Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Exact workload and final hardware path; three unrelated buyers and approved COM profile.

Steps

  1. Observe repeat purchases under original P14/P16 conditions, full job outcomes and operator/service costs.

Accept

All applicable COM targets met without hidden reimbursement. Queue expiry not counted as success. A monetary-only scope cannot claim this gate passed by exclusion.

Evidence the case requires

Buyer evidence, cost ledger, all-job traces and independent review.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Proving + independent customers
Plan pages
TV
TV-22Replaceable work-market gatewayPriority P1Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Two independent gateway implementations and job/settlement specification.

Steps

  1. Create jobs, switch providers/gateways, fail one service and deliver the same objective result using public inputs.

Accept

Correct payment/result without Labs approval; no concealed central dispatcher or irreversible dependency. External-chain receipts labelled separately.

Evidence the case requires

Gateway traces, escrow reconciliation, dependency-removal run.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Application + independent operators
Plan pages
TV
TV-23Obligation-based depositsPriority P1Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Proposed bond/default contract and volatile-collateral scenarios.

Steps

  1. Test reservation abandonment, invalid inputs, network pause, -90% collateral value and malicious claims.

Accept

No consensus influence bought; default reason objective; compensation limits explicit; viable small-operator participation and approved risk bounds.

Evidence the case requires

Adversarial model, state tests, risk/legal review.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Economics + security
Plan pages
TV
TV-24AI earns a separate commercial casePriority P1Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

One bounded model/job, provider hardware, verification tier and licences.

Steps

  1. Benchmark full delivery vs actual alternatives; test 90% lower unit prices, demand collapse, private-data exposure and substituted models.

Accept

Approved service economics and buyer gates pass; correctness/truth/privacy distinguished. No native price or perpetual yield assumption.

Evidence the case requires

End-to-end costs, repeat demand, licence/threat review.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Compute + independent reviewer
Plan pages
TV
TV-25Bounded machine purchasingPriority P1Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Approved account/paymaster permissions and chosen x402/agent interfaces.

Steps

  1. Inject hostile outputs/prompts, replayed requests, recursive spending, revoked permissions and gateway failure.

Accept

Spend never exceeds authorised destination/time/amount scope; no instruction changes authority. Draft standard support is described accurately.

Evidence the case requires

Property tests, loss-cap proof, revocation/audit logs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Application + security
Plan pages
TV
TV-26Cryptographic migration readinessPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Complete key/proof/transport/update inventory and external cryptographic review.

Steps

  1. Rehearse versioned signature/proof migration, downgrade/replay, mixed clients, inactive owners and minimum-node overhead.

Accept

No unreviewed assumption or automatic confiscation; migration can be explained and tested. No absolute quantum-proof claim or attack date inferred.

Evidence the case requires

Inventory, expert report, migration vectors, annual schedule.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Cryptography + protocol
Plan pages
TV
TV-27Private data and oracle assurancePriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Per-product claims, input trust sources, data-retention and execution model.

Steps

  1. Use forged data, hostile providers, telemetry leakage, unsupported attestation and false-but-correctly-executed AI outputs.

Accept

No claim exceeds tested guarantee; secrets/data protected to stated model; unauthenticated inputs not represented as objective truth.

Evidence the case requires

Threat model, exposure tests, labelled user flows.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Security + product
Plan pages
TV
TV-28Stable assets and bridge isolationPriority P1Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Only if enabled: issuer/bridge design, redemption rights, trust anchors and approved value caps.

Steps

  1. Test reserve/redemption failure, stale oracle, invalid/recovery certificates, contract compromise and emergency shutdown.

Accept

No hidden base-chain guarantee or forced reversal of final history; independent audit, conservative exposure and counsel approval.

Evidence the case requires

Risk dossier, scenarios, disclosure, independent tests.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Application + security + counsel
Plan pages
TV
TV-29Growth without inaccessible verificationPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Declared minimum node, projected data growth and alternative scaling design.

Steps

  1. Run cold/worst-case validation, state/pruning/bootstrap, censorship and aggregation withdrawal; model 10x/100x growth and fee compression.

Accept

Original minimum-node/security bounds hold; required data remains obtainable; security funding restated for changed fee routes.

Evidence the case requires

Capacity/availability results and revised economics.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Protocol + operations
Plan pages
TV
TV-30Energy and claims disciplinePriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Calibrated whole-system metering and workload allocation protocol.

Steps

  1. Measure mining, proving, mixed/time-shared operation, setup/recovery and unsuccessful work; review environmental text.

Accept

No double-counted savings; original meter tolerances satisfied; no marginal-energy/carbon claim beyond method.

Evidence the case requires

Raw meter traces, job ledger, method and external review.

Method
Automated + independent review
Cadence
Every release candidate
Owner
GPU + measurement
Plan pages
TV
TV-31Public-claim and activity reviewPriority P0Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Actual jurisdiction, audience, service, token-distribution and promotion plans.

Steps

  1. Counsel assesses applicable routes and reviews each value/rank/return/security assertion against evidence.

Accept

Written activity-specific clearance and approved wording; no future-value assertion in a covered MiCA white paper; no blanket exemption inferred from mining.

Evidence the case requires

Legal decision matrix, claim register, review dates.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Qualified counsel
Plan pages
TV
TV-32Observed leadership, not a roadmap certificatePriority P1Profile P00NOT RUNEvidence none yetLast run 9 Oct 2026, 09:45 UK

Setup

Approved peer universe; all applicable mandatory gates; stable release and 90-day observation.

Steps

  1. Run original P15/P16 comparisons and independently replay scoped rank data. Test changing peer/exclusion assumptions and missing data.

Accept

Contender requires original criteria; market-cap first requires highest 90-day median, 95% coverage; sustained daily-first convention also needs 80% of covered days. Never certify overall best from price alone.

Evidence the case requires

Independent panel report, full methods/data, scope and expiry of claim.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Independent acceptance panel
Plan pages
TV
21R15

R15: the 1.5x Research Programme packages (proposed; every package NOT RUN; the plan claims no pass)

10 packages from IGNEUM, The 1.5x Research Programme (9 October 2026); PROPOSED; every package NOT RUN; the plan claims no pass; the X and B cross-references on each package are the research-landing hand's reading of the plan against the brief's matrix and track B, for the coordinator to confirm; the lanes block names the owner lanes as the coordinator named them on 9 October

NOT RUN
Owner
the X and B lanes per package; the coordinator confirms the cross-references
Gate
1.5x programme packages closed
Fixtures
F0
Plan pages
docs/plans/igneum-2.0-master/1p5x/research-plan/packages.json (igneum-1p5x-research-plan.md, section 10 'Proposed execution packages' (the table whose rows begin '| R15-'))
10 cases: 0 passed under the standard, 0 running with team evidence, 10 not run, 0 deferred
R15-01R15-01: Release + measurementPriority P0Profile P04NOT RUNEvidence none yetLast run 9 Oct 2026, 12:45 UK

Setup

Package R15-01 of the 1.5x Research Programme (docs/plans/igneum-2.0-master/1p5x/research-plan/packages.json); the required artefact: Latest exact pack, physical assumptions, source manifest, current ratio reconciliation

Steps

  1. The lane(s) X0 produce the required artefact; the package's gate is read against it by the independent review.

Accept

No cross-version mixed baseline

Evidence the case requires

The run record of the package's lane(s) as recorded through tools/ci/test-record.mjs; every chip figure labelled WITNESS or BOUND; no raw hashes-per-second comparison without an approved equivalence.

Method
Automated + independent review
Cadence
Once per programme round
Owner
X0
Run
lab-20261009-01
Plan pages
R15
R15-02R15-02: GPU + hardwarePriority P0Profile P04NOT RUNEvidence none yetLast run 9 Oct 2026, 11:06 UK

Setup

Package R15-02 of the 1.5x Research Programme (docs/plans/igneum-2.0-master/1p5x/research-plan/packages.json); the required artefact: Component power/traffic model and sensitivity analysis

Steps

  1. The lane(s) X0, X5 produce the required artefact; the package's gate is read against it by the independent review.

Accept

No device/whole-machine boundary mismatch

Evidence the case requires

The run record of the package's lane(s) as recorded through tools/ci/test-record.mjs; every chip figure labelled WITNESS or BOUND; no raw hashes-per-second comparison without an approved equivalence.

Method
Automated + independent review
Cadence
Once per programme round
Owner
X0, X5
Run
r15-02-x7-20261009-01
Plan pages
R15
R15-03R15-03: GPU + memory analysisPriority P0Profile P04NOT RUNEvidence none yetLast run 9 Oct 2026, 11:06 UK

Setup

Package R15-03 of the 1.5x Research Programme (docs/plans/igneum-2.0-master/1p5x/research-plan/packages.json); the required artefact: Layer-8-off control and held-out cache curves

Steps

  1. The lane(s) X1 produce the required artefact; the package's gate is read against it by the independent review.

Accept

Distinct benefit after best cache adaptation

Evidence the case requires

The run record of the package's lane(s) as recorded through tools/ci/test-record.mjs; every chip figure labelled WITNESS or BOUND; no raw hashes-per-second comparison without an approved equivalence.

Method
Automated + independent review
Cadence
Once per programme round
Owner
X1
Run
r15-int8-20261009-01
Plan pages
R15
R15-04R15-04: GPU systemsPriority P0Profile P04NOT RUNEvidence none yetLast run 9 Oct 2026, 11:23 UK

Setup

Package R15-04 of the 1.5x Research Programme (docs/plans/igneum-2.0-master/1p5x/research-plan/packages.json); the required artefact: Compaction, exact-fold alternatives and tuning results

Steps

  1. The lane(s) X2, X3, X4 produce the required artefact; the package's gate is read against it by the independent review.

Accept

Byte agreement, real accepted-work savings

Evidence the case requires

The run record of the package's lane(s) as recorded through tools/ci/test-record.mjs; every chip figure labelled WITNESS or BOUND; no raw hashes-per-second comparison without an approved equivalence.

Method
Automated + independent review
Cadence
Once per programme round
Owner
X2, X3, X4
Run
1p5x-x4-20261009
Plan pages
R15
R15-05R15-05: CryptographyPriority P0Profile P04NOT RUNEvidence none yetLast run 9 Oct 2026, 11:06 UK

Setup

Package R15-05 of the 1.5x Research Programme (docs/plans/igneum-2.0-master/1p5x/research-plan/packages.json); the required artefact: Exact published MHPoW control, theorem audit, malicious fixtures

Steps

  1. The lane(s) B1 produce the required artefact; the package's gate is read against it by the independent review.

Accept

No improvised sampled-memory soundness

Evidence the case requires

The run record of the package's lane(s) as recorded through tools/ci/test-record.mjs; every chip figure labelled WITNESS or BOUND; no raw hashes-per-second comparison without an approved equivalence.

Method
Automated + independent review
Cadence
Once per programme round
Owner
B1
Run
r15-track-b-20261009-02
Plan pages
R15
R15-06R15-06: GPU + cryptographyPriority P0Profile P04NOT RUNEvidence none yetLast run 9 Oct 2026, 10:19 UK

Setup

Package R15-06 of the 1.5x Research Programme (docs/plans/igneum-2.0-master/1p5x/research-plan/packages.json); the required artefact: Theorem-preserving layout/parallelisation feasibility

Steps

  1. The lane(s) B3 produce the required artefact; the package's gate is read against it by the independent review.

Accept

GPU competitiveness and cheap-enough verification

Evidence the case requires

The run record of the package's lane(s) as recorded through tools/ci/test-record.mjs; every chip figure labelled WITNESS or BOUND; no raw hashes-per-second comparison without an approved equivalence.

Method
Automated + independent review
Cadence
Once per programme round
Owner
B3
Plan pages
R15
R15-07R15-07: Cryptography + hardwarePriority P0Profile P04NOT RUNEvidence none yetLast run 9 Oct 2026, 11:28 UK

Setup

Package R15-07 of the 1.5x Research Programme (docs/plans/igneum-2.0-master/1p5x/research-plan/packages.json); the required artefact: Joint accepted-proof resource frontier with concrete constants

Steps

  1. The lane(s) B2, B4 produce the required artefact; the package's gate is read against it by the independent review.

Accept

No invalid theorem composition

Evidence the case requires

The run record of the package's lane(s) as recorded through tools/ci/test-record.mjs; every chip figure labelled WITNESS or BOUND; no raw hashes-per-second comparison without an approved equivalence.

Method
Automated + independent review
Cadence
Once per programme round
Owner
B2, B4
Run
mhpow-b4-20261009-02
Plan pages
R15
R15-08R15-08: Independent ASIC teamPriority P0Profile P04NOT RUNEvidence none yetLast run 9 Oct 2026, 12:45 UK

Setup

Package R15-08 of the 1.5x Research Programme (docs/plans/igneum-2.0-master/1p5x/research-plan/packages.json); the required artefact: Re-optimised SRAM/DRAM/hybrid/recompute/PIM scenarios

Steps

  1. The lane(s) X5, B5 produce the required artefact; the package's gate is read against it by the independent review.

Accept

Full-storage adversary not excluded by price

Evidence the case requires

The run record of the package's lane(s) as recorded through tools/ci/test-record.mjs; every chip figure labelled WITNESS or BOUND; no raw hashes-per-second comparison without an approved equivalence.

Method
Automated + independent review
Cadence
Once per programme round
Owner
X5, B5
Run
lab-20261009-01
Plan pages
R15
R15-09R15-09: Measurement + economicsPriority P0Profile P04NOT RUNEvidence none yetLast run 9 Oct 2026, 12:45 UK

Setup

Package R15-09 of the 1.5x Research Programme (docs/plans/igneum-2.0-master/1p5x/research-plan/packages.json); the required artefact: Blind cohort confirmation and separate P12 outcomes

Steps

  1. The lane(s) X6 produce the required artefact; the package's gate is read against it by the independent review.

Accept

Strongest credible ratio, not average

Evidence the case requires

The run record of the package's lane(s) as recorded through tools/ci/test-record.mjs; every chip figure labelled WITNESS or BOUND; no raw hashes-per-second comparison without an approved equivalence.

Method
Automated + independent review
Cadence
Once per programme round
Owner
X6
Run
lab-20261009-01
Plan pages
R15
R15-10R15-10: Protocol/securityPriority P0Profile P04NOT RUNEvidence none yetLast run 9 Oct 2026, 10:19 UK

Setup

Package R15-10 of the 1.5x Research Programme (docs/plans/igneum-2.0-master/1p5x/research-plan/packages.json); the required artefact: Network and pool integration, no-rescue exercise, public evidence

Steps

  1. The lane(s) B6 produce the required artefact; the package's gate is read against it by the independent review.

Accept

Correctness and safe operation remain intact

Evidence the case requires

The run record of the package's lane(s) as recorded through tools/ci/test-record.mjs; every chip figure labelled WITNESS or BOUND; no raw hashes-per-second comparison without an approved equivalence.

Method
Automated + independent review
Cadence
Once per programme round
Owner
B6
Plan pages
R15
Profiles

The numbers each case is held to.

17 profiles, P00 to P16. A profile is frozen before the confirmatory run; weakening a target after a failure creates a different claim.

P00Approved as proposed

Frozen scope and approval

  1. Approve the release manifest, supported roles, numerical profiles, mandatory scenarios, trust/fault model, workload W, adapters and claims before confirmatory tests. Unknown values are BLOCKED, not defaults.
  2. Core safety and authentication invariants admit no waiver. Proposed performance or commercial targets may be replaced only before the confirmatory run, with an independent rationale and a versioned public scope.
  3. After a failure, weakening a target creates a different claim and requires a new assessment. Preserve all failed runs; do not average a blocker away.

Cited by 148 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P01Approved as proposed

Correctness and negative-test depth

  1. Zero observed invalid acceptance, unauthorised signature, conflicting finality within assumptions, duplicated reward or unexplained cross-backend state/hash disagreement.
  2. Minimum proposed campaign: 1,000,000 full-hash vectors per supported backend across all families, plus at least 10,000 malformed/boundary cases per relevant parser or binding class. Include exhaustive small-domain cases and historical regressions.
  3. All prescribed critical mutants must be detected. This sampling target is not a bound on cryptographic failure probability and does not replace independent reasoning about soundness or safety.

Cited by 69 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P02Approved as proposed

Hardware coverage and reproducibility

  1. At least 12 physical retail configurations: at least 3 NVIDIA, 3 AMD and 2 Apple configurations, at least two discrete-GPU generations, an advertised 8 GB mining tier and 12 GB proving tiers where claimed. Record usable, not nominal, memory.
  2. Declare a competitive core of at least 6 configurations spanning every advertised vendor and at least two discrete generations before optimisation. The wider cohort remains mandatory for access and economic tests; it cannot be silently dropped.
  3. Use 5 paired 30-minute steady-state runs per primary cell after at least 15 minutes of warm-up and a stable temperature trend. Calibrated wall meter uncertainty must be at most 2%. Run a 7-day soak on representative low/mid/high tiers.
  4. Three unaffiliated operators participate; every competitive-core cell is reproduced by at least two. Identical-SKU energy/accepted-work results must agree within 5% after declared environment corrections; unexplained variance blocks the headline.

Cited by 12 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P03Approved as proposed

Candidate improvement and honest-card budget

  1. For production candidate changes, per mandatory GPU cell: no more than 5% increase in joules per accepted work and no more than 2% decrease in accepted throughput versus the paired tuned baseline. Absolute safety limits always apply.
  2. G2 requires at least a 10% reduction in the strongest evaluated specialist advantage after redesign, outside the declared measurement/model uncertainty, while meeting those budgets. A failed experiment is not a successful upgrade.
  3. Existing clock-lock savings belong in the baseline. Long programs cannot pass by adding enough equally costly work to both devices to improve a ratio while materially worsening honest operation.

Cited by 8 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P04Approved as proposed

Scoped specialist-competition target

  1. Define R_E as GPU wall joules per accepted work divided by the lowest credible complete-system specialist joules for that same work. The proposed target is R_E at most 1.5 for every competitive-core cell at the same node and one node ahead.
  2. Evaluate at least three materially distinct specialist architectures, with one programmable multi-family design, and a second independent reviewer. Include shared/reduced memory, hybrid execution, selective participation and realistic power/host costs.
  3. Publish two-node-ahead and modular/reused-IP stress cases; they must satisfy the predeclared P12 economic envelope. No universal ceiling for unknown future hardware is claimed. Report model bounds separately from statistical confidence.
  4. A lower-bound specialist estimate, not a convenient average or a deliberately constrained reference architecture, drives the conservative comparison. Undefined or unbounded decision-critical assumptions make the result BLOCKED.

FAIL R_E target at most 1.5 at the same node and one node ahead; today's placed bracket 1.5x to 2.1x: FAIL

Cited by 24 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P05Approved as proposed

Measurement and inference protocol

  1. Pre-register primary metrics, cohorts, holdout seeds, run order, exclusions and analysis before confirmation. Keep tuning/training runs separate from holdout runs.
  2. Use independent runs/operators as measurement units. Report point estimates, two-sided 95% measurement intervals and absolute sample counts; handle time-series dependence with a declared block or run-level method.
  3. Apply conservative uncertainty to pass decisions. A confidence interval around measured GPU energy does not capture unknown ASIC architectures; model parameter ranges and expert judgement must be reported as such.
  4. Never compare raw hashes per second across different algorithms. Do not transform a five-year scenario sweep into a probability of chip arrival or a guarantee of future profitability.

Cited by 0 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P06Approved as proposed

Memory and support policy

  1. All advertised role/configuration combinations must finish without OOM, corruption or unsafe fallback. Publish a component memory budget, including display/OS, driver, miner, prover, aggregation and epoch construction.
  2. Proposed support horizon: at least 24 months of known schedule compatibility for the advertised entry tier, unless a narrower horizon is prominently approved before sale or launch. Removal changes the claim and must pass ECO-07.
  3. Treat 5.5 / 8.5 / 11.5 GiB as source candidates, not imposed final rules. Simultaneous operation, eviction and time-sharing are distinct advertised modes with separately measured cost.

Cited by 4 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P07Approved as proposed

Proof service capacity and fairness

  1. Freeze W as a meaningful workload mix, input sizes, proof format, fleet and requests/hour. Primary proposed target: 72 hours at W, plus 24 hours at 1.2W; at least 99.5% accepted jobs delivered valid within the contracted deadline.
  2. Default delivery targets for the declared internal reference workload: p95 at most 60 seconds and p99 at most 120 seconds from input-ready assignment through verified delivery. Also publish request-to-delivery including input wait; no claim may omit that delay.
  3. Request-to-delivery p99 must meet the separately approved customer deadline. Payment p99 must be at most 10 minutes after verified payable eligibility, with chain finality time reported separately. These defaults do not override a stricter contract.
  4. No statistically supported positive backlog drift at steady load, no silent drops; after 2W for 15 minutes, drain excess backlog within 30 minutes of return to W. Report rejected demand and accepted-job success separately.
  5. Proposed advertised-tier fairness: at least 90% timely valid assigned completions are paid under the approved rules; avoidable duplicate/retry work is at most 10% of total work. Reassignment policy must bound abandonment without promising every assignment a reward.

Cited by 15 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P08Approved as proposed

Fault assumptions and recovery

  1. F0 must state the exact safety threshold, quorum and authority-transition rule; the synchrony/participation assumptions for liveness; trusted inputs; and clock/expiry semantics. This manual supplies no substitute consensus rule.
  2. Exercise threshold-minus/at/plus cases, the 40/40/20 partition fixture, signing outages and 31/35/60/90 logical-day expiry cases. Preserve safety when liveness assumptions fail; do not demand finality from an unavailable quorum.
  3. After assumptions and input availability are restored: service replacement within 10 minutes and deterministic network convergence within 30 minutes on the reference topology. Different certified bounds must be approved beforehand.
  4. Accelerated-time simulation and real elapsed operation are separate evidence classes. Recovery may not reverse a guarantee previously represented as final.

Cited by 25 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P09Approved as proposed

Security and bounded resource requirements

  1. Zero unresolved critical or high-severity security findings on the claimed release. Independent scopes must cover consensus, proof soundness/parameters, implementation bypasses, wallet/isolation and relevant operational controls.
  2. Review the intended proof-system security level and assumptions explicitly; do not infer a security-bit claim from random rejection tests. Version every verifier, program and parameter set.
  3. Freeze maximum valid/invalid verification time, memory, disk and admission rates for ordinary validator hardware. At rated valid load plus the approved hostile load, no unbounded growth, invalid acceptance or unrecoverable process failure.
  4. For supported wallet fee-estimation cases, proposed absolute error at most 5% versus the specified charge when inputs are unchanged; deterministic fee-cap handling and explicit uncertainty otherwise. Customer contracts remain separately binding.

Cited by 30 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P10Approved as proposed

Ordinary-operator product targets

  1. At least 30 unaffiliated first-time study participants across supported Windows/macOS combinations. At least 90% install, configure safely and submit accepted work without staff help; p90 active setup at most 15 minutes. Publish complete download/dataset time separately.
  2. Pause/stop acknowledgement within 2 seconds, safe worker stop within 5 seconds where no documented atomic operation prevents it, and reliable restoration of original tuning settings. No hidden custody or silent update.
  3. Net-energy/fee displays reconcile within 5% under the declared measurement boundary. Incremental rejected-work loss on the normal home-link profile is at most 2 percentage points over the matched datacentre profile.
  4. Open miner efficiency is within 5% of the best independently tuned permitted implementation on identical work. For the declared single-card payout case, p95 payable-to-payment at most 24 hours and total payout friction at most 2% of earned value.
  5. Critical alerts are emitted within 60 seconds of detectable evidence. At least 90% of study users can identify the injected failure and follow the published safe action. No control target excuses a security failure.

Cited by 11 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P11Approved as proposed

No-founder exercise and independence

  1. At least 10 verified unaffiliated operators, three independently administered network/hosting domains and sufficient honest weight/capacity to satisfy F0 and W after founders are removed.
  2. Run at least 30 real elapsed days without founder mining, proving, aggregation, bootstrap, required RPC, private files or privileged interventions. Cross all known logical transitions separately without calling accelerated time real history.
  3. Document control by role and common dependencies; uncertain identities are not counted as independent. Within-assumption withdrawals must satisfy P08; losing more than the assumed quorum may cause a visible safe pause.

Cited by 4 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P12Approved as proposed

Five-year coexistence envelope

  1. Freeze a sourced revenue reference R and mandatory worlds before results. Sweep 0.25R, R, 4R and 10R; electricity at $0.03/$0.10/$0.25/$0.40 per kWh; 1/3/5-year productive life; zero/$20M/$75M development; private mining and hardware sales; no/normal/spiking external demand.
  2. Those values are proposed stress inputs, not current prices or forecasts. Declare which worlds have enough funded demand for rational ongoing service before running; retain collapse worlds as explicit safety/exit tests, not profitable successes.
  3. Proposed matched-tariff new-entry target in every mandatory sustainable world: median GPU/specialist total cost per accepted work at most 1.5, 90th percentile at most 1.75, and no advertised competitive-core cell above 2.0. Publish every cell, including heterogeneous tariffs.
  4. At least three purchasable GPU configurations across at least two advertised vendors must have positive modelled new-entry economics; at least 75% of the entry cohort must have positive marginal operating economics in those worlds. Report model uncertainty and failure regions.
  5. Do not impose GPU market share, specialist production limits, token appreciation, full research-cost recovery or automatic chip death to force the result. Any such condition must become an explicit limitation rather than a hidden assumption.

Cited by 24 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P13Deferred by the founder

Maintenance continuity

  1. Before a readiness claim, document at least 12 months of committed maintenance resources at the approved operating scope. Include engineering, security review, infrastructure, support and incident response.
  2. Use independently reviewable commitments and downside budgets. Uncommitted future sales, rising token prices, burned fees or assumed fundraising are not available resources.
  3. This is a proposed governance test, not a directive to change the supply cap, issuance allocation or fair-launch design.

Cited by 1 case. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P14Approved as proposed

Genuine commercial and developer proof

  1. At least three unrelated paying buyer organisations, each making at least three separate purchase decisions across at least 30 days; at least 1,000 meaningful verified external jobs in aggregate. Split invoices do not create independent demand.
  2. No project reimbursement, circular funding or undisclosed related party counts. Report customer concentration and churn; proposed maximum largest-buyer share is 70% of qualifying revenue.
  3. At least 20% aggregate contribution margin after directly attributable delivery costs, retries, refunds and support; publish fully loaded economics separately. At least 75% of sampled eligible operators have positive realised contribution on the declared workload.
  4. At least five unaffiliated developers complete a useful supported application or proof-service integration using public documentation. Customer confirmation and raw commercial evidence may remain confidential to the reviewer.

Cited by 10 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P15Approved as proposed

Comparative contention threshold

  1. Pre-register at least three relevant operating GPU-first peers, plus a real proving alternative for customer comparisons. Verify current versions at execution time. The source reference set is a starting point, not a claim about current rankings.
  2. Require at least three meaningful comparable dimensions with no material inferiority beyond a pre-agreed 10% margin against the best valid comparator, and at least two independently evidenced advantages against at least two peers.
  3. Advantages must be either a greater-than-10% measured improvement outside uncertainty or a directly tested control/capability difference with demonstrated user value. Non-comparable or missing data is not a win.
  4. A panel with hardware/economics, security/operations and customer/operator expertise must support the scoped contender conclusion. Passing these judgement-based thresholds does not certify a universal number-one ranking.

Cited by 5 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P16Approved as proposed

Observed durability and claim freshness

  1. At least 90 real elapsed days on the final compatible release family, at least 30 independently verified operators, and transparent eligibility/churn denominators. Material uncomparable changes reset affected observations.
  2. Proposed outcomes: at least 60% day-90 operator retention and at least 75% of eligible observed operators with positive measured marginal operation over the period. Report incentives and electricity assumptions; do not claim a downturn was observed if it was not.
  3. At least 99.9% availability for the declared customer service during eligible operating conditions, with all-in availability also reported; zero accepted invalid proofs or conflicting finality within F0 assumptions. Do not remove real incidents as maintenance to force a pass.
  4. Run fault injection on isolated infrastructure, not unsuspecting customers. Publish planned test windows separately. Reassess claims at least quarterly and immediately after material hardware, protocol, economics or security changes.

Cited by 5 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

Fixtures

What every run is built on.

F0

Release and assurance manifest

Exact commits, binaries, genesis/network ID, mining class, dataset schedule, EVM fork/deviations, program/verifier IDs, fees, supply, quorum/fault rules, trust anchors, activation and supported roles.

F1

Clean build environments

Pinned toolchains, dependency locks, clean OS images and documented signing/notarisation boundaries. No production secrets or private founder files.

F2

Hardware and measurement lab

Approved physical GPU cohort, calibrated wall meters, stable thermal conditions, driver/OS images and realistic home/datacentre link conditions.

F3

Workload and oracle catalogue

Fixed full-hash and EVM/proving jobs, independent reference implementations, real customer-sized payloads, held-out seeds and complete expected results.

F4

Authorised fault network

Independent nodes/operators; controllable latency, loss, clocks, partitions, storage faults and role withdrawals. Actual consensus paths plus separately labelled simulators.

F5

Negative and regression corpus

Malformed transactions/proofs, wrong roots/IDs, duplicate payments, bad authority tables, historical failures and deliberately faulty code mutants.

F6

Specialist implementation pack

Functionally checked architectures, RTL/physical estimates where feasible, memory and board assumptions, cost inputs, adaptation paths and uncertainty ranges.

F7

Economic and incentive models

Independently reproducible costs, entry/exit/difficulty policies, scenario grid, operator opportunity costs and money-flow conservation fixtures.

F8

User/customer/peer studies

Consenting unaffiliated users, contracted meaningful workloads, private ownership checks, dated competitor methods and independent analysis.

F9

Evidence and status vault

Immutable run IDs, raw logs, hashes, analysis code, exclusions, defects, reviewers, signatures, privacy controls and public redacted summaries.

What a full pass means

Independent passage of all mandatory and claimed-option gates, including commercial and comparative observation, can support a scoped leadership-contender assessment. It does not prove a universal rank or eliminate unknown future hardware risks.

Test design, not executed evidence. All numeric additions are proposed, not source-approved protocol rules. Optional claimed features require their tests; excluded features earn no pass credit.

Rules in force

  • P03: a candidate change pays at most 5 percent of joules per accepted work and loses at most 2 percent of accepted throughput against the paired tuned baseline (replaces the 10 percent budget from 18:2x UK)
  • P04: R_E at most 1.5 for every competitive-core cell at the same node and one node ahead against the lowest credible complete-system specialist; today's placed bracket (1.5x to 2.1x same-node) is a FAIL to work against and is served as such
  • P12: the matched-tariff median at most 1.5, p90 at most 1.75, no core cell above 2.0
  • P02: twelve retail configurations, three unaffiliated operators, the seven-day soak define D1's reproduction

Never served: guaranteed chip death, a universal ASIC-efficiency ceiling, chip-arrival probabilities, guaranteed profits, Ethereum security by compatibility, privacy from ZK, a numerical rank.

Source: docs/plans/igneum-2.0-test-registry.json, version 1.0, dated 8 October 2026, plan sha256 418b3b9f68f96a41. This copy was written when the page was built; the page checks the registry on the public git host every 60 seconds.

+ + + + + + + + + + +
+
+
+ +
Learn · ledger
+

The GPU network ledger

+

Every live GPU-mined chain we could pin, measured the same way on the same cards, with the same chip method, and ranked. Igneum is one row among the others, under the same rules.

+
+
+
+ +
+ +

The GPU network ledger

+

Every live GPU-mined chain we could pin, measured the same way on the same rented cards in the same sessions, with the same chip-design method applied to each, and ranked. Igneum sits in the table as one row among the others, under the same rules. Every number is measured or a labelled model with its source; a number that does not exist yet says "pending" and names who owes it; a chain we could not run in-house says NOT RUN and why. The full record with the lane bookkeeping is in the repository at docs/analysis/class-v6/1p5x/ledger/ (README.md and ledger.json); this page is rendered from the same data file.

+

<!-- ledger:stamp:start --> Data: ledger.json, stamp 2026-10-09, adversarial set v3 (build-1:/srv/artefacts/lab/adv/ (README.md, design-notes/adversarial-sets-v1-v2-v3.md, rows/, SHA256SUMS); set v3 commit b2b9ee0b9 on class-v6-adversary). <!-- ledger:stamp:end -->

+
+

The method, the same for every chain

+
  1. The object. Each chain's proof of work as its own pinned reference code, built from source (no downloaded miner binaries):
+

Igneum's frozen class v6 at its live 4 GiB dataset; the official ProgPoW 0.9.4 reference kernel for Ravencoin's KAWPOW (which is ProgPoW 0.9.4 with Ravencoin's constants, so the row is a labelled proxy) and the same row for Firo's FiroPoW; Iron Fish's FishHash reference library with a bit-exact CUDA port; the pinned chfast/ethash library's hashimoto at Ethereum Classic's current epoch; Ergo's Autolykos2 NOT RUN (the reason on the row).

+
  1. The card rows. One rented RTX 4090 and one rented RTX 5090 on uncapped hosts, every chain back to back in one session per
+

card at stock clocks; board power sampled at 1 Hz (idle not subtracted); nJ per hash = watts over MH/s; three runs, the median with its spread; the dataset size and the card's clock on every row; a read-only twin (the same memory reads, the arithmetic cut) where the harness has one, giving the card's memory share f.

+
  1. The chip rows. For each chain, the cheapest credible specialist chip on the same process node as the card, as a complete
+

machine, modelled and labelled as a model (never measured): the DRAM-board chip is the energy row, the full-SRAM die the residual. Two conventions beside every ratio: ours (the cheapest programmable core, fused where the work allows) and ProgPoW's own premise (the chip must keep a GPU-class datapath, so its edge is 1.1x to 1.2x on the compute term, weighted by f).

+
  1. The real chip. Ethereum Classic is the one chain here with a chip on the market, the Antminer E9 Pro; its published rate
+

and power sit on the row, and our modelled chip for Etchash sits beside it as the calibration of the model.

+
  1. The two phases. Before investment: can a chip maker recover its spend under growing, flat and falling prices. After, with
+

the spend sunk: who exits first on operating cost, with each chain's actual reward split. On Igneum a GPU earns the mining share plus the proving share (80 / 20); a hash chip earns the mining share only. On every other chain here the GPU earns mining only, so the second-income term is zero by construction.

+
  1. The ranking. (a) ascending on the DRAM-board ratio under our convention at the worse of the two cards (the lower ratio is
+

the smaller chip edge); (b) the same under ProgPoW's premise; (c) whether the chain's GPUs earn an income a hash chip cannot. A chain with a pending or proxy cell is ranked provisionally and says so; a NOT RUN chain is unranked.

+
+

The card rows (measured, board power, stock)

+

<!-- ledger:cards:start -->

+
chainalgorithmdataset on the rowreward split (mining / proving)RTX 4090 stock: nJ per hash (MH/s, W, f)RTX 5090 stock: nJ per hash (MH/s, W, f)twinsources
Igneumclass v6, the live signing object 0x2a1d6caab4c24564 (2.0 devnet, chain id 4465)4.29 GB (4,294,967,296 bytes); 2^30 words, the live policy (70a6c703); 256 random 4-byte reads per hash, 62,120 instructions per hash (instruction convention)80 / 20 (the Token Value volume on master (D04, token-value/README.md: the 80/20 emission allocation); PROVING_POOL_SHARE_PERCENT)8,369 MEASURED (30.67 MH/s, 256.7 W, f 0.848; spread 0.67%; vast 55009211, driver 580; stock (the pod refused -lgc); clocks_sm_median pending the ledger session)5,597 MEASURED (68.66 MH/s, 384.3 W, f 0.811; spread 2.11%; vast 55006481, driver 580; stock (the pod refused -lgc); the host cap 500 W, the card drew 384)yes (the same address stream, the arithmetic cut)RTX 4090: build-1:/srv/artefacts/lab/ctl-v6/vast-55009211/ (rows.jsonl, SHA256SUMS); the cohort table build-1:/srv/artefacts/lab/cohort/TABLE.md; RTX 5090: build-1:/srv/artefacts/lab/ctl-v6/vast-55006481/; the cohort table build-1:/srv/artefacts/lab/cohort/TABLE.md
RavencoinKAWPOW (ProgPoW 0.9.4 with Ravencoin's kiss99 constants, 7,500-block epochs and a 512-parent DAG; live since block 1,219,736, 6 May 2020)6.18 GB (6,182,403,712 bytes); KAWPOW's current DAG size at Ravencoin height 4,573,707 (epoch 609, read 13:0x UK): the official ProgPoW 0.9.4 kernel built at Ethash block 18,270,000 (epoch 609, the same byte count), harness progpow-094/gpu/pp_harness_18270000; KAWPOW's own constants NOT applied, so the row is 'ProgPoW 0.9.4 official at KAWPOW's DAG size (proxy)'; 64 coalesced 256-byte reads per hash; F1 GPU = CPU on both nonces (cpu/vectors-094-kawpow-size-18270000.txt)100 / 0 (Ravencoin's block reward goes to the miner in full (no second income to GPUs))6,920 MEASURED (prior row: kawpowminer, not the pinned kernel; a PROXY until the ledger session's pinned-kernel row lands) (58.95 MH/s, 409.0 W, f none; spread none; RunPod, the comparative lane a2ed5c31; stock)pending: pending (COHORT, the ledger session)yes, by construction (progpow-094/gpu/pp_twin 18270000 26 250: the 64 dependent entry reads per 16-lane hash)RTX 4090: build-1:/srv/artefacts/lab/adv/rows/rows.md (the ctl-progpow-094 section, card rows)
FiroFiroPoW (ProgPoW 0.9.4 with Firo's constants; live since block 419,264, 26 October 2021)= Ravencoin's row100 / 0= Ravencoin's row= Ravencoin's rowas Ravencoinas KAWPOW: the pinned ProgPoW 0.9.4 reference; FiroPoW differs from KAWPOW only in its constants and DAG schedule, so the lab serves ONE row for both and says so
Iron FishFishHash (live since hardfork 1, April 2024)4.83 GB (4,831,835,776 bytes); 37,748,717 items of 128 bytes, FIXED (no epochs); 96 random 128-byte reads per hash, 9,856 lane-instructions100 / 0 (Iron Fish's block reward is mining only)pending: pending (COHORT, the ledger session); CONTROLS' rate-only read 19.73 MH/s at stock, no sampler (rate only 19.73 MH/s)pending: pending (COHORT, the ledger session); CONTROLS' rate-only sm_120 read 45.37 MH/s full, 39.71 twin, F1 PASS (rate only 45.37 MH/s)yes (a trace replay of the kernel's own item indexes; its energy read as a bound: the twin runs 10 percent slower than the full kernel)RTX 4090: build-1:/srv/artefacts/lab/controls/fishhash/gpu/bench-4090.log; RTX 5090: build-1:/srv/artefacts/lab/controls/fishhash/ (fishhash.md)
Ethereum ClassicEtchash (Ethash with ECIP-1099's 60,000-block epochs; live since block 11,700,000, November 2020)4.64 GB (4,638,898,816 bytes); ETC height 25,502,946 (read 12:5x UK) = Etchash epoch 425 (ECIP-1099: height / 60,000), the harness's block argument 12,750,000 (the Ethash epoch with the same size table index); 64 coalesced 128-byte reads per hash (two 64-byte half-mixes); CONTROLS' rate-only read on a 4090 at stock 29.90 MH/s full and 29.90 twin (memory-bound)100 / 0 (ETC's block reward is mining only)pending: pending (COHORT, the ledger session; the harness staged 13:0x UK); CONTROLS' rate-only read 29.90 MH/s (rate only 29.90 MH/s)pending: pending (COHORT, the ledger session; the sm_120 build from etchash/src)yes, by constructionRTX 4090: build-1:/srv/artefacts/lab/controls/etchash/ (etchash.md)
ErgoAutolykos2 (k = 32, n = 26, Blake2b-256; the table grows 5 percent every 51,200 blocks)7.27 GB (7,272,058,080 bytes); the live table at Ergo height 1,890,820 (api.ergoplatform.com, 13:0x UK): N = 227,251,815 elements of 32 bytes (+5 percent at height 1,894,400; the row names its height); 33 random 32-byte reads per hash; the table builds on the device in 1.5 s; CONTROLS' rate-only read on a 4090 at stock 216.2 MH/s full, 201.8 twin100 / 0 (Ergo's block reward is mining only)pending: pending (COHORT, the ledger session; the harness staged 13:1x UK); CONTROLS' rate-only read 216.2 MH/s full, 201.8 twin (rate only 216.20 MH/s)pending: pending (COHORT, the ledger session; the sm_120 build from src)yes (a trace replay)RTX 4090: build-1:/srv/artefacts/lab/controls/autolykos/ (autolykos.md)
+

<!-- ledger:cards:end -->

+
+

The chip-to-GPU edge, both conventions

+

<!-- ledger:edge:start -->

+
chainthe cheapest credible same-node DRAM board (set v3, nJ per hash, band)ratio at the RTX 4090 stock (ours)ratio at the RTX 5090 stock (ours)ProgPoW-premise ratio at the RTX 4090ProgPoW-premise ratio at the RTX 5090the die as the residual (nJ; ratio at the worse card)real chip on the marketsource
Igneum1,542 (1,329 to 1,941); GDDR7 board + register file sized to the work + fused operations, N5; split memory 527 / ALU 166 / tax 849; WITNESS (modelled, complete machine, instruction convention)5.43x (4.31 to 6.30)3.63x (2.88 to 4.21)1.01x to 1.03x (f 0.853 measured)1.02x to 1.03x (f 0.811 measured on the stock pod)335 (N2 full-SRAM die, the coexistence row); 25.0xnone on the marketdocs/analysis/class-v6/1p5x/lab/adv/v3/ledger-rows.md and ledger-rows.json (class-v6-adversary 47f16b86f); build-1:/srv/artefacts/lab/adv/rows/ctl-v6.json and rows.md (set v3, 2026-10-09T11:33Z); the die 12.0x at the 5090 knee, USD 0.77 per MH/s
Ravencoin1,757 (1,453 to 2,147); GDDR7 board + register file sized to the work + fused operations, N5; bandwidth-bound at 16 KB per hash (93 MH/s per board); split memory 647 / ALU and tax per rows.md; WITNESS (modelled on the kawpowminer census as the work proxy until CONTROLS' trace replaces it)3.94x (3.22 to 4.76)pending1.10x to 1.20x (the premise's own figure; no measured twin on this kernel yet)1.10x to 1.20x (the premise's own figure; the twin row makes it measured)697 (N2 full-SRAM die, the coexistence row (USD 1.89 per MH/s); the cheapest specialist of any kind is near-memory base dies at 669 nJ); 9.9xnone on the marketdocs/analysis/class-v6/1p5x/lab/adv/v3/ledger-rows.md and ledger-rows.json (class-v6-adversary 47f16b86f); build-1:/srv/artefacts/lab/adv/rows/ctl-progpow-094.json (set v3)
Firo (= Ravencoin's row)1,757 (1,453 to 2,147); GDDR7 board + register file sized to the work + fused operations, N5; bandwidth-bound at 16 KB per hash (93 MH/s per board); split memory 647 / ALU and tax per rows.md; WITNESS (modelled on the kawpowminer census as the work proxy until CONTROLS' trace replaces it)3.94x (3.22 to 4.76)pending1.10x to 1.20x (the premise's own figure; no measured twin on this kernel yet)1.10x to 1.20x (the premise's own figure; the twin row makes it measured)697 (N2 full-SRAM die, the coexistence row (USD 1.89 per MH/s); the cheapest specialist of any kind is near-memory base dies at 669 nJ); 9.9xnone on the market= Ravencoin's row
Iron Fish1,051 (881 to 1,257); GDDR7 board + register file sized to the work + fused operations, N5; bandwidth-bound at 124 MH/s per board; 95 percent of the board's energy is the memory path; split memory 529 / ALU 46 / tax 503; WITNESS (modelled; the card's cell pending, so the ratio is pending)pendingpendingpending (needs the measured f from the twin)pending170 (full SRAM dies (three N2 reticles) + sized + fused operations); pendingnone on the marketbuild-1:/srv/artefacts/lab/adv/rows/ctl-fishhash.json and rows.md (set v3)
Ethereum Classic765 (638 to 919); GDDR7 board + register file sized to the work + fused operations, N5; USD 3.25 per MH/s; split per ledger-rows.md; WITNESS (modelled; the card cells pending, so the ratios are pending)pendingpending1.10x to 1.20x (the premise's own figure; the twin row makes it measured)1.10x to 1.20x (the premise's own figure)177 (N2 full-SRAM die, the coexistence row); pendingBitmain Antminer E9 Pro: 3,680 MH/s at 2,200 W = 598 nJ per hash, WITNESS (a manufacturer's published figure, not measured by the lab); Bitmain's stated figures as listed on minerstat's hardware page (https://minerstat.com/hardware/antminer-e9-pro): 3.68 GH/s on Ethash at 2,200 W, release 2023-02; 2,200 W / 3,680 MH/s = 0.598 J per MH = 598 nJ per hashdocs/analysis/class-v6/1p5x/lab/adv/v3/ledger-rows.md and ledger-rows.json (class-v6-adversary 47f16b86f, wording 82330b04c)
Ergopending: pending (ADVERSARY: the chip rows from CONTROLS' trace; default 15:00 UK, else pending (adversary))pendingpendingpendingpendingpendingnone on the marketpending
+

<!-- ledger:edge:end -->

+
+

The two phases with each chain's actual split

+

<!-- ledger:phases:start -->

+
chainsplitphase A (before investment)phase B (spend sunk)an income a hash chip cannot earnsource
Igneum80 / 20before investment (24 months, the mining share 80 percent of the year-1 subsidy): the same-node board maker recovers its spend on NO fleet from 100 to 100 M boards on the growing or flat price path (100,000 boards: net USD -55.4 M on 58.8 M revenue growing; -37.6 M on 76.6 M flat); only the falling path pays it; the N2 die recovers on no pathspend sunk, flat path at USD 0.10 per kWh, the chip at 10 percent of the hash: mining revenue USD 0.354 per TH; the GPU's proving income at the ratified 20 percent share USD 0.098 per TH against the board chip's operating advantage USD 0.046 per TH (GPU electricity 0.111 less the chip's electricity, hosting and maintenance 0.066): the GPU out-earns the built board chip; the cancelling proving share 9 percent (board), 13 (hybrid), 20 (die)yes by rule (the proving share of every block, 20 percent ratified); LIVE ON DEVNET with on-chain paid records (663 paid v1 segment records to 30 prover keys on chain 4465, the PROVING LIVE lane's file bd3f53c1 on build-1), not yet in a shipped packagebuild-1:/srv/artefacts/lab/adv/rows/rows.md (the two-phase section), ADVERSARY commit 545f3f8a0; ctl-v6-coexistence.json; WITNESS; phase B NOT LIVE until a shipped package runs a prover
Ravencoin100 / 0before investment: no fleet from 100 to 100 M machines recovers a board chip's spend on any path, because Ravencoin's whole mining emission over 24 months (about USD 2.9 M at the public price) sits below one USD 35 M design cost; 10,000 boards would take 56 percent of the 721 GH/s network and earn USD 1.6 M to 2.4 M against a USD 44 M spendspend sunk, mining only: mining revenue USD 0.064 per TH of the chain's own hashes; the board chip's recurring cost USD 0.069 per TH at ten cents; the chip's operating advantage over the RTX 4090 at stock (6,920 nJ) USD 0.123 per TH (the GPU's electricity 0.192 less the chip's 0.069) stands in full, no prover incomeno (the block reward is mining only)docs/analysis/class-v6/1p5x/lab/adv/v3/ctl-progpow-094-coexistence.json (rows[].phase_a, rows[].phase_b_split; method lab/adv/README.md section 14), ADVERSARY commit d7db3e596 on class-v6-adversary; WITNESS, the chain's own units, the 100/0 split, the same 24-month life, design cost and fleet rule as v6, the three price paths (flat at the public price, x2 growing, x0.5 falling, the hash held); the public lines on the row
Firo100 / 0as KAWPOWas KAWPOWnoas KAWPOW; = KAWPOW's row at a 100/0 split
Iron Fish100 / 0before investment: no fleet from 100 to 100 M machines recovers a board chip's spend on any path; Iron Fish's whole mining emission over 24 months is about USD 1.4 M at the public price (10,000 boards would take 84 percent of the hash for USD 1.1 M to 1.6 M)spend sunk, mining only: mining revenue USD 0.086 per TH of the chain's own hashes; the board chip's recurring cost USD 0.043 per TH at ten cents; the GPU side NOT RUN until the card cell lands; no prover income by constructionnodocs/analysis/class-v6/1p5x/lab/adv/v3/ctl-fishhash-coexistence.json, ADVERSARY commit d7db3e596 on class-v6-adversary; WITNESS, the chain's own units, the 100/0 split, the same life, design cost, fleet rule and price paths as v6; the GPU side of phase B NOT RUN until COHORT's card rows
Ethereum Classic100 / 0before investment: no fleet from 100 to 100 M machines recovers a board chip's spend on any path; ETC's whole mining emission over 24 months is about USD 83 M at the public price, but 10,000 boards are 2 percent of 120.9 TH/s and earn USD 1.0 M to 1.5 M, and 100,000 boards (13 percent) USD 9 M to 13 M against a USD 150 M spendspend sunk, mining only: mining revenue USD 0.0087 per TH of the chain's own hashes, below even the modelled board's recurring cost (USD 0.031 per TH) and below the E9 Pro's own electricity at ten cents (598 nJ = USD 0.017 per TH): at the public figures nobody mines ETC at a profit at ten cents and phase B is a loss on both sides; the GPU side NOT RUN until the card cell landsnodocs/analysis/class-v6/1p5x/lab/adv/v3/ctl-etchash-coexistence.json, ADVERSARY commit d7db3e596 on class-v6-adversary; WITNESS, the chain's own units, the 100/0 split, the same life, design cost, fleet rule and price paths as v6; the GPU side of phase B NOT RUN until COHORT's card rows
Ergo100 / 0pending (ADVERSARY)pending (ADVERSARY); no prover income by constructionnopending; pending (ADVERSARY at the 100/0 split, the public line on the row)
+

<!-- ledger:phases:end -->

+
+

The ranking

+

<!-- ledger:ranking:start --> (a) Ours, the same-node DRAM board at the worse card (the smaller chip edge first): No order in this column yet: a cross-chain comparison is made only between cells from the same card, state and session, and the measured cells today come from 2 sessions (lab-cohort-ctl-v6 (COHORT, 11:49 to 12:30 UK, one chain); comparative-lane a2ed5c31 (RunPod, one chain, an earlier session)); the ledger session (both cards, every chain back to back) fills it. Each chain's own number, same card and state, as it stands:

+
  • Igneum: RTX 4090 stock 5.43x (4.31 to 6.30); RTX 5090 stock 3.63x (2.88 to 4.21)
  • Ravencoin: RTX 4090 stock 3.94x (3.22 to 4.76); RTX 5090 stock pending (a pending or proxy cell in this row)
  • Iron Fish: unranked in this column (no measured card cell yet)
  • Ethereum Classic: unranked in this column (no measured card cell yet)
  • Ergo: unranked in this column (no measured card cell yet)
+

(b) ProgPoW's premise (the chip keeps a GPU-class datapath):

+
  • Igneum: RTX 4090 1.01x to 1.03x (f 0.853 measured); RTX 5090 1.02x to 1.03x (f 0.811 measured on the stock pod)
  • Ravencoin: RTX 4090 1.10x to 1.20x (the premise's own figure; no measured twin on this kernel yet); RTX 5090 1.10x to 1.20x (the premise's own figure; the twin row makes it measured)
  • Iron Fish: RTX 4090 pending (needs the measured f from the twin); RTX 5090 pending
  • Ethereum Classic: RTX 4090 1.10x to 1.20x (the premise's own figure; the twin row makes it measured); RTX 5090 1.10x to 1.20x (the premise's own figure)
  • Ergo: RTX 4090 pending; RTX 5090 pending
+

(c) Phase B, an income a hash chip cannot earn:

+
  • Igneum: yes by rule (the proving share of every block, 20 percent ratified); LIVE ON DEVNET with on-chain paid records (663 paid v1 segment records to 30 prover keys on chain 4465, the PROVING LIVE lane's file bd3f53c1 on build-1), not yet in a shipped package
  • Ravencoin: no (the block reward is mining only)
  • Firo: no
  • Iron Fish: no
  • Ethereum Classic: no
  • Ergo: no
+

<!-- ledger:ranking:end -->

+
+

The claim under test, clause by clause

+

The sentence below is served as a claim under test, each clause labelled by its state on the rows above. It reads as established only when every clause is supported; today it is not, and the table says which clause and why.

+

<!-- ledger:claim:start --> The headline, built from the supported clauses only: under ProgPoW's own convention, the lowest measured chip-to-GPU edge of the chains on this ledger; and the only chain on this ledger whose GPUs are paid, by rule, an income a hash chip cannot earn (LIVE ON DEVNET, on-chain records (the PROVING LIVE lane, read 11:50:22Z 9 October 2026): on chain id 4465 (the Igneum 2.0 devnet) 663 paid v1 segment records (8 shards plus aggregation each) = 653.93 IGN paid from the proving pool to 30 distinct prover keys across chain blocks 3,000 to 30,687 (tip 31,719 at the read), plus 6,474 paid v0 shard records = 7,196 IGN; read by igneum_getProvingStatus, igneum_getSegmentRecords (3,965 segments) and igneum_getSegment; evidence build-1:/srv/artefacts/proving-live/prov-ledger-4465-tip31719-115022Z.json sha256 bd3f53c18c3ffa20354ea62ade9fd5e7a5794202a71c3c369a5be71484f7143a. NOT YET LIVE IN A SHIPPED PACKAGE: the payees are the fleet's prover stack (the same binaries the 2.0.3.1 HiveOS package wraps, cut 18:00 UK); the apps' prover is on by default on 24 GB cards but no app-proved record is on the record yet; a full-epoch line follows by 16:00 UK).

+

The sentence as ordered, served as the claim under test: "the lowest measured chip-to-GPU edge of any live GPU network under a published method, on both conventions, and the only one whose GPUs earn income a chip cannot"

+

Rule: the headline reads only what the like-for-like rows support, clause by clause (main's ruling, 13:2x UK 9 October 2026); under the ledger's own convention the measured edge per chain on the same card and state is stated as numbers, with no ranking word until the rows say so after the ledger session.

+
clauseconventionstate on the current rowswhy
under ProgPoW's own convention, the lowest measured chip-to-GPU edge of the chains on this ledgerProgPoW's premise (a chip that keeps a GPU-class datapath)SUPPORTED on the current rowsIgneum v6 1.01x to 1.03x (its measured f 0.81 to 0.85) against ProgPoW's own 1.10x to 1.20x for KAWPOW and FiroPoW; FishHash and Etchash pending their twins
under the ledger's convention (the cheapest credible programmable specialist, adversarial set v3), each chain's measured edge on the same card and state, as numbersoursNUMBERS ONLY; no ranking until the ledger session (COHORT, both cards, every chain back to back, the pinned 0.9.4 kernel, twins; 14:45 UK)the current cells come from different sessions (the lab's cohort pods for v6, the comparative lane's pod for KAWPOW) and a cross-chain comparison is made only between cells from the same card, state and session; at the RTX 4090 at stock the cells read v6 5.4x (5.67x on the second pod) and KAWPOW 3.9x (a proxy row from an earlier session); FishHash and Etchash pending
and the only chain on this ledger whose GPUs are paid, by rule, an income a hash chip cannot earnphase B, each chain's actual reward splitLABELLED BY THE PROVING LIVE LANEthe proving share (20 percent ratified) is paid to GPUs for work a hash chip cannot do; every other chain on the ledger pays mining only; the live state of that income is the PROVING LIVE lane's evidence line
+

Withdrawn: the earlier line 'KAWPOW and FiroPoW read 5 to 6x on the measured 4090 rows and v6 reads 2.35x' is withdrawn: it compared v6 at the 5090's 1,300 MHz knee with KAWPOW at the 4090 at stock, two cards and two states; the like-for-like cells are the ones on this ledger.

+

The last clause's label from the PROVING LIVE lane: LIVE ON DEVNET, on-chain records (the PROVING LIVE lane, read 11:50:22Z 9 October 2026): on chain id 4465 (the Igneum 2.0 devnet) 663 paid v1 segment records (8 shards plus aggregation each) = 653.93 IGN paid from the proving pool to 30 distinct prover keys across chain blocks 3,000 to 30,687 (tip 31,719 at the read), plus 6,474 paid v0 shard records = 7,196 IGN; read by igneum_getProvingStatus, igneum_getSegmentRecords (3,965 segments) and igneum_getSegment; evidence build-1:/srv/artefacts/proving-live/prov-ledger-4465-tip31719-115022Z.json sha256 bd3f53c18c3ffa20354ea62ade9fd5e7a5794202a71c3c369a5be71484f7143a. NOT YET LIVE IN A SHIPPED PACKAGE: the payees are the fleet's prover stack (the same binaries the 2.0.3.1 HiveOS package wraps, cut 18:00 UK); the apps' prover is on by default on 24 GB cards but no app-proved record is on the record yet; a full-epoch line follows by 16:00 UK <!-- ledger:claim:end -->

+
+

Reproduce it tonight

+

The reproduction kit (the pinned references, the harnesses, the sampler, the session script, SHA256SUMS and the expected rows with their bands) is published from the build host when it lands; the link and its sha256 go here. One command per card; a 4090 at stock on an uncapped host reproduces the Igneum row inside its band in under ten minutes after the dataset builds.

+
itemstate
the kitpending
the kit's sha256pending
+
+

Generated from docs/ledger/gpu-ledger.md in the repository at build time. Times are UTC.

+
+
+ + + + + + + + \ No newline at end of file diff --git a/site/grants.html b/site/grants.html index 2573f33a1..50caf03fe 100644 --- a/site/grants.html +++ b/site/grants.html @@ -133,6 +133,7 @@ table{min-width:560px} EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -173,6 +174,7 @@ table{min-width:560px} EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -307,6 +309,7 @@ table{min-width:560px} Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/income.html b/site/income.html index 7b8d6a9c0..36c23c5d2 100644 --- a/site/income.html +++ b/site/income.html @@ -106,6 +106,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -146,6 +147,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -257,6 +259,7 @@ Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/index.html b/site/index.html index 734544bbc..0ac7c0757 100644 --- a/site/index.html +++ b/site/index.html @@ -124,6 +124,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -164,6 +165,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -330,6 +332,7 @@ Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/ledger.html b/site/ledger.html index 4899df433..e8cc8aa84 100644 --- a/site/ledger.html +++ b/site/ledger.html @@ -137,6 +137,7 @@ blockquote{margin:10px 0;padding:10px 14px;border-left:3px solid var(--line-2);c EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -177,6 +178,7 @@ blockquote{margin:10px 0;padding:10px 14px;border-left:3px solid var(--line-2);c EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -484,6 +486,7 @@ blockquote{margin:10px 0;padding:10px 14px;border-left:3px solid var(--line-2);c Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/light.html b/site/light.html index e7c461870..80f73730c 100644 --- a/site/light.html +++ b/site/light.html @@ -140,6 +140,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -180,6 +181,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -333,6 +335,7 @@ Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/litepaper.html b/site/litepaper.html index 6e2822a3a..bd48a243e 100644 --- a/site/litepaper.html +++ b/site/litepaper.html @@ -189,6 +189,7 @@ body.all .pager{display:none} EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -229,6 +230,7 @@ body.all .pager{display:none} EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -909,6 +911,7 @@ body.all .pager{display:none} Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/live.html b/site/live.html index 97a61c01d..1f5642e35 100644 --- a/site/live.html +++ b/site/live.html @@ -273,6 +273,7 @@ details.tablebar summary{display:flex;align-items:center} EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -313,6 +314,7 @@ details.tablebar summary{display:flex;align-items:center} EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -548,6 +550,7 @@ details.tablebar summary{display:flex;align-items:center} Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/metamask.html b/site/metamask.html index 646b7bb7f..555134327 100644 --- a/site/metamask.html +++ b/site/metamask.html @@ -134,6 +134,7 @@ ol{margin:0 0 14px;padding-left:22px}li{margin-bottom:6px} EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -174,6 +175,7 @@ ol{margin:0 0 14px;padding-left:22px}li{margin-bottom:6px} EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -323,6 +325,7 @@ ol{margin:0 0 14px;padding-left:22px}li{margin-bottom:6px} Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/miner.html b/site/miner.html index 15e9ce154..1ca8d07b4 100644 --- a/site/miner.html +++ b/site/miner.html @@ -129,6 +129,7 @@ pre b{color:var(--molten-text);font-weight:500} EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -169,6 +170,7 @@ pre b{color:var(--molten-text);font-weight:500} EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -494,6 +496,7 @@ pre b{color:var(--molten-text);font-weight:500} Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/miners.html b/site/miners.html index de0cec237..37e56c1e7 100644 --- a/site/miners.html +++ b/site/miners.html @@ -133,6 +133,7 @@ table{min-width:560px} EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -173,6 +174,7 @@ table{min-width:560px} EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -362,6 +364,7 @@ table.bench2 tr.detail .d{display:block;margin:0 0 4px}table.bench2 tr.detail b{ Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/oracle.html b/site/oracle.html index 0ca2ecbcf..3147c1e82 100644 --- a/site/oracle.html +++ b/site/oracle.html @@ -140,6 +140,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -180,6 +181,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -335,6 +337,7 @@ Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/partials/footer.html b/site/partials/footer.html index 4c0a93353..ecd1dd756 100644 --- a/site/partials/footer.html +++ b/site/partials/footer.html @@ -29,6 +29,7 @@ Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/partials/nav.html b/site/partials/nav.html index afbe2ad07..ad2945381 100644 --- a/site/partials/nav.html +++ b/site/partials/nav.html @@ -48,6 +48,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -88,6 +89,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. diff --git a/site/prize.html b/site/prize.html index 66c8d0501..e36c51ad7 100644 --- a/site/prize.html +++ b/site/prize.html @@ -106,6 +106,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -146,6 +147,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -265,6 +267,7 @@ Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/provenance.html b/site/provenance.html index 563a326da..f78ac3cce 100644 --- a/site/provenance.html +++ b/site/provenance.html @@ -133,6 +133,7 @@ table{min-width:560px} EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -173,6 +174,7 @@ table{min-width:560px} EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -306,6 +308,7 @@ table{min-width:560px} Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/proving.html b/site/proving.html index d84858b84..8f32e3f8d 100644 --- a/site/proving.html +++ b/site/proving.html @@ -159,6 +159,7 @@ main{padding-bottom:100px}.card{background:var(--row);border:1px solid var(--lin EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -199,6 +200,7 @@ main{padding-bottom:100px}.card{background:var(--row);border:1px solid var(--lin EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -337,6 +339,7 @@ main{padding-bottom:100px}.card{background:var(--row);border:1px solid var(--lin Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/randomx.html b/site/randomx.html index c3302c682..7148f41d5 100644 --- a/site/randomx.html +++ b/site/randomx.html @@ -132,6 +132,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -172,6 +173,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -297,6 +299,7 @@ Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/receipt.html b/site/receipt.html index f7c965d2c..816223a2b 100644 --- a/site/receipt.html +++ b/site/receipt.html @@ -138,6 +138,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -178,6 +179,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -332,6 +334,7 @@ Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/scenes.html b/site/scenes.html index 7fcdaad07..d2d17e1b0 100644 --- a/site/scenes.html +++ b/site/scenes.html @@ -124,6 +124,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -164,6 +165,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -299,6 +301,7 @@ Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/scorecard.html b/site/scorecard.html index f3403598f..611e07924 100644 --- a/site/scorecard.html +++ b/site/scorecard.html @@ -106,6 +106,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -146,6 +147,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -274,6 +276,7 @@ Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/sitemap.xml b/site/sitemap.xml index d136c7bb9..40c0c6be0 100644 --- a/site/sitemap.xml +++ b/site/sitemap.xml @@ -16,6 +16,7 @@ https://igneum.network/oracle2026-10-08weekly0.6 https://igneum.network/miners2026-10-07weekly0.6 https://igneum.network/claims2026-10-07monthly0.5 + https://igneum.network/gpu-ledger2026-10-09weekly0.6 https://igneum.network/randomx2026-10-07monthly0.5 https://igneum.network/provenance2026-10-07monthly0.4 https://igneum.network/dev-fee2026-10-07monthly0.4 diff --git a/site/swap.html b/site/swap.html index 422f8e1a3..25c126c48 100644 --- a/site/swap.html +++ b/site/swap.html @@ -143,6 +143,7 @@ dt{color:var(--ash)}dd{margin:0;font-family:var(--f-mono);font-size:13px;overflo EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -183,6 +184,7 @@ dt{color:var(--ash)}dd{margin:0;font-family:var(--f-mono);font-size:13px;overflo EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -357,6 +359,7 @@ dt{color:var(--ash)}dd{margin:0;font-family:var(--f-mono);font-size:13px;overflo Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/tuning.html b/site/tuning.html index 93f2f4d87..2c9419777 100644 --- a/site/tuning.html +++ b/site/tuning.html @@ -133,6 +133,7 @@ table{min-width:560px} EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -173,6 +174,7 @@ table{min-width:560px} EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -317,6 +319,7 @@ table{min-width:560px} Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/tx.html b/site/tx.html index 7e5e9d643..e6fd48f01 100644 --- a/site/tx.html +++ b/site/tx.html @@ -160,6 +160,7 @@ main{padding-bottom:100px}.card{background:var(--row);border:1px solid var(--lin EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -200,6 +201,7 @@ main{padding-bottom:100px}.card{background:var(--row);border:1px solid var(--lin EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -313,6 +315,7 @@ main{padding-bottom:100px}.card{background:var(--row);border:1px solid var(--lin Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/site/wallet.html b/site/wallet.html index 1d800b116..d40cb87dd 100644 --- a/site/wallet.html +++ b/site/wallet.html @@ -142,6 +142,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -182,6 +183,7 @@ EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. + GPU network ledgerEvery GPU-mined chain, measured the same way. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. Built on the shouldersEvery borrowed part, credited. @@ -431,6 +433,7 @@ Evidence Ledger: every criticism What Igneum does not claim + GPU network ledger Igneum vs RandomX Built on the shoulders diff --git a/tools/ci/batches/lab-20261009-01.json b/tools/ci/batches/lab-20261009-01.json index 37be513e1..75f2f0a59 100644 --- a/tools/ci/batches/lab-20261009-01.json +++ b/tools/ci/batches/lab-20261009-01.json @@ -26,7 +26,7 @@ "in_progress": true, "method": "model", "evidence": "docs/analysis/class-v6/1p5x/lab/README.md; docs/analysis/class-v6/1p5x/lab/table.md", - "note": "The lab's interface and the candidate table at the fan-out: the frozen v6 control carried from the record (the house 5090 at its knee 4,011 nJ per hash, board power; the X0 amendment 5b rows: the DRAM board 2.35x same node WITNESS, the N2 die 7.8x the worst credible), the cohort rows for the 3090, the 5080 and the AMD and Intel tiers NOT RUN, adversarial set v1 pending; the three other controls (ProgPoW 0.9.4 reference, FishHash, the cooperative ARX candidate) NOT RUN with their clocks. No score is the lab's until the cohort and the adversary rows are in; R15-01, R15-08 and R15-09 stay NOT RUN until read. X10 (cand-x10) joins the table NOT RUN with its per-lane assignments and clocks; COHORT's ctl-v6 denominator set is in flight on eight rented pods. 12:1x UK: adversarial set v1 on the table (the frozen v6's same-node board 2.57x, 2.04 to 3.00, the fused tail CLAIMED until the routed lanes land; the die 11.4x as a coexistence row); the coexistence table (interface section 8b) added as the scoreboard's headline; SEARCH's first screen recorded as SCREEN rejections. Still NOT RUN: no cohort score until COHORT's eight rows are read back. 12:2x UK: set v2 (the routed fused-ARX lanes) makes the v6 board 2.60x a WITNESS; the ctl-v6 coexistence table (the board holds at every price; the N2 die pushes the GPU owner out above 14,300 dies at USD 0.10) is the headline; X10 SCREEN with the card modelled (the board 3.00x at 118 loads). Still NOT RUN: the cohort rows in their timed runs. 12:3x UK: the first cohort cells (ctl-v6 at stock on rented 5090, 5080 and 3090 pods: the worst cell the 3090 at 8,429 nJ = 5.46x on set v2's same-node board, PARTIAL, the dataset size under decision after CONTROLS measured the live 4 GiB object at 2.4x the 1 GiB research pack's rate); X10's first measured cell (cand-x10b on the 4090 at stock 3,653 nJ per lane-work = 5.8x on the board; the fold buys nothing); set v3 (routed 64-register and multiply-xor lanes); the fourth to sixth review rulings (8c); the 4 GiB rule (8e). Every row still NOT RUN until read. 12:4x UK: ctl-v6's first full score over the NVIDIA cohort at stock (the worst cell the RTX 4090 uncapped 8,751 nJ = 5.67x on set v2's same-node board; every cell at 4 GiB, the earlier 2.4x reading an instrument artefact, corrected once); the two-phase rows (ADVERSARY 545f3f8a0, 36d17b15c): phase B NOT LIVE until a shipped package proves, the shipping row open; SEARCH's twenty candidates on set v3 none under 1.5x on any cell (SCREEN). Every row still NOT RUN until read. 13:0x UK: the decider closed on both cards (the 4 GiB object costs 2.0 to 2.9 percent of rate against its 1 GiB export; the 2.4x reading withdrawn as a contention fault); the read-headroom row answered (both cards at their activation limit); the uncapped 5090 cell 5,980 nJ = 3.88x on the board; the shipping row's facts by file and line with the Devnet 4 correction (a 24 GB card proves the v1 shard now; the proving row NOT LIVE until the epoch record by 16:00); the 4 GiB cap defined as the mining dataset floor only; the founder's ledger order (8f) applied. Every row still NOT RUN until read.", + "note": "The lab's interface and the candidate table at the fan-out: the frozen v6 control carried from the record (the house 5090 at its knee 4,011 nJ per hash, board power; the X0 amendment 5b rows: the DRAM board 2.35x same node WITNESS, the N2 die 7.8x the worst credible), the cohort rows for the 3090, the 5080 and the AMD and Intel tiers NOT RUN, adversarial set v1 pending; the three other controls (ProgPoW 0.9.4 reference, FishHash, the cooperative ARX candidate) NOT RUN with their clocks. No score is the lab's until the cohort and the adversary rows are in; R15-01, R15-08 and R15-09 stay NOT RUN until read. X10 (cand-x10) joins the table NOT RUN with its per-lane assignments and clocks; COHORT's ctl-v6 denominator set is in flight on eight rented pods. 12:1x UK: adversarial set v1 on the table (the frozen v6's same-node board 2.57x, 2.04 to 3.00, the fused tail CLAIMED until the routed lanes land; the die 11.4x as a coexistence row); the coexistence table (interface section 8b) added as the scoreboard's headline; SEARCH's first screen recorded as SCREEN rejections. Still NOT RUN: no cohort score until COHORT's eight rows are read back. 12:2x UK: set v2 (the routed fused-ARX lanes) makes the v6 board 2.60x a WITNESS; the ctl-v6 coexistence table (the board holds at every price; the N2 die pushes the GPU owner out above 14,300 dies at USD 0.10) is the headline; X10 SCREEN with the card modelled (the board 3.00x at 118 loads). Still NOT RUN: the cohort rows in their timed runs. 12:3x UK: the first cohort cells (ctl-v6 at stock on rented 5090, 5080 and 3090 pods: the worst cell the 3090 at 8,429 nJ = 5.46x on set v2's same-node board, PARTIAL, the dataset size under decision after CONTROLS measured the live 4 GiB object at 2.4x the 1 GiB research pack's rate); X10's first measured cell (cand-x10b on the 4090 at stock 3,653 nJ per lane-work = 5.8x on the board; the fold buys nothing); set v3 (routed 64-register and multiply-xor lanes); the fourth to sixth review rulings (8c); the 4 GiB rule (8e). Every row still NOT RUN until read. 12:4x UK: ctl-v6's first full score over the NVIDIA cohort at stock (the worst cell the RTX 4090 uncapped 8,751 nJ = 5.67x on set v2's same-node board; every cell at 4 GiB, the earlier 2.4x reading an instrument artefact, corrected once); the two-phase rows (ADVERSARY 545f3f8a0, 36d17b15c): phase B NOT LIVE until a shipped package proves, the shipping row open; SEARCH's twenty candidates on set v3 none under 1.5x on any cell (SCREEN). Every row still NOT RUN until read. 13:0x UK: the decider closed on both cards (the 4 GiB object costs 2.0 to 2.9 percent of rate against its 1 GiB export; the 2.4x reading withdrawn as a contention fault); the read-headroom row answered (both cards at their activation limit); the uncapped 5090 cell 5,980 nJ = 3.88x on the board; the shipping row's facts by file and line with the Devnet 4 correction (a 24 GB card proves the v1 shard now; the proving row NOT LIVE until the epoch record by 16:00); the 4 GiB cap defined as the mining dataset floor only; the founder's ledger order (8f) applied. Every row still NOT RUN until read. 13:1x UK: CONTROLS' done line (the four controls, Etchash and Autolykos2 staged bit-exact with SUMS); ADVERSARY's cross-chain phase A and B (no chain's emission recovers a board chip; the proving share the one term) and the E9 Pro calibration (1.28x pessimistic); the first founder bundle 985afee6. Every row still NOT RUN until read.", "claim_impact": "none" } ], diff --git a/tools/ci/site-nav-check.mjs b/tools/ci/site-nav-check.mjs index 77d17ea98..7dbc68280 100644 --- a/tools/ci/site-nav-check.mjs +++ b/tools/ci/site-nav-check.mjs @@ -15,7 +15,7 @@ const here = dirname(fileURLToPath(import.meta.url)); const GROUPS = { mine: ['/miner', '/download', '/app', '/wallet', '/miners', '/tuning', '/dev-fee', '/metamask'], network: ['/live', '/explorer', '/evidence', '/light', '/receipt', '/oracle'], - learn: ['/litepaper', '/income', '/economics', '/scorecard', '/prize', '/audit', '/docs', '/ledger', '/claims', '/randomx', '/provenance', '/acceptance'], + learn: ['/litepaper', '/income', '/economics', '/scorecard', '/prize', '/audit', '/docs', '/ledger', '/claims', '/gpu-ledger', '/randomx', '/provenance', '/acceptance'], build: ['/build', '/faucet', '/swap', '/grants', '/compatibility'], // the builder programme (8 October 2026): the developer entry page, the Devnet 3 faucet, the swap, the grants }; const ROUTES = Object.values(GROUPS).flat(); diff --git a/tools/ledger/render.mjs b/tools/ledger/render.mjs new file mode 100644 index 000000000..4a828ddad --- /dev/null +++ b/tools/ledger/render.mjs @@ -0,0 +1,155 @@ +// The GPU network ledger: one data file, every table rendered from it (the record README, the public page, the kit's README), +// so no two copies of a row can drift. Run from the repository root: +// node tools/ledger/render.mjs rewrite the marked blocks of the record and the page from ledger.json +// node tools/ledger/render.mjs --check exit 1 if either file is out of step with ledger.json (the gate's form) +// node tools/ledger/render.mjs --kit also write /ROWS.md (the expected rows and their bands) for a reproduction kit +// Every block sits between and in the markdown; the text outside is hand-written. +import { readFileSync, writeFileSync, existsSync, mkdirSync } from 'node:fs'; +import { join, dirname } from 'node:path'; +import { fileURLToPath } from 'node:url'; + +const here = dirname(fileURLToPath(import.meta.url)); +const repo = join(here, '..', '..'); +const DATA = join(repo, 'docs/analysis/class-v6/1p5x/ledger/ledger.json'); +const RECORD = join(repo, 'docs/analysis/class-v6/1p5x/ledger/README.md'); +const PAGE = join(repo, 'docs/ledger/gpu-ledger.md'); +const L = JSON.parse(readFileSync(DATA, 'utf8')); + +const n = (x, d = 0) => x == null ? 'pending' : Number(x).toLocaleString('en-GB', { minimumFractionDigits: d, maximumFractionDigits: d }); +const gb = b => b == null ? 'pending' : `${(b / 1e9).toFixed(2)} GB (${n(b)} bytes)`; +const chainOf = id => L.chains.find(c => c.id === id); +const cellOf = (c, card) => (c.same_row_as ? chainOf(c.same_row_as) : c).cells[card]; +const advOf = c => (c.same_row_as ? chainOf(c.same_row_as) : c).adversary; +const x = (v, d = 2) => v == null ? 'pending' : `${v.toFixed(d)}x`; + +// the ratio of a measured card cell over a modelled chip row, with the chip's band (a lower chip energy is a larger ratio) +function ratio(cell, chip) { + if (!cell || cell.nj == null || !chip || chip.nominal == null) return null; + const r = { nominal: cell.nj / chip.nominal }; + if (chip.low != null && chip.high != null) { r.low = cell.nj / chip.high; r.high = cell.nj / chip.low; } + return r; +} +const band = r => r == null ? 'pending' : (r.low != null ? `${x(r.nominal)} (${r.low.toFixed(2)} to ${r.high.toFixed(2)})` : x(r.nominal)); +const provisional = c => { + const cells = L.cards.map(k => cellOf(c, k.id)); + return cells.some(cell => !cell || cell.nj == null || /proxy|prior row/i.test(cell.status || '')); +}; + +function tableCards() { + const head = '| chain | algorithm | dataset on the row | reward split (mining / proving) | ' + L.cards.map(k => `${k.name} ${k.state}: nJ per hash (MH/s, W, f)`).join(' | ') + ' | twin | sources |'; + const sep = '|' + '---|'.repeat(5 + L.cards.length) + '---|---|'; + const rows = L.chains.map(c => { + if (c.not_run) return `| ${c.chain} | ${c.algorithm} | NOT RUN | ${c.split.mining} / ${c.split.proving} | ${L.cards.map(() => 'NOT RUN').join(' | ')} | NOT RUN | ${c.not_run} |`; + if (c.same_row_as) return `| ${c.chain} | ${c.algorithm} | = ${chainOf(c.same_row_as).chain}'s row | ${c.split.mining} / ${c.split.proving} | ${L.cards.map(() => `= ${chainOf(c.same_row_as).chain}'s row`).join(' | ')} | as ${chainOf(c.same_row_as).chain} | ${c.pin} |`; + const cells = L.cards.map(k => { + const cell = c.cells[k.id]; + if (!cell || cell.nj == null) return `pending: ${cell ? cell.status : 'no cell'}${cell && cell.mhs != null ? ` (rate only ${n(cell.mhs, 2)} MH/s)` : ''}`; + return `${n(cell.nj)} ${cell.status} (${n(cell.mhs, 2)} MH/s, ${n(cell.w, 1)} W, f ${cell.f == null ? 'none' : cell.f.toFixed(3)}; spread ${cell.spread_pct == null ? 'none' : cell.spread_pct + '%'}; ${cell.pod}; ${cell.clock})`; + }); + const src = L.cards.map(k => c.cells[k.id] && c.cells[k.id].source && c.cells[k.id].source !== 'pending' ? `${k.name}: ${c.cells[k.id].source}` : null).filter(Boolean).join('; ') || 'pending'; + return `| ${c.chain} | ${c.algorithm} | ${gb(c.dataset_bytes)}; ${c.dataset_note} | ${c.split.mining} / ${c.split.proving} (${c.split.source}) | ${cells.join(' | ')} | ${c.twin} | ${src} |`; + }); + return [head, sep, ...rows].join('\n'); +} + +function tableEdge() { + const head = '| chain | the cheapest credible same-node DRAM board (set ' + L.adversarial_set + ', nJ per hash, band) | ' + L.cards.map(k => `ratio at the ${k.name} ${k.state} (ours)`).join(' | ') + ' | ' + L.cards.map(k => `ProgPoW-premise ratio at the ${k.name}`).join(' | ') + ' | the die as the residual (nJ; ratio at the worse card) | real chip on the market | source |'; + const sep = '|' + '---|'.repeat(2 + 2 * L.cards.length) + '---|---|---|'; + const rows = L.chains.map(c => { + if (c.not_run) return `| ${c.chain} | NOT RUN | ${L.cards.map(() => 'NOT RUN').join(' | ')} | ${L.cards.map(() => 'NOT RUN').join(' | ')} | NOT RUN | none | NOT RUN |`; + const a = advOf(c); + const boardCell = a.board ? `${n(a.board.nominal)} (${n(a.board.low)} to ${n(a.board.high)}); ${a.board.design}; split ${a.board.split_nj}; ${a.status}` : `pending: ${a.status}`; + const ours = L.cards.map(k => band(ratio(cellOf(c, k.id), a.board))); + const prem = L.cards.map(k => (a.premise && a.premise[k.id]) || 'pending'); + const worst = L.cards.map(k => ratio(cellOf(c, k.id), a.die ? { nominal: a.die.nominal } : null)).filter(Boolean).sort((p, q) => q.nominal - p.nominal)[0]; + const die = a.die ? `${n(a.die.nominal)} (${a.die.design}); ${worst ? x(worst.nominal, 1) : 'pending'}` : 'pending'; + const chip = c.real_chip ? `${c.real_chip.name}: ${n(c.real_chip.mhs)} MH/s at ${n(c.real_chip.w)} W = ${n(c.real_chip.nj)} nJ per hash, ${c.real_chip.status}; ${c.real_chip.source}` : 'none on the market'; + const src = c.same_row_as ? `= ${chainOf(c.same_row_as).chain}'s row` : a.source; + return `| ${c.chain}${c.same_row_as ? ` (= ${chainOf(c.same_row_as).chain}'s row)` : ''} | ${boardCell} | ${ours.join(' | ')} | ${prem.join(' | ')} | ${die} | ${chip} | ${src} |`; + }); + return [head, sep, ...rows].join('\n'); +} + +function tablePhases() { + const head = '| chain | split | phase A (before investment) | phase B (spend sunk) | an income a hash chip cannot earn | source |'; + const sep = '|---|---|---|---|---|---|'; + const rows = L.chains.map(c => `| ${c.chain} | ${c.split.mining} / ${c.split.proving} | ${c.phases.A} | ${c.phases.B} | ${c.phases.income_a_chip_cannot_earn} | ${c.phases.source}; ${c.phases.status} |`); + return [head, sep, ...rows].join('\n'); +} + +function mechanism() { + const m = L.mechanism; if (!m) return ''; + const lines = [`**${m.title}**`, '', '| chain | the memory traffic per hash | what it costs the card | what it costs the chip | consequence for the ratio |', '|---|---|---|---|---|']; + for (const r of m.rows) lines.push(`| ${r.chain} | ${r.traffic} | ${r.card_cost} | ${r.chip_cost} | ${r.consequence} |`); + lines.push('', m.note); + return lines.join('\n'); +} + +function ranking() { + const scored = L.chains.filter(c => !c.not_run && !c.same_row_as).map(c => { + const a = advOf(c); + const cells = L.cards.map(k => cellOf(c, k.id)); + const rs = cells.map(cell => ratio(cell, a.board)).filter(Boolean); + const worst = rs.length ? Math.max(...rs.map(r => r.nominal)) : null; + const sessions = cells.filter(cell => cell && cell.nj != null).map(cell => cell.session || 'unstated'); + return { c, worst, rs, sessions, prov: provisional(c) || rs.length < L.cards.length }; + }); + // a cross-chain ORDER exists only when every compared cell comes from one session on the same card and state (main's ruling) + const measured = scored.filter(s => s.worst != null); + const allSessions = new Set(measured.flatMap(s => s.sessions)); + const lines = ['**(a) Ours, the same-node DRAM board at the worse card (the smaller chip edge first):**']; + if (measured.length >= 2 && allSessions.size === 1 && measured.every(s => !s.prov)) { + measured.sort((p, q) => p.worst - q.worst).forEach((s, i) => lines.push(`${i + 1}. ${s.c.chain}: ${x(s.worst)}`)); + } else { + lines.push(`No order in this column yet: a cross-chain comparison is made only between cells from the same card, state and session, and the measured cells today come from ${allSessions.size} sessions (${[...allSessions].join('; ')}); the ledger session (both cards, every chain back to back) fills it. Each chain's own number, same card and state, as it stands:`); + for (const s of measured) lines.push(`- ${s.c.chain}: ${L.cards.map((k, i) => `${k.name} ${k.state} ${band(ratio(cellOf(s.c, k.id), advOf(s.c).board))}`).join('; ')}${s.prov ? ' (a pending or proxy cell in this row)' : ''}`); + } + scored.filter(s => s.worst == null).forEach(s => lines.push(`- ${s.c.chain}: unranked in this column (no measured card cell yet)`)); + lines.push('', '**(b) ProgPoW\'s premise (the chip keeps a GPU-class datapath):**'); + for (const c of L.chains.filter(c => !c.not_run && !c.same_row_as)) lines.push(`- ${c.chain}: ${L.cards.map(k => `${k.name} ${(advOf(c).premise && advOf(c).premise[k.id]) || 'pending'}`).join('; ')}`); + lines.push('', '**(c) Phase B, an income a hash chip cannot earn:**'); + for (const c of L.chains) lines.push(`- ${c.chain}: ${c.phases.income_a_chip_cannot_earn}${c.not_run ? ' (NOT RUN)' : ''}`); + return lines.join('\n'); +} + +function claim() { + const k = L.claim; + const supported = k.clauses.filter(c => /^SUPPORTED/.test(c.state)).map(c => c.text); + const lines = ['**The headline, built from the supported clauses only:** ' + (supported.length ? supported.join('; ') + '; ' : '') + `${k.clauses[k.clauses.length - 1].text} (${k.proving_live_label}).`, '', + `The sentence as ordered, served as the claim under test: "${k.ordered_sentence}"`, '', `Rule: ${k.headline_rule}.`, '', + '| clause | convention | state on the current rows | why |', '|---|---|---|---|']; + for (const c of k.clauses) lines.push(`| ${c.text} | ${c.convention} | ${c.state} | ${c.why} |`); + lines.push('', `Withdrawn: ${k.withdrawn}.`, '', `The last clause's label from the PROVING LIVE lane: ${k.proving_live_label}`); + return lines.join('\n'); +} + +const BLOCKS = { cards: tableCards(), edge: tableEdge(), phases: tablePhases(), ranking: ranking(), mechanism: mechanism(), claim: claim(), stamp: `Data: ledger.json, stamp ${L.stamp}, adversarial set ${L.adversarial_set} (${L.adversarial_set_source}).` }; + +function fill(path) { + let s = readFileSync(path, 'utf8'); let changed = false; + for (const [name, body] of Object.entries(BLOCKS)) { + const re = new RegExp(`()[\\s\\S]*?()`); + if (!re.test(s)) continue; + const next = s.replace(re, `$1\n${body}\n$2`); + if (next !== s) { s = next; changed = true; } + } + return { s, changed }; +} + +const args = process.argv.slice(2); +const check = args.includes('--check'); +const kitAt = args.indexOf('--kit') >= 0 ? args[args.indexOf('--kit') + 1] : null; +let red = 0; +for (const p of [RECORD, PAGE]) { + if (!existsSync(p)) continue; + const { s, changed } = fill(p); + if (check) { if (changed) { console.log(`ledger: ${p} is out of step with ledger.json`); red = 1; } } + else if (changed) { writeFileSync(p, s); console.log(`ledger: wrote ${p}`); } +} +if (kitAt) { + mkdirSync(kitAt, { recursive: true }); + const rows = ['# Expected rows (the ledger, stamp ' + L.stamp + ')', '', 'A reproduction on the same card class at stock passes when its nJ per hash sits inside the band below (the spread of the lab\'s own repeats, 5 percent either side of the median; a board power cap or a locked clock puts the row outside the method).', '', '| chain | card | expected nJ per hash | band (pass) | the lab\'s cell |', '|---|---|---|---|---|']; + for (const c of L.chains) for (const k of L.cards) { const cell = cellOf(c, k.id); if (cell && cell.nj != null) rows.push(`| ${c.chain} | ${k.name} ${k.state} | ${n(cell.nj)} | ${n(cell.nj * 0.95)} to ${n(cell.nj * 1.05)} | ${cell.pod}; ${cell.source} |`); else if (!c.same_row_as) rows.push(`| ${c.chain} | ${k.name} ${k.state} | pending | pending | ${cell ? cell.status : 'NOT RUN'} |`); } + writeFileSync(join(kitAt, 'ROWS.md'), rows.join('\n') + '\n'); console.log(`ledger: wrote ${join(kitAt, 'ROWS.md')}`); +} +process.exit(red);