The F3 record and its harness crate (tools/attack/f3-cache: the extracted chain,
the exhaustive closure search, the pebbling cross-check, the store-set DP and
brute force, the two planted broken chains). The optimal-placement observation
(3.17 blocks per read at f=1/8, 16.0 at f=1/64) noted against funding.md B2.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The chip-model sweep reproduces the numbers (2.1x at k=1 GDDR7, 3.9x at k=0.33,
matching fud-ledger M32). The finding is the framing: M32 calls k=0.33 the X9's
measured core and the ladder branch section 5a calls it a measured class, but
the Antminer X9 was withdrawn before launch and never benchmarked, so k=0.33 is
a claimed datasheet bound. This also questions the merged ledger X34 (RandomX
has a shipping chip). The public X9 sentences are held unchanged until the
coordinator research agent confirms the withdrawal; the re-cut is specified.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The internal cryptanalysis pass before the freeze tag cryptanalysis-target-1
(docs/plans/cryptanalysis.md 4.2). Ten rows with method, known-failed shape,
gate and status. Landed: F5 chip-model sweep (the 2.1x per joule edge over the
5090 at v4 and k=1 reproduces exactly on the GDDR7 measured-anchor column; AWS
F2 hour skipped, no AWS account on this Mac; X9 k=0.33 carried as a claimed
pessimistic bound from a withdrawn design, with the NRE-recovery economic row);
F6 verifier v4 average 4.90 to 5.06 ms one-core cold, 8.23 ms half-core proxy,
under the 10 ms gate (worst-case 10^5 search and the laptop run owed). The rest
are RUNNING or, for F9 header grinding, BLOCKED on the PC 2 or rented-pod go.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The two files stay on their branches (tail-emission, vote-weigh) and are not merged here; the section names the branch and commit for each.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The fleet's 22:09 UK incident (a Mac-side pkill -f <log file name> matched nothing, the roll-everything script lived on and wiped a held box) and the day's two pgrep self-matches are one class. The check flags pgrep -f / pkill -f with a plain literal (every one on a line), any pgrep/pkill on a file-name shape, and ps | grep with a literal; it allows the bracket form, -x, -F pidfile, kill $(cat pidfile), a variable and a full path; 11 banned and 16 allowed shapes in its self-test; 0.15 s over the tree. The 25 pkill -f sp1-gpu-server inside bash -c bodies (which matched the calling bash) are pkill -x; the other 11 literals take the bracket form; prover-socket-check accepts both. Row R in the record; the CLAUDE.md rule names the check and covers pkill and file names.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The box's 34 red rows of 6 October classified (docs/analysis/ci-failures-2026-10-06.md section 6): 22 iterations, 12 in three real classes (instant deaths with nothing kept, a shared worktree directory, an unread dry run). remote-run.sh now: pre-flight (subcommand, manifest, -p package, --features) refuses in a second with exit 3 and a class; the last 400 lines of every run kept in /srv/builds/_log/runs; a class on every row (compile-error, link-error, test-failure, instant, no-test-matched, slot-timeout, no-dir, preflight-*); a cargo test whose filter matched no test exits 3; a per-worktree lock in checkout and run mode; every red row appended to /srv/ci-red/red.jsonl as source box. red-watch.mjs never posts a box row alone and sends one digest a day (counts per class with each class's guard); the timer runs tick. Shared group cired on the box so the runner and build append to one file. Shown in a sandbox on the box: pass, failing test, empty filter, bad package, bad feature, missing subcommand, compile error, broken manifest, two concurrent runs of one worktree.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- docs/analysis/horizon-2026-10.md section 1 rewritten as a standalone page: the project lead's three lines verbatim (fees cannot fund security for a decade; miners need to be the security; wrong constants and claims in our own text) with the recorded meaning (miners are the security always, no time bound, no stake, no outside checkpoints or committee; emission plus fees pay the miners, nobody pays upkeep; emission never decays on a schedule that assumes fees take over); the nine items with what landed tonight (proof verification in consensus da2d17ec with the switch off by default; the leave item 766e70ca; seven-window signalling 0760b844; the peer-driven unwrap class 8e2f5cbe; the receive-side version gate f1ea7a38; Ember's pause wording and activation guard b43d329, e5e1e92, e54a87b; the export-disk cap f9ad70e; the nine ledger rows plus X31 to X33); lane 8's measured verdicts (B never as class content, C the class v5 candidate); lane 5's 1 block/s verdict with the three gates for 10; the four decisions still owed
- lanes table, section 4 (lanes 5, 6, 8) and section 5 (A2 dropped) brought current
- docs/plans/ledger-decisions.md: the fud-close file (c6b0bad) now on master, since docs/fud-ledger.md already points at it, with the standing decisions section appended
- docs/analysis/block-rate-devnet2.md: lane 5's experiment from gpu-fleet b965b64, unchanged
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
pgrep -x git over the whole machine kept the lock whenever any git ran (the pre-push hook's own git push, another agent's build) and the checkout died with "index.lock: File exists". The fact is the lock's age. Class Q in docs/analysis/ci-failures-2026-10-06.md with the GIT_DIR leak of the previous commit.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
168 non-green runs since the first workflow run were classified (docs/analysis/ci-failures-2026-10-06.md): 102 were tree checks that finish in under 25 s on the pushing machine, 40 were GitHub-side refusals nobody saw.
tools/ci/pre-push.sh is the one list of fast checks; ci.yml's site job calls it with --ci and the pre-push hook with --hook (full gate for master and release-*, structural checks for other refs; never writes into the worktree). tools/ci/export-exclude.txt lists research documents outside the public export list, pruned by identity-check.sh and by the mirror's sync.sh (self-test: an excluded path may quote the patterns, an exported one may not); polish.md and this record are its first entries, which makes master green. tools/ci/windows-paths-check.sh (colon, trailing dot or space, reserved names, over 240 characters) runs as the pre-commit hook on staged paths and in the gate. tools/ci/red-watch.mjs plus the red job on the box's runner record one line per failed master or release-* run to /srv/ci-red/red.jsonl; igneum-ci-red.timer posts each once to the updates channel. pow and sims read IGNEUM_CI_RUNNER for the box. no-foreign-tree-writes.sh no longer exits silently on its warning pipeline under pipefail.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Every shipped surface audited against a named comparator with the file or screen: the pause of
6 October had no cause on any surface for two hours (the node reports no frozen-table reason,
the observer copies the flag alone, /live computes the silent share from the sliding table,
Ember has no pause state); a fresh machine meets two warnings before the first screen (ad hoc
codesign, no notarisation, unsigned Windows installer); every update has been urgent since the
0.3.14 manifest (fork_is_close treats any passed activation as close). Rows Q1 to Q105 with
severity, hours, owner and gate; cross-cutting: one formatter table for every number, the five
6 October rule rows without a tools/ci check, the forbidden-string scope gaps.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/analysis/horizon/new-pow.md sections 0 to 9: scheme A (mining is proving) never, on bytes,
the verifier and sampleability; scheme B (the tensor-shaped integer shadow) prototyped as
proto-newpow/mma-shadow and measured, never as class content on the energy reading, with the R8
two-output correction; scheme C (proof of stored state, sd1: the daily dataset derived from the
execution state) prototyped as proto-newpow/state-dataset, measured on the GPU and the box's
CPU, and put forward as the class v5 candidate with its spec items and the Devnet 2 gate. The
lane's standing rule: a shadow lever only works through joules the honest card is forced to
spend, so shadow work goes where the GPU is least efficient per op. Chip rows in
sim/horizon/new-pow/chip_rows.py by the chip-model-v3 method. Rented box addresses replaced by
placeholders in the READMEs and the run script.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Utility curves for IGN beyond gas with dollar inputs labelled; the proving price as the
forgone subsidy (1 / network hash) against Boundless's published rate; the adopted job floor
overprices the market above about USD 0.014 per IGN; a ten-year security budget with the
measured 5090 row (sustained hash USD 24.8 per GH/s-day against USD 281 rented, so the 20-day
34 percent weight attack costs 11.8x the honest fleet at every price); sim/economy re-run with
the eleven measured cards under eight stresses (T1 to T5 hold; a ten-day prover refusal strands
547,570 IGN a day of pool credit in the escrow with no rule to return it); the dev fee, the
signalling game, and the twelve-row table of what Kaspa, Monero, Ethereum and the zk rollups
did (rusty-kaspa cited by file and line).
Models: sim/horizon/economy-and-utility/ (utility.py, stress.py, security_budget_10y.py,
signal_game.py, devfee.py, results/).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/analysis/51-percent.md: what a 51 percent attacker can and cannot do on Igneum, with
numbers (the selected-chain race over a 90-s hold, the lock as the reorder bound, the veto
at 1/3 of weight and its rental cost, the departure case and the LEAVE item, the p2p surface).
docs/analysis/horizon/consensus-security.md: the attack catalogue across GHOSTDAG ordering,
the difficulty rule, the finality weight, miner signalling, proof records, the exec layer and
p2p, each with the bound and the rental cost at the measured USD 11.7 per GH/s-hour; the
pruned-node unwrap class with its sibling list in the sync and IBD flows; fourteen ranked
defences, three of them not recommended with the reason.
Models and results: sim/horizon/consensus-security/ (ghostdag_sim.py, finality_horizon.py,
cost_model.py, signalling.py, result files).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The 6 October 2026 pause from the observer rows: 20 keys holding 42.7 percent of the frozen
voter table left in three minutes; locks formed without the hub; the 2/3 rule paused at
checkpoint 6843 (53.1 percent of total) and the frozen table (Q5) held the pause for a window
where rule v2 would have locked after 35 minutes. Candidate rules run in a copy of the finality
simulator (seeds 7, 11, 13): only the departure announcement keeps 0 conflicting locks and ends
the pause under an hour. Weight capture priced at the measured USD 11.7 per GH/s-hour: the veto
0.52 x N for 30 days (USD 4,300 per GH/s of network), a lock alone 2.03 x N. Lock delay by voter
count measured on node 1; the ZK light client and prover attestations costed.
Models: sim/horizon/finality-and-weight/ (finality_horizon.py, weight_capture.py,
lightclient_cost.py, merge_results.py, results/).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
the project lead's 6 October 2026 ask: deep backward and forward research across the hash, finality,
economy, network and every shipped surface. This commit carries the first three lanes.
- docs/analysis/horizon/algorithm.md: the chip model on the 6 October numbers (f = 1 GDDR7
chip 5.7x per joule against the 5090 at class v3, 2.1x at class v4 with k = 1), the FPGA
lane tightened to 0.30x to 0.47x per watt, the reserve R0 to R8, the reconciled shadow-N
ladder (section 5.3a) with HBM4 and three verifier brackets, the first measured verifier
proxy on igneum-build-1 (class v4 5.06 ms cold, dr736 10.51: out), the dataset schedule
to 2030; model sim/horizon/algorithm/model.py.
- docs/analysis/horizon/frontier.md: sixteen ideas ranked by payoff over difficulty with the
Monero and Kaspa attacks, prior art cited, the honest never column; model
sim/horizon/frontier/frontier_model.py.
- docs/analysis/horizon/new-pow.md sections 0 to 4: three new proof-of-work schemes defined,
reviewed in two personas, scheme A (mining is proving) ruled out on bytes and
sampleability, B and C in prototype on two rented 4090s; measured rows follow.
- docs/analysis/horizon-2026-10.md: the summary skeleton and the lane table.
Every rental cost cites docs/bench-log.md "Rental cost of hash, 6 October 2026".
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
From the Horizon lane analyses of 6 October 2026 (docs/analysis/horizon/algorithm.md sections 5.1, 5.4 and 8;
docs/analysis/horizon/frontier.md sections 3.11, 4.1 and item I13; both land with the lane's own commit).
(1) Wherever the litepaper or the home page implied that the hourly program, the era draw or the instruction reserve
defeat a chip by surprise (the hero SVG line, the home hourly-program note, the Mining section's three ideas, the
"Every six months" row, the "A chip is impossible" item), the text now says what holds: they are automatic schedule
changes against fixed datapaths and against human forks; a chip wired for one program is useless; against the chip
that stores the dataset every drawn parameter is firmware and everything it needs is public at genesis, so the defence
is the latency-shadow work (class v4) and the price per joule. Ledger M32.
(2) docs/analysis/chip-model-v3.md section 5.3: the HBM activate-bound ceiling (8 per 12 ns, 10.7 G reads/s a stack)
is marked UNMEASURED beside the JEDEC HBM2 figure (tFAW 28 ns, 4 activates: 2.3 G), and the public FPGA line carries
only the measured row (Shuhai, FCCM 2020: 2.4 G reads/s, 0.30x to 0.39x of the RTX 5090 per watt) until an AWS F2
hour measures the ceiling. Ledger M33.
(3) The finality section's "What is not here" paragraph and the glance table's Finality row carry, verbatim: "No coin
is staked. The only thing at stake is 30 days of public work: a vote key's weight is its blue blocks over the window,
and equivocation strips it for 30 days." Ledger F26.
(4) "For miners", under the three-streams table: all of Ethereum L1's proving is about USD 36 a day at the September
2026 tracker cost (a secondary source) against about USD 13,700 a day of year-1 emission at USD 0.005 per IGN (the
price an input, not a forecast), so external proving is a small second income at launch and the lottery pays the
bills. Ledger E19.
docs/fud-ledger.md gains the four rows (Conceded, stated, 6 October 2026); site/ledger.html regenerated (171 entries);
tools/ci/ledger-text-check.mjs carries the five new stated sentences (48 sentences, 0 missing).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
PC 2 job run-ca3-shadow-pc2-20261006 (card empty, every pack bit-exact against the Mac): the 5090 holds its rate to
150,800 ops per hash and loses 2.7 percent at 199,600 under the app's 431 W cap, which binds from 102,100 ops up and
takes the clock from 3,037 to 1,834 MHz (86 MH/s at 330,700 ops); 350 W at the control, 2.65 to 3.27 microjoules per
hash; marginal ALU energy 10 to 13 pJ per counted op. Clock rows OWED (nvidia-smi refused -lgc without rights). Chip
side at N = 100,000 and k = 1: 2.1x over the 5090 on GDDR7, 0.9x over the M5 Max. GO at mx8+sh256x27.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The M5 Max ladder (Metal, packbench, IOReport GPU and DRAM watts without root): latency-bound to about 100,000 ops per
hash, the 5 percent point about 130,000, 11 to 27 W GPU at 100,000 ops, 0.78 to 1.40 microjoules per hash; the
verifier's law 2.06 ms + 3.2 us per 1,000 shadow instructions per warp on one core; every pack bit-exact. The
analysis file with the knob, the chip side (k = 1, 1.5, 0.3), the gates and the consequences; the bench-log entry;
the 5090 rows pending the PC 2 job (the playbook now carries the core-clock rows and the sh256x40 rung).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/plans/counter-asic-3-derivation.md (the design, the acceptance test, the interpreter, the allowance argument,
the measurements, the PROPOSED reserve entry R0 for 1.13.2, what is owed), docs/analysis/chip-model-v3.md section 6
(the per-day derivation rows at 1.0x to 3x allowances), the bench-log entry, relay/playbooks/ca3-derive-pc2.ps1
(one PC 2 job: self-fetched packs zip, the installed worker through NVRTC, the card off only under test with its
key from settings.json). Verifier 4.875 / 4.944 ms per unit on one M5 Max core under the measure lock against
x8's 2.061 / 2.063; Metal build 29 ms against 22; hash rate equal; bit-exact on Metal and Apple OpenCL.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
f = 0, 0.25, 0.5, 0.75, 1 on GDDR7 (the 5090's board), one HBM3 stack and eight HBM3 stacks, scored in energy per
hash, reads in flight per watt, rate per chip and dollars per MH/s against the RTX 5090 at 136.1 MH/s and 326 W.
The curve is monotone toward f = 1; the f = 1 chip reads 5.1x (GDDR7) to 9.2x (HBM3) per joule in the model and
2.1x to 4.8x by the Ethash precedent: over 2x. The mixer and item 2 do not touch it; the levers named are the
5090's watts under a power cap (a PC 2 job, owed) and program work in the latency shadow. Inputs cited with URLs
read 6 October 2026; the mixer counted from memhard.rs at 128 hoisted / 144 unhoisted ops per application.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>