diff --git a/docs/plans/finality-native-runs-2026-10-09.md b/docs/plans/finality-native-runs-2026-10-09.md new file mode 100644 index 000000000..d4b4a5c57 --- /dev/null +++ b/docs/plans/finality-native-runs-2026-10-09.md @@ -0,0 +1,48 @@ +# The native finality runs of 9 October 2026 (the node lane; Review B F04 and I03; V6-09 beside them) + +Status: PLANNED (written 8 October 2026, 21:4x UK, main's order under the night rule). The runs start from 00:30 UK on build-8 and build-9 (build-7 for the two-node cache case), under the lease pool, every process under a pid watcher that restarts it and records the restart; the rows land in `sim/results_v2.md` under "Rule v4" with their result files under `sim/finality-attacks-results/` and the registry batch (FIN-08, FIN-02's native half, ROT-05, VER-08's recovery row) through `tools/ci/test-record.mjs`, by 07:00 UK. An accelerated simulation is evidence of the rule's shape, never operating history: every row below runs on real nodes with the 60x file's windows (W = 120 DAA s at 1 block/s) and says so. + +The harness: `tools/finality-attacks/v3.mjs` (three nodes on the 60x file, six voters, one-way delay 300 ms per proxied link, the pass lines of `finality-guarantees.md` 6.7), extended for the rows that need a third island, an equivocating key, a stopped voter, a succession item and a backfilled checkpoint history; the extensions land with the rows. The node: the 2.0.2 line (successor-2.0.1 at or after 45e7b910: rule v4 with the pause fix 6872db13, the lock kind of F04, the finality-backed take of a9ff0a25) in the gate pair under `/srv/artefacts/200-/node-lane` (gate evidence; never a fleet binary). + +## 1. The 40/40/20 case past the window with equivocation (F04, the reviewer's hard FAIL line) + +Three islands by weight 40 / 40 / 20 (keys p0,p1 on n0; p2,p3 on n1; q0 on n2, shares 0.2 / 0.2 / 0.2 / 0.2 / 0.2 across five keys, the sixth key e the equivocator at 0.2 placed by the row), WARM 230 s, SPLIT 420 s (longer than the window after the last lock), HEAL 400 s, 1 block/s in all, rule v4 with the recovery on. + +| row | the equivocator e | expected under 6.2 and 6.5 | the FAIL line | +|---|---|---|---| +| 1a | absent (honest three-way) | no side locks during the split (no island holds more than half of the anchored table), every node pauses, the heal locks within two intervals, 0 conflicts | any lock during the split; any conflicting certificate | +| 1b | mines on island A only (reaching 60 of the anchored table on A) | A recovers once a full window has passed (the recovery lock at the first index past the window), B and C pause, the heal brings B and C onto A's chain, 0 conflicts | a lock on B or C; two certificates at one index | +| 1c | mines dust-valid on A AND B (the 6.5 bound: both at 60 percent) | BOTH A and B recover after the window: two recovery certificates at one index, the measured conflict the spec names; the heal strips e (3.6) and reports the pair under 3.11.4; the history through the anchored lock untouched | a recovery lock presented as final on any surface (lockKind must read "recovery" on both); the anchored history moving | +| 1d | 1c under the pause-only variant (recovery off) | no lock on any side during the split, the pause until the heal, 0 conflicts (the strictly stronger guarantee of 6.5) | any lock during the split | + +Measured per row: new locks per side during the split (index and DAA), the lock kind on `igneum_getFinalityCheckpoints` (final or recovery), conflicting certificates logged, disagreeing locked indices after the heal, the equivocator's strip at the heal (the ban line), every pre-heal lock kept, the first lock after the heal (s). + +## 2. The pause-only alternative with backfill, missing history and the old keys returning (I03) + +Rule v4, recovery off. A chain is run 230 s with six voters, then split 3/3 for 420 s (no lock on either side, the pause), then healed; during the heal window: (a) a fresh node joins from genesis and must backfill every checkpoint and certificate (the historical-checkpoint backfill; it reads the same latest lock as the three), (b) one node restarts from a datadir with its finality state removed (missing historical data: it rebuilds from the chain's carried certificates and must agree), (c) every old key returns and signs (the pause ends on two thirds, the lock within two intervals). Measured: the backfilled node's locked indices equal the others' (0 disagreement), the restarted node's, the first lock after the return, 0 conflicts. + +## 3. Authority succession and strip, restart, certificate arrival order, seed boundaries (I03) + +| row | shape | expected | +|---|---|---| +| 3a | a voter leaves (W7, the leave item carried) mid-window, the rest sign | the frozen table reduces by the leaver (frozen_floor), the next lock at two thirds of the remaining; the leaver's weight never counts | +| 3b | a key is stripped (an equivocation evidence item carried) one interval before a lock | the strip applies before the lock's test; a certificate carrying the stripped key's signature counts it as 0 | +| 3c | a voter restarts between determination and lock (kept datadir) | it votes once (no double vote), the lock forms on time, its locks equal the others' after the restart | +| 3d | two certificates for consecutive indices arrive in reverse order at a node (the fleet's 263-then-262 read on hub-1) | both lock under the rule, the LOCKED line prints the certificate's fractions (the 2.0.2 log fix), no "signed 0" artefact | +| 3e | a seed boundary (the epoch's reference block) inside a pause | the seed is drawn from the chain block below the lead whether or not it is locked (section 8); mining continues; the first lock after the pause names a block past the boundary | + +## 4. The inter-chain verifier and a recovery lock (I03) + +The Sepolia certificate verifier (dex lane's bridge, 0x874D8Be5… on igneum-devnet-4's voter table) given (i) a final certificate, (ii) a recovery certificate from row 1b: it accepts (i) as final; for (ii) it must read lockKind "recovery" and never present it as final (the bridge doc 829b839ec: recovery locks fail closed on the verifier, which reads only weight). The row records what the verifier answers for each and the receipt page's word; a recovery certificate accepted as final is the FAIL line. + +## 5. V6-09, cold compressed verification on the minimum validator (with the enforced-proving lane) + +One validator node pinned to one core (taskset), no warm relay cache (fresh datadir, the pool empty), fed by a relay peer: (a) ten cold valid shard proofs in one block's carried records (the measured 0.668 to 0.710 s a proof on one loaded core); (b) ten expensive-invalid payloads (proofs whose bytes deserialise to the largest accepted shape and fail at the last check) with the relay's pre-deserialise cap (MAX_PROOF_BYTES in consensus-core, V6-08's constant) and the in-flight bound of 8; (c) a forged record under each pair across the key and fee transitions, before, at and after activation, on an unmodified validator. Measured per row: verify seconds per proof, block-validation time against the deadline, the NotReady retries, memory before and after deserialising, the carrier paid exactly once (igneum_getProofRecords on the validator against the relay's), the forged record refused with its reason. The rows go to the test map cell `harness:v6-09-cold-verify` with the F0 fixture, by 12:00 UK 9 October. + +## 6. The two-node cache-history test (F01, with the proving lane's fix 3f672661) + +Two nodes, one with a warm verdict cache built on carriers 1..k, one cold, both fed the same blocks in a different order (the cold one sees the later carrier first): identical block-validity verdicts and identical payouts (igneum_getProofRecords and the paid map equal on both), with the known-failed shape first (the pre-fix node's cached context refusal replayed under a later carrier, the 19:49 UK reproduction). On build-7 by 03:00 UK. + +## Boxes and clocks + +build-8: sections 1 and 2 (the 40/40/20 rows 1a to 1d, then the backfill case), from 00:30, rows by 05:00. build-9: sections 3 and 4 (after the 2.0.2 line's gate ends), from 01:00, rows by 06:00; section 5 with the enforced-proving lane's fixtures, rows by 12:00. build-7: section 6, by 03:00. Every run under `lease pool N --class release` with a pid file and a watcher; a stall is recorded for the 08:00 read-back, never a hand-made lock. The rows land in sim/results_v2.md with their result files and the registry batch by 07:00 UK, the plan's status moved to MEASURED per section as each lands.