PC 1 on 0.3.14 (6 October 2026, 18:16Z, block 140,662): "segment 140661: port state root 0xe45c... differs from the
node's 0xddd7...". The export was [140661, 140662] with the dump; the 0.3.14 exporter seeds from segment 140,661 and
never replays it, so the only exporter that replays 140,661 (from the restart state, hence the mismatch) is the one
from before 0.3.14: the installed binary was not replaced, the same class as the stale verifier host. The prover's
failure line now names the stale exporter by path when the export carries preState and the output has no "account
dump" line (exporter_failure, unit-tested with the PC 1 text); the real line stays when the exporter did read the dump.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- app/igneum-app/src/prover.rs: igneum_exportSegments [n-1, n] for a shard and [first-1, last] for a segment (never
from 0: on a restarted node the records below the restart carry zero roots and the exporter refused every cut,
the fleet 16:02Z); exec_boundary() reads igneum_getExecStatus.restartNumber (or the startedFrom text on a
0.3.13 node) and the prover never claims a shard or a segment below it
- proving/igneum-prove/export: seeds the port from the export's preState, checks its root against the node's at the
dump's block and replays from the next segment; the restart-replay path stays for exports without a dump
- tools/exec-sync/reorg.mjs: a 300-chain-block reorg on a private fast-time simnet, two cases (the ring, the
persisted-generation fallback after a restart), 18 checks; A's lone miner casts no finality vote because one key
at 83% of the window certified its own branch in the first run and the finality rule refused B's chain, by design
- tools/exec-sync/net.mjs: case 5 (an unreadable flag file blocks loudly, never genesis) and case 6 (the export from
one block below carries the dump; the exporter cuts from it), 15 checks
- bench/proof-systems: the rented RTX 4060 8 GB rows (46) and the table
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
v1 shard 574.4 s at po2 20 (10.66 GB RSS), 698.7 s at po2 19 (8.40 GB), 560.9 s at po2 21 (20.44 GB); empty shard
47.9 s (8.32 GB); receipt 223,882 bytes at every po2; verify 9 to 10 ms in process, 0.21 s verify mode; every
receipt verified against the pinned image id; CPU build 585.8 s for the ratio 0.98. Metal: no circuit in 3.0.6
selects the Metal HAL and this Mac has no metal compiler, so no Metal figure exists; PC 2 (CUDA) measures next.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The same shard statement bytes as the SP1 guest, committed as the journal. RISC Zero's accelerated crates pinned by
tag (k256 0.13.4, crypto-bigint 0.5.5, tiny-keccak 2.0.2, sha2 0.10.9 and 0.11.0). Pinned image id
0x9ae0f416ee43e9ea8908c555d424fe23e3592677ffc42a763476623d0eb5cf72 under elf/manifest-r0.json. This Mac has no
metal compiler (Command Line Tools, no Xcode) and risc0 3.0.6 selects no Metal HAL in any circuit, so a local
risc0-build-kernel patch writes an empty metallib behind RISC0_SKIP_METAL_KERNELS.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Scope (SP1 shard and aggregator guests, pinned ids and pin script, the node's
verifier path and record rules of spec 7.7 and 7.8, the version 2 RISC Zero
guest when it lands), deliverables, six candidate reviewers with published
zkVM audits and their sources, cost basis from public rate cards and
comparable engagement sizes, and when it bites. Totals refreshed.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
One prover at 2.2% coverage never had 8 consecutive proven blocks (C47, 6 October 2026); claiming whole segments makes it complete about 1 segment in 75 instead of none. The choice is deterministic per key (FNV of first block and key hash) over the untouched whole segments inside their deadline by a margin (240 DAA or 1.5x the last segment's time); the per-block path stays as the fallback. Unit tests for the grid, the grouping, the margin, the attempted set and the per-key order; 120 app tests, 8 core and 9 host tests pass.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The statement and the pinned guests are unchanged; every fixture proof verifies as before. The defaults stay (batch-log2 22, SP1 defaults): the one knob that moves a mining card's prover costs a fifth of the hash rate; the plan carries the trade for the project lead and the batch fold for the next pin. Measured: docs/bench-log.md "aggregation cost on the RTX 5090"; the plan line: docs/plans/proving-v1.md "Aggregation cost (5 October, night)". Also: make-package's gate skips the exporter's .node-plan.json side files and takes the run lock for its execute step; the state-reply class (/api/state answering {} once paid_wei passes u64::MAX) found on the way and fixed on the app branch at 42f36b3.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit ea38ece9eaa5949dd657cbfea5308c4948177ff8)
serde_json's to_value refuses a u128 over u64::MAX (18.45 IGN) and state_json turned the error into json!({}). A paid shard is 1.23 IGN on average, so a proving machine's dashboard went blank about 15 paid shards after every app start. Unit test over the boundary; 114 app tests pass.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>