docs/spec/proving-enforcement.md (the rule in the body and the payment, the named switch verifier_in_consensus and what each object does, the tests per refusal, the cost section, the activation plan, the four-stage P22 statement, the fast-time case); the ledger entries P21 and P22 updated; infra/fast-time/override-60x.json lists the switch; infra/fast-time/proving-enforcement.mjs runs the seven shapes across the floor. The node code is on enforced-proving-node (the fork, 0.3.25 node line).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The external review of 8 October 2026 (accepted 16:1x UK): the boundary must be explicit; a timeout alone cannot tell a node whether missing miners are gone or partitioned. Rule v4: the frozen table is anchored (never expires by time) and, after a full window with no certificate, a lock needs Q3 plus more than half of the anchored table on the chain through the last certified checkpoint (the majority-continuity recovery, verifiable from the chain). Safety and Liveness stated with their arguments, the pause's duration by cause, what is not guaranteed, the single answer on program rotation during a pause (seeds from chain blocks, O-4.3 closed), the four interface words and where each interface shows them.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Spec 01 1.4.6: the constants table gains ACCEPT_TAG, LANES, the (c'') window-cap literal and the first-refused reading of MAX_SATURATED. tools/ci/spec-constants-check.mjs joins the gate: every "Constant | Value | Where" table of spec 01 against the crate's pub const items (an expression over constants evaluated, a byte string compared, a pending row skipped while the constant is absent), known-failed fixture first. igneum-pow/tests/spec_readback.rs derives every pinned id of the "Seed | Attempt | Id | Note" table through the crate and draws each class v4 row with its era to the stated attempt; a must-differ row asserts another id (box suite on the branch: 64 + 7 + 4 + 19 + 2 + 7 + 2 passed, build-remote rc 0).
tools/ledger-page.mjs: both entry heading forms render (M1 and AP-F8-1; the single-letter form dropped every in-house pass row from /ledger), the pass gets its own section, a known-failed self-test in the gate. docs/fud-ledger.md drops the USD 50,000 prize clauses and "paid independent cryptanalysis" (decision item 1 of 6 October: no bounty; the in-house rule of 7 October), so the regenerated site/ledger.html carries neither. checks.txt regenerated (73 checks).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
1.4.3 rewritten: the draw's two per-register states (fresh, fresh_value), the dataflow table and the shared-operand rule the class v4 shape uses for the load source, the empty-list fallback, the era window draws, the shadow block's draw from the same stream (256 ALU slots, era draws consumed), the draw counts per class (592, 720, 3,536).
1.4.6 rewritten into 1.4.6.1 to 1.4.6.6: (a) over two passes of the base instructions, (b), (a') to its fixpoint then a checking pass over base then shadow, (c) with the shadow block executed 27 times per iteration and its inputs and limits in tables, (c') saturated sources at 164 of 16,384, (c'') the distinct-index ratio at 2^20 evaluations with the 0.98 floor and its integer form, the attempts and the two caps (32; 256) with the measured per-part rates, the last resort stated as unreachable and unverified (fails (a) on 251 of 3,000 seeds), the program id with the generator-4 "sub/" || 3_le16 suffix and the class-rung form, a "Constants of the shipped rule" table and a "Pinned program ids" table in the shape the hash lane's read-back test parses.
1.7 gains the shadow block's execution; 1.13.1 names the ninth consumed era draw (the latency ladder); 1.8.5 carries the one-line pointer to class v5's 1.8.6 (agreed with the v5 lane).
docs/fud-ledger.md AP-F8-5 (the finding, the fix, the check); docs/ledger-public.md regenerated.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
generator.rs: IdRecipe (bytes + labelled parts), program_id_recipe and program_id_class_recipe build the bytes the id hashes and the text program.json prints, Program::program_id_derivation picks the form as program_id does. emit.rs prints that text. Spec 01 section 1.4.6 (the "Program id" paragraph) states the suffix, the class v5 form (generator 5, no suffix) and the rung form. tests/derivation.rs re-derives each of the 18 pinned packs' ids from its own derivation string with the pack's fields only (the plain text gives 8aa9f185d63f269e for the devnet v4 pack where the id is a785001687d8688a: the known-failed case). Packs: program.json re-exported for the 7 generator-4 packs and the 9 shadow ladder packs, one line each (the derivation); every other file byte-identical on re-export, ids and fingerprints unchanged. No object change.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The sweep (main's item 1): 199 tracked text files, 783 lines. The founder's full name, first name and possessive become "the founder" (sentence starts capitalised); the lowercase operating-system user name in WSL paths and commands becomes <user>; the second owner login becomes "the second owner login"; the three earlier businesses and the two other brands become "the other business", "the earlier entity", "the earlier business" and "another brand"; the Chrome profile rule names the igneum.network profile, not the profile's label. The standing commit login igneum-labs is not a founder term here: the fresh-repository step renames it in the history (docs/plans/history-rewrite.md, tools/repo/fresh-repo.sh).
The patterns never appear in plain text in the tree (a plaintext list would be the hit): tools/ci/founder-strings.b64 (perl regex, tab, a sample per row) is read by tools/ci/founder-strings-check.sh (every tracked text file, perl, known-failed first: the self-test plants each row's sample in a fixture and the hit must name the file), by tools/community/discord-hooks.mjs (the guard's founder and business rows; the test takes its fixtures from the samples) and by tools/repo/fresh-repo.sh (the business names of the rewrite rules). site/forbidden-strings.txt carries the same patterns as b64: lines, decoded case-insensitive by site/scrub.mjs and tools/ci/launch-gates-check.mjs (whose fixture now plants an encoded made-up name). The check runs in the gate's tree checks on every merge.
Not in this commit, by main's word: the 105 commit messages and 40 personal-identity commits that need the history rewrite (listed, not run), and the secrets found by gitleaks over the history (reported with owners).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/design/genesis-forward.md names the three fields, their defaults, the digest change and the gates; spec 03 W1 and W5
amended and the W5 implementation row filled; spec 01 the cache rung beside the schedule; spec 04 the class-group VDF's
quantum fallback flagged, not sized; infra/fast-time/key-succession.mjs (3 nodes, one CPU miner each: the window fills,
a succession carried once on every node, refused twice, scheme 1 refused by every node; the known-failed case
--expect no-succession first); override-60x.json carries the four new keys at never.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>