diff --git a/docs/build/README.md b/docs/build/README.md index 4789d31fa..5133a9999 100644 --- a/docs/build/README.md +++ b/docs/build/README.md @@ -6,11 +6,11 @@ |---|---| | `build.md` | [igneum.network/build](https://igneum.network/build): what is different (built to prove every block, a lock in minutes, nothing to stake, the EVM unchanged), the chain ids and endpoints, the wallet, the explorer, the faucet, the five-minute contract, the browser verifier | | `grants.md` | [igneum.network/grants](https://igneum.network/grants): the tiers, what a grant is, how to apply, the review, the honest lines | -| `first-contract.md`, `first-contract-test.sh` | the walkthrough and the script that runs it end to end on Devnet 3 from a build box; the PASS line is the test record | -| `rpc.md` | the JSON-RPC method list as the node serves it, read from a Devnet 3 node, with the probe | -| `faucet.md` | the Devnet 3 faucet: rules, where it runs, how it is funded | +| `first-contract.md`, `first-contract-test.sh` | the walkthrough and the script that runs it end to end on the devnet from a build box; the PASS line is the test record | +| `rpc.md` | the JSON-RPC method list as the node serves it, read from a devnet node, with the probe | +| `faucet.md` | The devnet faucet: rules, where it runs, how it is funded | | `verify-a-block.md` | the in-browser checkpoint verifier, twelve lines | The faucet service is `infra/build-server/faucet/`. The grant application template is `.forgejo/issue_template/grant.md`. -Served-text rules (the site audit reads every page before it lands): no em dashes, short sentences, one to three points per block, nothing that reads as an offer, a price or a promise of value; devnet and testnet coins have no value; no amount, price or date is promised. +Served-text rules (the site audit reads every page before it lands): no em dashes, short sentences, one to three points per block, nothing that reads as an offer, a price or a promise of value; devnet coins have no value; no amount, price or date is promised. diff --git a/docs/build/build.md b/docs/build/build.md index 64f153607..0e312f2e4 100644 --- a/docs/build/build.md +++ b/docs/build/build.md @@ -4,7 +4,7 @@ This file is the source of [igneum.network/build](https://igneum.network/build). ## What is different -**Every block is built to be proven.** A chain block carries a zero-knowledge proof of its execution. The miners are the provers: the same cards that find blocks prove them, in shards. On Devnet 3 a share of blocks carries a proof today; the live page shows the share and the lag, and the design target at launch is under a minute. Full nodes execute every block themselves, so a bad proof is a light-client problem and never a chain split. +**Every block is built to be proven.** A chain block carries a zero-knowledge proof of its execution. The miners are the provers: the same cards that find blocks prove them, in shards. On the devnet a share of blocks carries a proof today; the live page shows the share and the lag, and the design target at launch is under a minute. Full nodes execute every block themselves, so a bad proof is a light-client problem and never a chain split. **A lock in minutes, not an hour of confirmations.** Miners sign a checkpoint every 30 seconds. When two thirds of the mining weight of the last 30 days have signed, the checkpoint is locked. Weight is blocks mined, nothing else. The lock lands in about two minutes. The [litepaper](/litepaper) has the rule. @@ -14,28 +14,30 @@ This file is the source of [igneum.network/build](https://igneum.network/build). ## Networks -| | Devnet 3 | Testnet | Mainnet | -|---|---|---|---| -| Chain id | {{rm:network.chain_id}} (`{{rm:network.chain_id_hex}}`) since its class v5 floor on 8 October 2026; 4463 below it | 4462 (`0x116e`) | 4461 (`0x116d`) | -| Network id | `{{rm:network.id}}` | `igneum-testnet-1` | not started | -| RPC | `{{rm:network.rpc}}` (a node you run serves `http://127.0.0.1:26790`) | `https://rpc.testnet.igneum.network` (answers; nothing mines there yet, so a transaction waits) | none | -| Coins | no value, resets without notice | no value, resets with notice | not started | -| Symbol, decimals | IGN, 18 | IGN, 18 | IGN, 18 | -| Machine-readable | [/release.json](/release.json): the chain id, the source commits and fingerprints, the mining class, the finality rule, the proof program ids, the fee schedule and the current version per platform, with a generated date | | | +| | Igneum 2.0 devnet | +|---|---| +| Chain id | 4464 (`0x1170`) | +| Network id | `igneum-devnet-4` | +| RPC | `https://rpc.devnet.igneum.network` (a node you run serves `http://127.0.0.1:26790`) | +| Coins | no value, resets without notice | +| Symbol, decimals | IGN, 18 | +| Machine-readable | [/release.json](/release.json): the chain id, the source commits and fingerprints, the mining class, the finality rule, the proof program ids, the fee schedule and the current version per platform, with a generated date | -Devnet 3 is where you build today. It is a developer network: it resets without notice and its coins have no value. Its public RPC takes the read methods, `eth_sendRawTransaction` and a wRPC websocket at `/ws`, at 20 requests a second per address. The public testnet exists, its RPC answers, and no blocks are being produced on it until it opens. Mainnet has no date. Devnet 3 answered 4463 until its class v5 floor at DAA 68,400 on 8 October 2026 and 4464 from it; read it with `eth_chainId` rather than fixing it, since a transaction signed for the wrong id is refused. +The devnet is where you build today. It is a developer network: it resets without notice and its coins have no value. Its public RPC takes the read methods, `eth_sendRawTransaction` and a wRPC websocket at `/ws`, at 20 requests a second per address. Read the chain id with `eth_chainId` rather than fixing it, since a transaction signed for the wrong id is refused. + +Mainnet has not started and has no date. Its chain id, 4461 (`0x116d`), is reserved in the node. ## Endpoints and tools - **Wallet.** Any Ethereum wallet. [Add Igneum to MetaMask](/metamask) with one click, or the [Igneum wallet](/wallet). -- **Faucet.** [10 IGN of Devnet 3 coin](/faucet) per address per day. No account. +- **Faucet.** [10 IGN of the devnet coin](/faucet) per address per day. No account. - **Explorer.** [The explorer](/explorer) shows blocks, the DAG, miners and addresses. The EVM views, transactions and contracts, are being built and link from the same page as they land. -- **Swap.** [The swap](/swap): test tokens on Devnet 3, every swap in a proven block. +- **Swap.** [The swap](/swap): test tokens on the devnet, every swap in a proven block. - **Source.** [git.igneum.network/igneum-network/igneum](https://git.igneum.network/igneum-network/igneum): the node, the miner, the site, and these pages under `docs/build/`. ## Your first contract in five minutes -With [Foundry](https://getfoundry.sh). Tested end to end on Devnet 3 on a build box; the full walkthrough with the expected output is [docs/build/first-contract.md](https://git.igneum.network/igneum-network/igneum/src/branch/master/docs/build/first-contract.md). +With [Foundry](https://getfoundry.sh). Tested end to end on the devnet on a build box; the full walkthrough with the expected output is [docs/build/first-contract.md](https://git.igneum.network/igneum-network/igneum/src/branch/master/docs/build/first-contract.md). ``` curl -L https://foundry.paradigm.xyz | bash && foundryup @@ -63,7 +65,7 @@ The call answers `1`. Paste the transaction hash into [the explorer](/explorer). ## The RPC the node serves -Read from a Devnet 3 node, not from a spec. `web3_clientVersion` answers `igneumd/2.1.0/execution-layer-v3`. The full list, served and not served, with the probe that produced it: [docs/build/rpc.md](https://git.igneum.network/igneum-network/igneum/src/branch/master/docs/build/rpc.md). +Read from a devnet node, not from a spec. `web3_clientVersion` answers `igneumd/2.1.0/execution-layer-v3`. The full list, served and not served, with the probe that produced it: [docs/build/rpc.md](https://git.igneum.network/igneum-network/igneum/src/branch/master/docs/build/rpc.md). - **Served.** `eth_chainId`, `eth_blockNumber`, `eth_getBalance`, `eth_getTransactionCount`, `eth_getCode`, `eth_getStorageAt`, `eth_getBlockByNumber`, `eth_getBlockByHash`, `eth_getTransactionByHash`, `eth_getTransactionReceipt`, `eth_getBlockReceipts`, `eth_getLogs`, `eth_call`, `eth_estimateGas`, `eth_gasPrice`, `eth_maxPriorityFeePerGas`, `eth_feeHistory`, `eth_sendRawTransaction`, `eth_syncing`, `eth_accounts`, `net_version`, `net_peerCount`, `net_listening`, `web3_clientVersion`. - **Igneum's own.** `igneum_getExecStatus`, `igneum_getProvingStatus`, `igneum_getShardPlan`, `igneum_getProofRecords`, `igneum_getTransactionStatus`, `igneum_estimateGas`, `igneum_getBudgets` and the segment and proof calls. `igneum_estimateGas` returns both gas dimensions and whether a call exceeds the proving limit. @@ -86,4 +88,4 @@ console.log(r.verified, r.signers, 'of', r.voters, 'voters', r.ms, 'ms'); - [Discord](https://discord.gg/igneum), the builders channel. - [Grants](/grants) for tooling, reference apps, infrastructure and research. -Devnet and testnet coins have no value. Nothing on this page is an offer to sell anything. +Devnet coins have no value. Nothing on this page is an offer to sell anything. diff --git a/docs/build/faucet.md b/docs/build/faucet.md index d98163047..c346b9ccc 100644 --- a/docs/build/faucet.md +++ b/docs/build/faucet.md @@ -1,11 +1,11 @@ -# The Devnet 3 faucet +# The devnet faucet -[igneum.network/faucet](https://igneum.network/faucet) sends 10 IGN of Devnet 3 coin to an address. Once per address per day, once per connection per day. No account. +[igneum.network/faucet](https://igneum.network/faucet) sends 10 IGN of the devnet coin to an address. Once per address per day, once per connection per day. No account. ## What it is - A small Node service on a build box, `infra/build-server/faucet/faucet.mjs`, behind Caddy at `faucet.igneum.network`. The page on igneum.network posts to it. -- It signs a plain transfer with its own key and sends it to the Devnet 3 node on the same box by address (`FAUCET_RPC`), never chosen by chain id. The chain id it signs with is read from that node on every send: Devnet 3 moved from 4463 to 4464 at its class v5 floor on 8 October 2026. +- It signs a plain transfer with its own key and sends it to the devnet node on the same box by address (`FAUCET_RPC`), never chosen by chain id. The chain id it signs with is read from that node on every send. - The key lives only in the service's environment file on that box. It is not in the repository and not on the site. ## The rules, as the code enforces them @@ -20,7 +20,7 @@ The faucet's balance is refilled from the devnet's funder as it runs down. When it is empty the page says so and sends nothing. -## Devnet 3 coin +## The devnet coin No value. Not for sale, not redeemable, not a claim on anything. The chain resets without notice and balances do not carry over. Mainnet starts from an empty genesis. @@ -33,4 +33,3 @@ infra/build-server/faucet/faucet.sh status # the unit, the balance, the node infra/build-server/faucet/faucet.mjs --self-test # the limiter: known-failed cases first ``` -The public testnet faucet is a separate thing: `site/api/faucet.mjs` is prepared for it and answers "not open yet" until the testnet starts. diff --git a/docs/build/first-contract.md b/docs/build/first-contract.md index afa2c39f7..3acad5e96 100644 --- a/docs/build/first-contract.md +++ b/docs/build/first-contract.md @@ -1,16 +1,16 @@ -# Your first contract on Devnet 3, in five minutes +# Your first contract on the devnet, in five minutes -With Foundry. Tested end to end on Devnet 3 from a build box on 8 October 2026; the pass line and the exact output are at the end. Hardhat, ethers and viem work the same way: chain id 4463 and the RPC below. +With Foundry. Tested end to end on a build box; the pass line and the exact output are at the end. Hardhat, ethers and viem work the same way: chain id 4464 and the RPC below. ## 0. What you need - Foundry: `curl -L https://foundry.paradigm.xyz | bash && foundryup`. About a minute. -- The RPC. Devnet 3's public endpoint is `https://rpc.devnet.igneum.network`. A node you run yourself serves `http://127.0.0.1:26790`. +- The RPC. The devnet's public endpoint is `https://rpc.devnet.igneum.network`. A node you run yourself serves `http://127.0.0.1:26790`. - Nothing else. No account, no sign-up. ``` export RPC=https://rpc.devnet.igneum.network -cast chain-id --rpc-url $RPC # 4464 (4463 before the class v5 floor of 8 October 2026) +cast chain-id --rpc-url $RPC # 4464 ``` ## 1. A key, for the devnet only @@ -82,16 +82,16 @@ cast receipt 0xTXHASH --rpc-url $RPC ## The test record -Run on a build box against its own Devnet 3 node (the box that also fronts the public RPC and runs the faucet), with Foundry 1.8.5 and a fresh key, through `docs/build/first-contract-test.sh`. The pass line is appended below by the run. +Run on a build box against its own devnet node (the box that also fronts the public RPC and runs the faucet), with Foundry 1.8.5 and a fresh key, through `docs/build/first-contract-test.sh`. The pass line is appended below by the run. ``` -PASS 10:17:23Z: Devnet 3 chain id 4463, faucet drip 0x8620e9d894484e824e4ac33002946a00e2f75823ea6db0da0ad29f1af142e8f2, deployed Counter at 0x6345265C6Db0b3713eb6645d795d0B52FE0a4201 (tx 0xcf77b4822d51f3c60ecdf6d7dbbe67524d42071f06c76e1cf9b0511d64783574), increment then setNumber(41) read back 41, receipt status 1 (success), block 27055, 24 s end to end, Foundry 1.8.5 +PASS 10:17:23Z: devnet chain id 4463, faucet drip 0x8620e9d894484e824e4ac33002946a00e2f75823ea6db0da0ad29f1af142e8f2, deployed Counter at 0x6345265C6Db0b3713eb6645d795d0B52FE0a4201 (tx 0xcf77b4822d51f3c60ecdf6d7dbbe67524d42071f06c76e1cf9b0511d64783574), increment then setNumber(41) read back 41, receipt status 1 (success), block 27055, 24 s end to end, Foundry 1.8.5 ``` -Through the public endpoints, `https://rpc.devnet.igneum.network` and `https://faucet.igneum.network`, from the box: the first faucet drip and the first reader-path deploy on Devnet 3. +Through the public endpoints, `https://rpc.devnet.igneum.network` and `https://faucet.igneum.network`, from the box: the first faucet drip and the first reader-path deploy on the devnet. After the class v5 floor moved the chain id to 4464 the same afternoon, from a second box: ``` -PASS 12:38:39Z: Devnet 3 chain id 4464, faucet drip 0xa54fdb7e964dab095aaccaab36ea548fc3fa8727acb809b593c2d4d1359c233f, deployed Counter at 0x7de503a4F39feEBCE8c4ABbAcC04282EE75120Fe (tx 0x6ccdbb4f6393fcf09e58ba2f4de1af98c547eeab6f02d93eacfebae883200dc6), increment then setNumber(41) read back 41, receipt status 1 (success), block 29878, 12 s end to end, Foundry 1.8.5 +PASS 12:38:39Z: devnet chain id 4464, faucet drip 0xa54fdb7e964dab095aaccaab36ea548fc3fa8727acb809b593c2d4d1359c233f, deployed Counter at 0x7de503a4F39feEBCE8c4ABbAcC04282EE75120Fe (tx 0x6ccdbb4f6393fcf09e58ba2f4de1af98c547eeab6f02d93eacfebae883200dc6), increment then setNumber(41) read back 41, receipt status 1 (success), block 29878, 12 s end to end, Foundry 1.8.5 ``` diff --git a/docs/build/grants.md b/docs/build/grants.md index a9d8c5865..c4136d156 100644 --- a/docs/build/grants.md +++ b/docs/build/grants.md @@ -4,7 +4,7 @@ This file is the source of [igneum.network/grants](https://igneum.network/grants ## What a grant is -Grants are paid in IGN from the dev fee fund, on delivery. You propose a piece of work, it is accepted with a written definition of done, you build it, and it runs on the public testnet. Not a salary, not an advance, not an investment. +Grants are paid in IGN from the dev fee fund, on delivery. You propose a piece of work, it is accepted with a written definition of done, you build it, and it runs on the devnet. Not a salary, not an advance, not an investment. The money is the dev fee fund: the IGN that the Ember dev fee collects. Ember, the official miner, takes an optional 1% of a miner's rewards, in full view and off with one flag; that fee goes to Igneum Labs, the company that ships the software. The protocol itself carries no fee, no fund and no allocation, and no grant is paid from emission. [The dev fee](/dev-fee) has the mechanism. @@ -24,7 +24,7 @@ A grant is sized by the work in front of it, not by a table. Two grants in the s Open an issue on [git.igneum.network/igneum-network/igneum](https://git.igneum.network/igneum-network/igneum/issues/new?template=.forgejo%2Fissue_template%2Fgrant.md) and pick the Grant template. It asks for: 1. What you will build, in a paragraph, and which tier it is. -2. What done looks like: what runs where, what a reviewer can click or call to see it working on the public testnet. +2. What done looks like: what runs where, what a reviewer can click or call to see it working on the devnet. 3. Your public work: a repository, a package, a paper, a deployed thing. 4. How you want to be reached. @@ -34,11 +34,11 @@ A short issue is fine. The definition of done is the part that matters. - Every Friday. Each open application gets one of three answers inside seven days: accepted with a definition of done, questions, or no with the reason. - Accepted work is tracked in its issue. The reviewer and the builder agree the definition of done there before any work starts. -- Delivery is reviewed on the public testnet first. Payment follows the review, in the issue, in the open. +- Delivery is reviewed on the devnet. Payment follows the review, in the issue, in the open. ## The honest lines -- Devnet and testnet coins have no value. Before mainnet there is no IGN with value: a grant delivered on the testnet is recorded in its issue, and payment comes from the fund when the fund holds IGN. Nothing is promised about when, or whether, that is. +- Devnet coins have no value. Before mainnet there is no IGN with value: a grant delivered on the devnet is recorded in its issue, and payment comes from the fund when the fund holds IGN. Nothing is promised about when, or whether, that is. - No amount, price or date is promised. The fund is what the dev fee collects, and it is zero today. - A grant is for work delivered, never for a user count, a listing, a post or a referral. - Igneum Labs may decline any application and may close the programme; what has been accepted and delivered is still paid. diff --git a/docs/build/rpc.md b/docs/build/rpc.md index f6dc6d079..d04e2337b 100644 --- a/docs/build/rpc.md +++ b/docs/build/rpc.md @@ -1,6 +1,6 @@ -# The JSON-RPC a Devnet 3 node serves +# The JSON-RPC a devnet node serves -Read from the node, not from a spec: every method below was sent to a Devnet 3 node on 8 October 2026 (`web3_clientVersion` answered `igneumd/2.1.0/execution-layer-v3`, `eth_chainId` `0x116f`, block 26,666) and sorted by what came back. A method the node does not know answers JSON-RPC error `-32601`. The probe is at the end; run it against your own node to refresh this file. +Read from the node, not from a spec: every method below was sent to a devnet node on 8 October 2026 (`web3_clientVersion` answered `igneumd/2.1.0/execution-layer-v3`, `eth_chainId` `0x116f`, block 26,666) and sorted by what came back. A method the node does not know answers JSON-RPC error `-32601`. The probe is at the end; run it against your own node to refresh this file. Transport: HTTP POST, JSON-RPC 2.0, one request per call, no batches tested. The public endpoint is `https://rpc.devnet.igneum.network`; a node you run serves `http://127.0.0.1:26790`. The DAG side of the node (blocks, the mempool, the vote table) speaks the Kaspa-style gRPC and wRPC on their own ports; the explorer and the observer use those, a contract developer needs only what is here. @@ -9,9 +9,9 @@ Transport: HTTP POST, JSON-RPC 2.0, one request per call, no batches tested. The | Method | Note | |---|---| | `web3_clientVersion` | `igneumd//execution-layer-v3` | -| `net_version` | the chain id as a decimal string, `"4464"` (`"4463"` before the class v5 floor) | +| `net_version` | the chain id as a decimal string, `"4464"` | | `net_listening`, `net_peerCount` | | -| `eth_chainId` | `0x1170` (4464) on Devnet 3 since its class v5 floor at DAA 68,400 on 8 October 2026; `0x116f` (4463) below it. Read it, never fix it | +| `eth_chainId` | `0x1170` (4464) on the Igneum 2.0 devnet. Read it, never fix it | | `eth_blockNumber` | the executed chain tip | | `eth_syncing` | `false` when the executor is at the tip | | `eth_mining` | `false` from the RPC's point of view: mining is the miner's, not the node's | @@ -76,4 +76,4 @@ for m in web3_clientVersion eth_chainId eth_blockNumber eth_newFilter eth_subscr done ``` -Devnet 3 resets without notice and its coins have no value. +The devnet resets without notice and its coins have no value. diff --git a/docs/evidence.md b/docs/evidence.md index 40556bc8b..4c63f5c02 100644 --- a/docs/evidence.md +++ b/docs/evidence.md @@ -1,121 +1,59 @@ -# Igneum evidence: every public claim, with its status +# Igneum facts: every Igneum 2.0 claim, with its status -4 October 2026. One row per claim the homepage (`site/index.html`) and the litepaper (`site/litepaper.html`) make. Every number here is copied from `docs/bench-log.md`, which names the machine, the date and the command, or from the result files it names; nothing is restated from memory. Where a bench-log figure is approximate, this table says so. +8 October 2026. The facts page restarts at Igneum 2.0: one row per claim, each traceable to a landed document in this repository, the path in the row. Every number carries its label (measured, modelled, synthesised, designed); nothing is restated from memory. ## The six labels | Label | Meaning | |---|---| -| designed | A decision in the design document or the specification. No code carries it, or the code is a stub | -| implemented | Code exists in this repository with test vectors, and the vectors pass. Not run as a measurement of the claim | +| designed | A decision in the design document, the plan or the specification. No code carries it, or the code is a stub | +| implemented | Code exists with test vectors, and the vectors pass. Not run as a measurement of the claim | | activated | The code is live on a named chain by its activation height, and a node's own line says so. Not yet a measurement of the claim | -| tested by the team | The claim was measured or exercised by the project's own people and agents on a named machine, and the result is in the bench log | +| tested by the team | The claim was measured or exercised by the project's own people and agents on a named machine, and the result is in a landed document | | reproduced externally | Somebody outside the project ran the published command on their own hardware and got the published result | | reviewed independently | Somebody outside the project, paid or not, read the code or the rule and published their finding | -Four rules for reading the table: +Five rules for reading the table: -1. Nothing on this chain has been reproduced externally or reviewed independently. Every row's last column says "none yet". Nobody outside the project has run a published command or published a reading of the code yet, so the first three labels are the ceiling today. -2. A status applies to the exact version in the row. An audit of one version never covers a newer one; when the version changes, the status falls back to "tested by the team" until the new version is reproduced or reviewed again. -3. "Tested by the team" on one machine is one machine. The rows say which. Discrete AMD, Intel and a 2019-class CPU core have not run anything. -4. The 12-node cloud network of 4 October 2026 (`infra/cloud-devnet`, cloud VMs in five locations) is the project's own. Rows that cite it are tested by the team, not reproduced externally. -5. The labels stay distinct and a claim never moves up a label without the artefact that label names (the table "What would move a row"). The public reference repository exists now (the specifications, the `igneum-pow` crate, the simulators and the test material, at git.igneum.network); the full node, the miner and the proving code open later, so a row that cites them is tested by the team until they do. +1. Nothing on this chain has been reproduced externally or reviewed independently. Every row's last column says "none yet". Nobody outside the project has run a published command or published a reading of the code yet, so the first four labels are the ceiling today. +2. A status applies to the exact version or document in the row. An audit of one version never covers a newer one; when the version changes, the status falls back until the new version is tested, reproduced or reviewed again. +3. "Tested by the team" on one machine is one machine. The rows say which. Cards the project rents are the project's own measurement, as are the project's own rigs; neither is a reproduction. +4. The labels stay distinct and a claim never moves up a label without the artefact that label names (the table "What would move a row"). The public reference repository exists (the specifications, the `igneum-pow` crate, the simulators and the test material, at git.igneum.network); the full node, the miner and the proving code open later, so a row that cites them is tested by the team at most until they do. +5. A failure is a fact. An experiment that did not work is a row like any other, labelled by how it was measured, with the document that records it. -Versions in the table: `igneum-pow` is the Rust crate at `igneum-pow/Cargo.toml`, version 0.2.0 since 4 October 2026 (generator version 2; 0.1.0 rows are marked). "Repo" commits are this repository's. "Fork" commits are `vendor/igneum-node` and its worktrees (`-v4`, `-diff`, `-exec`, `-harness`, `-fin-fixes`), which are not in this repository's history; the row names the fork commit or branch as the bench log does. The first devnet is devnet v4 (genesis 10:05 BST, 4 October 2026, branch `devnet-v4`). Devnet 3 (`igneum-devnet-3`, chain id 4463 from genesis and {{rm:network.chain_id}} since its class v5 floor at DAA 68,400; node {{rm:source.node.commit}} on {{rm:source.node.branch}}, igneum-pow {{rm:source.pow.commit}}, {{rm:read_at_short}}; the current state is the [release manifest](/release.json), filled at build time) made its first block at 17:06 UTC on 7 October 2026 with every upgrade on from block zero (class v4 sub-version 3, the era VDF, difficulty v2, finality v3, proving v0 and v1, the ladder at rung 0, calibrated fees) and locked its first checkpoint at 19:02 UTC; rows that name the live devnet without a chain are the first devnet's, and Devnet 3 readings are marked. The spec is `docs/spec/` version 0.1. +Versions in the table: "the release manifest" is `site/release-manifest.json`, served at /release.json and regenerated at the Igneum 2.0 devnet's first block; "node fork" commits are the node fork's, which is not in this repository's history until the node opens; a document path is this repository's. ## The table | # | Claim | Where it is made | Status | Version or commit | Reproducible test | Result, date, machine | Independent verification | |---|---|---|---|---|---|---|---| -| 1 | A new mining program every hour, compiled by the miner, with no human in the loop and no pause in mining | Homepage hero and "This hour's program"; litepaper Mining | tested by the team | igneum-pow 0.2.0; repo `b27da39`, `1292110`, `100c5d7`; fork `devnet-v4` `6457ca95` | The live devnet v4: the node announces `next_epoch_seed` 150 DAA past the seed score, `igneum-miner` sends `prepare` to its worker, the worker builds the next program while the current one mines; Metal (`proto-metal/igneum-bench`), CUDA and OpenCL workers; bench-log "first hourly program swap on the live devnet" | Epoch boundary at DAA 3,600 (11:05:07 BST, 4 October 2026) crossed live on three vendors: the Mac M5 Max (Metal) compiled the next program in 82 ms, 449 DAA before the boundary, swapped in 0.01 ms, 26.7 MH/s before and after; the RTX 5090 compiled in 1,285 ms, swapped in 0.00 ms, 121.8 before and 123.4 MH/s after; the integrated AMD chip 2.74 MH/s before and after. 0 restarts, 0 rejected blocks, 0 rebuilds. The epoch seed is the epoch block hash; the delay of row 2 is not wired in. At a later boundary (DAA 18,000) one OpenCL worker on PC 2 stayed on the previous epoch after an app reinstall and answered 514 jobs with a seed mismatch; fixed in the miner (`3bfe346f`, workers emit a `need` line), the swap time of that forced prepare not measured | none yet | -| 2 | The program seed passes through a 10-minute verifiable delay from a certified checkpoint, so nobody can grind the seed | Litepaper Mining, vs RandomX ("Closed by a verifiable delay") | implemented | repo `792776e`; `proto-vdf/` | `proto-vdf` full 10-minute runs and the tamper cases in `proto-vdf/README.md`; bench-log "proto-vdf" | Class group 1024-bit: 163,000 squarings per second, 10-min eval 585.4 s, prove 9.1 s on 12 threads, verify 4.47 ms, 516-byte proof; wrong checkpoint, flipped seed bit and T+1 all rejected; grinding model gains 0 blocks per epoch with the delay against +3.62 at a 30% advantage without it. 3 October 2026, Apple M5 Max, one core. Prototype only: not in the node on 4 October either, not reviewed against chiavdf (O-4.1) | none yet | -| 3 | The dataset is memory-hard: computing an item costs more than loading it, and every hash does 128 distinct dataset reads | Litepaper Mining and vs RandomX; homepage vs RandomX ("Memory 2 GB, growing") | tested by the team | repo `58a5a63` (memory-hard), `b27da39` (generator 2); igneum-pow 0.2.0 (`memhard.rs`, `generator.rs`, `accept.rs`); spec 01 sections 1.4.2 to 1.4.6; `proto-metal/MEMHARD.md` | `proto-metal/igneum-bench --inline-dataset` against the honest run at 1 GiB and 256 MiB; `igneum-census --gen v2 --warps 64` over 20,000 programs; bench-log "memory-hard dataset" and "generator version 2 adopted" | Honest 45.2 Mhash/s, inline (never reads the dataset) 9.49 Mhash/s, ratio 0.21 at 1 GiB, 0.10 at 256 MiB. 3 October 2026, Apple M5 Max. Generator 2, 4 October 2026: 20,000 programs, 128 static loads on every program, distinct addresses per hash mean 127.9, minimum 120.1; 5.2% of candidates rejected by the acceptance rule. The price of the 128 fresh reads is the hash rate: Apple OpenCL 45.0 MH/s on a version 1 program with 80 distinct loads against 27.5 to 27.9 on version 2; the RTX 5090 229 MH/s on a 104-load version 1 program at 1 GiB (3 October) against 121.8 to 124.2 MH/s mining version 2 on the live devnet (4 October). Apple only for the shortcut ratio (O-1.5); the on-die cache question of ledger M16 is unchanged | none yet | -| 4 | The same program produces identical hashes on three GPU vendors, cache and dataset included | Litepaper vs RandomX ("Bit-exact on Apple, NVIDIA and AMD, measured"), For miners; homepage | tested by the team | repo `f2e903e`, `0f1fdaf` (version 1 packs), `b27da39` (version 2 packs `igneum-genesis-mh`, `igneum-devnet-v4-epoch0`); igneum-pow 0.2.0 | The 96 test vectors of a pack through `proto-metal/igneum-bench`, `proto-cuda/host.cu`, `proto-opencl/host.c`; batch fingerprint at `--batch-log2 24`; the miner's CPU re-check of every share a GPU worker finds on the devnet; bench-log entries "RTX 5090, memory-hard dataset", "AMD gfx1036", "RTX 5090 through NVIDIA OpenCL", "generator version 2 adopted", "the gfx1036 worker fault" | Version 1: 96/96 on Apple Metal (M5 Max), NVIDIA CUDA and NVIDIA OpenCL (RTX 5090, Windows), AMD OpenCL (Ryzen 7 9800X3D integrated gfx1036, 1 compute unit), Apple OpenCL, pocl and two CPU references; batch fingerprint `98af644e993239e2` over 16.7 million nonces identical on the AMD chip and the 5090, 3 October 2026. Version 2: 96/96 on Apple Metal, Apple OpenCL and the CUDA and OpenCL emulators with identical fingerprints; on real NVIDIA and AMD silicon the version 2 vectors have not run as a pack, but both mined accepted blocks on the live devnet with the CPU re-check clean on every share (RTX 5090 at 124.2 MH/s, gfx1036 at 3.3 MH/s), 4 October 2026. The AMD device is an integrated chip; no discrete AMD card and no Intel card has run anything (O-1.15) | none yet | -| 5 | A CPU verifies one hash in under 10 ms by simulating one warp | Litepaper Mining ("about ten milliseconds"), vs RandomX; roadmap gate 2 | tested by the team | repo `75cac18`, `b27da39`; igneum-pow 0.2.0 (`verify.rs`) | `cargo test` and the crate bench in `igneum-pow/`; bench-log "igneum-pow: Rust crate bit-exact with proto-metal" and "generator version 2 adopted" | 0.411 to 0.579 ms per 32-lane warp steady, 0.41 to 0.87 ms cold, average of 20, 1 GiB dataset, cache held, one M5 Max performance core, 3 October 2026; version 2 units 0.631 ms (average of 20), cold 0.67 to 0.81 ms, 4 October 2026. Gate margin about 16x on this core. Not measured on a 2019-class laptop core (O-1.14) | none yet | -| 6 | The hash is bound to the header: one nonce serves one header, and a wrong nonce is rejected | Spec 1.6; litepaper Mining (implied by "checks a hash") | tested by the team | repo `33f7b33`, `9812466`, `b27da39`; igneum-pow 0.2.0 (`bind.rs`, bound vectors re-cut for version 2, 39 crate tests) | `igneum-miner bad-nonce` against a devnet node; `igneum-pow hash-bound` for the 96-nonce job across the 2^32 lane boundary; bench-log "first devnet blocks on the real lottery hash" and "generator version 2 adopted" | 833 blocks accepted by `igneum-lottery-v1-bound` on 3 nodes, 0 rejections; `bad-nonce` gave Reject(BlockInvalid); Metal, OpenCL and CUDA (emulated) workers bit-exact with the crate on the lane-boundary job, 3 October 2026, Apple M5 Max. Version 2: the node's engine reports `igneum-lottery-v2-bound`, 39 of 39 crate tests, and the live devnet v4 accepts its blocks under it, 4 October 2026 | none yet | -| 7 | The devnet runs at one block a second | Homepage stats ("1 / s"); litepaper Speed; roadmap phase 3 | tested by the team | repo `9812466`, `e9328c6`, `8dae48b`; fork `devnet-v4` `dc749905` | The merged node's 3-node test network (`igneum-devnet-880`, 960 s); the live devnet v4 record `sim/difficulty/records/live-2026-10-04.csv`; the 12-node cloud network's arrival logs; bench-log "devnet-v4 integration", "difficulty rule v2", "first devnet blocks" | Devnet 3, 7 October 2026: first block accepted at 17:06 UTC, 85 of 85 GPU blocks by 17:10 UTC and 287 by 17:14 UTC, 0 rejected (`docs/plans/release-0.3.22.md` section 5). Merged node, 4 October 2026, Apple M5 Max: 1,055 blocks in 960 s, 1.03 blocks/s, sink identical on 3 nodes at 31 of 31 samples, 0 rejected. Live devnet v4 the same day: 49 to 81 blocks a minute while two RTX 5090s joined and left (row 12), 1.1 to 1.2 blocks/s in the oscillating window, then within 1.3% per minute with one PC and the Mac. The 12-node cloud network at one block a second: 644 blocks in a 10-minute window. The 3 October CPU devnet: 1.29 blocks/s over 641 s, 1.03 after the first retarget. The phase 3 gate also asks for proofs under 60 s behind the tip; no proof is on the chain (row 15) | none yet | -| 8 | Blocks are mined by GPUs on Apple and NVIDIA | Homepage live strip; journey phase 3 ("GPU miners on three vendors") | tested by the team | repo `9812466`, `e9328c6`, `d7e1f89`, `2309c8d`; fork `devnet-v4` | Metal worker `proto-metal/igneum-bench --serve` driven by `igneum-miner --worker`; the live devnet v4 hash-rate record `sim/difficulty/records/live-2026-10-04-hashrate.csv` (587 worker STATUS lines by run id); bench-log "first devnet blocks", "devnet v4 cut-over", "difficulty rule v2", "first machine on the Igneum Miner app" | Metal: 506 jobs, 5,636 blocks found and accepted, 0 rejected, 0 CPU/GPU mismatches, 28.2 MH/s wall, 3 October 2026. Live devnet v4, 4 October 2026: PC 1's RTX 5090 at 122 MH/s with 8 identities, PC 2's at 124 MH/s with 8 identities (117 to 119 MH/s inside the one-click app, 34 accepted blocks in its first minute, CPU re-check OK on every share), the Mac's Metal worker at 26.7 MH/s; 17 vote keys signed the first finality lock (row 10); from the afternoon an Apple silicon laptop outside the project at 21.0 MH/s through the app (row 30). Two RTX 5090s and two Apple chips; no other NVIDIA model has mined | none yet | -| 9 | Blocks are mined by a GPU on AMD | Journey phase 3 ("three vendors") | tested by the team | repo `2c4b30f` (generic OpenCL worker, `--pack`), `112acf6` (fault guards); bound kernel `kernel_bound.cl` in the pack | `igneum-worker-opencl.exe --pack` on PC 2's integrated Radeon against the live devnet v4 through the Windows package; bench-log "the gfx1036 worker fault", "first hourly program swap", "first machine on the Igneum Miner app" | PC 2's integrated gfx1036 (1 compute unit) mined on the live devnet on 4 October 2026: 8 accepted blocks at 3.3 MH/s over 577 s with the CPU re-check clean, and 2.74 MH/s through the hourly program swap with 0 rejected. At about 600 s the AMD runtime began answering every call with success while running nothing (906 jobs became 56,384 in 30 s, 4.3 GH/s of phantom work); not reproduced on Apple OpenCL in 4,565 jobs with 0 leaked objects; the worker and miner now refuse a job 20x faster than the mean or an unchanged output buffer and restart (`112acf6`), and the next gfx1036 run names the guard that fires. One integrated chip; no discrete AMD card has run anything | none yet | -| 10 | Checkpoints lock every 30 s of chain at two thirds of all 30-day weight, and the floor stops conflicting locks in partitions and eclipses for as long as neither side's own new blocks carry it past two thirds of its window (about 10 days of a 30-day window at a 50/50 split) | Litepaper Finality, "What Igneum does not claim"; homepage "locked every 30 seconds" | tested by the team | repo `a3a9833` (2/3 floor, O-3.15), `bbb264a` (simulation), `c16ccf1`; fork `devnet-v4` `6457ca95` (`FLOOR_NUM / FLOOR_DEN` 2/3), `da1eb889` (F17 by-weight sortition, F1 first-month gate `min_daa = window`); spec 3.3, 3.3.1, 3.7, 3.9 | The live devnet v4 (`getFinalityCheckpoints`, `tools/observer/observer.mjs`, `/api/checkpoint`); `sim/finality_v2.py --floor 1.0`, scenarios A to L; the three-node, six-voter partition runs `igneum-devnet-921` to `-923`; `tools/finality-attacks` scenarios 1 to 6 and 8; bench-log "first finality lock on the live devnet", "finality floor 2/3", "finality v2 attack harness", "finality fixes F17 and F1" | Devnet 3, 7 October 2026: finality rule v3 from block zero, first lock at 19:02 UTC, under two hours after the first block (`docs/plans/release-0.3.22.md`). The first devnet: the first lock on the live devnet was checkpoint 242 at 12:03:44 BST on 4 October 2026, two hours after genesis (the window and `min_daa` are 7,200 DAA), with 77.4% of all weight and of active weight signed by 12 aggregated votes from 17 vote keys; `observer.mjs` saw it 0.7 s after the miner's own lock line. By 13:21 UTC the observer held 280 certificates, indices 241 to 522 (DAA 7,229 to 17,982), 17 to 27 voters, no index with two hashes. Test networks, 4 October 2026, Apple M5 Max: a 4/2 split locked on the 4 side (67.9%) 2 to 8 s after the cut and never on the 2 side, 0 conflicts; a 3/3 split locked on neither side for 150 s with 0 conflicts, where the 3 October floor (56.7%) would have locked both sides at 76 and 106 s; the rule guarantees one lock history for partitions shorter than the window bound W / (3R) (200 s on that test network's 1,800-DAA window, about 40 minutes on the devnet, about 10 days at the 30-day mainnet window); beyond that bound each side can reach two thirds of its own window, so the next finality rule freezes the weight table at the last certified checkpoint and pauses instead. Simulator with the 2/3 floor: 0 conflicts up to a 33% equivocator (34% splits a 50/50 partition), silent weight pauses locks from 34%, a 50/50 partition locks alone from day 10.1. Harness: equivocating keys stripped on every node, Sybil dust at zero weight, a pulsed miner's weight equal to its block share (ratio 0.96 to 1.0), the first-month gate stops a young window locking under one key. Not demonstrated: certificate injection on the wire, an eclipse with a private fork, the 2-hour presence window at mainnet length | none yet | -| 11 | Hashrate that arrived today has almost no vote: ten days of the whole network's hashrate to reach a third of the weight, twenty for two thirds; 51% never reaches two thirds while honest miners stay | Litepaper Finality; homepage firsts | tested by the team | repo `bbb264a`; `sim/finality_v2.py` | Scenario B of `sim/finality_v2.py`, seeds 7 and 11 | share(t) = (t/30) x a/(1+a) holds to 0.04 points; a renter equal to the whole honest network (a = 1) crosses 1/3 on day 20 and never reaches 2/3; a = 9 crosses 1/3 on day 11.1 and 2/3 on day 22.2. The ten-day figure is a = infinity, honest miners gone. 3 October 2026, Apple M5 Max. A model with 1,000 Pareto keys and no DAG; the live devnet's window is two hours old, so the claim has no live measurement yet | none yet | -| 12 | The difficulty rule recovers from a hashrate step within minutes, where Kaspa's sampled rule never settles. A step inside an epoch set the rule oscillating on the live devnet on 4 October 2026; rule v2 removes it in the simulator and on a test network and is built but not yet rolled out | Spec 2.3; litepaper Speed (implied); bench page | tested by the team | repo `e9328c6`, `abb5a5d` (attacks), `67bf226` (rule v2); fork `difficulty` branch (timestamp fix) and `devnet-v4` `a21ff239` (`difficulty_v2_activation_daa`, `REF_WINDOW_V2 = 600`); `sim/difficulty/sim.py --live` | The live record `sim/difficulty/records/live-2026-10-04.csv` (8,090 headers, `pull_live.py`) and the hash-rate record beside it; `sim/difficulty/sim.py` on the synthetic set and the DAG replay; `sim/difficulty/attacks/attacks.py`; `sim/difficulty/testnet_v2.py` (3 nodes, activation at DAA 900); `cargo test --release -p kaspa-consensus --lib difficulty` (15 pass); bench-log "difficulty controller", "difficulty rule under attack", "timestamp attack fixed", "difficulty rule v2" | Live devnet v4, 4 October 2026 (UTC): a second RTX 5090 joining 7 minutes into an epoch (about 152 to 280 MH/s) hardened the difficulty 70M to 144M in 90 s and then swung by about a third for 40 minutes around the true level of 139M while the epoch-long reference lane carried the join; that card leaving for 4 minutes eased 116M to 67M and back to 106M; the epoch boundary with both PCs restarting took 152M to 77M in 3 minutes, after which the rule held within 1.3% per minute with no flips. Cause: the reference lane covered the whole epoch, so a mid-epoch step polluted it for the hour and the 25% trigger flipped on the short lane's noise. The DAG replay reproduces the record (std of log difficulty 0.115 against 0.134, 4.3 peaks against 4). Rule v2 (reference window 600 DAA) on the replay: std 0.026, 0 flips, mean 142.6M against 139M true; on a 3-node test network the v2 nodes eased a leave with no peak and held a rejoin within 3% after 60 s, and a node without the activation height forked off at it as designed. Rule v2 rolled onto the 12-node cloud network on 4 October (all nodes crossed the height on one chain; a hash-rate step then settled in 160 to 270 s with no swing) and activates on the devnet at DAA 33,000 the same evening. Timestamp forging (ledger M23) fixed the same day: a 50% forger drifts the rate under 1.1% where the 3 October rule gave it a 9.9x difficulty. Simulator, settled seconds: x50 step 62 to 66 (Kaspa 1,542), /50 step 657 to 753 (Kaspa 12,296). Apple M5 Max under load 7 to 442; the DAG model is fitted on one scale; the pool hopper's 0.7-point excess over Kaspa's rule stays open | none yet | -| 13 | Every node executes the ordered transactions natively and reaches the same state root | Litepaper Proving ("Every node executes ... natively"), Building ("runs on Igneum unchanged") | tested by the team | repo `f5f8c80`, `8dae48b`; fork `devnet-v4` `dc749905`; revm 43.0.3 | `node tools/evm-smoke/smoke.mjs` against a 3-node `igneumd`; `igneum-exec-diff seq.json`; bench-log "execution layer devnet v3" and "devnet-v4 integration" | Simnet, 3 October 2026: 87 of 87 viem checks, state roots identical on 3 nodes at four heights, 57 executed and 19 skipped transactions agree with plain revm, 0 mismatches. Merged node on real proof of work, 4 October 2026: 84 of 85 checks (the miss needs parallel blocks the network did not produce in 36 s), 59 transfers in 10 chain blocks, state roots identical on 3 nodes, `igneum-exec-diff` 0 mismatches over 59 transactions; the live devnet v4 runs this execution layer. Apple M5 Max. The prover is a stub; state is rebuilt from genesis at start; no EVM transaction relay between nodes | none yet | -| 14 | Ethereum bytecode runs unchanged, with the documented differences of spec 7.1 | Homepage Build card; litepaper Building | tested by the team | as row 13; fixes `F-exec-A`, `F-exec-B` (spec 7.5) | `tools/evm-smoke/smoke.mjs`: deploy via viem, `increment`, `hashLoop`, `eth_estimateGas`, `eth_getLogs`; `tools/exec-attacks` scenarios 1 and 3; bench-log "execution layer attack fixes" | Deployment, calls, reverts, logs and gas estimates behave as viem expects; chain id 4463 at that version (4464 since the class v5 floor, 8 October 2026); the prototype pgas table gives 0.0095 to 0.028 pgas per gas, below the design's band before calibration, 3 October 2026. 4 October 2026: a transaction that would cross the block's proving budget is refused by the mempool and, if forced in, aborted and charged with its nonce advanced (25 of 25 checks; 30 of 30 malformed cases). Apple M5 Max. The `Prover` precompile, proof records and the shard planner are not in the node | none yet | -| 15 | Every block is proven, with the proof landing within about a minute at launch | Homepage stats ("~60 s to a proof"); litepaper Proving; roadmap phase 3 gate | implemented | repo `d7e1f89` (GPU proof), `e01a3cc`, `292e800`, `eedd136` (`proving/igneum-prove`: shard cutter, MPT witnesses, shard and aggregator guests); SP1 6.8.1; spec 7.2, 7.6 | `proving/windows-wsl2` (SETUP-PROVER, PROVE-BLOCK) on the RTX 5090; `igneum-prove-host --mode block` on `proving/fixtures/`; bench-log "proving v0 on the RTX 5090" and "proving: devnet v4 shards" | First GPU proof of an Igneum block, 4 October 2026, RTX 5090 (WSL2, SP1 cuda, mining paused): fixture `block-78-increment` (2 transactions), core proof 1.4 s (7.3 MB, verify 0.221 s), compressed proof 2.7 s (1.27 MB, verify 0.038 s), post-state and receipts roots identical to the node's; 15.7x and 20.6x faster than a loaded M5 Max CPU. The same day on that CPU (load 38 to 47): a three-shard block proved shard by shard and aggregated by recursion, 19 min (1,139 s) end to end, 245 to 337 s per compressed shard proof, every proof verified. What is not there: no proof is produced, carried or checked on the chain (the devnet prover is a stub that signs claims), the proving pool pays nobody (row 21), the block proven is far below one shard, and the 60-second figure remains a design target; the pass mark is the standard in `docs/benchmarks/proving-e2e.md`. Second RTX 5090 run, 4 October 2026 evening (job run-20261004-173115): a full shard at the provisional S_p (6.75 M pgas, 60.8 M cycles) executed in 1.63 s, core proof 8.3 s (18.1 MB), compressed proof 10.9 s (1.27 MB, verify 0.040 s); a two-shard block (13.5 M pgas) proved shard by shard (11.7 s and 10.0 s) and aggregated in 2.2 s, 24 s of GPU stages end to end, every proof verified, six tampered witnesses rejected. The two host defects (an abort after the upload, an idle wait that turned out to be an unbuffered 18 MB proof save through the WSL2 file bridge, 24 minutes) are fixed (ledger P20) 5 October 2026, live devnet with real transactions (bench-log "real transactions, the first non-empty shard proven and paid"): block 72704 shard 0, 29 transfers, 5,800 pgas, proven on PC 2 in 34 s, verified on the Mac in 0.297 s and paid 1.7623 IGN, 53 s after the chain block executed; of about 1,400 blocks in the 20-minute window 36 were proven (the one prover takes the newest shard assigned to it), so "every block" is not yet true; a second content shard (72803, all copies skipped) failed the native-execution veto on the exporter's block structure, fixed with fixtures the same day, the node side pending the 0.3.9 rollout 5 October 2026, evening (bench-log "proving v1"): the aggregated segment record, the chain rule and the unproven rule are implemented behind `proving_v1_activation_daa` (branch proving-v1, not on the devnet before 0.3.11); on the RTX 5090 a chain of 8 consecutive live blocks proved and aggregated by recursion in 135.6 s with the miner on the card (17 s a block, one proof of 1,272,909 bytes attesting all 8, verified in 0.04 s); the 3-node fast-time harness paid a segment record 1.0 s after submission and refused a late one after its deadline (21 checks); the devnet itself, with one prover, carried proofs for 2.4% of blocks over 30 minutes at a block-to-record latency p50 44 s, p99 52 s. The "within about a minute" holds per proven block; "every block" needs 18 mining 5090s or 6 proving-only cards at empty blocks on the measured rates, and the mandatory rule stays off until the share is one | none yet | -| 16 | A 12 GB card proves one shard in about 20 s (WITHDRAWN 5 October 2026: a 24 GB card proves a full shard at the adopted size in 4.3 s; 32 GB mines and proves) | Litepaper Proving ("The proving budget"); roadmap gate 2 | designed | spec 5.1 (Target), 7.6 (`S_p` provisional, 7,500,000 pgas = `B_p` / 4) | `PROVE-SHARD.bat` on the RTX 5090 (pending); the end-to-end standard in `docs/benchmarks/proving-e2e.md`; bench-log "proving: devnet v4 shards" | Measured on a 32 GB card, not yet on a 12 GB card. A shard at the provisional `S_p` is 60.8 M SP1 cycles on the prototype pgas table (9 cycles per pgas, 44 per EVM gas; the modexp entry about 100x its SP1 cost); on an RTX 5090 (4 October 2026 evening, job run-20261004-173115) it executed in 1.63 s and its compressed proof took 10.9 s, verified in 0.040 s, so the 32 GB card is inside the 20 s target with margin. Whether a 12 GB card proves it at all, and in what time, is the next measurement (an RTX 3060 and an RTX 5060 Ti 16 GB are on order). A per-shard time can be met by shrinking the shard, so the project does not use it as a pass mark 5 October 2026, evening (bench-log "proving v1", the S_p curve): measured on the RTX 5090 with SP1 6.8.1's GPU prover, the card to itself, 1-s nvidia-smi samples: an empty shard 13,874 MiB and 2.2 s; a full shard at the ADOPTED v1 budget (30,000 pgas, 4.7 M cycles) 20,434 MiB and 4.3 s; the full prototype shard (6.75 M pgas, 60 M cycles) 28,307 MiB and 10.8 s; beside the miner 15,670 and 30,039 MiB. No environment knob of SP1 moves the 13.9 GB floor and the GPU server has no options of its own, so on this build a 12 GB card proves nothing, a 16 GB card only empty shards, a 24 GB card the adopted full shard alone and beside the miner (22,210 MiB and 13.2 s, measured on the 32 GB card: the 5090's allocation pattern, not yet a run on a 24 GB card) and a 32 GB card the prototype shard beside the miner with 2.5 GB spare. The litepaper line now says so; the 12 GB gate returns when a prover build with a smaller floor is measured on a 12 GB card | none yet | -| 17 | The chip resistance claim, served as the class v6 close words it, the claim statement above the sentence: Igneum remains competitive on accessible commodity GPUs even when specialised mining hardware is assumed to exist, remain compatible and seek profit; its security does not rely on identifying that hardware or retiring it through emergency changes. Class v6 adopts the 64-register window and retains it across every rotation. Current modelling places the strongest specialised designs assessed against the GPU tier at about 2.3x to 3.3x energy-efficiency advantage a node ahead (2.0x to 2.9x on the GPU's own node), a bracket that is approximate and provisional until the placed gated core rows land. The long-program and select-tree proposals were rejected. Economic resistance depends on development cost, deployment economics and productive hardware lifetime; family transitions receive an obsolescence benefit only where a loss of competitiveness is demonstrated; programmable multi-epoch designs are included in the assessment. Beside it: class v4 is live from the first block on the testnet and the mainnet; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 15 days a century, both routed to the next class; datacentre silicon does not change the question; the three statements (energy resistance, economic resistance, response capability) are served separate, with the harness and the scoring rule linked | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | the GPU side tested by the team (the RTX 5080 and RTX 5090 clock-lock passes under class v4, every card, the verifier, the two attack-pass bounds, the H100); the chip core synthesised on ASAP7 and scaled to N3, claimed; the chip's memory modelled; the node column claimed scaling; the economic surface modelled, first cut, conditional; the rotation schedule measured per boundary; class v5 designed; the Antminer X5 an observed comparison, not a ceiling; the X9 a withdrawn pre-order, never benchmarked | `docs/design/class-v6-rotating-family.md` section 10 (10.0 to 10.0h, the close and its two accepted external reviews, 8 October 2026); `docs/design/class-v5-stored-state.md` sections 0, 13 and 14 and `docs/design/class-v5-harness/` (branch class-v5); `docs/design/class-rotation-four-layers.md`; `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; the H100 row of 7 October; `docs/plans/cryptanalysis/in-house-pass.md` (the internal adversarial pass) | the scoring rule in the close (the minimum over workloads of the maximum over free adversarial designs of the GPU's joules per hash over the adversary's, under the 10 percent GPU-cost budget at the lock, the verifier limit, cross-vendor correctness and hardware accessibility); the card rows by the benchmark package; the class v5 harness and the family harness; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); the class v4 efficiency passes (bench log "7 to 8 October 2026, the class v4 efficiency passes: the core clock lock on the RTX 5090 and the RTX 5080", measured): the 5090 at 136.84 MH/s and 475.5 W unlocked, 134.98 at 316.3 W at a 1,400 MHz core lock, the best points class v4 at 1,200 MHz (133.80 MH/s, 305.1 W, 0.439 MH/W) and class v3 at 1,300 MHz (134.62, 223.3 W, 0.603), the premium 145 W unlocked and 82 W at the best points, the knee 1,300 MHz; the RTX 5080 (8 October 2026, the dock card of the three-card Windows rig) at 71.41 MH/s and 253.1 W unlocked under class v4 against 71.28 at 169.7 W under class v3, the best points class v4 at 1,100 MHz (71.20 MH/s, 146.6 W, 0.486 MH/W) and class v3 at 1,000 MHz (71.11, 103.7 W, 0.686), the premium 83.4 W unlocked and 41 W at the best points, the knee between 1,000 and 900 MHz; per tier: a 5080 owner on class v4 locked near 1,100 MHz pays 147 W instead of 253 for 0.3 percent less rate, MH per watt up 72 percent, the lever Ember Tune's core-clock knob in 0.3.24; 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; the GPU side of the close: the RTX 5080 at its 1,100 MHz lock 2.06 microjoules per hash and the RTX 5090 at its 1,300 MHz lock 2.33 (class v4, 8 October 2026); the modelled bracket about 2.3x to 3.3x a node ahead and 2.0x to 2.9x node for node (approximate, provisional; the clock-gated base core k about 0.37 at N3, the gated window adding about 0.13; the first placed core 64 percent above synthesis), the placed gated row expected near 2.6x to 3.1x and 2.3x to 2.7x and served when it lands; the shadow's premium on a 5090 81.8 W at its knee (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W; class v3 at 1,300 MHz 134.62 at 223.3 W; 7 October 2026); 1.067x at the ceiling; 12 percent on 15 days a century; 10.85 ms at rung 3; 6 to 8 October 2026, the M5 Max, the desk rigs' RTX 5090, RTX 5080, RX 9070 XT and RTX 4070, rented pods, a rented H100 SXM, igneum-build-1 Bitmain's Antminer X9 (RandomX; 1,000 KH/s, 2,472 W, 2.47 J per KH, USD 5,600; pre-orders 26 December 2025) was withdrawn in mid-May 2026 with buyers refunded before any unit shipped, no independent benchmark, commodity Sophgo SG2044 server SoCs with an AES accelerator, no tapeout: it is a precedent on the served pages, not a chip core against the model (attack pass AP-F5-1, 7 October 2026; the close's 10.0f, 8 October 2026). Withdrawn from the served pages on 8 October 2026 and not restated: the 2.1x and 3.4x launch line, the 5x to 9x class v3 baseline, the ladder's 2.8x row, the USD 100 M pay-back row, any chip-arrival probability, the lifetime claim and the USD 300 M and 340 M lines. | none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), whose floor reading is in (measured, 8 October 2026; ledger AP-F8-1 and AP-F8-6): nine of nine hot sets refused; the diffuse era-stride excess, bounded under 0.1 percent of a hash's reads per site, is not caught by the floor and is the next class's test, and no outside review has run yet | -| 18 | The chip resistance measurements: the program is latency-bound (dependent reads spread over the whole dataset), not bandwidth-bound, on every card we own, and sits beyond a card's on-chip cache; measured 8 October 2026: the distinct-index floor holds at 0.995 on every accepted program, about half of epochs carry one load site with a biased address bit at the era's stride rotation, priced at about 1.6 percent of a hash's reads to a chip storing half the dataset and nothing to one storing all of it (`docs/analysis/class-v6/family-gate.md`, lane D; adv-cache-2's `report-chained-cache-2.md` section 2.3 on its branch; ledger AP-F8-7) | Litepaper Mining ("waits on memory latency, not on maths or bandwidth"), vs RandomX; the numbers page | tested by the team | readwidth e752fc7 (`docs/plans/read-width.md`), ca2-era 78c0ee4, ca2-cache 2de19e5 (`docs/plans/hot-table.md`) | The dependent-read probes at 32 to 1,024 MiB and the hash rate per class on the three cards; the latency-bound share = rate over the probe ceiling per load | Latency-bound share at the 1 GiB dataset: RTX 5090 0.96 (v2) and 1.01 (v3), RX 9070 XT 0.87 and 0.95, M5 Max 1.01 and 1.06; wider reads do not close the AMD gap (the 9070 XT does 2.4 G dependent reads per second at every width; the 5090 goes bandwidth-bound at 64 B, share 0.58); a 32 to 96 MiB hot table is not kept resident by any card while the dataset streams (g 0.80 to 0.87 in the added form). 5 October 2026 | none yet | -| 19 | The lottery hash is sound as a hash: uniform output, deterministic, no out-of-bounds read, fuzzed; class v3 bit-exact on the three vendors | Litepaper vs RandomX ("Every number above is measured and logged"), the numbers page | tested by the team | ca2-mixer 1ab8b21 (`tests/mixer.rs`, `tests/scratch.rs`), ca2-era 78c0ee4, ca2-soundness a465881 (`docs/analysis/scratch-soundness.md`), `igneum-pow/tests/packs.rs` | The crate suite (53 + 4 + 19 + 7), the Metal fuzz, edge, stats and determinism runs on the v3 construction, the pack vectors and 2^24 fingerprints on Metal, Apple OpenCL, the RTX 5090 and the RX 9070 XT, the 1,024-hash CPU re-check per card | Class v3 (mixer x8 + era): 200-program fuzz 200 of 200 on Metal, every tenth on Apple OpenCL; the pinned v3 packs 3/3 + 3/3 and 96 of 96 lanes on Metal and Apple OpenCL; the six era packs' fingerprints equal on the three vendors (PC 1 job run-ca2-era-pc1-20261005, 5 October 2026); the v2 exports byte-identical on the v3 crate; the final-class PC rows and the G2 re-check: job run-ca2-era-pc1b-20261005 (pending at the time of writing) | none yet | -| 20 | No premine, no pre-sale, no allocation: every coin is minted by the schedule and every coin goes to the block producer (80%) and the proving pool (20%) | Homepage stats and Economics tiles; litepaper Supply, Economics | implemented | repo `6ac80a3`; fork "igneum-node devnet v0"; `consensus/core/src/igneum.rs`, `coinbase.rs` | `cargo test -p kaspa-consensus-core igneum` (8 pass: subsidy table, ramp, split, cap) and `cargo test -p kaspa-consensus coinbase` (8 pass); `igneum-miner inspect 40`; bench-log "igneum-node devnet v0" | Coinbases on the devnet: 80/20 exact on 39 of 39 single-payee blocks, the 20% to the `igneum-proving-pool-v0` output; the per-second schedule sums to under the 4,000,000,000 cap by less than 100 coins; 3,168,808,781 units per DAA second in years 0 to 2, halving at 63,115,200 DAA s. 3 October 2026, Apple M5 Max. The devnet genesis carries no allocation; the mainnet genesis does not exist yet, so the claim is about the code and the stated rule, not a launch that has happened | none yet | -| 21 | The proving pool's 20% reaches shard provers and aggregators | Litepaper Economics; homepage "20% provers" | tested by the team | spec 5.3; `proving/igneum-prove` carries the prover's payout address in every shard proof (ledger P12) | None. The pool output exists (row 20); the payout from it against proof records is unwritten. Since 5 October 2026: the payout rule is live on the devnet (`proving.rs shard_payouts`, the carrying segment pays the first valid record per shard its part of the segment's pool credit) | The escrow accumulated on the simnet (92.55 IGN at the end of the v3 run) and nothing can draw it. Rule decided: per block, divided among shards by consensus proving cost, sortition to 8 provers for 10 s then open (spec 7.2). The economy model of 4 October 2026 (`sim/economy`, 1,000 operators, 30 days) kept every block proven within 60 s under six stress scenarios; a model, not hardware Live devnet, 5 October 2026: 388 shards paid by 16:02 UTC, 446.13 IGN from the pool to PC 2's payout address, 0.8813 IGN per mergeset block of the proven segment (bench-log entries of 5 October: "the first shards proven, verified and paid" and "real transactions, the first non-empty shard proven and paid") | none yet | -| 22 | The base fee is burned in full and the priority fee splits 80% to the miner and provers, 20% to the apps whose code ran | Homepage Economics caption and Build card; litepaper "Where fees go" | tested by the team | repo `f5f8c80`; fork worktree `vendor/igneum-node-exec` | `tools/evm-smoke/smoke.mjs` receipt checks; bench-log "execution layer devnet v3" | Transfer receipt: `burnedProvingFee` 200 gwei, `minerTip` 16,800 gwei (80%), unregistered developer share 4,200 gwei burned; contract call: 80% to the miner, 20% credited to the payee the constructor registered, balance delta equal. 3 October 2026, Apple M5 Max simnet. The provers' part of the 80% is not split out (no provers exist); the base fee stayed at the 1 gwei floor throughout | none yet | -| 23 | No fee to any team, foundation or fund; 0 admin keys in consensus | Homepage Economics tiles and caption; litepaper "No fund, no foundation" and Governance | designed | spec 5.5, 5.6 (decided 3 October 2026); spec 08 | Reading: no coinbase output, fee route or consensus key in the fork names any party (`coinbase.rs`, `docs/fork-divergence.md`) | The emission code has two outputs (row 20) and the fee code has three routes (row 22), none to a team. The 1% fee of the official client is a client setting, not a protocol rule, and is not implemented. The release key of spec 08 signs client updates (the Igneum Miner app's over-the-air manifest since 4 October 2026, Ed25519) and holds no consensus power; its custody policy is open (O-8.1) | none yet | -| 24 | External proving jobs pay 90% to the provers who delivered and burn 10%, once settled in IGN | Homepage "IGN burned from jobs, phase two"; litepaper Proving and Economics | designed | spec 5.4 | None. Needs the proof bridge (spec 7.3, phase two) and the settlement switch (O-5.2) | At launch jobs are paid on the customer's chain in the customer's currency and nothing is burned (ledger P10). No job market code exists | none yet | -| 25 | The 4 billion cap, halving every two years, with a 30-day ramp from 10% | Homepage "4B IGN hard cap"; litepaper Supply and the emission chart | tested by the team | repo `6ac80a3`; fork `consensus/core/src/igneum.rs` | `cargo test -p kaspa-consensus-core igneum`; bench-log "igneum-node devnet v0" | Ramp day 0 paid 10.03% of the full rate (317,767,704 units at DAA 806); the schedule table and the cap assert in the crate's own tests. 3 October 2026, Apple M5 Max. Base unit (8 or 18 decimals) is open (O-2.6); the spec was changed to follow the code's 365.25-day year (ledger E9) and a test that reads the published numbers back is still owed | none yet | -| 26 | A phone or browser verifies the chain from a locked checkpoint, at about 3.44 MB per day in checkpoint mode | Homepage "Browser checks Igneum" card; litepaper Building ("Light clients"), firsts row 6 | designed | spec 10 (10.5 bytes per day: 3.44 MB at 1,000 voters, 6.68 MB at 10,000, derived, approximate); repo `f874f80` for the browser card; `site/api/checkpoint.mjs` | None for the byte figure; `site/verify/` for the card against `/api/checkpoint`. BLS verification on a phone and in WebAssembly is O-10.3; the full-header mode on a phone is O-10.4 | Since 12:03 BST on 4 October 2026 the homepage card verifies the live devnet's own certificates in the tab (index 522 with 27 voters at 13:42 UTC), BLS aggregate against the voter list the node serves, light client v0; before that it verified the 3 October test network's. The byte figure is arithmetic on designed sizes (header 400 bytes, proof 400 bytes), measured nowhere; the execution proof the card would also check is not on the chain (row 15) | none yet | -| 27 | The node survives malformed input, floods, withholding, partitions and eclipses | Litepaper Speed ("GHOSTDAG, the BlockDAG consensus proven on Kaspa"); spec 2 | tested by the team | repo `394030c`, `8dae48b`, `6b5bd92`; fork worktree `vendor/igneum-node-harness` and `devnet-v4`; `tools/harness/`; `infra/cloud-devnet/experiments/partition.sh` | `tools/harness/` against a private `igneumd` test network; the merged node's harness scenarios 2 and 5; the cloud network's 10-minute partition of Singapore (`results/2026-10-04/partition-sin-20261004-110906/partition.md`); bench-log "consensus attack harness", "devnet-v4 integration" | 3 October 2026, Apple M5 Max: 63 malformed cases, node up on every one; withholding at 10% to 45% within 2 sigma of share; partitions of 120 s to 3,700 s healed to one chain in 10 s; eclipse victims rejoined in 10 s; 50x floods left template p95 under 4 ms; one FAIL, a 45% withholder releasing every 20 blocks took 50.7% of blues (bound 47.4%). Merged node, 4 October 2026: 63 cases, node up, 0 cache builds; the 10 s timestamp floor and future bound exact. Cloud network, 4 October 2026: 12 nodes in five locations on their own chain, Singapore cut off by iptables for 10 minutes; the two minority nodes adopted the majority chain 10 and 14 s after the heal with reorgs of 445 and 516 blocks, the majority's deepest reorg was 2 blocks, 0 conflicting locks (none were possible: the weight window stood at DAA 3,030 of 7,200). CPU miners only; the finality rules under partition are row 10 | none yet | -| 28 | Headers are validated cheaply before the lottery engine runs, so forged timestamps cannot force 256 MiB cache builds | Spec 2.4; ledger M15 | tested by the team | repo `0953ec7`, `8dae48b`; fork worktree `vendor/igneum-node-r3` branch `r3-fixes` at `5166ee26`, merged into `devnet-v4` | `measure_m15_attack_before_and_after` (ignored test, release, `--features igneum-pow`); kaspa-pow 8, header_processor 1, p2p `pow_guard` 2 tests; harness scenario 5 on the merged node | 50 forged headers: before, 50 cold builds in 10,595 ms and the live day evicted; after, 0 builds, all 50 rejected in 14 ms, 3 October 2026, Apple M5 Max under load 60 to 110. Merged node, 4 October 2026: 63 harness cases with 0 cache builds (the node log shows one build, the honest day) and the M15 p2p cases disconnected by the strike guard; the live devnet v4 runs it. Measured through the validate path with `skip_proof_of_work`, not the daemon RPC | none yet | -| 29 | Blocks reach every node well inside GHOSTDAG's delay bound across continents | Litepaper Speed (GHOSTDAG at one block a second); spec 03 C1 (lock latency); `infra/cloud-devnet/README.md` | tested by the team | repo `6b5bd92`; `infra/cloud-devnet/experiments/latency.sh`, `analyze.py`; the Linux cross-build `infra/cross/build-linux.sh` | 12 `igneumd` nodes on cloud VMs in Helsinki, Falkenstein, Ashburn, Hillsboro and Singapore (own chain `igneum-devnet-20`, one CPU trickle miner each), a ping matrix, then 10 minutes of per-node arrival logs joined on block hash; `results/2026-10-04/latency/propagation.md` and `rtt-by-region.md` | 644 blocks in the window, 642 seen by at least 80% of nodes; arrival at a node minus the first arrival anywhere: p50 343 ms, p90 497 ms, p99 666 ms, max 2,313 ms; by region p50 239 ms (Falkenstein) to 413 ms (Singapore), p90 455 to 632 ms; inter-region RTT 35 ms (Helsinki to Falkenstein) to 289 ms (Ashburn to Singapore); first arrival minus header time median 490 ms. 4 October 2026. The network is the project's own: 12 nodes not 20 (a new account's limits), CPU hash rate only, clocks by chrony, one evening of data; the 5 s bound behind GHOSTDAG k is a design parameter this run did not challenge | none yet | -| 30 | One click: install, press start, the card mines; the app looks after its node | Homepage Mine section ("One click: install, press start"); litepaper "One click, for everyone else"; journey phase 5 | tested by the team | repo `3bb50d6`, `2c4b30f`, `6461540` (package 0.3.0: prebuilt NVRTC CUDA worker and generic OpenCL worker, driver only), `a1a33cb`, `7c794df`, `0d4498e`, `6c083db` (Igneum Miner 0.3.0), `78903cd` (0.3.1, over-the-air updates) | `Igneum-Miner-Setup-0.3.0.exe` (runner-built, unsigned) on a Windows PC with an RTX 5090 and no toolchain; `proto-cuda/nvrtc/emu/serve-check.sh` on the Mac; `proto-cuda/windows-app/TEST.md`; bench-log "one-click Windows workers", "first machine on the Igneum Miner app", "a node 60 s behind the clock is silently dead", "the gfx1036 worker fault" | Four machines by 15:45 BST on 4 October 2026: PC 2, then PC 1 (RTX 5090 at 110 MH/s under the 80% power cap), the project's Apple M5 Max (25 MH/s) and the outside Apple silicon laptop (row 29), all on Igneum Miner 0.3.1. The NVRTC worker compiled the pack on the card with no toolchain installed and mined at 124.2 MH/s, equal to the nvcc-built worker, 0 rejected, CPU re-check clean; inside the app 117 to 119 MH/s with 34 accepted blocks in the first minute, the integrated AMD chip at 3.3 MH/s beside it (row 9). Two defects found by the install, both fixed the same hour: a clock 62 s slow after a power cut made the node reject every relayed block for 12 minutes with no visible reason (the app now reads the skew from the node's warnings, the block timestamps over the EVM RPC and an HTTPS Date header, warns over 5 s and blocks Start over 10 s, with a one-click clock sync; checked on the Mac with a fake 60 s skew; a one-line node warning is filed), and the node card said "syncing" while the miner was already accepted. The Mac could only emulate the NVIDIA path (17 of 17 sampled hashes) and the AMD path on Apple OpenCL (15 of 15). Over-the-air updates were dry-run on a private devnet (0.3.0 to 0.3.1 and back), not on a user's machine. The installer is unsigned (SmartScreen "run anyway"). Second machine, the same afternoon: a friend of the project installed Igneum Miner 0.3.1 from the DMG on an Apple silicon laptop with no toolchain and no instructions beyond five steps; the node synced from the seed, the Metal worker reported ready, 33 accepted blocks and 0 rejected in 7 minutes at 21.0 MH/s average, CPU re-check OK on every share, uploads arriving every minute under its per-install id. That laptop is not the project's hardware, but the result is observed through the project's own log intake and reported by the project, so it stays tested by the team until an outsider publishes a run of their own. The devnet's other GPU machines (PC 1 and the Mac) run the same workers through the launcher, not the app | none yet | -| 31 | Card lifetime: a 4 GB card mines about four years and an 8 GB card about twelve, under the dataset's step schedule (2 GB at genesis, doubling at years 4, 12, 28, 60) with the cache freed after the daily build | Litepaper Hardware and vs RandomX ("Dataset" row); homepage Mine card and "Memory" row | designed | `docs/analysis/card-lifetime-2026-10-05.md` (branch card-lifetime 1fecfe2); spec 1.13.3 option (b) recommended to the owner 5 October 2026 (`docs/plans/counter-asic-2-rollout.md` 6c) | The per-tier working-set arithmetic of that document (GTX 1650, RTX 3050, RTX 3060, RTX 4090 tiers) against the step schedule | A design claim: under the continuous mapping (a) a 4 GB card is out within 1 to 1.5 years and an 8 GB card at 6 to 7.5 years, so the sentence is true only under the step schedule (b), which the spec has not yet fixed (O-1.13) | none yet | +| 1 | The Igneum 2.0 devnet (`igneum-devnet-4`): started fresh on 8 October 2026 from the release cut; chain id 4464; the release manifest (/release.json) carries its commits and is regenerated at its first block | This page; the live page | designed (starting) | the release manifest (/release.json) | `docs/plans/igneum-2.0.md` (the 2.0 reset: the network restarts as the 2.0 devnet); the row moves to activated when a node's own line shows the first block and the manifest is regenerated from it | 8 October 2026: no first block yet (designed); chain id 4464 (designed) | none yet | +| 2 | Proof verification is enforced in consensus before the no-rescue exercise (D5's prerequisite). Today the rule is off: every producer verifies proofs off the consensus path, and a block carrying a matching statement without a valid proof is not refused by consensus | `docs/plans/igneum-2.0.md` D5; this page | implemented (switched off on the devnet) | node fork `f8da7515`: the switch is `proving_consensus_verify_daa` in `consensus/core/src/config/params.rs` (the plan names it `verifier_in_consensus` and `proof_rule_active_from`), the rule `check_carried_proofs` in `consensus/src/pipeline/body_processor/body_validation_in_context.rs`, the gate `proof_rule_applies` in `consensus/core/src/proving.rs` | Read the devnet parameters at that commit: `proving_consensus_verify_daa: u64::MAX` (never) in the devnet's parameters, which the 2.0 devnet inherits; the pass condition is the switch set to an activation height on the exercise network and a node's line naming it | 8 October 2026: read from the node source, not measured; the switch reads never on the devnet (implemented, not activated) | none yet | +| 3 | The 64-register window per lane costs a GPU under 1 percent of rate at stock, and at most 5 percent per load with the liveness chain | The litepaper (class v6); `docs/plans/igneum-2.0.md` D1 (the placed 64-register rows) | tested by the team | `docs/analysis/class-v6/connected-state.md` section 4; `docs/design/class-v6-rotating-family.md` section 10.0e | The class v5 nvcc harness and the kit worker, both packs on the same card minutes apart, 250 batches of 2^24, nvidia-smi at 1 Hz, vectors PASS on every row (`connected-state.md` section 4); the per-load rows of the full chain against the base (`class-v6-rotating-family.md` 10.0e) | 8 October 2026, rented RTX 5090 (575 W cap) and RTX 4090 (450 W cap) at stock: energy per hash +0.6 percent on the RTX 5090 and -0.9 percent on the RTX 4090, inside the run-to-run noise; under 1 percent of rate; 80 to 87 registers per thread, no spill (all measured). Per load: RTX 5090 16.7 nJ base, 17.6 nJ full chain; RTX 4090 26.0 nJ, 27.0 nJ (measured). The lock row on the project's own rigs is owed | none yet | +| 4 | Reorganising the same work around live state (the connected-state variant, experiment D2(a)) does not reduce a specialised chip's edge: KILL as a class | `docs/plans/igneum-2.0.md` D2(a); this page | tested by the team (a published failure) | `docs/analysis/class-v6/connected-state.md` (the verdict, section 6) | The census, liveness and GPU rows in `connected-state.md` sections 2 to 4; the chip side priced on the drawn program by synthesis (a model, never a lower bound) | 8 October 2026, verdict 17:25 UK: the window is necessary (63 of 64 registers live at every address, measured) but only its width reaches the chip, +1.2 pJ per lane-op at N5 (synthesised); the window moves the chip's edge 1.10x node for node against a 1.25x gate (modelled); the GPU side +0.6 percent energy per hash on the RTX 5090, -0.9 percent on the RTX 4090 at stock (measured). Rearranging the dependency graph of the same operations moves neither side | none yet | +| 5 | "A GPU-secured network for Ethereum-compatible applications and verifiable computation." served on every page | Every page | designed (served) | `docs/plans/igneum-2.0.md` (the objective: the positioning line) | `node tools/ci/ledger-text-check.mjs`: the sentence pinned (R0) on the home page, the litepaper and this page | 8 October 2026: on this page; the home page and the litepaper carry it as their 2.0 text lands (designed) | none yet | +| 6 | The chip claim as served: "Igneum remains competitive on accessible commodity GPUs even when specialised mining hardware is assumed to exist, remain compatible and seek profit; its security does not rely on identifying that hardware or retiring it through emergency changes." Under it the three statements, separate: energy (the modelled bracket about 2.3x to 3.3x a node ahead and 2.0x to 2.9x node for node, approximate and provisional until the placed gated core rows land), economic and response capability, rotation an optional improvement. Class v5 derives the dataset from chain state; whether that excludes a specialised design is under evaluation (Deliverable 3), since a design that tracks state is not excluded by staleness. The energy ratio is not the pass criterion: the coexistence model ([docs/analysis/class-v6/coexistence-model.md](https://git.igneum.network/igneum-network/igneum/src/branch/master/docs/analysis/class-v6/coexistence-model.md)) is, and its first run's result is served with its conditions | The litepaper (the chip model) | designed (the bracket modelled; the GPU side tested by the team) | `docs/design/class-v6-rotating-family.md` section 10 (10.0h to 10.0n, 8 October 2026); `docs/plans/igneum-2.0.md` D3 and D4 | the scoring rule in the close (the minimum over workloads of the maximum over free adversarial designs of the GPU's joules per hash over the adversary's, under the 10 percent GPU-cost budget at the lock, the verifier limit, cross-vendor correctness and hardware accessibility); the placed rows are D3's | the GPU side measured: the RTX 5080 at its 1,100 MHz lock 2.06 microjoules per hash and the RTX 5090 at its 1,300 MHz lock 2.33 (8 October 2026, the project's own rigs and rented pods); the chip side synthesised and claimed, its placed gated row pending | none yet | ## Count by status | Status | Rows | |---|---| -| designed | 5 (rows 16, 17, 23, 24, 26) | -| implemented | 3 (rows 2, 15, 20) | -| tested by the team | 22 (rows 1, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 18, 19, 21, 22, 25, 27, 28, 29, 30) | +| designed | 3 (rows 1, 5, 6) | +| implemented | 1 (row 2) | +| activated | 0 | +| tested by the team | 2 (rows 3, 4) | | reproduced externally | 0 | | reviewed independently | 0 | -31 rows. The rendered page is `site/evidence.html`, generated from this file by `site/build.mjs` (since 6 October 2026); the text is judgement, so this file is edited by hand and the page follows. - -## What moved on 4 October 2026 - -| Row | Before | After | Why | -|---|---|---|---| -| 1 | tested by the team (one vendor, 3 October) | tested by the team (three vendors on the live devnet, no pause) | the first hourly swap on the live devnet | -| 3 | 80 to 112 loads with repeats | 128 distinct reads per hash, the rate cost stated | generator version 2 | -| 9 | implemented | tested by the team | the integrated AMD chip mined accepted blocks on the live devnet | -| 10 | "the floor stops conflicting locks" | "... for as long as neither side's own blocks carry it past two thirds of its window" | the 205-s split on a full window certified both sides (F21) | -| 12 | "recovers within about a minute" | "within minutes; a mid-epoch step oscillated for 40 minutes; v2 built, rollout pending" | the live oscillation of 4 October | -| 15 | designed | implemented | a GPU proved a block, off-chain | -| 26 | test-network certificate | live devnet certificate | the first live lock | -| 29, 30 | new | tested by the team | the cloud network's propagation run; the one-click app on PC 2 | - -## What moved on 5 October 2026 - -| Row | Before | After | Why | -|---|---|---|---| -| 15 | implemented | implemented, with a live result | the first non-empty shard (block 72704, 29 transfers) proven, verified and paid on the devnet; not every block is proven yet | -| 21 | designed | tested by the team | 388 shards paid from the pool on the live devnet, the rule in `proving.rs`, the numbers in the bench log | - -## What moved on 7 October 2026 - -| Row | Before | After | Why | -|---|---|---|---| -| 7 | the first devnet's block rate | Devnet 3's first block and its first minutes added | Devnet 3 started at 17:06 UTC with every upgrade on from block zero | -| 10 | rule v2, first lock 4 October | Devnet 3's first lock under rule v3 at 19:02 UTC added | the first lock on Devnet 3 | -| 17 | 136 MH/s at 350 W (class v3) | the class v4 efficiency pass added: 136.84 MH/s at 475.5 W unlocked, 134.98 MH/s at 316.3 W locked, control 134.68 MH/s at 228.0 W | the 5090 efficiency pass | -| rule 1 | "the repository is private until the public testnet" | the ceiling is stated without the repository's state | the repository links moved to git.igneum.network | - -## What moved on 8 October 2026 - -| Row | Before | After | Why | -|---|---|---|---| -| 17 | the 5090's efficiency pass | the RTX 5080's clock-lock pass beside it (71.41 MH/s at 253.1 W unlocked, 71.20 at 146.6 W at 1,100 MHz, the premium 83.4 W to 41 W) and the per-tier reading | the bench log's efficiency-passes entry | -| versions | chain id 4463, release 0.3.22 | the chain id at genesis and since the floor, the node, pow and app versions read from the release manifest at build time (/release.json) | an accepted external review: no status page hand-carries a number | -| labels | five labels | six: "activated" between implemented and tested by the team; the reference-repository wording corrected (specs, pow crate, simulators and test material public; node, miner and proving later) | the same review | -| 17 | the 2.1x to 3.4x launch line, the 5x to 9x baseline, the 2.8x rung, the USD 100 M pay-back row | the class v6 close's served sentence with the bracket (about 2.3x to 3.3x a node ahead, 2.0x to 2.9x node for node, approximate and provisional until the placed gated core row), the three statements separate, the harness and scoring-rule links, every number labelled | two accepted external reviews of the close (`docs/design/class-v6-rotating-family.md` 10.0f and 10.0g); the lifetime claim and the USD 300 M and 340 M lines withdrawn before they were served | +6 rows. The rendered page is `site/evidence.html` (served at /evidence), generated from this file by `site/build.mjs`; the text is judgement, so this file is edited by hand and the page follows. ## What would move a row | From | To | What it takes | |---|---|---| -| designed | implemented | Code in this repository with test vectors that pass | -| implemented | tested by the team | A bench-log entry with the machine, the date, the command and the number | +| designed | implemented | Code with test vectors that pass | | implemented | activated | A node's own start line on a named chain naming the rule and its activation height | +| implemented | tested by the team | A landed document with the machine, the date, the command and the number | | tested by the team | reproduced externally | The code the row names public in the reference repository (the specifications, the pow crate, the simulators and the test material are; the full node, the miner and the proving code open later), the command published, and a third party's run with the same result, linked from the row | | reproduced externally | reviewed independently | A named reviewer's published finding on that version. Funding for review is `docs/plans/funding.md` | | any | the row's status falls back | A new version of the code or rule the row names | diff --git a/docs/fud-ledger-2.0.md b/docs/fud-ledger-2.0.md new file mode 100644 index 000000000..a4f2511f6 --- /dev/null +++ b/docs/fud-ledger-2.0.md @@ -0,0 +1,303 @@ +# Igneum 2.0 criticism ledger + +Written fresh on 8 October 2026 against the Igneum 2.0 brief (`docs/plans/igneum-2.0.md`). One entry per pin group: the challenge an outsider would raise, in the critic's words where a review supplied them; the status today; the answer; the evidence as a landed document; and the pin the entry answers. A pin closes only with a landed document and its pass condition met, so anything not yet delivered is Open with the pass condition named. The earlier ledger stays in the repository as history and is neither served nor linked. + +Entry format (read by `tools/ledger-page.mjs` and `tools/ledger/export-public.mjs`): `### . `, a quoted challenge line, `Status: <word> (<date>): ...` where the word is one of the six statuses' words, `Answer:`, `Evidence:`, `Pin:`. A status that changes gets a new Status paragraph below the old one; the last one is current. + +## The objective and the four properties + +### R0. "Another zkEVM" +"This is another zkEVM chain with a mining story attached." + +Status: Decided (8 October 2026): the positioning line is served on every page, and "zkEVM" appears only under the architecture explanation. + +Answer: The line is "A GPU-secured network for Ethereum-compatible applications and verifiable computation." Igneum is a sovereign GPU-mined network that runs Ethereum-compatible applications and proves their execution; the proof architecture is explained beneath that line, with its three boundaries (B1 to B3), and never leads. + +Evidence: `docs/plans/igneum-2.0.md` (the objective: the positioning line; the site reset: every page carries it). The facts page row 5 (`docs/evidence.md`). + +Pin: Architecture and product, sixth box (every served page carries the positioning line and the three boundaries); Site reset, fourth box. + +### R1. A specialised miner will remove most of the cost +"GPU-friendly hashes always fall to chips. A specialist strips everything a GPU carries that the hash does not need." + +Status: Open (8 October 2026): pass when the best supported cost and energy advantage of a re-optimised, programmable adversary sits inside the chosen competitiveness envelope, with its uncertainty published (D3). + +Answer: The target is contestable mining, not chip destruction: a manufacturer with a profitable product is not the failure; an exclusive, durable advantage large enough to displace the accessible GPU fleet is. Two measured results already bound the design. The connected-state reorganisation was killed as a class because rearranging the same operations moves neither side (D2). The mixed FP32 branch was killed because deterministic FP32 costs the cards 15 to 26 percent energy per hash against a 10 percent budget and widens the chip's edge to 3.0x to 3.2x (measured cards, modelled chip). Both stay as regression controls. + +Evidence: `docs/plans/igneum-2.0.md` (the objective, property 1; D1, the mixed FP32 kill; D2(a)); `docs/analysis/class-v6/connected-state.md`. + +Pin: The objective, property 1; D3 pass condition. + +### R2. Ordinary operators will be priced out +"Competitive hardware ends up in a few warehouses. A home miner with a used card has no chance." + +Status: Open (8 October 2026): pass when the reference GPU population is published with both tests per class (existing owner and new entrant) and the cost per accepted unit of work is served for each class. + +Answer: The cohort is the discrete-GPU population, used cards included. Each class gets two tests: the existing owner (power, wear, fees, alternative use) and the new entrant (purchase, operating cost, resale). The central measure is cost per accepted unit of work: annualised hardware, power, hosting, failures and fees over annual accepted work. Nothing here is measured yet as a population. + +Evidence: `docs/plans/igneum-2.0.md` (D1: the reference GPU population, the two tests, the central measure; the standing rule on the cohort). + +Pin: The objective, property 2; D1, sixth to eighth boxes. + +### R3. Mining and proving will not pay once issuance falls +"The subsidy carries everyone at launch. When issuance falls the miners and provers leave." + +Status: Open (8 October 2026): pass when the five-year coexistence model names credible conditions for sustained commodity participation and names where it fails; a result needing a small network, token appreciation or scheduled chip death has not passed. + +Answer: The model replaces the capex wall. It covers growing and shrinking networks, reduced issuance, cheap and dear electricity, replacement and resale on both sides, changing proving demand and miners who react. Its mandatory stress case assumes the opponent's development is already paid for. + +Evidence: `docs/plans/igneum-2.0.md` (D4). + +Pin: The objective, property 3; D4 pass condition. + +### R4. The defence is a rescue fork waiting to happen +"When a chip arrives you will change the algorithm in an emergency, like everyone else." + +Status: Decided (8 October 2026): no property assumes a future emergency algorithm change; rotation is optional to the security argument, and seed delay is evaluated only as seed-selection protection. + +Answer: The four properties must hold with no rescue upgrade assumed. The no-rescue network exercise (D5) is the test: epoch boundaries crossed, signing interrupted, the network partitioned, major operators removed, hostile proof submissions, independently written clients, with specified behaviour and no emergency algorithm change or privileged intervention. That exercise is Open. + +Evidence: `docs/plans/igneum-2.0.md` (the objective, property 4; the standing rules; D5). + +Pin: The objective, property 4; D5 pass condition. + +## The five deliverables + +### D1. The numbers cannot be reproduced +"Your measurements come from your own machines and your own scripts. Nobody can check them." + +Status: Open (8 October 2026): pass when an independent operator reproduces the baseline within declared tolerances from the served kit alone. + +Answer: One exact generator, verifier, dataset policy, compiler configuration and measurement harness, pinned by digest and served. Mining and proving are measured together on the final configuration, with wall power beside device telemetry, accepted and rejected work, compile time, memory use and sustained thermals. Nobody outside the project has reproduced anything yet. + +Evidence: `docs/plans/igneum-2.0.md` (D1); `docs/evidence.md` (rule 1: nothing reproduced externally or reviewed independently). + +Pin: D1 pass condition. + +### D2. Reorganising the work will not stop a specialist +"A specialist separates storage, arithmetic and memory scheduling. Rearranging the same work does not change what an operation costs." + +Status: Conceded (8 October 2026): the connected-state variant, D2(a), is a KILL as a class; the memory-sharing attack, D2(b), is Open. + +Answer: The critic is right for D2(a). With the same operations reorganised so that live state feeds every load address, the 64-register window is necessary (63 of 64 registers live at every address, measured), but a chip answers with a clock-gated register file that pays per write, so only the window's width reaches it: +1.2 pJ per lane-op at N5 (synthesised), moving the chip's edge 1.10x node for node against a 1.25x gate (modelled). The generator variant and the liveness tool stay behind a flag. D2(b) prices memory sharing, recomputation and data-local execution against class v6; pass when a candidate improves against re-optimised adversaries across the declared population within the preset cost and verification limits, otherwise class v6 stands and the experiment is published as a failure. + +Evidence: `docs/analysis/class-v6/connected-state.md` (the verdict); the facts page row 4 (`docs/evidence.md`). + +Pin: D2, first box (a) and second box (b). + +### D3. Chips do not expire on schedule +"Your economics assume every chip dies at the next family epoch. A programmable chip survives every family you publish." + +Status: Conceded (8 October 2026): "every chip dies within a family epoch" is out of the baseline economic model, and chip-arrival percentages are not published. + +Answer: The adversary is allowed to survive: whole-system cost minimised across every published family, free to change lane count, register implementation, instruction storage, memory technology, scheduling and support hardware, placed rather than synthesised, with a three-year stress life. Next-generation opponents are in the matrix. Pass when its best supported cost and energy advantage sits inside the chosen competitiveness envelope with uncertainty published; 1.5x energy is a research goal, not the pass criterion. That is Open. + +Evidence: `docs/plans/igneum-2.0.md` (the standing rules; D3). + +Pin: D3, first to fourth boxes and the pass condition. + +### D4. The capex wall is a fiction +"Your wall assumes the attacker pays for development. Somebody already has." + +Status: Open (8 October 2026): pass when the five-year coexistence model, whose mandatory stress case has development already paid for, names credible conditions for commodity participation and where they fail. + +Answer: The capex wall is replaced. Tariff advantage is shown apart from hardware advantage, and the economics page resolves the tip-share discrepancy with an explicit user-funded proving payment and congestion pricing, burn treated separately, the hard cap and no development tax kept. A profit-maximising operator simulation (mine, prove internally, prove externally, switch off) must show pricing and capacity rules restoring service without an administrator. + +Evidence: `docs/plans/igneum-2.0.md` (D4). + +Pin: D4, first, fifth to seventh boxes and the pass condition. + +### D5. Proofs are not a protocol guarantee yet +"Proof verification sits off the consensus path. A modified producer can include a matching statement without the valid proof and collect a payout it did not earn." + +Status: Conceded (8 October 2026): consensus does not enforce proofs today; the switch is in the node and reads never on the devnet. Pass when proof verification is enforced in consensus, live on the exercise network. + +Answer: Every producer verifies proofs off the consensus path today, so the network demonstrates proving activity rather than enforcing a permissionless proving economy. The rule and its activation switch exist in the node fork and are off on the devnet. Enforcement in consensus is the prerequisite of the no-rescue exercise, and node 2.0.0 follows it. + +Evidence: the facts page row 2 (`docs/evidence.md`); `docs/plans/igneum-2.0.md` (D5, first box; Versioning). + +Pin: D5, first box (the prerequisite). + +## Pools, software and participation + +### P1. A pool controls its miners' votes +"Whoever runs the pool votes with everyone's work. Finality by pool operator." + +Status: Open (8 October 2026): pass when the member's retained voting key is committed into its work at protocol level, payment aggregation is separate and verifiable, and pool identity substitution is resisted. + +Answer: Vote keys stay with the miner at protocol level; the pool aggregates payment, not votes. Not built yet. + +Evidence: `docs/plans/igneum-2.0.md` (Pools, software and participation). + +Pin: Pools, first box. + +### P2. Pools take custody and home miners lose to latency +"Pools hold the coins, minimum payouts strand small miners, and a home connection loses accepted work to a datacentre." + +Status: Open (8 October 2026): pass on non-custodial payouts with practical minimums, local work verification and low-bandwidth participation, and on a published measurement of the accepted-work penalty for home internet against datacentre connections. + +Answer: P2Pool is the precedent, not the code. Neither the payout design nor the latency measurement exists yet. + +Evidence: `docs/plans/igneum-2.0.md` (Pools, second and third boxes). + +Pin: Pools, second and third boxes. + +### P3. Firo's miner is the bar +"Firo's reference miner supports NVIDIA and AMD, charges no developer fee, and reports performance within about 1 percent of closed miners. Ember has to meet that." + +Status: Open (8 October 2026): pass when Ember reaches good operating points without third-party software and its optimisation work, compiler settings and safe tuning logic are published beside a comparison. + +Answer: Agreed that this is the bar. The within-1-percent figure is Firo's own report (claimed, not measured here). Ember is measured against it, not against whitepapers. + +Evidence: `docs/plans/igneum-2.0.md` (Pools, fourth box; Leadership tests, first box). + +Pin: Pools, fourth box; Leadership tests, first box (Firo). + +## Architecture and proving + +### A1. Why not an Ethereum L2 +"If you run EVM contracts and ZK proofs, settle on Ethereum like everyone else." + +Status: Decided (8 October 2026): three separate decisions: EVM-compatible execution for developers (revm), SP1 as the one well-tested proving backend behind a versioned interface, and sovereign GPU-mined consensus. Not an Ethereum L2. + +Answer: An L2 would suit a project whose objective is Ethereum settlement. Igneum's objective is an independent network secured by accessible hardware. Sovereignty has a cost: the network must establish its own consensus security, data availability and credible cross-chain verification, and execution proofs do not remove those duties. + +Evidence: `docs/plans/igneum-2.0.md` (Architecture and product, first box). + +Pin: Architecture and product, first box. + +### A2. Proof-system flexibility becomes arbitrary acceptance +"A replaceable proof system means the chain accepts whatever prover is fashionable." + +Status: Decided (8 October 2026): program identities, verifier versions and security parameters are pinned in the protocol; one backend first, a second only where justified, never interchangeable immature backends. + +Answer: The interface stays replaceable; what the chain accepts does not. Pinning in the protocol is designed and not yet shown on the devnet. + +Evidence: `docs/plans/igneum-2.0.md` (Architecture and product, second box). + +Pin: Architecture and product, second box. + +### A3. Rotation is not the defence +"Your resistance is the rotation: when a chip shows up you will identify it and fork it out." + +Status: Decided (8 October 2026): no chip detection in consensus, no hardware whitelists, attestation, per-address quotas or self-reported GPU bonuses; rotation is optional to the security argument. + +Answer: Igneum's mining design accepts that specialised hardware may be built; its security does not rely on identifying that hardware or retiring it through emergency changes. Class v6 adopts the 64-register window and retains it across every rotation. The window costs a GPU under 1 percent of rate at stock (measured on rented RTX 5090 and RTX 4090 cards, 8 October 2026). The long-program and select-tree proposals stay out as regression controls. + +Evidence: the facts page row 3 (`docs/evidence.md`); `docs/analysis/class-v6/connected-state.md`; `docs/plans/igneum-2.0.md` (the standing rules). + +Pin: Standing rules (no detection, rotation optional); D3 (the adversary that survives rotation). + +### A4. A concentrated prover can stall the chain +"Separate roles on paper. In practice one big prover withholds proofs and useful operation stops." + +Status: Open (8 October 2026): pass when a withholding concentrated prover is exercised on the no-rescue network with replacement operators, usable inputs, reassignment and explicit behaviour during proof delays, and the network behaves as specified with no privileged intervention. + +Answer: Winning the mining lottery and producing proofs stay separate, and they must remain separable during a failure, not only on paper. + +Evidence: `docs/plans/igneum-2.0.md` (D5, fourth box). + +Pin: D5, fourth box. + +### A5. Your miner promise covers hardware your prover does not +"The miner runs on AMD and Apple, but the proving income needs NVIDIA." + +Status: Conceded (8 October 2026): proving runs on NVIDIA; AMD and Apple mine. The product language states it plainly. + +Answer: The proving stack is judged on the full pipeline: inputs, proving, aggregation, verification, payment, memory footprint and mining income forgone. A fast shard result is not enough when aggregation or memory pressure makes ordinary operators uncompetitive. + +Evidence: `docs/plans/igneum-2.0.md` (Architecture and product, fourth box). + +Pin: Architecture and product, fourth box. + +### A6. "Everything runs unchanged" is a claim, not a test +"EVM-compatible until the block context, the randomness or the fees differ." + +Status: Open (8 October 2026): pass when compatibility ships as a product deliverable: representative contracts, wallet fee estimation, indexing, failed transactions, receipts and application assumptions tested, with the documented set of differences (block context, randomness, two-dimensional fees). + +Answer: The differences are known and are listed; the test suite that makes compatibility a deliverable does not exist yet. + +Evidence: `docs/plans/igneum-2.0.md` (Architecture and product, third box). + +Pin: Architecture and product, third box. + +### A7. The proving market is revenue you do not have +"Internal payouts on a valueless devnet show a mechanism, not demand." + +Status: Conceded (8 October 2026): the external proving market is not built and stays out of revenue assumptions until it is. + +Answer: The ladder: prove Igneum's own execution; then one external customer's exact workload with repeat paid jobs; then further workloads only where the fleet has a demonstrated edge. Pilots and announcements do not count; customers repeatedly paying for proofs at prices that carry reliable service and an operator margin do. + +Evidence: `docs/plans/igneum-2.0.md` (Architecture and product, fifth box; Leadership tests, third box). + +Pin: Architecture and product, fifth box; Leadership tests, third box. + +## The three boundaries + +### B1. Proven execution means the block is final +"The block is proven, so it is final." + +Status: Decided (8 October 2026): the boundary is stated wherever the proof architecture is explained. + +Answer: Proven execution is not finality. A proof shows a block's execution was computed correctly; finality is a property of the chain's own consensus and checkpoints. + +Evidence: `docs/plans/igneum-2.0.md` (the objective: the three boundaries). + +Pin: The objective, the three boundaries; Architecture and product, sixth box. + +### B2. EVM-compatible means Ethereum's security +"It runs Ethereum contracts, so it inherits Ethereum's security." + +Status: Decided (8 October 2026): the boundary is stated wherever the proof architecture is explained. + +Answer: EVM compatibility is not Ethereum security. Igneum is a sovereign network: its security is its own GPU-mined consensus, not Ethereum's validators. + +Evidence: `docs/plans/igneum-2.0.md` (the objective: the three boundaries). + +Pin: The objective, the three boundaries; Architecture and product, sixth box. + +### B3. ZK means private +"Zero knowledge, so my transactions are private." + +Status: Decided (8 October 2026): the boundary is stated wherever the proof architecture is explained. + +Answer: ZK is not privacy. The proofs here verify execution; transaction data is public, and privacy would need additional application or protocol design. + +Evidence: `docs/plans/igneum-2.0.md` (the objective: the three boundaries). + +Pin: The objective, the three boundaries; Architecture and product, sixth box. + +## Comparisons and leadership + +### C1. Ravencoin already does this +"KAWPOW already keeps consumer GPUs competitive, allows for future chips and does not plan forks as the normal defence." + +Status: Open (8 October 2026): pass when benchmarks against Ravencoin's KAWPOW, an operating system with the same stated objective, are published and show a stronger result or a more valuable overall offering. + +Answer: Restating the goal is not enough. Igneum is measured against the operating system, not its whitepaper. + +Evidence: `docs/plans/igneum-2.0.md` (Leadership tests, first box). + +Pin: Leadership tests, first box (Ravencoin). + +### C2. Ergo is an operating benchmark +"Ergo already runs a GPU memory-hard design with live pooling, emission and difficulty changes." + +Status: Open (8 October 2026): pass when the comparison with Ergo, on its live behaviour rather than its papers, is published. + +Answer: Ergo is a reference point, not a whitepaper competitor; the comparison is owed. + +Evidence: `docs/plans/igneum-2.0.md` (Leadership tests, first box). + +Pin: Leadership tests, first box (Ergo). + +### C3. Number one is unsupported +"You claim to be the best GPU network before anyone outside has checked anything." + +Status: Conceded (8 October 2026): no "number one" claim before comparative results and adoption exist. + +Answer: The ceiling of the served ranking language is serious contention for the top of the GPU-mining space on engineering and operator proposition. The tests that would earn more are miners staying through hard conditions, customers repeatedly paying for proofs, and the network running without the founding team (D5); none is met yet. + +Evidence: `docs/plans/igneum-2.0.md` (Leadership tests, second to fifth boxes). + +Pin: Leadership tests, fifth box (served ranking language); second to fourth boxes. diff --git a/docs/ledger-public-pre-2.0.md b/docs/ledger-public-pre-2.0.md new file mode 100644 index 000000000..31eccf5e5 --- /dev/null +++ b/docs/ledger-public-pre-2.0.md @@ -0,0 +1,202 @@ +# Igneum criticism ledger, public shape + +Generated by `tools/ledger/export-public.mjs` from `docs/fud-ledger.md`; a gate check fails when the two drift. One row per item: the claim or criticism, its status, what was done, and the evidence. Internal identifiers, times of day and team-member names are left out on purpose; the full ledger is published with the repository. + +194 items. By status: Conceded, stated 52; Fixed 31; Decided 22; Fixed on a branch, pending merge 14; Answered by design 9; Answered with evidence 6; Fixed, stated 4; Closed by rule 3; Open 3; Spec fixed 2; Fixed, stated; restated 2; Answered by design, with a correction to our own text 1; Answered with evidence, stated 1; Answered by design for finality, Conceded for the lottery 1; Conceded, implemented, stated 1; Rule implemented and measured; launch month simulated 1; Answered by design, with the concession stated 1; Conceded, stated in the litepaper and the design doc 1; Answered with evidence at 1 block/s 1; Conceded, stated in the simulation report 1; Answered by design, with the dependency conceded. Update 7… 1; Conceded, stated in the litepaper, with the dial explained 1; Closed by spec 1; Conceded by decision, stated in the design doc 1; Answered by design, with the founder's edge conceded 1; Answered by design, with a metrics caveat 1; Closed by removal, 3 October 2026 1; Conceded, stated in the litepaper 1; Conceded, stated in the design doc 1; Measured on the live node line, and the overlay does NOT… 1; Conceded, stated in the simulation 1; Conceded in part, labelled, stated 1; Fixed in the node 1; Answered with evidence for the largest body the rules allow 1; Fixed in the proving code 1; Fixed in the spec 1; Rule fixed 1; Rule written 1; Fixed, logged 1; Answered with evidence for the test half 1; Fixed in the node and shipped, rule not yet activated on… 1; Simulation half run 1; Answered with evidence for all four 1; Written 1; Designed 1; Fixed and confirmed 1; Rolled out 1; Conceded by decision 1; Conceded, scheduled, stated 1; Conceded, contained by rule, stated 1; Fixed on a branch and verified locally 1; Answered with evidence and stated 1; Answered with evidence for PC 2 1; Answered by design and with evidence 1; Fixed in part, finding bounded, stated 1; Open, priced 1; Fixed as a genesis lever, measurement owed 1. + +| Id | Claim or criticism | Status | What was done | Evidence | +|---|---|---|---|---| +| M1 | The program space is tiny | Decided | No standing bounty. | [docs/bench-log.md](../docs/bench-log.md) | +| M2 | Your own prototype is not memory-hard | Conceded, stated | `Site/litepaper.html`, Monero's idea section, the "Measured so far" paragraph, "computing items on the fly runs 4.8x slower than loading them"; What Igneum does not claim, "A memory-hard prototype on every vendor". | [proto-metal/TESTS.md](../proto-metal/TESTS.md) | +| M3 | Kaspa said ASIC resistant too | Answered by design, with a correction to our own text | First the correction: Kaspa did not promise ASIC resistance. kHeavyHash was designed to be friendly to specialised and optical hardware, and the Kaspa community expected chips (approximate, from memory; cite the Kaspa… | design doc, "ASIC resistance" section. | +| M4 | ProgPoW already did this and you do not mention it | Conceded, stated | `Site/litepaper.html`, precedents table row 1, "ProgPoW, as KAWPOW on Ravencoin since 2020". | [vendor/](../vendor/) | +| M5 | Your load count varies 6x between programs | Fixed | Generator version 2 draws exactly 16 load slots per program (spec 01 section 1.4.2, `igneum-pow/src/generator.rs`), and the fresh-source rule of 1.4.3 with the acceptance rule of 1.4.6 fixes the distinct count too,… | [proto-metal/TESTS.md](../proto-metal/TESTS.md) | +| M6 | Weak programs | Fixed | The acceptance rule of spec 01 section 1.4.6 (`igneum-pow/src/accept.rs`, mirrored in `proto-metal/main.swift`) rejects a candidate with a stale load source, a register without an injecting write, a nonce-independent… | [proto-metal/TESTS.md](../proto-metal/TESTS.md) | +| M7 | No cryptographic analysis at all | Conceded, stated | `Site/litepaper.html`, Mining section, "The hash is a lottery, not a general-purpose cryptographic hash" and "Open: no analysis of the lottery properties exists yet". | [proto-metal/TESTS.md](../proto-metal/TESTS.md) | +| M8 | Only two vendors, two programs, one day | Decided | A discrete AMD card (9070 XT) and a 12 GB NVIDIA card (4070) are on order for PC 2; the measurement runs on arrival. | [docs/bench-log.md](../docs/bench-log.md) | +| M9 | The 10 ms CPU verification gate is unmeasured | Conceded, stated | `Site/litepaper.html`, Mining section, "Measured: 0.41 to 0.58 ms per warp on one Apple M5 Max core with the 256 MB cache"; vs RandomX "Light verification" row. | [docs/bench-log.md](../docs/bench-log.md) | +| M10 | "Bound by memory bandwidth" is wrong | Answered with evidence, stated | `Site/litepaper.html`, Mining section, "bound by random memory access. | [docs/bench-log.md](../docs/bench-log.md) | +| M11 | Hourly JIT on real rigs | Decided | The mixed-generation rig is borrowed from a farm operator later, at the HiveOS package's first test; the 9070 XT on order gives the ROCm half on PC 2. | [docs/bench-log.md](../docs/bench-log.md) | +| M12 | Rentable hashrate is not just NiceHash | Answered by design for finality, Conceded for the lottery | Both halves true. | [sim/results.md](../sim/results.md) | +| M13 | Macs mine too is marketing | Conceded, stated | `Site/litepaper.html`, For miners, Hardware, "Macs mine too, at about a fifth of a flagship card: Measured, 26.7 against 123 million hashes a second" (confirmed by grep tonight; the projected-earnings half is not… | [docs/bench-log.md](../docs/bench-log.md) | +| M32 | "Automatic anti-ASIC escalators" overstates what the era draw and the instruction reserve do | Conceded, stated | The era draw and the instruction reserve are automatic schedule changes against fixed datapaths and against human forks; against the stored-dataset chip every drawn parameter is firmware, and the defence against that… | [docs/analysis/horizon/algorithm.md](../docs/analysis/horizon/algorithm.md) | +| M33 | The FPGA ceiling rests on a tFAW the JEDEC HBM2 table does not give | Conceded, stated | The public FPGA line carries only the measured row, 2.4 G reads/s per card and 0.30x to 0.39x of the RTX 5090 per watt (Shuhai, FCCM 2020 Fig 7; the tFAW arithmetic from ICCAD 2021 Table I), and the 11.4 G bank-bound… | [docs/analysis/horizon/algorithm.md](../docs/analysis/horizon/algorithm.md) | +| M34 | The shadow size N is a constant of the binary, so the one lever against the dataset-storing chip needs a fork to move | Conceded, implemented, stated | The public text carries the ladder (`site/litepaper.html`, Mining: the six-rung genesis ladder of the latency shadow with a measured admissibility flag per rung, moved by miner signalling, never by a fork; and the X9… | [docs/design/latency-ladder.md](../docs/design/latency-ladder.md) | +| F1 | Finality is attackable for the first month | Rule implemented and measured; launch month simulated | The harness text only: `tools/finality-attacks/run.mjs` names the 2/3-of-total floor in the s6 comments and criterion and in the s5 result line, where it still said 56.7%; the scenario logic is untouched. | [sim/](../sim/) | +| F2 | The two-hour presence window is an eclipse vector | Closed by rule | Correct that the presence window trades safety for liveness. | [sim/results.md](../sim/results.md) | +| F3 | Participation grinding through the bitmap | Decided | The per-block vote bound and the bitmap wire bound of spec 3.4.2 items 2 and 3 are adopted for gate 3; the spec moves them from Proposed to Decided at the next spec edit. | design doc Finality v2, Quorum item 2 and Checkpoints item 3. | +| F4 | It is proof of stake with extra steps | Answered by design, with the concession stated | The committee's weight is blocks mined in the last 30 days. | [sim/results.md](../sim/results.md) | +| F5 | The headline arithmetic is misread on purpose | Conceded, stated | `Site/litepaper.html`, Finality, "an attacker producing every block on the chain, with honest miners gone" and "An attacker matching the honest network needs twenty days for a third and never reaches two thirds"; the… | [sim/results.md](../sim/results.md) | +| F6 | Equivocation costs nothing that matters | Conceded, stated in the litepaper and the design doc | True. | design doc Finality v2, Checkpoints item 4 and Residual risks bullet 1. | +| F7 | A 2-minute checkpoint on a DAG with a 1-hour merge bound | Answered with evidence at 1 block/s | Fair. | design doc Finality v2, Checkpoints item 1 and "Three experiments before gate 3". | +| F8 | The simulation has no network in it | Conceded, stated in the simulation report | Correct. | [sim/results.md](../sim/results.md) | +| F9 | Half the hashrate leaves and finality stalls for ten days | Answered by design | That table is the all-keys denominator, which the simulation recommended for safety. | [sim/results.md](../sim/results.md) | +| F10 | Pools hold the votes | Conceded, stated | `Site/litepaper.html`, Finality, "Pools carry their hashers' votes, so vote concentration equals pool concentration, and it is public"; Governance, "governed by the hashrate that powers it". | design doc Finality v2, Residual risks bullet 3. | +| F11 | VDFs are exotic | Answered by design, with the dependency conceded. Update 7… | The era VDF is in the node (spec 4.4 Implemented, behind `era_vdf_activation_daa`, never until the founder sets it per network), on a fixed-width integer with no C library, with the hash-chain fallback behind the… | design doc Finality v2, Lottery seeds items 1 and 2, Residual risks bullet 5, "Three experiments before gate 3". | +| F12 | Nothing outside the chain, except | Answered by design | Those are code dependencies, chosen because each is open source and replaceable, and none is another chain's consensus. | CLAUDE.md design paragraph; design doc "Decided" paragraph. | +| F13 | Why prove every block if every node executes anyway | Answered by design | Full nodes execute natively so users see state in about a second. | design doc, "Proving speed on consumer GPUs" risk item and "Who needs" paragraph. | +| F26 | "No stake" needs its one sentence: what is at stake, and what strips it | Conceded, stated | `Site/litepaper.html`, the finality section's "What is not here" paragraph and the "Igneum at a glance" Finality row carry the sentence verbatim: "No coin is staked. | [docs/analysis/horizon/frontier.md](../docs/analysis/horizon/frontier.md) | +| P1 | The 20-second shard is a number you made up | Conceded, stated | `Site/litepaper.html`, Proving, The proving budget, "Target: shard size will be set so a 12 GB card proves one shard in about 20 seconds. | [site/journey.json](../site/journey.json) | +| P2 | Real-time proving needs a hundred GPUs per block | Conceded, stated in the litepaper, with the dial explained | True, and the litepaper says a full block needs a cluster of 100 to 200 consumer GPUs, approximate. | design doc "Unit economics of a proof"; litepaper "What Igneum does not claim" item 1. | +| P3 | A phone verifies in milliseconds is a SNARK-wrapper claim | Answered by design | The design rule covers the claim (design 5.6 `wrap`, R4: the aggregated block proof wrapped once into a small curve-based proof by the aggregator) and the public text says what is and is not measured… | not yet. | +| P4 | Trustless light clients need a consensus proof you do not have | Conceded, stated | `Site/litepaper.html`, precedents table row 6, "The consensus proof that makes the checkpoint self-verifying is phase two"; Building item 2, "Light clients". | design doc, hostile review table rows "Slashing an external prover" and "One-proof light clients". | +| P5 | EVM "unchanged" on a DAG is false | Closed by spec | Correct. | design doc, hostile review table row "EVM semantics on a DAG". | +| P6 | The proving market is tiny | Conceded, stated | `Site/litepaper.html`, The problem, "a supplier whose marginal cost is close to power"; "cheapest supplier" and "lowest cost" absent from the page (grep, tonight). | design doc "Market size, honestly" and "Existing prover networks" table (labelled from memory). | +| P7 | A soundness bug in SP1 is a consensus failure | Conceded, stated | `Site/litepaper.html`, Abstract, "Writing new code, including an emergency fix to the proof system, is the one thing that takes a person"; Proving, "no node accepts a block with a wrong state root". | design doc "Proof system churn" risk item. | +| P8 | Fastest prover wins all the shards | Closed by rule | Fair, and the lottery/proving separation does not by itself fix it. | design doc "Proving speed on consumer GPUs" risk item and Finality v2 "Fees". | +| P9 | Shard griefing | Decided | The parameter table's values are the phase 4 devnet's starting values (8 assignees, a 25-s exclusive window, a 120-s job claim timeout, no shard bond, the external job bond set on the devnet); the devnet measurement… | design doc, Security model table row 3. | +| P10 | External jobs are paid off-chain, so where is the burn | Conceded, stated | `Site/litepaper.html`, Economics, "Outside customers pay in their own currency on their own chain at launch; settlement in IGN with a 10% burn follows when the proof bridge lets Igneum see the payment"; the route table… | design doc "The first six months" risk item and hostile review table row "Slashing an external prover". | +| P24 | "20 percent of emission to provers" without the caveat that consensus does not verify the proof | Conceded, stated | `Site/litepaper.html`, Economics, the 20% proving-pool row carries the caveat: consensus does not yet verify the carried proof, it checks the record's statement against native execution and its signature, so today a… | [docs/analysis/horizon/consensus-security.md](../docs/analysis/horizon/consensus-security.md) | +| P25 | Unclaimed pool credit is stranded in the escrow | Conceded, stated | `Site/litepaper.html`, Economics, the 20% proving-pool row carries the note: unclaimed pool credit is today stranded in the escrow, no rule returns it; the fix rolls an unproven shard's credit into the next proven… | [docs/analysis/horizon/economy-and-utility.md](../docs/analysis/horizon/economy-and-utility.md) | +| E1 | Hard cap plus burn is a security budget cliff | Conceded by decision, stated in the design doc | True, and the design doc records the choice: "A 1% tail is the Monero model and the safer choice for security on its own." The argument for the cap is that Igneum miners keep earning from in-chain proving fees and… | design doc "Decision: hard cap". | +| E2 | Half the coins in two years is an insider schedule | Answered by design, with the founder's edge conceded | The schedule (1 billion a year halving every two years, 30-day ramp from 10% to 100%) is public, fixed at genesis and the same for every miner. | litepaper "Supply" and "Fair launch, announced". | +| E3 | The 20% developer share enables wash gas | Answered by design, with a metrics caveat | The base fee is burned in full, so every wash transaction loses its whole base fee. | design doc Finality v2 "Fees"; litepaper "What a builder gets for being early". | +| E4 | 5% of gas to the dev fund is a tax | Closed by removal, 3 October 2026 | There is no development fund. | spec section 5.5; design doc "No development fund, so nothing to fight over". | +| E5 | "Not one coin to a founder" is false | Conceded, stated | `Site/litepaper.html`, Economics, "No fund, no foundation, no fee to the team", "1 block in 100 pays the project"; `site/index.html`, Economics, "The one payment to the project is the Ember software's optional 1% dev… | design doc "No development fund, so nothing to fight over". | +| E6 | Two-year halvings bleed hashrate | Conceded, stated | `Site/litepaper.html`, Economics, Security after the subsidy, "The schedule is a bet, not a measurement: a halving halves emission income overnight if price and fees do nothing", with Kaspa's reduction marked… | none; decision in design doc "Supply". | +| E7 | No stablecoin liquidity without a trusted bridge | Decided | Correct. | design doc, hostile review table row "One-proof light clients and committee-free bridges". | +| E8 | Founders seeding the DEX is market making by insiders | Conceded, stated | True and stated in the litepaper. | litepaper "Liquidity from the people who are there". | +| E19 | "Proving: a second income" without the arithmetic of how small it is | Conceded, stated | `Site/litepaper.html`, "For miners", under the three-streams table: all of Ethereum L1's proving is about USD 36 a day at the September 2026 tracker cost (USD 0.005 a block x 7,200 blocks; the tracker figure is a… | [docs/analysis/horizon/frontier.md](../docs/analysis/horizon/frontier.md) | +| E20 | "Proofs at the cost of power" is the electricity, not the price | Conceded, stated | `Site/litepaper.html`, The problem ("a supplier whose electricity cost is close to power and whose price is the subsidy it forgoes, which falls as the network's hash grows"), Building on Igneum ("Proofs priced by the… | [docs/analysis/horizon/economy-and-utility.md](../docs/analysis/horizon/economy-and-utility.md) | +| E21 | The dev fee is 1 percent of the producer share, and the funding plan's ceiling took all rewards | Conceded, stated | `Site/litepaper.html`, the payment-routes row 6 and the Ember section read "default-on, switchable, 1 percent of the producer share"; `docs/plans/funding.md` section 4's ceiling is 1 percent of the producer share, USD… | [docs/analysis/horizon/economy-and-utility.md](../docs/analysis/horizon/economy-and-utility.md) | +| G1 | No cryptography team | Conceded, stated | `Site/litepaper.html`, Questions miners ask, "reviewers will be named and paid before gate 3"; What Igneum does not claim, "A cryptography team. | design doc "Team" paragraph. | +| G2 | An AI designed this | Conceded, stated | `Site/litepaper.html`, cover, "Method one founder with AI systems"; Who are you?, "One founder, pseudonymous, working with AI systems". | [.claude/agents/](../.claude/agents/) | +| G3 | Who are you | Decided | No team page for now; the litepaper says the team is pseudonymous and names no team page. | [site/journey.json](../site/journey.json) | +| G4 | No admin keys, except in everything that matters | Conceded, stated | The home page was redrawn as one statement, the live scene, three facts and the downloads, so the tile "admin keys in consensus" is no longer on `site/index.html`; the sentence stands on `site/litepaper.html`,… | litepaper "Governance". | +| G5 | No multi-client | Conceded, stated in the litepaper | True at launch. | litepaper "Governance", last bullet. | +| G6 | Stratum v2 does not make pools unable to censor | Conceded, stated | `Site/litepaper.html`, Governance, "Pools can be bypassed on transaction choice". | none in repository. | +| G7 | The one-click app is an update key over the network | Decided | Correct. | not yet. | +| G8 | Governance by hashrate is governance by two pools | Conceded, stated in the design doc | True in the same way it is true on Bitcoin, where miner signalling activated SegWit and Taproot. | design doc Finality v2, Residual risks bullet 3. | +| G15 | Three signalling thresholds, four numbers across the documents | Conceded, stated | One sentence in `site/litepaper.html`, Governance ("Miners set what genesis leaves open") and Mining ("Miners hold the switch"): miners signal three things at three thresholds, 60 percent of blue blocks over two weeks… | [docs/analysis/horizon/economy-and-utility.md](../docs/analysis/horizon/economy-and-utility.md) | +| C1 | vs Monero: GPUs were excluded on purpose | Answered by design | Monero chose the CPU for egalitarian reasons and accepted botnets as the price. | litepaper "For miners", hardware paragraph. | +| C2 | vs Monero: "no chip in seven years" is not proof | Conceded, stated | The home page no longer carries the RandomX paragraph; "since 2019 (approximate)" and "precedent, not proof" stand on `site/litepaper.html` (vs RandomX, Mining). | none. | +| C3 | vs Kaspa: you misrepresent them | Conceded, stated | `Site/litepaper.html`, The problem, "Chips arrived, as on Kaspa, whose hash was designed to welcome them"; Speed, "Kaspa has run in production since 2021 (approximate), forked from rusty-kaspa"; precedents row 5,… | none in repository; `vendor/rusty-kaspa` to be cloned and cited. | +| C4 | vs Kaspa: a finality overlay changes GHOSTDAG's guarantees | Measured on the live node line, and the overlay does NOT… | A NEW SERIOUS FINDING (5 October 2026 sweep; owner: cryptographer and consensus engineer, decision owner the founder). | [sim/results.md](../sim/results.md) | +| C5 | vs Ethereum: you compare inclusion to finality | Conceded, stated | `Site/litepaper.html`, Speed, "Inclusion is not confirmation on either chain". | litepaper "Speed". | +| C6 | vs Ethereum: every one of your components is a research project | Conceded, stated | `Site/litepaper.html`, Roadmap, "the combination is the risk the gates price" and "Dates slip. | litepaper "Roadmap". | +| C7 | vs Bitcoin: hashrate that follows price is the design, you penalise it | Conceded, stated in the simulation | Correct. | [sim/results.md](../sim/results.md) | +| C8 | vs Ergo, Ravencoin, Conflux: GPU mining has a home | Conceded, stated | `Site/litepaper.html`, The problem, "Ergo, Ravencoin and Conflux still mine on GPUs at a fraction of the 2022 fleet (approximate)"; precedents row 3 names Conflux. | none in repository; to be cited from their repositories. | +| C9 | vs Aleo: you will centralise the same way | Closed by rule | See P8. | design doc "Existing prover networks" table, Aleo row. | +| C10 | vs Boundless and Succinct: you cannot bid there without their tokens | Conceded, stated | `Site/litepaper.html`, Proving for everyone else, "Boundless provers post ZKC and Succinct provers stake PROVE (approximate, from their documentation)". | design doc "Existing prover networks" table, labelled approximate. | +| C11 | vs everyone: "firsts" that are not | Conceded, stated | `Site/litepaper.html`, precedents table, "We know of no chain that combines them"; Building, "that we know no other EVM chain offers". | this ledger. | +| C12 | vs Monero: you borrowed the hash idea and left out the point | Answered by design | Transactions on Igneum are public, as on Ethereum. | CLAUDE.md rules (privacy rejected). | +| L1 | It is a security under Howey | Open | Only the founder's decision with counsel settles it; counsel engaged since 6 October 2026 (decisions item 6). | design doc "Legal" paragraph. | +| L2 | Financial promotion rules | Open | Only the founder's decision with counsel settles it; the text half is stated (the schedule facts above). | none. | +| L3 | GoDaddy domains are a seizure risk | Decided | The nameserver move to deSEC in one sitting with every domain's Vercel verification checked afterwards; a non-US registrar in December 2026 when the transfer lock ends. | CLAUDE.md "Domains". | +| L4 | Paying testnet miners real money is a payment before launch | Open | Only the founder's decision with counsel settles it. | design doc "The first six months". | +| L5 | Trademark | Answered with evidence | The clearance search is recorded in the repository as the entry asked, `docs/legal/trademark-search-2026-10-03.md` (3 October 2026, one verdict per register: EUIPO RISK, IGNIUM EUTM 018212492 live in classes 36 and 42;… | none. | +| L6 | A permissionless job market paid in dollars is money transmission | Answered by design | At launch jobs are paid on the customer's chain, in the customer's asset, by the customer's contract, to the prover's address; Igneum operates no custody and takes no cut off-chain. | design doc "The first six months". | +| X1 | "Reproducible from the repository" and the repository is private | Conceded, stated | `Site/litepaper.html`, vs RandomX "Track record" row, "The specification, reference hash, test vectors and simulators are public now (git.igneum.network/igneum-network/spec). | [site/index.html](../site/index.html) | +| X2 | "Get the miner" with no miner | Conceded, stated | `Site/index.html`, hero button "See the miner"; the Mine section's download buttons carry the shipped devnet build's version and size (v0.3.9) beside "Public testnet: not yet open; the devnet build is here for people… | [site/index.html](../site/index.html) | +| X3 | "Proven by fire" when nothing has run | Conceded in part, labelled, stated | The proofs feed moved to the litepaper's proving section with the home-page redesign and reads "Live rows arrive with the public testnet. | [site/index.html](../site/index.html) | +| X4 | Thirteen months with one founder | Conceded, stated | The roadmap is aggressive and every phase is a gate that can repeat or stop the project, which the litepaper says. | litepaper "Roadmap"; design doc "Team". | +| X5 | 1,000 independent miners is a Sybil number | Decided | The independence definition as written, with the silent-fleet addition (a key with no fingerprint counts as its own class only when its address is in an autonomous system no other key uses); the observer columns on… | [site/journey.json](../site/journey.json) | +| X6 | The one-click app is a honeypot vector | Decided | Correct on all three. | not yet. | +| X7 | No community exists | Conceded, stated | This ledger's submission line names hello@igneum.network and the spec issues route; `site/litepaper.html` last paragraph and the footer on every page carry both. | [site/index.html](../site/index.html) | +| X8 | Exchange listings as a roadmap item | Conceded, stated | The home page's journey is no longer shown (the inlined feed remains in the page source); the sentence "No listing is arranged, promised or sought by the project" stands on `site/litepaper.html` Roadmap phase 6 and in… | [site/journey.json](../site/journey.json) | +| X9 | Launch hashrate will be trivial | Conceded, stated | `Site/litepaper.html`, Finality, "In the chain's first 30 days no checkpoint locks at all"; Fair launch, "The first 30 days of mainnet run on proof of work alone". | [sim/results.md](../sim/results.md) | +| X10 | Five milestones in one day | Conceded, stated | `Site/index.html`, journey section, "The log below is the engineering log's dated entries, newest first. | [site/journey.json](../site/journey.json) | +| M14 | A pulsed rental against the block-count DAA buys weight at a discount | Answered with evidence | , ledger close round 1: M14 and F14 the 50x pulse against a lagging retarget inside the finality simulator, both W2 forms"). | [sim/difficulty/devnet-2026-10-03.csv](../sim/difficulty/devnet-2026-10-03.csv) | +| M15 | A header with any past timestamp or any claimed DAA score makes the node build a 256 MiB cache | Fixed | Correct. | [docs/fork-divergence.md](../docs/fork-divergence.md) | +| M16 | The 256 MiB cache fits on a die, so the recompute attacker is compute bound | Answered with evidence | On the 5090 the recompute attacker with the cache inside the 96 MiB L2 (the SRAM emulation, 64 and 32 MiB masks, bit-exact against the stored construction) runs at 33.9 Mhash/s against 132.2 honest for the same… | [proto-metal/MEMHARD.md](../proto-metal/MEMHARD.md) | +| M17 | Every ahead-of-time miner stops at the epoch boundary; whoever compiles in process mines alone | Fixed | And measured on the live devnet at the DAA 3,600 boundary (`docs/bench-log.md`, "first hourly program swap"): prepare sent 449 DAA before the boundary; Metal compiled in 82 ms, CUDA ran nvcc in the background in 1,285… | [proto-cuda/windows-miner/start-mining.ps1](../proto-cuda/windows-miner/start-mining.ps1) | +| M18 | The per-hash random data path is a one-bit select | Conceded, stated | `Site/litepaper.html`, Mining table "Every hash" row, "The one-bit select inside the maths costs a chip nothing and is not a defence"; vs RandomX "Random program" row, "the 128 dataset addresses change with the nonce". | [site/litepaper.html](../site/litepaper.html) | +| M19 | The census that justifies the generator rule has blank cells, and the spec still carries the free load count | Fixed | Correct. | [docs/analysis/weak-program-census-2026-10-03.md](../docs/analysis/weak-program-census-2026-10-03.md) | +| M20 | Pruning proofs are checked with the kHeavyHash stub | Fixed in the node | Correct. | [docs/fork-divergence.md](../docs/fork-divergence.md) | +| M21 | GHOSTDAG k is Kaspa's table value for Kaspa-sized bodies | Answered with evidence for the largest body the rules allow | , ledger close round 1: M21 block propagation with bodies at the mass limit, k re-derived"); the red rate under such bodies is not measured. | [docs/design/execution-layer.md](../docs/design/execution-layer.md) | +| F14 | Weight in blocks over a window in blocks under a lagging retarget | Answered with evidence | , ledger close round 1: M14 and F14 the 50x pulse against a lagging retarget inside the finality simulator, both W2 forms"). | [sim/results_v2.md](../sim/results_v2.md) | +| F15 | Merge depth is not the reorg bound; the finality depth is | Spec fixed | Spec 2.1 names the finality depth as the reorg bound and merge depth as a merge limit only, spec 3.8 and 3.9 tell exchanges to wait 12 hours of past-median time when `finality_active` is false, and the simnet reorg… | the files above. | +| F16 | A lock can become uncertified after a heal | Decided | Option B, a verified certificate is never withdrawn (spec 3.11.4); the 3.5 paragraph is replaced by 3.11.4's text after `c4-fix` merges, `finality_conflict` and the `finality_active` clear go into the node, the forced… | spec 3.5, 3.9. | +| F17 | Keys are free and the official client mints eight per card | Decided | The client defaults to one vote key per machine, identities share it (spec 3.4.2 item 4); the bitmap bound as item 3. | [proto-cuda/windows-miner/start-mining.ps1](../proto-cuda/windows-miner/start-mining.ps1) | +| F18 | "A silent minority cannot freeze finality" is false under the floor | Fixed | Correct. | [sim/results_v2.md](../sim/results_v2.md) | +| P11 | The native-execution veto makes block validity depend on the node's current selected chain | Fixed | Spec 7.2 item 5 and `docs/design/execution-layer.md` 5.5 and D12 are relative to the carrying block's own selected-parent chain; the two-node reorg test is a row in the design document's 8.5. | [docs/design/execution-layer.md](../docs/design/execution-layer.md) | +| P12 | An aggregator can name itself as every prover | Fixed in the proving code | Every shard proof's public values carry the prover's payout address (`ShardOutput.prover`), the aggregated block proof commits keccak over the provers in shard order and the shard program's verifying-key hash… | [docs/design/execution-layer.md](../docs/design/execution-layer.md) | +| P13 | The litepaper still claims shards with a bond | Fixed | `Site/litepaper.html`, Proving, "How a block gets proven". | [site/litepaper.html](../site/litepaper.html) | +| P14 | Two definitions of the proving base fee, and a quote that cannot know the ratio | Fixed in the spec | One definition. | [docs/design/execution-layer.md](../docs/design/execution-layer.md) | +| P15 | RPC blocks are segments, so `gasUsed` can exceed `gasLimit` | Fixed on a branch, pending merge | `Igneum/exec/src/rpc.rs` reports `gasLimit` as k x `BLOCK_EXECUTION_GAS_LIMIT` for a k-block segment (k = the record's mergeset length, at least 1), beside the segment's `gasUsed`, so `gasUsed <= gasLimit` holds for an… | [docs/design/execution-layer.md](../docs/design/execution-layer.md) | +| E9 | The specification's year is 365 days; the code's is 365.25 | Fixed | Spec 2.5 follows the code (365.25-day year, 63,115,200-s halving, 31.688 IGN per DAA second, 8 decimals noted under O-2.6). | [consensus/core/src/igneum.rs](../consensus/core/src/igneum.rs) | +| E10 | Reds are paid in the code and "more blocks never means more coins" is false | Fixed | Spec 2.5 says reds inside the DAA window are paid to the merging miner (80%) and the pool (20%), that `E` is paid per block so coins are blocks times `E` under the controller's rate, and that the cap is unaffected;… | [docs/review/round-3-2026-10-03.md](../docs/review/round-3-2026-10-03.md) | +| E11 | The homepage burns job fees at launch | Fixed | `Site/index.html`, "Proofs sold to other chains" caption and the tile now read "phase two"; the quoted paragraph had already left the page when the homepage was trimmed (commit a commit). | [site/index.html](../site/index.html) | +| C13 | Monero's seven years do not price a 256 MiB SRAM die | Conceded, stated | `Site/litepaper.html`, What Igneum does not claim, "they say nothing about the price of a chip with the 256 MB cache on its die, and that price is a cost model, not a measurement". | none beyond M16. | +| L7 | "Where the price comes from" | Fixed | Heading "Where fees go" and the sentence deleted, `site/litepaper.html` Economics. | [site/litepaper.html](../site/litepaper.html) | +| L8 | Third-party names as implied outcomes | Conceded, stated | `Site/litepaper.html`, Questions builders ask, "whether it is issued is Circle's decision"; Canto and Blast absent from the page (grep, tonight). | [site/litepaper.html](../site/litepaper.html) | +| G9 | The release-key the team is one person, and a lost key cannot be revoked | Rule fixed | Spec 8.2 item 5, rotation signed by the current key and revocation signed by the previous key (a pre-signed certificate for K0), both published in a block; item 2 moves the policy to before the client ships and adds… | spec 8.2. | +| G10 | The signalling default on first run | Rule written | `Docs/spec/08-client-security.md` 8.3 item 2 now ends: on first run there is no last choice, the client signals nothing until the user chooses, and the interface shows that nothing is being signalled. | [docs/spec/08-client-security.md](../docs/spec/08-client-security.md) | +| X12 | Tonight's numbers are quoted before they are logged, and the worker efficiency gap is unexplained | Fixed, logged | Bench-log "5 October 2026 (night), ledger close round 1: X12 the 3 October devnet run from its record"; the launcher half (the eight processes' summed status) stays open until the PC's log is read. | [sim/difficulty/devnet-2026-10-03.csv](../sim/difficulty/devnet-2026-10-03.csv) | +| M22 | The ASIC challenge has no scoring rules, and 2x is not the economic line | Decided | No bounty, so no bounty terms; M22's metrics (hashes per second and per joule per program over at least 100 epochs as a distribution, capital cost per unit of hash rate at a stated volume, the longevity term, the… | M1, O-1.17, spec 1.13 and 1.16, M16's arithmetic. | +| F19 | Old vote keys can be bought; fresh hashrate cannot buy weight | Answered with evidence | A bought key is worth the blocks it holds and nothing more. | [sim/results_v2.md](../sim/results_v2.md) | +| F20 | During a finality pause the program must keep advancing, and nothing says which guarantees survive | Answered with evidence for the test half | , ledger close round 1: F20 finality pause under a 45% silent set through four epoch boundaries"); the gate-3 wording of the four guarantees (O-3.16, O-4.3) stays a decision for the founder. | spec 4.3 (O-4.3), 3.3.1, 3.5, 3.7 item 2, 3.9. | +| F22 | Certificates carry 8 to 10 of 12 votes on a healthy network, so locks sit a hair above the floor | Fixed in the node and shipped, rule not yet activated on… | True as measured, and the cause is not a cut-off at all: the node builds the certificate the instant the votes it holds meet Q3, and carries that one. | [infra/cloud-devnet/results/2026-10-04/partition-sin-20261004-140305/partition.md](../infra/cloud-devnet/results/2026-10-04/partition-sin-20261004-140305/partition.md) | +| P16 | The proving gate can be passed by shrinking the shard | Decided | A 12 GB NVIDIA card (4070) is on order for PC 2; O-7.1 runs end to end on it when it arrives, inside the phase 2 gate. | [docs/bench-log.md](../docs/bench-log.md) | +| P17 | Interfaces must show four states, and the design shows three | Fixed on a branch, pending merge | a fork a commit (a commit rebased onto the 0.3.11 fork tip a commit in round 3), suite igneum-exec 16 of 16 on the Mac (labelled a Mac run), the O-7.2 conformance run PASSED on a fast-time 3-node network (bench-log… | execution-layer 2.3, 2.4, 8.2; phone-app 3 and 9; spec 3.9, 10.1. | +| E12 | Selfish operators under a price shock | Simulation half run | No backlog in any scenario, every block proven within 60 s in every hour, hash troughs at 82% of its pre-event level under b and 75% under d (80% at day 30), 10% of cards off under b… | spec 5.1, 5.3, 7.2; execution-layer 4.3, 9.1 R8. | +| E13 | One diagram per payment route, or operator income and protocol income blur | Conceded, stated | `Site/litepaper.html`, Economics, "Every payment route", six rows (emission; base fee; priority fee; external job at launch; external job after the proof bridge; the official client's dev fee as operator income),… | [docs/commercial/prover-customer-brief.md](../docs/commercial/prover-customer-brief.md) | +| E14 | No funding table | Decided | The funding table stays internal until counsel has read it; one public sentence in the litepaper names the unfunded lines (the second client, the external reviewers, the bounty before escrow). | E4, E5, G1, G5; fud-fixes rows 47, 50, 71. | +| E15 | The security budget through successive halvings with low fees and no external demand | Decided | The 4,000,000,000 IGN hard cap stays absolute and there is no tail emission. | spec 2.5, 5.1 to 5.4; E1, E6. | +| G11 | Publish the inspectable components now, labelled experimental | Decided | The specification subset is public as `igneum-network/spec` (`docs/plans/public-repo.md`), labelled; the node fork, the proving code and the harnesses stay private until the benchmark. | [docs/fud-fixes.md](../docs/fud-fixes.md) | +| X13 | One paying customer for a stated reason | Decided | The paid pilot stays in phase 5, the phase 4 gate stays the signature, nothing moves earlier before counsel answers L4. | [site/journey.json](../site/journey.json) | +| X14 | Concentration is unmeasured in four places | Answered with evidence for all four | , ledger close round 2: X14 signing concentration from block payloads"); the independence definition stays the founder's (X5). | X5, F10, P12, spec 9.4.2. | +| X15 | Remove the founders from a test network and show what continues | Answered by design | The design rules the sentence rests on are in force (every node ships a VDF evaluator, spec 4.5; the seed list ships in the client, spec 10.6; no project-run service sits in consensus, no stake, no fee to any team,… | [site/litepaper.html](../site/litepaper.html) | +| X16 | An evidence page with four labels | Written | `Docs/evidence.md`, one row per public claim with five labels (tonight, counting the label column of the claims table: designed 9, implemented 8, tested by the team 26, reproduced externally 3, reviewed independently 2). | [docs/bench-log.md](../docs/bench-log.md) | +| X17 | The miner app must show net earnings and keep jobs away from keys | Designed | Spec 8.8 and phone-app 4.1; measurement O-8.2 and the escape test O-8.3 scheduled for the phase 4 devnet. | [site/litepaper.html](../site/litepaper.html) | +| P18 | The mempool queues transactions no block can carry | Fixed | Correct, and low: the queue slot was reserved against the sender's funds, so it was self-limited. | [docs/bench-log.md](../docs/bench-log.md) | +| P19 | An over-budget proving transaction runs for free, every time, and blocks its sender | Fixed | Correct, medium. | [docs/bench-log.md](../docs/bench-log.md) | +| P20 | The SP1 GPU client panics on shutdown and the compressed stage waited ten minutes | Fixed and confirmed | The buffered save closed the gap, the core proof finished at and the compressed stage started at; shard timings repeated within 0.3 s (core 9.1 s, compressed 10.5 s); a guest that returned 0 bytes on the second run was… | [docs/bench-log.md](../docs/bench-log.md) | +| M23 | Forge timestamps inside the rules and the controller mines you a 10x difficulty for free | Fixed | Correct on every point, and measured first by our own attack run (`sim/difficulty/attacks/README.md`, scenarios 3 and 7): in the simulator a 50% forger took the block rate to 0.12 (earliest stamp) and 0.56 (latest) of… | [docs/bench-log.md](../docs/bench-log.md) | +| P21 | The SP1 proof is not what consensus checks in proving v0 | Decided | Proving v0 (every producer verifies off the consensus path) through the public testnet; the in-consensus verifier is the execution engineer's plan item for after it; the litepaper sentence labelled Open stands. | none named | +| P22 | The rewards and payouts are inputs to the shard proof, not outputs | Answered by design | The design rule that contains it is in force, spec 7.7 item 6 and design 5.5: the rewards and payouts a shard statement carries are checked against every node's own consensus derivation, so a proof over any other list… | none named | +| M24 | Your two-lane controller oscillates for an hour when a second miner joins mid-epoch | Rolled out | Rule v2 activated on the live devnet at DAA 33,000 by the height switch after a 12-node cloud rehearsal (settle 157 to 272 s, no swing); node 1, the seed, the observer and the three app machines crossed the height on… | [sim/difficulty/records/live-2026-10-04.csv](../sim/difficulty/records/live-2026-10-04.csv) | +| D1 | Your users are a gate, not a fact | Conceded, stated | Correct on the count and on the definition. | [docs/bench-log.md](../docs/bench-log.md) | +| D2 | The app share pays nothing | Conceded, stated | `Site/litepaper.html`, Building, Why build here, "a million 100,000-gas calls a day at a 1 gwei tip pays about 7,300 IGN a year"; Canto and Blast absent from the page (grep, tonight). | [docs/design/developer-adoption.md](../docs/design/developer-adoption.md) | +| D3 | Proof of work in 2027 is a perception cost you cannot measure | Conceded, stated | `Site/litepaper.html`, What Igneum does not claim, "A label that costs nothing. | [site/litepaper.html](../site/litepaper.html) | +| D4 | No dollar, no DeFi | Conceded by decision | , restated here for builders. | [docs/review/round-3-2026-10-03.md](../docs/review/round-3-2026-10-03.md) | +| D5 | I cannot debug a revert | Conceded, scheduled, stated | `Site/litepaper.html`, What Igneum does not claim, "A chain you can debug today. | [docs/design/execution-layer.md](../docs/design/execution-layer.md) | +| D6 | A forged job result reaches my contract and nobody vetoes it | Conceded, contained by rule, stated | `Site/litepaper.html`, What Igneum does not claim, "A veto on job results. | [docs/design/execution-layer.md](../docs/design/execution-layer.md) | +| X23 | One shipped key is an administrator channel to the founder's PCs | Fixed on a branch, pending merge | Three tiers in `relay/lib/guard.mjs` (`authVia`): the console token (header or the phone page's path), the relay's own key (`RELAY_KEY`: reads and reports, never `task`, `run`, `name`, `role`, `secret`, `delete`), and… | [docs/review/round-4-2026-10-04.md](../docs/review/round-4-2026-10-04.md) | +| X24 | The relay token rides in the URL on every request | Fixed on a branch, pending merge | Every client and Mac tool calls `/api/relay?fn=<fn>` with `x-relay-token` (and `x-igneum-key`) as headers: `igneum-agent.ps1` and `send.ps1` (`Api-Url`), `agent.sh` and `send.sh` (through a 0600 curl config file, `-K`,… | [tools/relay.mjs](../tools/relay.mjs) | +| X25 | The PC agent installs itself at every logon, at highest privilege, on every start | Fixed on a branch, pending merge | `Igneum-agent.ps1` calls `Arm-Restart` only on the two paths that end in `shutdown.exe /r` (a task that printed `RELAY-REBOOT` on its own line AND was queued with `--reboot` or `--reboot-continue`), sets… | [relay/clients/igneum-agent.ps1](../relay/clients/igneum-agent.ps1) | +| X26 | The feed is a permanent transcript, and it holds the dl token by design | Fixed on a branch, pending merge | Retention 30 days (`relay/lib/handler.mjs` `expire`: `DELETE... | [relay/lib/handler.mjs](../relay/lib/handler.mjs) | +| X27 | The relay has no clean rotation and no sender binding | Fixed on a branch, pending merge | A per-machine secret (64 hex, `node tools/relay.mjs secret PC1`: written to `~/.config/igneum/relay-machines/PC1` at 0600, its sha256 bound on the relay with `POST secret` (token only), carried to the PC as… | [relay/README.md](../relay/README.md) | +| X28 | Relay hygiene, minor | Fixed on a branch, pending merge | The remaining points. | [lib/wake.mjs](../lib/wake.mjs) | +| G12 | The PoW schedule comes from the environment on every network, including mainnet | Fixed | . | the files above. | +| G13 | The update signature covers binaries that nobody signed | Fixed on a branch and verified locally | The chain already on master was read end to end and run, not asserted. | [packaging/windows/push-inputs.sh](../packaging/windows/push-inputs.sh) | +| G14 | Secrets and identity in the history of a repository with a public date | Decided | `TZ=UTC` in every commit path the tooling owns: `tools/ship-app.mjs` (`git` runs with `env: { TZ: 'UTC' }`), `packaging/ota/publish-jobs.sh` (`export TZ=UTC`, found by the class check), `tools/repo/fresh-repo.sh`… | [tools/ship-app.mjs](../tools/ship-app.mjs) | +| X18 | Two nodes with two override files connect, and only some mismatches fork | Fixed | . | the files above. | +| F23 | The equivocation ban is node-local, so honest nodes refuse each other's certificates | Fixed | . | the files above. | +| F24 | A checkpoint determination is never revisited | Fixed | . | the files above. | +| F25 | The fast-time harnesses cannot start a node, and the timestamp probe tests the old rule | Fixed | Correct, measured. | [rt/logs/fa_s8/n0/node.log](../rt/logs/fa_s8/n0/node.log) | +| X19 | Operational knobs and silences in the shipped node | Fixed on a branch, pending merge | The node half, fork commit a commit. | [protocol/flows/src/flowcontext/clock_skew.rs](../protocol/flows/src/flowcontext/clock_skew.rs) | +| X20 | Cold-sync checkpoint determination is indices times chain length | Fixed on a branch, pending merge | `Consensus/src/processes/finality.rs` `on_virtual_changed` resolves every index the sink can determine in ONE descending walk of the selected chain (`chain_blocks_at`, targets highest first), where it walked from the… | [consensus/src/processes/finality.rs](../consensus/src/processes/finality.rs) | +| M25 | The miner takes the day length from its environment, and the schedule global can tear | Fixed on a branch, pending merge | Correct. | [igneum/miner/src/main.rs](../igneum/miner/src/main.rs) | +| M26 | The interval fault guard freezes its baseline and loops | Fixed | `IntervalGuard` builds its baseline from the healthy intervals of the current worker process (a moving average, two intervals before it can trip) and forgets it when the worker restarts; the STATUS line is printed on a… | [docs/bench-log.md](../docs/bench-log.md) | +| M27 | A flapping node makes the worker rebuild once per template | Fixed | Correct. | the files above. | +| M28 | The kernel text is bound only to its own directory | Fixed on a branch, pending merge | Correct. | [proto-cuda/nvrtc/packfile.h](../proto-cuda/nvrtc/packfile.h) | +| X21 | A wrong program burns power with a green rate | Fixed | Correct. | the files above. | +| X22 | Worker restart paths, minor | Fixed on a branch, pending merge | The four remaining paths. | [app/igneum-app/src/engine.rs](../app/igneum-app/src/engine.rs) | +| E16 | The 20% pool is burned on the live chain, and the text says it pays provers | Answered with evidence and stated | Correct for the live devnet-v4 line. | [docs/review/round-4-2026-10-04.md](../docs/review/round-4-2026-10-04.md) | +| L9 | "100% to miners and provers", "0% anyone else", and no word that devnet coins have no value | Conceded, stated | `Site/index.html`, `site/miner.html` and `site/wallet.html`, a line beside every download control, "Devnet: coins have no value and the chain may be reset."; `site/index.html` Economics tiles, "of emission to miners… | the files above. | +| M29 | The litepaper's app paragraph describes an app that does not exist | Conceded, stated | `Site/litepaper.html`, For miners, "One click, for everyone else", rewritten to Ember 0.3.9 from `app/igneum-app/ui/index.html` (hash rate, blocks found, node, next program, finality votes, the proving tile, the devnet… | [ui/app.js](../ui/app.js) | +| M30 | A block or transaction flood grows the 0.3.4 node by hundreds of megabytes in a minute | Fixed | Measured, cause not yet isolated. | [docs/bench-log.md](../docs/bench-log.md) | +| M31 | The 0.3.4 node cannot produce a block template on mainnet, testnet or simnet parameters | Fixed | Measured on the execution-layer attack network (`tools/exec-attacks/net.sh` runs `--simnet` with no override): three nodes up, 0 blocks, every template refused with that line (`docs/review/redteam-2026-10-04.md` row 27). | [rt/logs/exec_b/miner_node1.log](../rt/logs/exec_b/miner_node1.log) | +| E17 | Unlogged inputs behind the economics, minor | Answered with evidence for PC 2 | RTX 5090 honest 132.2 Mhash/s at 326.6 W median, 3,060 MHz, 50 to 54 C, 100% utilisation (0.40 Mhash/J); 346.9 W at 8 warps per block; the inline settings 415.7 W and 431.0 W (the power limit). | [docs/review/round-4-2026-10-04.md](../docs/review/round-4-2026-10-04.md) | +| E18 | The dev fee is a protocol fee with better PR | Answered by design and with evidence | The fee exists and is disclosed; the rest is wrong in three places. | [docs/design/miner-dev-fee.md](../docs/design/miner-dev-fee.md) | +| X29 | Host and file hygiene, minor | Decided | The curl part: `infra/gpu-bench/upload.sh` writes `header = "x-igneum-key:..."` to a 0600 temporary config and calls `curl -K`; `proto-cuda/windows-app/upload-log.bat` and `proto-cuda/windows-miner/upload-log.bat` do… | [infra/gpu-bench/upload.sh](../infra/gpu-bench/upload.sh) | +| X30 | The live page and the bench page exposed operational detail | Fixed | `Ac89a37` and a commit (a scrubbed copy, the build fails on any private string), a commit (none of the three in the public API), a commit (the menu). | the commits above. | +| X31 | The public testnet dated "August 2027" on the site | Fixed, stated | Every mention of the month is gone from the site and no date is given. | [docs/plans/testnet-go.md](../docs/plans/testnet-go.md) | +| X32 | The roadmap carried calendar months beside a testnet that is weeks away | Fixed, stated | Every calendar month is out of the roadmap. | [site/litepaper.html](../site/litepaper.html) | +| X33 | The public benchmark dated "January 2027" | Fixed, stated | Both sentences read "The public benchmark with a leaderboard ships with the public testnet." (`site/litepaper.html`, For miners and Questions miners ask). | [site/litepaper.html](../site/litepaper.html) | +| X34 | RandomX described as chip-free | Fixed, stated | Four sentences corrected, each with the X9 as the stated fact and its date; every sentence that only names the technique stands. | [site/index.html](../site/index.html) | +| X35 | The class v4 chip headline stated as one number, 2.1x | Fixed, stated; restated | The served chip text is the third review's claim statement ("Igneum remains competitive on accessible commodity GPUs even when specialised mining hardware is assumed to exist, remain compatible and seek profit; its… | [docs/design/latency-ladder.md](../docs/design/latency-ladder.md) | +| X36 | The X9 described as a shipping chip | Fixed, stated; restated | The X9 appears on the served pages only as a precedent (the pre-order, the withdrawal, no benchmark) and no served sentence uses its claimed core as a chip core against the model; the Antminer X5 is served as an… | [site/index.html](../site/index.html) | +| X37 | The class v4 energy premium is a cost the user pays, not a line in a model | Answered with evidence | Measured on the RTX 5090, 145 W of premium unlocked and 82 W at the knee; the RTX 5080 at stock 84 W, its grid running; the team identity says the premium needed for 2x at k = 1 is 103 W at the lock and a premium of… | [docs/plans/counter-asic-3-status.md](../docs/plans/counter-asic-3-status.md) | +| N1 | A 0.3.15 node on the live file wrote blocks every 0.3.14 node rejected | Fixed | The class v4 signal (PROPOSED, `docs/plans/counter-asic-3-node.md` section 6) is the producer's object version in the high byte of the header version; the first 0.3.15 build stamped it from the binary alone, so on the… | [infra/fast-time/node-compat.mjs](../infra/fast-time/node-compat.mjs) | +| N2 | Any peer could crash any pruned node with a sync request below its retention | Fixed | `SyncManager::antipast_hashes_between` (the IBD headers path, `RequestHeaders`) unwrapped the GHOSTDAG reads of the requested low block and of every chain block of the walk; a pruned node holds no GHOSTDAG data below… | unit test `a_sync_request_below_retention_is_an_error_not_a_panic` (a chain of six headers, the genesis's GHOSTDAG… | +| P23 | An unwound transaction leaves the node's view until its sender resends it | Fixed on a branch, pending merge | a fork a commit (the P23 commit, on the merge of `ledger-fixes` and `ledger-fixes-2` onto the 0.3.11 fork tip a commit); `EvmPool::on_chain_removed` (igneum/exec/src/pool.rs) and `ExecService::requeue_unwound`… | [igneum/exec/src/pool.rs](../igneum/exec/src/pool.rs) | +| AP-F8-1 | A load whose source was last written by `or`, `mul` or `mulhi` makes a cross-hash hot set | Fixed in part, finding bounded, stated | Class v4 sub-version 3 (igneum-pow a commit, the audit-freeze tag) is frozen with the dataflow rule, the shared-operand rule, the 0.98 ratio and the total draw; the in-house pass's F8 re-gate reads 60 of 64 seeds under… | [docs/analysis/ca3-v4-uniform.md](../docs/analysis/ca3-v4-uniform.md) | +| AP-F8-4 | The program id's derivation text omitted generator 4's sub-version suffix (interoperability, documentation; no object change) | Fixed | The id and its printed derivation come from one byte recipe (`generator::IdRecipe`, `program_id_recipe`, `program_id_class_recipe`, `Program::program_id_derivation`), so the two cannot drift; the emitter prints that… | [igneum-pow/tests/derivation.rs](../igneum-pow/tests/derivation.rs) | +| AP-F8-5 | The public specification did not describe the shipped acceptance rule (documentary; no object change) | Spec fixed | Sections 1.4.3 and 1.4.6 of `docs/spec/01-lottery-hash.md` rewritten to the shipped rule at igneum-pow a commit with every constant named and every order of operations stated (1.4.3: the two per-register states of the… | [docs/analysis/cryptanalysis/report-acceptance-rule-3.md](../docs/analysis/cryptanalysis/report-acceptance-rule-3.md) | +| AP-F8-7 | The hash's reads are not uniformly random: about half of epochs carry one load site with a biased address bit | Open, priced | 1.6 percent at f = 1/2, nothing at f = 1; the served sentence corrected 8 October 2026 (the site the team, by the team's word): the litepaper's lead reads "dependent reads spread over a multi-gigabyte dataset", the… | [docs/analysis/class-v6/family-gate.md](../docs/analysis/class-v6/family-gate.md) | +| GF1 | A post-quantum signature scheme would need a hard fork, and every vote key is a public BLS12-381 point | Fixed | The byte costs nothing now and a fork later. | none named | +| GF2 | A vote key cannot move: a miner who changes keys re-earns 30 days of weight, and so does the post-quantum migration | Fixed | The successor inherits the window, not a fresh one, so a key rotation costs no weight and the migration of GF1 is one item per key. | none named | +| GF3 | A 256 MB on-chip cache makes the lottery hash 2 to 3x cheaper for the card that has it, and the cache size is a constant | Fixed as a genesis lever, measurement owed | Consumer LLC is 96 to 128 MB today and datacentre 256 MB (`chip-model-v3`, approximate), so the shortcut is a datacentre card's today and a consumer card's in a generation or two. | none named | +| GF4 | The class-group VDF falls to the same quantum computer | Conceded, stated | `Site/litepaper.html`, What Igneum does not claim, "A delay function that outlives a quantum computer. | none named | diff --git a/docs/ledger-public.md b/docs/ledger-public.md index 36ea9be19..68d7783c3 100644 --- a/docs/ledger-public.md +++ b/docs/ledger-public.md @@ -1,202 +1,34 @@ # Igneum criticism ledger, public shape -Generated by `tools/ledger/export-public.mjs` from `docs/fud-ledger.md`; a gate check fails when the two drift. One row per item: the claim or criticism, its status, what was done, and the evidence. Internal identifiers, times of day and team-member names are left out on purpose; the full ledger is published with the repository. +Generated by `tools/ledger/export-public.mjs` from `docs/fud-ledger-2.0.md`; a gate check fails when the two drift. One row per item: the claim or criticism, its status, what was done, and the evidence. Internal identifiers, times of day and team-member names are left out on purpose; the full ledger is published with the repository. -194 items. By status: Conceded, stated 52; Fixed 31; Decided 21; Fixed on a branch, pending merge 14; Answered by design 9; Answered with evidence 6; Fixed, stated 4; Closed by rule 3; Open 3; Spec fixed 2; Fixed, stated; restated 2; Answered by design, with a correction to our own text 1; Answered with evidence, stated 1; Answered by design for finality, Conceded for the lottery 1; Conceded, implemented, stated 1; Rule implemented and measured; launch month simulated 1; Answered by design, with the concession stated 1; Conceded, stated in the litepaper and the design doc 1; Answered with evidence at 1 block/s 1; Conceded, stated in the simulation report 1; Answered by design, with the dependency conceded. Update 7… 1; Conceded, stated in the litepaper, with the dial explained 1; Closed by spec 1; Conceded by decision, stated in the design doc 1; Answered by design, with the founder's edge conceded 1; Answered by design, with a metrics caveat 1; Closed by removal, 3 October 2026 1; Conceded, stated in the litepaper 1; Conceded, stated in the design doc 1; Measured on the live node line, and the overlay does NOT… 1; Conceded, stated in the simulation 1; Conceded in part, labelled, stated 1; Fixed in the node 1; Answered with evidence for the largest body the rules allow 1; Fixed in the proving code 1; Fixed in the spec 1; Rule fixed 1; Rule written 1; Fixed, logged 1; Answered with evidence for the test half 1; Fixed in the node and shipped, rule not yet activated on… 1; Simulation half run 1; Answered with evidence for all four 1; Written 1; Designed 1; Fixed and confirmed 1; Fixed in the node behind a named switch 1; Rolled out 1; Conceded by decision 1; Conceded, scheduled, stated 1; Conceded, contained by rule, stated 1; Fixed on a branch and verified locally 1; Answered with evidence and stated 1; Answered with evidence for PC 2 1; Answered by design and with evidence 1; Fixed in part, finding bounded, stated 1; Open, priced 1; Fixed as a genesis lever, measurement owed 1. +26 items. By status: Open 12; Decided 8; Conceded 6. | Id | Claim or criticism | Status | What was done | Evidence | |---|---|---|---|---| -| M1 | The program space is tiny | Decided | No standing bounty. | [docs/bench-log.md](../docs/bench-log.md) | -| M2 | Your own prototype is not memory-hard | Conceded, stated | `Site/litepaper.html`, Monero's idea section, the "Measured so far" paragraph, "computing items on the fly runs 4.8x slower than loading them"; What Igneum does not claim, "A memory-hard prototype on every vendor". | [proto-metal/TESTS.md](../proto-metal/TESTS.md) | -| M3 | Kaspa said ASIC resistant too | Answered by design, with a correction to our own text | First the correction: Kaspa did not promise ASIC resistance. kHeavyHash was designed to be friendly to specialised and optical hardware, and the Kaspa community expected chips (approximate, from memory; cite the Kaspa… | design doc, "ASIC resistance" section. | -| M4 | ProgPoW already did this and you do not mention it | Conceded, stated | `Site/litepaper.html`, precedents table row 1, "ProgPoW, as KAWPOW on Ravencoin since 2020". | [vendor/](../vendor/) | -| M5 | Your load count varies 6x between programs | Fixed | Generator version 2 draws exactly 16 load slots per program (spec 01 section 1.4.2, `igneum-pow/src/generator.rs`), and the fresh-source rule of 1.4.3 with the acceptance rule of 1.4.6 fixes the distinct count too,… | [proto-metal/TESTS.md](../proto-metal/TESTS.md) | -| M6 | Weak programs | Fixed | The acceptance rule of spec 01 section 1.4.6 (`igneum-pow/src/accept.rs`, mirrored in `proto-metal/main.swift`) rejects a candidate with a stale load source, a register without an injecting write, a nonce-independent… | [proto-metal/TESTS.md](../proto-metal/TESTS.md) | -| M7 | No cryptographic analysis at all | Conceded, stated | `Site/litepaper.html`, Mining section, "The hash is a lottery, not a general-purpose cryptographic hash" and "Open: no analysis of the lottery properties exists yet". | [proto-metal/TESTS.md](../proto-metal/TESTS.md) | -| M8 | Only two vendors, two programs, one day | Decided | A discrete AMD card (9070 XT) and a 12 GB NVIDIA card (4070) are on order for PC 2; the measurement runs on arrival. | [docs/bench-log.md](../docs/bench-log.md) | -| M9 | The 10 ms CPU verification gate is unmeasured | Conceded, stated | `Site/litepaper.html`, Mining section, "Measured: 0.41 to 0.58 ms per warp on one Apple M5 Max core with the 256 MB cache"; vs RandomX "Light verification" row. | [docs/bench-log.md](../docs/bench-log.md) | -| M10 | "Bound by memory bandwidth" is wrong | Answered with evidence, stated | `Site/litepaper.html`, Mining section, "bound by random memory access. | [docs/bench-log.md](../docs/bench-log.md) | -| M11 | Hourly JIT on real rigs | Decided | The mixed-generation rig is borrowed from a farm operator later, at the HiveOS package's first test; the 9070 XT on order gives the ROCm half on PC 2. | [docs/bench-log.md](../docs/bench-log.md) | -| M12 | Rentable hashrate is not just NiceHash | Answered by design for finality, Conceded for the lottery | Both halves true. | [sim/results.md](../sim/results.md) | -| M13 | Macs mine too is marketing | Conceded, stated | `Site/litepaper.html`, For miners, Hardware, "Macs mine too, at about a fifth of a flagship card: Measured, 26.7 against 123 million hashes a second" (confirmed by grep tonight; the projected-earnings half is not… | [docs/bench-log.md](../docs/bench-log.md) | -| M32 | "Automatic anti-ASIC escalators" overstates what the era draw and the instruction reserve do | Conceded, stated | The era draw and the instruction reserve are automatic schedule changes against fixed datapaths and against human forks; against the stored-dataset chip every drawn parameter is firmware, and the defence against that… | [docs/analysis/horizon/algorithm.md](../docs/analysis/horizon/algorithm.md) | -| M33 | The FPGA ceiling rests on a tFAW the JEDEC HBM2 table does not give | Conceded, stated | The public FPGA line carries only the measured row, 2.4 G reads/s per card and 0.30x to 0.39x of the RTX 5090 per watt (Shuhai, FCCM 2020 Fig 7; the tFAW arithmetic from ICCAD 2021 Table I), and the 11.4 G bank-bound… | [docs/analysis/horizon/algorithm.md](../docs/analysis/horizon/algorithm.md) | -| M34 | The shadow size N is a constant of the binary, so the one lever against the dataset-storing chip needs a fork to move | Conceded, implemented, stated | The public text carries the ladder (`site/litepaper.html`, Mining: the six-rung genesis ladder of the latency shadow with a measured admissibility flag per rung, moved by miner signalling, never by a fork; and the X9… | [docs/design/latency-ladder.md](../docs/design/latency-ladder.md) | -| F1 | Finality is attackable for the first month | Rule implemented and measured; launch month simulated | The harness text only: `tools/finality-attacks/run.mjs` names the 2/3-of-total floor in the s6 comments and criterion and in the s5 result line, where it still said 56.7%; the scenario logic is untouched. | [sim/](../sim/) | -| F2 | The two-hour presence window is an eclipse vector | Closed by rule | Correct that the presence window trades safety for liveness. | [sim/results.md](../sim/results.md) | -| F3 | Participation grinding through the bitmap | Decided | The per-block vote bound and the bitmap wire bound of spec 3.4.2 items 2 and 3 are adopted for gate 3; the spec moves them from Proposed to Decided at the next spec edit. | design doc Finality v2, Quorum item 2 and Checkpoints item 3. | -| F4 | It is proof of stake with extra steps | Answered by design, with the concession stated | The committee's weight is blocks mined in the last 30 days. | [sim/results.md](../sim/results.md) | -| F5 | The headline arithmetic is misread on purpose | Conceded, stated | `Site/litepaper.html`, Finality, "an attacker producing every block on the chain, with honest miners gone" and "An attacker matching the honest network needs twenty days for a third and never reaches two thirds"; the… | [sim/results.md](../sim/results.md) | -| F6 | Equivocation costs nothing that matters | Conceded, stated in the litepaper and the design doc | True. | design doc Finality v2, Checkpoints item 4 and Residual risks bullet 1. | -| F7 | A 2-minute checkpoint on a DAG with a 1-hour merge bound | Answered with evidence at 1 block/s | Fair. | design doc Finality v2, Checkpoints item 1 and "Three experiments before gate 3". | -| F8 | The simulation has no network in it | Conceded, stated in the simulation report | Correct. | [sim/results.md](../sim/results.md) | -| F9 | Half the hashrate leaves and finality stalls for ten days | Answered by design | That table is the all-keys denominator, which the simulation recommended for safety. | [sim/results.md](../sim/results.md) | -| F10 | Pools hold the votes | Conceded, stated | `Site/litepaper.html`, Finality, "Pools carry their hashers' votes, so vote concentration equals pool concentration, and it is public"; Governance, "governed by the hashrate that powers it". | design doc Finality v2, Residual risks bullet 3. | -| F11 | VDFs are exotic | Answered by design, with the dependency conceded. Update 7… | The era VDF is in the node (spec 4.4 Implemented, behind `era_vdf_activation_daa`, never until the founder sets it per network), on a fixed-width integer with no C library, with the hash-chain fallback behind the… | design doc Finality v2, Lottery seeds items 1 and 2, Residual risks bullet 5, "Three experiments before gate 3". | -| F12 | Nothing outside the chain, except | Answered by design | Those are code dependencies, chosen because each is open source and replaceable, and none is another chain's consensus. | CLAUDE.md design paragraph; design doc "Decided" paragraph. | -| F13 | Why prove every block if every node executes anyway | Answered by design | Full nodes execute natively so users see state in about a second. | design doc, "Proving speed on consumer GPUs" risk item and "Who needs" paragraph. | -| F26 | "No stake" needs its one sentence: what is at stake, and what strips it | Conceded, stated | `Site/litepaper.html`, the finality section's "What is not here" paragraph and the "Igneum at a glance" Finality row carry the sentence verbatim: "No coin is staked. | [docs/analysis/horizon/frontier.md](../docs/analysis/horizon/frontier.md) | -| P1 | The 20-second shard is a number you made up | Conceded, stated | `Site/litepaper.html`, Proving, The proving budget, "Target: shard size will be set so a 12 GB card proves one shard in about 20 seconds. | [site/journey.json](../site/journey.json) | -| P2 | Real-time proving needs a hundred GPUs per block | Conceded, stated in the litepaper, with the dial explained | True, and the litepaper says a full block needs a cluster of 100 to 200 consumer GPUs, approximate. | design doc "Unit economics of a proof"; litepaper "What Igneum does not claim" item 1. | -| P3 | A phone verifies in milliseconds is a SNARK-wrapper claim | Answered by design | The design rule covers the claim (design 5.6 `wrap`, R4: the aggregated block proof wrapped once into a small curve-based proof by the aggregator) and the public text says what is and is not measured… | not yet. | -| P4 | Trustless light clients need a consensus proof you do not have | Conceded, stated | `Site/litepaper.html`, precedents table row 6, "The consensus proof that makes the checkpoint self-verifying is phase two"; Building item 2, "Light clients". | design doc, hostile review table rows "Slashing an external prover" and "One-proof light clients". | -| P5 | EVM "unchanged" on a DAG is false | Closed by spec | Correct. | design doc, hostile review table row "EVM semantics on a DAG". | -| P6 | The proving market is tiny | Conceded, stated | `Site/litepaper.html`, The problem, "a supplier whose marginal cost is close to power"; "cheapest supplier" and "lowest cost" absent from the page (grep, tonight). | design doc "Market size, honestly" and "Existing prover networks" table (labelled from memory). | -| P7 | A soundness bug in SP1 is a consensus failure | Conceded, stated | `Site/litepaper.html`, Abstract, "Writing new code, including an emergency fix to the proof system, is the one thing that takes a person"; Proving, "no node accepts a block with a wrong state root". | design doc "Proof system churn" risk item. | -| P8 | Fastest prover wins all the shards | Closed by rule | Fair, and the lottery/proving separation does not by itself fix it. | design doc "Proving speed on consumer GPUs" risk item and Finality v2 "Fees". | -| P9 | Shard griefing | Decided | The parameter table's values are the phase 4 devnet's starting values (8 assignees, a 25-s exclusive window, a 120-s job claim timeout, no shard bond, the external job bond set on the devnet); the devnet measurement… | design doc, Security model table row 3. | -| P10 | External jobs are paid off-chain, so where is the burn | Conceded, stated | `Site/litepaper.html`, Economics, "Outside customers pay in their own currency on their own chain at launch; settlement in IGN with a 10% burn follows when the proof bridge lets Igneum see the payment"; the route table… | design doc "The first six months" risk item and hostile review table row "Slashing an external prover". | -| P24 | "20 percent of emission to provers" without the caveat that consensus does not verify the proof | Conceded, stated | `Site/litepaper.html`, Economics, the 20% proving-pool row carries the caveat: consensus does not yet verify the carried proof, it checks the record's statement against native execution and its signature, so today a… | [docs/analysis/horizon/consensus-security.md](../docs/analysis/horizon/consensus-security.md) | -| P25 | Unclaimed pool credit is stranded in the escrow | Conceded, stated | `Site/litepaper.html`, Economics, the 20% proving-pool row carries the note: unclaimed pool credit is today stranded in the escrow, no rule returns it; the fix rolls an unproven shard's credit into the next proven… | [docs/analysis/horizon/economy-and-utility.md](../docs/analysis/horizon/economy-and-utility.md) | -| E1 | Hard cap plus burn is a security budget cliff | Conceded by decision, stated in the design doc | True, and the design doc records the choice: "A 1% tail is the Monero model and the safer choice for security on its own." The argument for the cap is that Igneum miners keep earning from in-chain proving fees and… | design doc "Decision: hard cap". | -| E2 | Half the coins in two years is an insider schedule | Answered by design, with the founder's edge conceded | The schedule (1 billion a year halving every two years, 30-day ramp from 10% to 100%) is public, fixed at genesis and the same for every miner. | litepaper "Supply" and "Fair launch, announced". | -| E3 | The 20% developer share enables wash gas | Answered by design, with a metrics caveat | The base fee is burned in full, so every wash transaction loses its whole base fee. | design doc Finality v2 "Fees"; litepaper "What a builder gets for being early". | -| E4 | 5% of gas to the dev fund is a tax | Closed by removal, 3 October 2026 | There is no development fund. | spec section 5.5; design doc "No development fund, so nothing to fight over". | -| E5 | "Not one coin to a founder" is false | Conceded, stated | `Site/litepaper.html`, Economics, "No fund, no foundation, no fee to the team", "1 block in 100 pays the project"; `site/index.html`, Economics, "The one payment to the project is the Ember software's optional 1% dev… | design doc "No development fund, so nothing to fight over". | -| E6 | Two-year halvings bleed hashrate | Conceded, stated | `Site/litepaper.html`, Economics, Security after the subsidy, "The schedule is a bet, not a measurement: a halving halves emission income overnight if price and fees do nothing", with Kaspa's reduction marked… | none; decision in design doc "Supply". | -| E7 | No stablecoin liquidity without a trusted bridge | Decided | Correct. | design doc, hostile review table row "One-proof light clients and committee-free bridges". | -| E8 | Founders seeding the DEX is market making by insiders | Conceded, stated | True and stated in the litepaper. | litepaper "Liquidity from the people who are there". | -| E19 | "Proving: a second income" without the arithmetic of how small it is | Conceded, stated | `Site/litepaper.html`, "For miners", under the three-streams table: all of Ethereum L1's proving is about USD 36 a day at the September 2026 tracker cost (USD 0.005 a block x 7,200 blocks; the tracker figure is a… | [docs/analysis/horizon/frontier.md](../docs/analysis/horizon/frontier.md) | -| E20 | "Proofs at the cost of power" is the electricity, not the price | Conceded, stated | `Site/litepaper.html`, The problem ("a supplier whose electricity cost is close to power and whose price is the subsidy it forgoes, which falls as the network's hash grows"), Building on Igneum ("Proofs priced by the… | [docs/analysis/horizon/economy-and-utility.md](../docs/analysis/horizon/economy-and-utility.md) | -| E21 | The dev fee is 1 percent of the producer share, and the funding plan's ceiling took all rewards | Conceded, stated | `Site/litepaper.html`, the payment-routes row 6 and the Ember section read "default-on, switchable, 1 percent of the producer share"; `docs/plans/funding.md` section 4's ceiling is 1 percent of the producer share, USD… | [docs/analysis/horizon/economy-and-utility.md](../docs/analysis/horizon/economy-and-utility.md) | -| G1 | No cryptography team | Conceded, stated | `Site/litepaper.html`, Questions miners ask, "reviewers will be named and paid before gate 3"; What Igneum does not claim, "A cryptography team. | design doc "Team" paragraph. | -| G2 | An AI designed this | Conceded, stated | `Site/litepaper.html`, cover, "Method one founder with AI systems"; Who are you?, "One founder, pseudonymous, working with AI systems". | [.claude/agents/](../.claude/agents/) | -| G3 | Who are you | Decided | No team page for now; the litepaper says the team is pseudonymous and names no team page. | [site/journey.json](../site/journey.json) | -| G4 | No admin keys, except in everything that matters | Conceded, stated | The home page was redrawn as one statement, the live scene, three facts and the downloads, so the tile "admin keys in consensus" is no longer on `site/index.html`; the sentence stands on `site/litepaper.html`,… | litepaper "Governance". | -| G5 | No multi-client | Conceded, stated in the litepaper | True at launch. | litepaper "Governance", last bullet. | -| G6 | Stratum v2 does not make pools unable to censor | Conceded, stated | `Site/litepaper.html`, Governance, "Pools can be bypassed on transaction choice". | none in repository. | -| G7 | The one-click app is an update key over the network | Decided | Correct. | not yet. | -| G8 | Governance by hashrate is governance by two pools | Conceded, stated in the design doc | True in the same way it is true on Bitcoin, where miner signalling activated SegWit and Taproot. | design doc Finality v2, Residual risks bullet 3. | -| G15 | Three signalling thresholds, four numbers across the documents | Conceded, stated | One sentence in `site/litepaper.html`, Governance ("Miners set what genesis leaves open") and Mining ("Miners hold the switch"): miners signal three things at three thresholds, 60 percent of blue blocks over two weeks… | [docs/analysis/horizon/economy-and-utility.md](../docs/analysis/horizon/economy-and-utility.md) | -| C1 | vs Monero: GPUs were excluded on purpose | Answered by design | Monero chose the CPU for egalitarian reasons and accepted botnets as the price. | litepaper "For miners", hardware paragraph. | -| C2 | vs Monero: "no chip in seven years" is not proof | Conceded, stated | The home page no longer carries the RandomX paragraph; "since 2019 (approximate)" and "precedent, not proof" stand on `site/litepaper.html` (vs RandomX, Mining). | none. | -| C3 | vs Kaspa: you misrepresent them | Conceded, stated | `Site/litepaper.html`, The problem, "Chips arrived, as on Kaspa, whose hash was designed to welcome them"; Speed, "Kaspa has run in production since 2021 (approximate), forked from rusty-kaspa"; precedents row 5,… | none in repository; `vendor/rusty-kaspa` to be cloned and cited. | -| C4 | vs Kaspa: a finality overlay changes GHOSTDAG's guarantees | Measured on the live node line, and the overlay does NOT… | A NEW SERIOUS FINDING (5 October 2026 sweep; owner: cryptographer and consensus engineer, decision owner the founder). | [sim/results.md](../sim/results.md) | -| C5 | vs Ethereum: you compare inclusion to finality | Conceded, stated | `Site/litepaper.html`, Speed, "Inclusion is not confirmation on either chain". | litepaper "Speed". | -| C6 | vs Ethereum: every one of your components is a research project | Conceded, stated | `Site/litepaper.html`, Roadmap, "the combination is the risk the gates price" and "Dates slip. | litepaper "Roadmap". | -| C7 | vs Bitcoin: hashrate that follows price is the design, you penalise it | Conceded, stated in the simulation | Correct. | [sim/results.md](../sim/results.md) | -| C8 | vs Ergo, Ravencoin, Conflux: GPU mining has a home | Conceded, stated | `Site/litepaper.html`, The problem, "Ergo, Ravencoin and Conflux still mine on GPUs at a fraction of the 2022 fleet (approximate)"; precedents row 3 names Conflux. | none in repository; to be cited from their repositories. | -| C9 | vs Aleo: you will centralise the same way | Closed by rule | See P8. | design doc "Existing prover networks" table, Aleo row. | -| C10 | vs Boundless and Succinct: you cannot bid there without their tokens | Conceded, stated | `Site/litepaper.html`, Proving for everyone else, "Boundless provers post ZKC and Succinct provers stake PROVE (approximate, from their documentation)". | design doc "Existing prover networks" table, labelled approximate. | -| C11 | vs everyone: "firsts" that are not | Conceded, stated | `Site/litepaper.html`, precedents table, "We know of no chain that combines them"; Building, "that we know no other EVM chain offers". | this ledger. | -| C12 | vs Monero: you borrowed the hash idea and left out the point | Answered by design | Transactions on Igneum are public, as on Ethereum. | CLAUDE.md rules (privacy rejected). | -| L1 | It is a security under Howey | Open | Only the founder's decision with counsel settles it; counsel engaged since 6 October 2026 (decisions item 6). | design doc "Legal" paragraph. | -| L2 | Financial promotion rules | Open | Only the founder's decision with counsel settles it; the text half is stated (the schedule facts above). | none. | -| L3 | GoDaddy domains are a seizure risk | Decided | The nameserver move to deSEC in one sitting with every domain's Vercel verification checked afterwards; a non-US registrar in December 2026 when the transfer lock ends. | CLAUDE.md "Domains". | -| L4 | Paying testnet miners real money is a payment before launch | Open | Only the founder's decision with counsel settles it. | design doc "The first six months". | -| L5 | Trademark | Answered with evidence | The clearance search is recorded in the repository as the entry asked, `docs/legal/trademark-search-2026-10-03.md` (3 October 2026, one verdict per register: EUIPO RISK, IGNIUM EUTM 018212492 live in classes 36 and 42;… | none. | -| L6 | A permissionless job market paid in dollars is money transmission | Answered by design | At launch jobs are paid on the customer's chain, in the customer's asset, by the customer's contract, to the prover's address; Igneum operates no custody and takes no cut off-chain. | design doc "The first six months". | -| X1 | "Reproducible from the repository" and the repository is private | Conceded, stated | `Site/litepaper.html`, vs RandomX "Track record" row, "The specification, reference hash, test vectors and simulators are public now (git.igneum.network/igneum-network/spec). | [site/index.html](../site/index.html) | -| X2 | "Get the miner" with no miner | Conceded, stated | `Site/index.html`, hero button "See the miner"; the Mine section's download buttons carry the shipped devnet build's version and size (v0.3.9) beside "Public testnet: not yet open; the devnet build is here for people… | [site/index.html](../site/index.html) | -| X3 | "Proven by fire" when nothing has run | Conceded in part, labelled, stated | The proofs feed moved to the litepaper's proving section with the home-page redesign and reads "Live rows arrive with the public testnet. | [site/index.html](../site/index.html) | -| X4 | Thirteen months with one founder | Conceded, stated | The roadmap is aggressive and every phase is a gate that can repeat or stop the project, which the litepaper says. | litepaper "Roadmap"; design doc "Team". | -| X5 | 1,000 independent miners is a Sybil number | Decided | The independence definition as written, with the silent-fleet addition (a key with no fingerprint counts as its own class only when its address is in an autonomous system no other key uses); the observer columns on… | [site/journey.json](../site/journey.json) | -| X6 | The one-click app is a honeypot vector | Decided | Correct on all three. | not yet. | -| X7 | No community exists | Conceded, stated | This ledger's submission line names hello@igneum.network and the spec issues route; `site/litepaper.html` last paragraph and the footer on every page carry both. | [site/index.html](../site/index.html) | -| X8 | Exchange listings as a roadmap item | Conceded, stated | The home page's journey is no longer shown (the inlined feed remains in the page source); the sentence "No listing is arranged, promised or sought by the project" stands on `site/litepaper.html` Roadmap phase 6 and in… | [site/journey.json](../site/journey.json) | -| X9 | Launch hashrate will be trivial | Conceded, stated | `Site/litepaper.html`, Finality, "In the chain's first 30 days no checkpoint locks at all"; Fair launch, "The first 30 days of mainnet run on proof of work alone". | [sim/results.md](../sim/results.md) | -| X10 | Five milestones in one day | Conceded, stated | `Site/index.html`, journey section, "The log below is the engineering log's dated entries, newest first. | [site/journey.json](../site/journey.json) | -| M14 | A pulsed rental against the block-count DAA buys weight at a discount | Answered with evidence | , ledger close round 1: M14 and F14 the 50x pulse against a lagging retarget inside the finality simulator, both W2 forms"). | [sim/difficulty/devnet-2026-10-03.csv](../sim/difficulty/devnet-2026-10-03.csv) | -| M15 | A header with any past timestamp or any claimed DAA score makes the node build a 256 MiB cache | Fixed | Correct. | [docs/fork-divergence.md](../docs/fork-divergence.md) | -| M16 | The 256 MiB cache fits on a die, so the recompute attacker is compute bound | Answered with evidence | On the 5090 the recompute attacker with the cache inside the 96 MiB L2 (the SRAM emulation, 64 and 32 MiB masks, bit-exact against the stored construction) runs at 33.9 Mhash/s against 132.2 honest for the same… | [proto-metal/MEMHARD.md](../proto-metal/MEMHARD.md) | -| M17 | Every ahead-of-time miner stops at the epoch boundary; whoever compiles in process mines alone | Fixed | And measured on the live devnet at the DAA 3,600 boundary (`docs/bench-log.md`, "first hourly program swap"): prepare sent 449 DAA before the boundary; Metal compiled in 82 ms, CUDA ran nvcc in the background in 1,285… | [proto-cuda/windows-miner/start-mining.ps1](../proto-cuda/windows-miner/start-mining.ps1) | -| M18 | The per-hash random data path is a one-bit select | Conceded, stated | `Site/litepaper.html`, Mining table "Every hash" row, "The one-bit select inside the maths costs a chip nothing and is not a defence"; vs RandomX "Random program" row, "the 128 dataset addresses change with the nonce". | [site/litepaper.html](../site/litepaper.html) | -| M19 | The census that justifies the generator rule has blank cells, and the spec still carries the free load count | Fixed | Correct. | [docs/analysis/weak-program-census-2026-10-03.md](../docs/analysis/weak-program-census-2026-10-03.md) | -| M20 | Pruning proofs are checked with the kHeavyHash stub | Fixed in the node | Correct. | [docs/fork-divergence.md](../docs/fork-divergence.md) | -| M21 | GHOSTDAG k is Kaspa's table value for Kaspa-sized bodies | Answered with evidence for the largest body the rules allow | , ledger close round 1: M21 block propagation with bodies at the mass limit, k re-derived"); the red rate under such bodies is not measured. | [docs/design/execution-layer.md](../docs/design/execution-layer.md) | -| F14 | Weight in blocks over a window in blocks under a lagging retarget | Answered with evidence | , ledger close round 1: M14 and F14 the 50x pulse against a lagging retarget inside the finality simulator, both W2 forms"). | [sim/results_v2.md](../sim/results_v2.md) | -| F15 | Merge depth is not the reorg bound; the finality depth is | Spec fixed | Spec 2.1 names the finality depth as the reorg bound and merge depth as a merge limit only, spec 3.8 and 3.9 tell exchanges to wait 12 hours of past-median time when `finality_active` is false, and the simnet reorg… | the files above. | -| F16 | A lock can become uncertified after a heal | Decided | Option B, a verified certificate is never withdrawn (spec 3.11.4); the 3.5 paragraph is replaced by 3.11.4's text after `c4-fix` merges, `finality_conflict` and the `finality_active` clear go into the node, the forced… | spec 3.5, 3.9. | -| F17 | Keys are free and the official client mints eight per card | Decided | The client defaults to one vote key per machine, identities share it (spec 3.4.2 item 4); the bitmap bound as item 3. | [proto-cuda/windows-miner/start-mining.ps1](../proto-cuda/windows-miner/start-mining.ps1) | -| F18 | "A silent minority cannot freeze finality" is false under the floor | Fixed | Correct. | [sim/results_v2.md](../sim/results_v2.md) | -| P11 | The native-execution veto makes block validity depend on the node's current selected chain | Fixed | Spec 7.2 item 5 and `docs/design/execution-layer.md` 5.5 and D12 are relative to the carrying block's own selected-parent chain; the two-node reorg test is a row in the design document's 8.5. | [docs/design/execution-layer.md](../docs/design/execution-layer.md) | -| P12 | An aggregator can name itself as every prover | Fixed in the proving code | Every shard proof's public values carry the prover's payout address (`ShardOutput.prover`), the aggregated block proof commits keccak over the provers in shard order and the shard program's verifying-key hash… | [docs/design/execution-layer.md](../docs/design/execution-layer.md) | -| P13 | The litepaper still claims shards with a bond | Fixed | `Site/litepaper.html`, Proving, "How a block gets proven". | [site/litepaper.html](../site/litepaper.html) | -| P14 | Two definitions of the proving base fee, and a quote that cannot know the ratio | Fixed in the spec | One definition. | [docs/design/execution-layer.md](../docs/design/execution-layer.md) | -| P15 | RPC blocks are segments, so `gasUsed` can exceed `gasLimit` | Fixed on a branch, pending merge | `Igneum/exec/src/rpc.rs` reports `gasLimit` as k x `BLOCK_EXECUTION_GAS_LIMIT` for a k-block segment (k = the record's mergeset length, at least 1), beside the segment's `gasUsed`, so `gasUsed <= gasLimit` holds for an… | [docs/design/execution-layer.md](../docs/design/execution-layer.md) | -| E9 | The specification's year is 365 days; the code's is 365.25 | Fixed | Spec 2.5 follows the code (365.25-day year, 63,115,200-s halving, 31.688 IGN per DAA second, 8 decimals noted under O-2.6). | [consensus/core/src/igneum.rs](../consensus/core/src/igneum.rs) | -| E10 | Reds are paid in the code and "more blocks never means more coins" is false | Fixed | Spec 2.5 says reds inside the DAA window are paid to the merging miner (80%) and the pool (20%), that `E` is paid per block so coins are blocks times `E` under the controller's rate, and that the cap is unaffected;… | [docs/review/round-3-2026-10-03.md](../docs/review/round-3-2026-10-03.md) | -| E11 | The homepage burns job fees at launch | Fixed | `Site/index.html`, "Proofs sold to other chains" caption and the tile now read "phase two"; the quoted paragraph had already left the page when the homepage was trimmed (commit a commit). | [site/index.html](../site/index.html) | -| C13 | Monero's seven years do not price a 256 MiB SRAM die | Conceded, stated | `Site/litepaper.html`, What Igneum does not claim, "they say nothing about the price of a chip with the 256 MB cache on its die, and that price is a cost model, not a measurement". | none beyond M16. | -| L7 | "Where the price comes from" | Fixed | Heading "Where fees go" and the sentence deleted, `site/litepaper.html` Economics. | [site/litepaper.html](../site/litepaper.html) | -| L8 | Third-party names as implied outcomes | Conceded, stated | `Site/litepaper.html`, Questions builders ask, "whether it is issued is Circle's decision"; Canto and Blast absent from the page (grep, tonight). | [site/litepaper.html](../site/litepaper.html) | -| G9 | The release-key the team is one person, and a lost key cannot be revoked | Rule fixed | Spec 8.2 item 5, rotation signed by the current key and revocation signed by the previous key (a pre-signed certificate for K0), both published in a block; item 2 moves the policy to before the client ships and adds… | spec 8.2. | -| G10 | The signalling default on first run | Rule written | `Docs/spec/08-client-security.md` 8.3 item 2 now ends: on first run there is no last choice, the client signals nothing until the user chooses, and the interface shows that nothing is being signalled. | [docs/spec/08-client-security.md](../docs/spec/08-client-security.md) | -| X12 | Tonight's numbers are quoted before they are logged, and the worker efficiency gap is unexplained | Fixed, logged | Bench-log "5 October 2026 (night), ledger close round 1: X12 the 3 October devnet run from its record"; the launcher half (the eight processes' summed status) stays open until the PC's log is read. | [sim/difficulty/devnet-2026-10-03.csv](../sim/difficulty/devnet-2026-10-03.csv) | -| M22 | The ASIC challenge has no scoring rules, and 2x is not the economic line | Decided | No bounty, so no bounty terms; M22's metrics (hashes per second and per joule per program over at least 100 epochs as a distribution, capital cost per unit of hash rate at a stated volume, the longevity term, the… | M1, O-1.17, spec 1.13 and 1.16, M16's arithmetic. | -| F19 | Old vote keys can be bought; fresh hashrate cannot buy weight | Answered with evidence | A bought key is worth the blocks it holds and nothing more. | [sim/results_v2.md](../sim/results_v2.md) | -| F20 | During a finality pause the program must keep advancing, and nothing says which guarantees survive | Answered with evidence for the test half | , ledger close round 1: F20 finality pause under a 45% silent set through four epoch boundaries"); the gate-3 wording of the four guarantees (O-3.16, O-4.3) stays a decision for the founder. | spec 4.3 (O-4.3), 3.3.1, 3.5, 3.7 item 2, 3.9. | -| F22 | Certificates carry 8 to 10 of 12 votes on a healthy network, so locks sit a hair above the floor | Fixed in the node and shipped, rule not yet activated on… | True as measured, and the cause is not a cut-off at all: the node builds the certificate the instant the votes it holds meet Q3, and carries that one. | [infra/cloud-devnet/results/2026-10-04/partition-sin-20261004-140305/partition.md](../infra/cloud-devnet/results/2026-10-04/partition-sin-20261004-140305/partition.md) | -| P16 | The proving gate can be passed by shrinking the shard | Decided | A 12 GB NVIDIA card (4070) is on order for PC 2; O-7.1 runs end to end on it when it arrives, inside the phase 2 gate. | [docs/bench-log.md](../docs/bench-log.md) | -| P17 | Interfaces must show four states, and the design shows three | Fixed on a branch, pending merge | a fork a commit (a commit rebased onto the 0.3.11 fork tip a commit in round 3), suite igneum-exec 16 of 16 on the Mac (labelled a Mac run), the O-7.2 conformance run PASSED on a fast-time 3-node network (bench-log… | execution-layer 2.3, 2.4, 8.2; phone-app 3 and 9; spec 3.9, 10.1. | -| E12 | Selfish operators under a price shock | Simulation half run | No backlog in any scenario, every block proven within 60 s in every hour, hash troughs at 82% of its pre-event level under b and 75% under d (80% at day 30), 10% of cards off under b… | spec 5.1, 5.3, 7.2; execution-layer 4.3, 9.1 R8. | -| E13 | One diagram per payment route, or operator income and protocol income blur | Conceded, stated | `Site/litepaper.html`, Economics, "Every payment route", six rows (emission; base fee; priority fee; external job at launch; external job after the proof bridge; the official client's dev fee as operator income),… | [docs/commercial/prover-customer-brief.md](../docs/commercial/prover-customer-brief.md) | -| E14 | No funding table | Decided | The funding table stays internal until counsel has read it; one public sentence in the litepaper names the unfunded lines (the second client, the external reviewers, the bounty before escrow). | E4, E5, G1, G5; fud-fixes rows 47, 50, 71. | -| E15 | The security budget through successive halvings with low fees and no external demand | Decided | The 4,000,000,000 IGN hard cap stays absolute and there is no tail emission. | spec 2.5, 5.1 to 5.4; E1, E6. | -| G11 | Publish the inspectable components now, labelled experimental | Decided | The specification subset is public as `igneum-network/spec` (`docs/plans/public-repo.md`), labelled; the node fork, the proving code and the harnesses stay private until the benchmark. | [docs/fud-fixes.md](../docs/fud-fixes.md) | -| X13 | One paying customer for a stated reason | Decided | The paid pilot stays in phase 5, the phase 4 gate stays the signature, nothing moves earlier before counsel answers L4. | [site/journey.json](../site/journey.json) | -| X14 | Concentration is unmeasured in four places | Answered with evidence for all four | , ledger close round 2: X14 signing concentration from block payloads"); the independence definition stays the founder's (X5). | X5, F10, P12, spec 9.4.2. | -| X15 | Remove the founders from a test network and show what continues | Answered by design | The design rules the sentence rests on are in force (every node ships a VDF evaluator, spec 4.5; the seed list ships in the client, spec 10.6; no project-run service sits in consensus, no stake, no fee to any team,… | [site/litepaper.html](../site/litepaper.html) | -| X16 | An evidence page with four labels | Written | `Docs/evidence.md`, one row per public claim with five labels (tonight, counting the label column of the claims table: designed 9, implemented 8, tested by the team 26, reproduced externally 3, reviewed independently 2). | [docs/bench-log.md](../docs/bench-log.md) | -| X17 | The miner app must show net earnings and keep jobs away from keys | Designed | Spec 8.8 and phone-app 4.1; measurement O-8.2 and the escape test O-8.3 scheduled for the phase 4 devnet. | [site/litepaper.html](../site/litepaper.html) | -| P18 | The mempool queues transactions no block can carry | Fixed | Correct, and low: the queue slot was reserved against the sender's funds, so it was self-limited. | [docs/bench-log.md](../docs/bench-log.md) | -| P19 | An over-budget proving transaction runs for free, every time, and blocks its sender | Fixed | Correct, medium. | [docs/bench-log.md](../docs/bench-log.md) | -| P20 | The SP1 GPU client panics on shutdown and the compressed stage waited ten minutes | Fixed and confirmed | The buffered save closed the gap, the core proof finished at and the compressed stage started at; shard timings repeated within 0.3 s (core 9.1 s, compressed 10.5 s); a guest that returned 0 bytes on the second run was… | [docs/bench-log.md](../docs/bench-log.md) | -| M23 | Forge timestamps inside the rules and the controller mines you a 10x difficulty for free | Fixed | Correct on every point, and measured first by our own attack run (`sim/difficulty/attacks/README.md`, scenarios 3 and 7): in the simulator a 50% forger took the block rate to 0.12 (earliest stamp) and 0.56 (latest) of… | [docs/bench-log.md](../docs/bench-log.md) | -| P21 | The SP1 proof is not what consensus checks in proving v0 | Fixed in the node behind a named switch | , after an external review the founder accepted at: a valid SP1 proof is a condition of payment in consensus. | none named | -| P22 | The rewards and payouts are inputs to the shard proof, not outputs | Answered by design | The design rule that contains it is in force, spec 7.7 item 6 and design 5.5: the rewards and payouts a shard statement carries are checked against every node's own consensus derivation, so a proof over any other list… | none named | -| M24 | Your two-lane controller oscillates for an hour when a second miner joins mid-epoch | Rolled out | Rule v2 activated on the live devnet at DAA 33,000 by the height switch after a 12-node cloud rehearsal (settle 157 to 272 s, no swing); node 1, the seed, the observer and the three app machines crossed the height on… | [sim/difficulty/records/live-2026-10-04.csv](../sim/difficulty/records/live-2026-10-04.csv) | -| D1 | Your users are a gate, not a fact | Conceded, stated | Correct on the count and on the definition. | [docs/bench-log.md](../docs/bench-log.md) | -| D2 | The app share pays nothing | Conceded, stated | `Site/litepaper.html`, Building, Why build here, "a million 100,000-gas calls a day at a 1 gwei tip pays about 7,300 IGN a year"; Canto and Blast absent from the page (grep, tonight). | [docs/design/developer-adoption.md](../docs/design/developer-adoption.md) | -| D3 | Proof of work in 2027 is a perception cost you cannot measure | Conceded, stated | `Site/litepaper.html`, What Igneum does not claim, "A label that costs nothing. | [site/litepaper.html](../site/litepaper.html) | -| D4 | No dollar, no DeFi | Conceded by decision | , restated here for builders. | [docs/review/round-3-2026-10-03.md](../docs/review/round-3-2026-10-03.md) | -| D5 | I cannot debug a revert | Conceded, scheduled, stated | `Site/litepaper.html`, What Igneum does not claim, "A chain you can debug today. | [docs/design/execution-layer.md](../docs/design/execution-layer.md) | -| D6 | A forged job result reaches my contract and nobody vetoes it | Conceded, contained by rule, stated | `Site/litepaper.html`, What Igneum does not claim, "A veto on job results. | [docs/design/execution-layer.md](../docs/design/execution-layer.md) | -| X23 | One shipped key is an administrator channel to the founder's PCs | Fixed on a branch, pending merge | Three tiers in `relay/lib/guard.mjs` (`authVia`): the console token (header or the phone page's path), the relay's own key (`RELAY_KEY`: reads and reports, never `task`, `run`, `name`, `role`, `secret`, `delete`), and… | [docs/review/round-4-2026-10-04.md](../docs/review/round-4-2026-10-04.md) | -| X24 | The relay token rides in the URL on every request | Fixed on a branch, pending merge | Every client and Mac tool calls `/api/relay?fn=<fn>` with `x-relay-token` (and `x-igneum-key`) as headers: `igneum-agent.ps1` and `send.ps1` (`Api-Url`), `agent.sh` and `send.sh` (through a 0600 curl config file, `-K`,… | [tools/relay.mjs](../tools/relay.mjs) | -| X25 | The PC agent installs itself at every logon, at highest privilege, on every start | Fixed on a branch, pending merge | `Igneum-agent.ps1` calls `Arm-Restart` only on the two paths that end in `shutdown.exe /r` (a task that printed `RELAY-REBOOT` on its own line AND was queued with `--reboot` or `--reboot-continue`), sets… | [relay/clients/igneum-agent.ps1](../relay/clients/igneum-agent.ps1) | -| X26 | The feed is a permanent transcript, and it holds the dl token by design | Fixed on a branch, pending merge | Retention 30 days (`relay/lib/handler.mjs` `expire`: `DELETE... | [relay/lib/handler.mjs](../relay/lib/handler.mjs) | -| X27 | The relay has no clean rotation and no sender binding | Fixed on a branch, pending merge | A per-machine secret (64 hex, `node tools/relay.mjs secret PC1`: written to `~/.config/igneum/relay-machines/PC1` at 0600, its sha256 bound on the relay with `POST secret` (token only), carried to the PC as… | [relay/README.md](../relay/README.md) | -| X28 | Relay hygiene, minor | Fixed on a branch, pending merge | The remaining points. | [lib/wake.mjs](../lib/wake.mjs) | -| G12 | The PoW schedule comes from the environment on every network, including mainnet | Fixed | . | the files above. | -| G13 | The update signature covers binaries that nobody signed | Fixed on a branch and verified locally | The chain already on master was read end to end and run, not asserted. | [packaging/windows/push-inputs.sh](../packaging/windows/push-inputs.sh) | -| G14 | Secrets and identity in the history of a repository with a public date | Decided | `TZ=UTC` in every commit path the tooling owns: `tools/ship-app.mjs` (`git` runs with `env: { TZ: 'UTC' }`), `packaging/ota/publish-jobs.sh` (`export TZ=UTC`, found by the class check), `tools/repo/fresh-repo.sh`… | [tools/ship-app.mjs](../tools/ship-app.mjs) | -| X18 | Two nodes with two override files connect, and only some mismatches fork | Fixed | . | the files above. | -| F23 | The equivocation ban is node-local, so honest nodes refuse each other's certificates | Fixed | . | the files above. | -| F24 | A checkpoint determination is never revisited | Fixed | . | the files above. | -| F25 | The fast-time harnesses cannot start a node, and the timestamp probe tests the old rule | Fixed | Correct, measured. | [rt/logs/fa_s8/n0/node.log](../rt/logs/fa_s8/n0/node.log) | -| X19 | Operational knobs and silences in the shipped node | Fixed on a branch, pending merge | The node half, fork commit a commit. | [protocol/flows/src/flowcontext/clock_skew.rs](../protocol/flows/src/flowcontext/clock_skew.rs) | -| X20 | Cold-sync checkpoint determination is indices times chain length | Fixed on a branch, pending merge | `Consensus/src/processes/finality.rs` `on_virtual_changed` resolves every index the sink can determine in ONE descending walk of the selected chain (`chain_blocks_at`, targets highest first), where it walked from the… | [consensus/src/processes/finality.rs](../consensus/src/processes/finality.rs) | -| M25 | The miner takes the day length from its environment, and the schedule global can tear | Fixed on a branch, pending merge | Correct. | [igneum/miner/src/main.rs](../igneum/miner/src/main.rs) | -| M26 | The interval fault guard freezes its baseline and loops | Fixed | `IntervalGuard` builds its baseline from the healthy intervals of the current worker process (a moving average, two intervals before it can trip) and forgets it when the worker restarts; the STATUS line is printed on a… | [docs/bench-log.md](../docs/bench-log.md) | -| M27 | A flapping node makes the worker rebuild once per template | Fixed | Correct. | the files above. | -| M28 | The kernel text is bound only to its own directory | Fixed on a branch, pending merge | Correct. | [proto-cuda/nvrtc/packfile.h](../proto-cuda/nvrtc/packfile.h) | -| X21 | A wrong program burns power with a green rate | Fixed | Correct. | the files above. | -| X22 | Worker restart paths, minor | Fixed on a branch, pending merge | The four remaining paths. | [app/igneum-app/src/engine.rs](../app/igneum-app/src/engine.rs) | -| E16 | The 20% pool is burned on the live chain, and the text says it pays provers | Answered with evidence and stated | Correct for the live devnet-v4 line. | [docs/review/round-4-2026-10-04.md](../docs/review/round-4-2026-10-04.md) | -| L9 | "100% to miners and provers", "0% anyone else", and no word that devnet coins have no value | Conceded, stated | `Site/index.html`, `site/miner.html` and `site/wallet.html`, a line beside every download control, "Devnet: coins have no value and the chain may be reset."; `site/index.html` Economics tiles, "of emission to miners… | the files above. | -| M29 | The litepaper's app paragraph describes an app that does not exist | Conceded, stated | `Site/litepaper.html`, For miners, "One click, for everyone else", rewritten to Ember 0.3.9 from `app/igneum-app/ui/index.html` (hash rate, blocks found, node, next program, finality votes, the proving tile, the devnet… | [ui/app.js](../ui/app.js) | -| M30 | A block or transaction flood grows the 0.3.4 node by hundreds of megabytes in a minute | Fixed | Measured, cause not yet isolated. | [docs/bench-log.md](../docs/bench-log.md) | -| M31 | The 0.3.4 node cannot produce a block template on mainnet, testnet or simnet parameters | Fixed | Measured on the execution-layer attack network (`tools/exec-attacks/net.sh` runs `--simnet` with no override): three nodes up, 0 blocks, every template refused with that line (`docs/review/redteam-2026-10-04.md` row 27). | [rt/logs/exec_b/miner_node1.log](../rt/logs/exec_b/miner_node1.log) | -| E17 | Unlogged inputs behind the economics, minor | Answered with evidence for PC 2 | RTX 5090 honest 132.2 Mhash/s at 326.6 W median, 3,060 MHz, 50 to 54 C, 100% utilisation (0.40 Mhash/J); 346.9 W at 8 warps per block; the inline settings 415.7 W and 431.0 W (the power limit). | [docs/review/round-4-2026-10-04.md](../docs/review/round-4-2026-10-04.md) | -| E18 | The dev fee is a protocol fee with better PR | Answered by design and with evidence | The fee exists and is disclosed; the rest is wrong in three places. | [docs/design/miner-dev-fee.md](../docs/design/miner-dev-fee.md) | -| X29 | Host and file hygiene, minor | Decided | The curl part: `infra/gpu-bench/upload.sh` writes `header = "x-igneum-key:..."` to a 0600 temporary config and calls `curl -K`; `proto-cuda/windows-app/upload-log.bat` and `proto-cuda/windows-miner/upload-log.bat` do… | [infra/gpu-bench/upload.sh](../infra/gpu-bench/upload.sh) | -| X30 | The live page and the bench page exposed operational detail | Fixed | `Ac89a37` and a commit (a scrubbed copy, the build fails on any private string), a commit (none of the three in the public API), a commit (the menu). | the commits above. | -| X31 | The public testnet dated "August 2027" on the site | Fixed, stated | Every mention of the month is gone from the site and no date is given. | [docs/plans/testnet-go.md](../docs/plans/testnet-go.md) | -| X32 | The roadmap carried calendar months beside a testnet that is weeks away | Fixed, stated | Every calendar month is out of the roadmap. | [site/litepaper.html](../site/litepaper.html) | -| X33 | The public benchmark dated "January 2027" | Fixed, stated | Both sentences read "The public benchmark with a leaderboard ships with the public testnet." (`site/litepaper.html`, For miners and Questions miners ask). | [site/litepaper.html](../site/litepaper.html) | -| X34 | RandomX described as chip-free | Fixed, stated | Four sentences corrected, each with the X9 as the stated fact and its date; every sentence that only names the technique stands. | [site/index.html](../site/index.html) | -| X35 | The class v4 chip headline stated as one number, 2.1x | Fixed, stated; restated | The served chip text is the third review's claim statement ("Igneum remains competitive on accessible commodity GPUs even when specialised mining hardware is assumed to exist, remain compatible and seek profit; its… | [docs/design/latency-ladder.md](../docs/design/latency-ladder.md) | -| X36 | The X9 described as a shipping chip | Fixed, stated; restated | The X9 appears on the served pages only as a precedent (the pre-order, the withdrawal, no benchmark) and no served sentence uses its claimed core as a chip core against the model; the Antminer X5 is served as an… | [site/index.html](../site/index.html) | -| X37 | The class v4 energy premium is a cost the user pays, not a line in a model | Answered with evidence | Measured on the RTX 5090, 145 W of premium unlocked and 82 W at the knee; the RTX 5080 at stock 84 W, its grid running; the team identity says the premium needed for 2x at k = 1 is 103 W at the lock and a premium of… | [docs/plans/counter-asic-3-status.md](../docs/plans/counter-asic-3-status.md) | -| N1 | A 0.3.15 node on the live file wrote blocks every 0.3.14 node rejected | Fixed | The class v4 signal (PROPOSED, `docs/plans/counter-asic-3-node.md` section 6) is the producer's object version in the high byte of the header version; the first 0.3.15 build stamped it from the binary alone, so on the… | [infra/fast-time/node-compat.mjs](../infra/fast-time/node-compat.mjs) | -| N2 | Any peer could crash any pruned node with a sync request below its retention | Fixed | `SyncManager::antipast_hashes_between` (the IBD headers path, `RequestHeaders`) unwrapped the GHOSTDAG reads of the requested low block and of every chain block of the walk; a pruned node holds no GHOSTDAG data below… | unit test `a_sync_request_below_retention_is_an_error_not_a_panic` (a chain of six headers, the genesis's GHOSTDAG… | -| P23 | An unwound transaction leaves the node's view until its sender resends it | Fixed on a branch, pending merge | a fork a commit (the P23 commit, on the merge of `ledger-fixes` and `ledger-fixes-2` onto the 0.3.11 fork tip a commit); `EvmPool::on_chain_removed` (igneum/exec/src/pool.rs) and `ExecService::requeue_unwound`… | [igneum/exec/src/pool.rs](../igneum/exec/src/pool.rs) | -| AP-F8-1 | A load whose source was last written by `or`, `mul` or `mulhi` makes a cross-hash hot set | Fixed in part, finding bounded, stated | Class v4 sub-version 3 (igneum-pow a commit, the audit-freeze tag) is frozen with the dataflow rule, the shared-operand rule, the 0.98 ratio and the total draw; the in-house pass's F8 re-gate reads 60 of 64 seeds under… | [docs/analysis/ca3-v4-uniform.md](../docs/analysis/ca3-v4-uniform.md) | -| AP-F8-4 | The program id's derivation text omitted generator 4's sub-version suffix (interoperability, documentation; no object change) | Fixed | The id and its printed derivation come from one byte recipe (`generator::IdRecipe`, `program_id_recipe`, `program_id_class_recipe`, `Program::program_id_derivation`), so the two cannot drift; the emitter prints that… | [igneum-pow/tests/derivation.rs](../igneum-pow/tests/derivation.rs) | -| AP-F8-5 | The public specification did not describe the shipped acceptance rule (documentary; no object change) | Spec fixed | Sections 1.4.3 and 1.4.6 of `docs/spec/01-lottery-hash.md` rewritten to the shipped rule at igneum-pow a commit with every constant named and every order of operations stated (1.4.3: the two per-register states of the… | [docs/analysis/cryptanalysis/report-acceptance-rule-3.md](../docs/analysis/cryptanalysis/report-acceptance-rule-3.md) | -| AP-F8-7 | The hash's reads are not uniformly random: about half of epochs carry one load site with a biased address bit | Open, priced | 1.6 percent at f = 1/2, nothing at f = 1; the served sentence corrected 8 October 2026 (the site the team, by the team's word): the litepaper's lead reads "dependent reads spread over a multi-gigabyte dataset", the… | [docs/analysis/class-v6/family-gate.md](../docs/analysis/class-v6/family-gate.md) | -| GF1 | A post-quantum signature scheme would need a hard fork, and every vote key is a public BLS12-381 point | Fixed | The byte costs nothing now and a fork later. | none named | -| GF2 | A vote key cannot move: a miner who changes keys re-earns 30 days of weight, and so does the post-quantum migration | Fixed | The successor inherits the window, not a fresh one, so a key rotation costs no weight and the migration of GF1 is one item per key. | none named | -| GF3 | A 256 MB on-chip cache makes the lottery hash 2 to 3x cheaper for the card that has it, and the cache size is a constant | Fixed as a genesis lever, measurement owed | Consumer LLC is 96 to 128 MB today and datacentre 256 MB (`chip-model-v3`, approximate), so the shortcut is a datacentre card's today and a consumer card's in a generation or two. | none named | -| GF4 | The class-group VDF falls to the same quantum computer | Conceded, stated | `Site/litepaper.html`, What Igneum does not claim, "A delay function that outlives a quantum computer. | none named | +| R0 | "Another zkEVM" | Decided | The positioning line is served on every page, and "zkEVM" appears only under the architecture explanation. | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| R1 | A specialised miner will remove most of the cost | Open | Pass when the best supported cost and energy advantage of a re-optimised, programmable adversary sits inside the chosen competitiveness envelope, with its uncertainty published (D3). | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| R2 | Ordinary operators will be priced out | Open | Pass when the reference GPU population is published with both tests per class (existing owner and new entrant) and the cost per accepted unit of work is served for each class. | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| R3 | Mining and proving will not pay once issuance falls | Open | Pass when the five-year coexistence model names credible conditions for sustained commodity participation and names where it fails; a result needing a small network, token appreciation or scheduled chip death has not… | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| R4 | The defence is a rescue fork waiting to happen | Decided | No property assumes a future emergency algorithm change; rotation is optional to the security argument, and seed delay is evaluated only as seed-selection protection. | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| D1 | The numbers cannot be reproduced | Open | Pass when an independent operator reproduces the baseline within declared tolerances from the served kit alone. | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| D2 | Reorganising the work will not stop a specialist | Conceded | The connected-state variant, D2(a), is a KILL as a class; the memory-sharing attack, D2(b), is Open. | [docs/analysis/class-v6/connected-state.md](../docs/analysis/class-v6/connected-state.md) | +| D3 | Chips do not expire on schedule | Conceded | "Every chip dies within a family epoch" is out of the baseline economic model, and chip-arrival percentages are not published. | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| D4 | The capex wall is a fiction | Open | Pass when the five-year coexistence model, whose mandatory stress case has development already paid for, names credible conditions for commodity participation and where they fail. | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| D5 | Proofs are not a protocol guarantee yet | Conceded | Consensus does not enforce proofs today; the switch is in the node and reads never on the devnet. | [docs/evidence.md](../docs/evidence.md) | +| P1 | A pool controls its miners' votes | Open | Pass when the member's retained voting key is committed into its work at protocol level, payment aggregation is separate and verifiable, and pool identity substitution is resisted. | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| P2 | Pools take custody and home miners lose to latency | Open | Pass on non-custodial payouts with practical minimums, local work verification and low-bandwidth participation, and on a published measurement of the accepted-work penalty for home internet against datacentre… | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| P3 | Firo's miner is the bar | Open | Pass when Ember reaches good operating points without third-party software and its optimisation work, compiler settings and safe tuning logic are published beside a comparison. | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| A1 | Why not an Ethereum L2 | Decided | Three separate decisions: EVM-compatible execution for developers (revm), SP1 as the one well-tested proving backend behind a versioned interface, and sovereign GPU-mined consensus. | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| A2 | Proof-system flexibility becomes arbitrary acceptance | Decided | Program identities, verifier versions and security parameters are pinned in the protocol; one backend first, a second only where justified, never interchangeable immature backends. | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| A3 | Rotation is not the defence | Decided | No chip detection in consensus, no hardware whitelists, attestation, per-address quotas or self-reported GPU bonuses; rotation is optional to the security argument. | [docs/evidence.md](../docs/evidence.md) | +| A4 | A concentrated prover can stall the chain | Open | Pass when a withholding concentrated prover is exercised on the no-rescue network with replacement operators, usable inputs, reassignment and explicit behaviour during proof delays, and the network behaves as specified… | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| A5 | Your miner promise covers hardware your prover does not | Conceded | Proving runs on NVIDIA; AMD and Apple mine. | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| A6 | "Everything runs unchanged" is a claim, not a test | Open | Pass when compatibility ships as a product deliverable: representative contracts, wallet fee estimation, indexing, failed transactions, receipts and application assumptions tested, with the documented set of… | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| A7 | The proving market is revenue you do not have | Conceded | The external proving market is not built and stays out of revenue assumptions until it is. | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| B1 | Proven execution means the block is final | Decided | The boundary is stated wherever the proof architecture is explained. | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| B2 | EVM-compatible means Ethereum's security | Decided | The boundary is stated wherever the proof architecture is explained. | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| B3 | ZK means private | Decided | The boundary is stated wherever the proof architecture is explained. | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| C1 | Ravencoin already does this | Open | Pass when benchmarks against Ravencoin's KAWPOW, an operating system with the same stated objective, are published and show a stronger result or a more valuable overall offering. | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| C2 | Ergo is an operating benchmark | Open | Pass when the comparison with Ergo, on its live behaviour rather than its papers, is published. | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | +| C3 | Number one is unsupported | Conceded | No "number one" claim before comparative results and adoption exist. | [docs/plans/igneum-2.0.md](../docs/plans/igneum-2.0.md) | diff --git a/docs/provenance.md b/docs/provenance.md index 2b8fda547..77906d097 100644 --- a/docs/provenance.md +++ b/docs/provenance.md @@ -8,8 +8,8 @@ How to read the licence column. "Verified" means the LICENSE file or the crate's | Component | Origin (project, licence, repository) | What Igneum changed | Why the design needs the change | How the change is measured | |---|---|---|---|---| -| GHOSTDAG ordering | Kaspa, rusty-kaspa. ISC, verified (`vendor/rusty-kaspa/LICENSE`, "Copyright (c) 2022-2024 Kaspa developers"; workspace `license = "ISC"`). https://github.com/kaspanet/rusty-kaspa | Unchanged algorithm. Parameters set for 1 block per second: k 18, 10 max parents, mergeset limit 180, merge depth 3,600 blocks (`consensus/core/src/config/bps.rs`, `params.rs`) | Launch rate is 1 block a second (CLAUDE.md), rising later. These are the values Kaspa mainnet ran before Crescendo, so nothing new is asserted about the ordering | Spec section 2.1; bench-log "igneum-node devnet v0: 3-node igneum-devnet at 1 BPS"; a test in `params.rs` pins every value | -| Node software (the fork) | rusty-kaspa v2.1.0, commit `01b532e8` (22 Sep 2026). ISC, verified. Fork at `vendor/igneum-node`, one commit per change on top of the base | Header gains `vote_key_hash`; genesis blocks; network ids `igneum-*`; devnet ports; DNS seeders emptied; address prefixes; emission schedule and 80/20 coinbase; PoW engine trait; PoW check moved after GHOSTDAG; rename of every user-visible string to `igneumd`. Full list: `docs/fork-divergence.md` | Each row there states the reason. The short version: finality rule v2 needs a vote key in every header, the emission is Igneum's own, the lottery hash needs chain state, and no Igneum node may ever dial a Kaspa peer | `docs/fork-divergence.md` (file, change, why, risk, merge note per row); bench-log devnet v0 and "first devnet blocks on the real lottery hash" entries; the four-node rename test of 3 Oct 2026 | +| GHOSTDAG ordering | Kaspa, rusty-kaspa. ISC, verified (`vendor/rusty-kaspa/LICENSE`, "Copyright (c) 2022-2024 Kaspa developers"; workspace `license = "ISC"`). https://github.com/kaspanet/rusty-kaspa | Unchanged algorithm. Parameters set for 1 block per second: k 18, 10 max parents, mergeset limit 180, merge depth 3,600 blocks (`consensus/core/src/config/bps.rs`, `params.rs`) | Launch rate is 1 block a second (CLAUDE.md), rising later. These are the values Kaspa mainnet ran before Crescendo, so nothing new is asserted about the ordering | Spec section 2.1; the measurement record in the repository (docs/bench-log.md); a test in `params.rs` pins every value | +| Node software (the fork) | rusty-kaspa v2.1.0, commit `01b532e8` (22 Sep 2026). ISC, verified. Fork at `vendor/igneum-node`, one commit per change on top of the base | Header gains `vote_key_hash`; genesis blocks; network ids `igneum-*`; devnet ports; DNS seeders emptied; address prefixes; emission schedule and 80/20 coinbase; PoW engine trait; PoW check moved after GHOSTDAG; rename of every user-visible string to `igneumd`. Full list: `docs/fork-divergence.md` | Each row there states the reason. The short version: finality rule v2 needs a vote key in every header, the emission is Igneum's own, the lottery hash needs chain state, and no Igneum node may ever dial a Kaspa peer | `docs/fork-divergence.md` (file, change, why, risk, merge note per row); the measurement record in the repository (docs/bench-log.md); the four-node rename test of 3 Oct 2026 | | Difficulty controller | Kaspa sampled DAA (KIP-4) in rusty-kaspa, ISC, verified, kept as the retarget. Prior art studied: LWMA by Zawy (zawy12/difficulty-algorithms, licence approximate: MIT) and Monero's sorted and trimmed window (monero-project/monero, approximate: BSD-3-Clause). No code from either | Unchanged in the fork today (comment block only, `consensus/core/src/config/constants.rs`). The hash speed steps at every hourly program change, so a rule that tracks a step within an epoch is in progress: a two-speed rule (fast response to a step, slow drift otherwise). Not in spec 0.1 | Programs differ in cost (35 to 48 Mhash/s across seeds on one GPU), so a 44-minute window spends half an epoch at the wrong block rate | Spec section 2.3 names the two remedies and the gate 2 simpa run that decides; bench-log first-run and RTX 5090 entries hold the per-seed rates. The two-speed rule gets its own bench-log entry when it is simulated | | Random-program idea | RandomX by tevador, Monero. Licence approximate: BSD-3-Clause. https://github.com/tevador/RandomX (not yet cloned under `vendor/`; CLAUDE.md asks for it) | The idea only. Igneum's generator is new code (`igneum-pow/src/generator.rs`): a program drawn once per hourly epoch and compiled to native GPU code, with a per-hash random data path. RandomX draws a program per hash and interprets it on a CPU | A GPU cannot interpret a fresh program per hash at a useful rate; it compiles one program per hour instead. The target hardware is the opposite of RandomX's by design | Spec section 1 (generator, test vectors); bench-log "proto-metal first run", "RTX 5090 first run", "igneum-pow bit-exact" (96/96 vectors, three GPU vendors) | | Memory-hard dataset | RandomX cache lineage (tevador, BSD-3-Clause approximate): a small cache that derives a large dataset by dependent reads | New construction, same shape: 256 MiB cache of chained ChaCha12 blocks, 8 dependent reads per item, dataset 1 GiB in the prototype and 2 GB at genesis, growing on a genesis-fixed schedule (`igneum-pow/src/memhard.rs`, `proto-metal/MEMHARD.md`) | A light verifier must hold only the cache; a miner must hold the dataset; the dataset must outgrow any fixed chip memory. RandomX's dataset has one size for ever | `proto-metal/MEMHARD.md` section 2.2 (recompute 4.8x slower than load, Apple only); bench-log "memory-hard dataset" entries on Metal and the RTX 5090 | @@ -17,11 +17,11 @@ How to read the licence column. "Verified" means the LICENSE file or the crate's | ProgPoW and KAWPOW | ProgPoW (EIP-1057 text, ifdefelse/ProgPOW; KAWPOW on Ravencoin since 2020, RavenProject/Ravencoin, MIT approximate). Prior art, no code used. Not yet cloned; `docs/fud-fixes.md` item 48 asks for the clone and citation before the repository is public | Nothing taken. The difference: ProgPoW and KAWPOW randomise the maths inside a fixed program shape every few blocks; Igneum regenerates the whole program every hour over a growing dataset, with automatic era draws and no human in the loop | Stated so that the "first" claim in the litepaper is accurate (FUD ledger M4) | Litepaper "What has never been done before", row 1, rewritten 3 Oct 2026 | | Class-group VDF | Chia, chiavdf. Apache-2.0, verified (`vendor/chiavdf/LICENSE`), commit `7e62ce14`. Wesolowski's proof (Efficient Verifiable Delay Functions, EUROCRYPT 2019), a paper, no licence | NUDUPL and NUCOMP ported from chiavdf's `qfb_nudupl` and `qfb_nucomp` into `proto-vdf` (Rust, over GMP through `rug`); fresh 1024-bit prime discriminant per input; 256-bit Fiat-Shamir prime (Chia uses 264); Igneum tags for the epoch and era paths. The textbook composition is kept as an oracle | The program seed must come from a certified checkpoint with a delay no miner can skip, so the seed cannot be ground. Chia's group needs no trusted setup | Spec section 4.2 (15,000 random cases agree with the oracle; 163,000 squarings per second; 4.5 ms verify); bench-log "proto-vdf" entry. GMP itself: LGPL-3.0 or GPL-2.0 dual, approximate, prototype only; the production dependency is decided with the wire format (O-4.5) | | revm | Ethereum ecosystem, bluealloy/revm. Licence approximate: MIT. https://github.com/bluealloy/revm (not yet cloned) | Unchanged, credited. Driven by an Igneum block executor that feeds it the DAG's canonical sequence with the environment table of spec 7.1 and two-dimensional gas | The same EVM runs natively and inside the zkVM (reth, rsp and SP1 Reth all use it), so native and proven execution share one code path | `docs/design/execution-layer.md` D6 and section 2.1; differential test plan against reth (section 8.5). Nothing measured yet | -| SP1-class provers | Succinct, succinctlabs/sp1. Licence approximate: MIT or Apache-2.0. Not yet cloned | Unchanged, behind the versioned `ProofSystem` trait (`docs/design/execution-layer.md` 5.6). Version 1 is SP1 (Hypercube class, hash-based). Devnet v1 runs a stub that signs claims | Consumer cards prove hash-based systems without elliptic-curve MSM; the trait makes a swap a release (90% signalling, 3-month overlap, one wrap), never a redesign | No SP1 shard has been proven on any card in this repository (FUD ledger P1, P3). Phase 2 gate: shard time on a 3060-class card, published pass or fail | +| SP1-class provers | Succinct, succinctlabs/sp1. Licence approximate: MIT or Apache-2.0. Not yet cloned | Unchanged, behind the versioned `ProofSystem` trait (`docs/design/execution-layer.md` 5.6). Version 1 is SP1 (Hypercube class, hash-based). An early devnet ran a stub that signs claims | Consumer cards prove hash-based systems without elliptic-curve MSM; the trait makes a swap a release (90% signalling, 3-month overlap, one wrap), never a redesign | No SP1 shard has been proven on any card in this repository (FUD ledger P1, P3). Phase 2 gate: shard time on a 3060-class card, published pass or fail | | BLS12-381 | Curve by Barreto, Lynn and Scott; blst by Supranational. Licence approximate: Apache-2.0. https://github.com/supranational/blst (not yet cloned) | Unchanged, credited. The header carries the BLAKE2b hash of a G1 compressed public key (48 bytes); every voter signs every 30-s checkpoint; signatures aggregate | Finality rule v2 needs one aggregate signature per checkpoint from thousands of keys | Spec section 3.1 (W1) and 2.4; `sim/results_v2.md` for the rule itself. Signature cost not yet measured | | Hashing in the node | rusty-kaspa `crypto/hashes`, ISC, verified. Crates linked by the fork, licences read from the local cargo registry: blake2b_simd 1.0.2 (MIT), blake3 1.8.3 (CC0-1.0 or Apache-2.0), sha2 0.10.8 (MIT or Apache-2.0), keccak 0.1.6 (Apache-2.0 or MIT); sha3 0.10.8 not in the local registry, approximate: MIT or Apache-2.0 | Unchanged, credited. BLAKE2b with domain separation for block, transaction and PoW pre-hashes (`BlockHash`, `TransactionHash`, ...), BLAKE3 keyed for the sequencing-commitment and payload hashers, SHA-256 for ECDSA signing hashes, cSHAKE256 (Keccak) in the kHeavyHash stub that stays as the default engine and for pruning-proof block levels | The chain's hash for everything except the lottery is the one the forked commit uses (spec 0.6), so nothing unverified enters consensus | `hash_override_nonce_time` gained one field (fork-divergence row 1); every header-hash test vector was regenerated and the four genesis hashes re-derived | | Address format | Bitcoin BIP 173 character set (bech32, Pieter Wuille and Greg Maxwell; BIP licence approximate: BSD-2-Clause) with the CashAddr polymod checksum of Bitcoin Cash (the source cites bch.info), as implemented in rusty-kaspa `crypto/addresses/src/bech32.rs`, ISC, verified | Prefixes only: `igneum`, `igneumtest`, `igneumsim`, `igneumdev` (Kaspa: `kaspa`, `kaspatest`, `kaspasim`, `kaspadev`). The script public key behind an address is unchanged | No Igneum address string may parse as a Kaspa address on any network | Fork-divergence row 9; test vectors in `addresses` and `txscript` regenerated and passing | -| The EVM | Ethereum (Yellow Paper and ethereum/execution-specs, CC0 approximate). Cancun opcode set, precompiles 0x01 to 0x09 | Semantics on a DAG: `block.number` is selected-chain height, `block.timestamp` is non-decreasing by a max rule, `prevrandao` is the VDF epoch seed, chain ids 4461, 4462, 4463 (historical: Devnet 3 answers chain id 4464 since its class v5 floor at DAA 68,400 on 8 October 2026, 4463 below it; the current id is in /release.json); 0x0a absent; gas has a second dimension | Blocks on a DAG have no single parent and no header state root; proving cost is a second resource; the random beacon must be unbiasable | Spec section 7.1 (normative table); devnet measurement R9 for timestamp drift; `ethereum/tests` replay in the differential plan | +| The EVM | Ethereum (Yellow Paper and ethereum/execution-specs, CC0 approximate). Cancun opcode set, precompiles 0x01 to 0x09 | Semantics on a DAG: `block.number` is selected-chain height, `block.timestamp` is non-decreasing by a max rule, `prevrandao` is the VDF epoch seed, chain id 4464 on the devnet and 4461 reserved for mainnet (the current id is in /release.json); 0x0a absent; gas has a second dimension | Blocks on a DAG have no single parent and no header state root; proving cost is a second resource; the random beacon must be unbiasable | Spec section 7.1 (normative table); devnet measurement R9 for timestamp drift; `ethereum/tests` replay in the differential plan | | kHeavyHash (kept as a stub) | Kaspa, rusty-kaspa `crypto/hashes/src/pow_hashers.rs` and `consensus/pow/src/matrix.rs`, ISC, verified | Kept untouched as `HeavyHashEngine`, the default engine when the `igneum-pow` feature is off, and the block-level source for pruning proofs until seeds are threaded through | Lets the devnet run and lets upstream pow changes merge cleanly | Fork-divergence rows 14 and 15; open item in the same file (pruning-proof block levels) | ## What is new in Igneum @@ -30,7 +30,7 @@ Nothing here has a precedent that Igneum could have copied. Each item names the | Piece | What it is | Where it is specified or measured | |---|---|---| -| The hourly header-bound GPU program | A program drawn per epoch from a VDF seed, compiled to native GPU code, with the nonce-zeroed header hash absorbed into the init words so one nonce serves one header | Spec section 1 and `igneum-pow/src/bind.rs`; bench-log "first devnet blocks on the real lottery hash" | +| The hourly header-bound GPU program | A program drawn per epoch from a VDF seed, compiled to native GPU code, with the nonce-zeroed header hash absorbed into the init words so one nonce serves one header | Spec section 1 and `igneum-pow/src/bind.rs`; the measurement record in the repository (docs/bench-log.md) | | Sustained-mining finality, rule v2 | Vote weight is blue blocks per BLS vote key over a flat 30-day window; every voter signs every 30-s checkpoint; lock at 2/3 of active weight and at least 56.7% of total weight; no stake, no other chain | Spec section 3; `sim/results_v2.md` (0 conflicting locks in every partition and eclipse scenario) | | Two-dimensional gas and the per-frame app share | Execution gas on Ethereum's schedule plus proving gas from a calibrated table; 20% of the priority fee attributed per call frame to the registered developer of the contract that ran | Spec sections 5.1, 5.2; `docs/design/execution-layer.md` section 4 | | The shard market and the native proving precompile | Shards cut from the native trace, assigned by sortition to 8 eligible provers for 10 s, then open; a `Prover` system contract that takes a job and returns the result by a later proof record | Spec section 7.2; `docs/design/execution-layer.md` sections 5 and 6 | diff --git a/site/404.html b/site/404.html index 2466fee6d..fb8ed730e 100644 --- a/site/404.html +++ b/site/404.html @@ -4,7 +4,7 @@ <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1, viewport-fit=cover"> <title>Page not found. Igneum - + @@ -77,7 +77,7 @@ main{flex:1} IGNEUM - devnet + Igneum 2.0 devnet starting