The first stage run built v4 on igneum-seed-1 in 60 min 49 s and then failed on `igneumd --version | head -1` under
pipefail, because the devnet-v4 igneumd prints its version and exits 1. The post-build steps now write to files and
test them; the tarball is unpacked once per src.stamp so a rerun is incremental; `stage-v4.sh <seed> resume` reruns
the build script on the tree already on the VM and then waits and installs.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Windows combined package 0.2.0 (proto-cuda/windows-app): v4 exes from target-integration, peers = seed then Mac,
fresh appdir devnet-v4, one miner and one worker per card with --identities 8, --evm-address (PAYOUT_EVM or derived
per vendor from the PC name), voting on (VOTE=0 opts out), --prepare-packs for the hot swap with --exit-on-seed-change
as the fallback, --yes on the node, STATUS regex tolerant of the v4 now= segment, version in the dashboard header.
Mac app 0.2.0 (packaging/mac): v4 binaries, Metal worker rebuilt for macOS 11, data folder devnet-v4, EVM payout,
identities in one process, synced= flag honoured. Seed (infra/seed-nodes): stage-v4.sh builds v4 on the VM as a
niced, memory-capped transient service and installs a disabled igneumd-v4 unit with a fresh data dir; switch-v4.sh
swaps the units (--back reverses); health.sh reports active-v4. Runbook: docs/plans/cutover-2026-10-04.md.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Spec 2.3: rule 1 measures every chain step on a sanitised clock stored per header
(c(b) = max(c(p) + clamp(t(b) - c(p), -20 T, +20 T), t(b) - 60 T), step min(c(b) - c(p),
20 T)); rule 4 bounds the output to [2^128, MAX_DIFFICULTY_TARGET]; the timestamp rules
are Igneum's own, 10 s ahead of the clock and 10 s behind the selected parent beside the
unchanged past-median rule; new parameter rows, the bounds paragraph rewritten (the old
"next honest block cancels it" was the attack), the attack and test-network results added.
sim/difficulty/sim.py: class Igneum carries the same clock, lag bound and floor, so the
rule as simulated is the rule as coded (attacks.py's igneum-san is now identical to it).
docs/analysis/difficulty-2026-10-03.md section 11: the attack, the three parts, before and
after tables (simulator seeds 7 to 9, base-profile regression within 10% on the 3-seed
means, pool hopping unchanged, the two 15-minute 3-node forger runs), unit tests, limits.
docs/bench-log.md: the 4 October entry. docs/fud-ledger.md: M23, status Fixed.
Node side: vendor/igneum-node branch difficulty, commit 52eacad9.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- spec 3.10: C5/3.8 (min_daa = weight window, window-filling report), Q4 (drawn aggregator at
once, fallback for anyone), S1 (draw by weight), 3.9 (finality_reason) rows for fin-fixes da1eb889
- fork-divergence: four rows for the fin-fixes files and the merge note against the difficulty
branch (hot swap is already in master)
- bench-log: unit tests and the scenario 2 and 5 re-runs before (master) and after (fin-fixes)
- fud-ledger: F17 and F1 status lines
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Simulator harness over sim/difficulty/sim.py with multi-miner attribution and in-rule timestamp forging, a 3-node CPU test network (ports 27700+), results and bench-log entry. Timestamp stretching inside Kaspa's rules drops the Igneum block rate 34 to 88% (the per-step clamp cancels forged and honest pairs to zero time); proposed 10 s timestamp bounds plus a sanitised running clock in the chain steps (+0.7% to +1.1% drift at 50% in the simulator). Block flood underflows the 192-bit work after 4,142 blocks; a 2^128 target floor proposed. Rule not changed.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
tools/finality-attacks: run.mjs drives a private igneum-devnet-800 network (ports 27800+,
/tmp/igneum-fin-attacks, skip_proof_of_work) with the test-only hostile flags of igneum-miner
(vmine, --equivocate, --sybil, --drop-votes, --pulse, fin-rpc-attack; worktree fin-attacks on
master c6d47547..2a00ff55). Seven scenarios in priority order 3,2,1,6,4,8,5 with a spec 03
criterion and a measured result each; README carries the catalogue, what needs a finality-aware
p2p probe, and a proposed diff for every FAIL.
Results (six voters): S3 dishonest aggregators PASS (35/35/35 locks, 0 conflicts, 1,018 ms);
S2 Sybil dust: weights PASS, aggregator sortition FAIL (per key, ledger F17); S1 equivocation
PASS (2/2/2 stripped, 0 conflicts); S6A 3/3 partition FAIL (floor is time-bounded, one side
crossed 56.7% at 84 s of a 90 s split, T* = 2F/13R, 9.2 days for a 50/50 split at mainnet
scale); S6B 4/2 PASS; S4 vote-dropping producer PASS (0 ms added); S8 malformed votes over
RPC PASS (9 cases, no crash); S5 pulse: no retarget amplification (ratio 0.999) PASS,
lock-alone FAIL (a 20 s burst locked checkpoints 1 to 10 alone on a young window, ledger F1,
spec 3.8 not implemented). S7 eclipse not run.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
No per-job growth in any worker or in the miner's memory. The STATUS rates are cumulative averages
(a fast first interval decays by construction), and the miner's Seeder walks the selected chain from
the sink to the epoch start on every memo miss (one getBlock per block, up to 3,600), a gap between
jobs that grew 0.10 s to 0.33 s across epoch 2 on the PC and reset at the epoch boundary while the
difficulty held. Reproduced on the Metal worker (churn on, off, on). One versus eight workers at two
fixed difficulties: 4% and 1% constant cost, no decay. Fix as a unified diff, not applied.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
sim/economy/sim.py: 1,000 operators choosing MINE, PROVE, HYBRID or OFF per card class with their own clients; sortition by weight with the 10-s window then open claiming, external jobs with the 90/10 split, backlog rule, difficulty clamps, GBM price. Scenarios a to f, 5 seeds: no backlog, no window miss, hash floor 0.74 of pre-event. Traffic sensitivity finds the shortage oscillation only above the proving fleet's capacity (100 to 300 shards per block); at 100 the sortition window (10 s to 20 s) is the lever that removes it. docs/analysis/economy-2026-10-04.md holds the model, assumptions, results, worst case and the proposal (window = p90 shard time plus a swap, 25 s at today's targets; B_p tied to the live fleet), not applied.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Adversarial robustness and conformance tests of the execution layer against a
throwaway 3-node simnet on ports 27600+. Six scenarios, each a runnable command
with a design-derived pass criterion and a measured result: malformed/boundary
txs, nonce games across parallel blocks, RPC fuzz, pgas exhaustion, reorgs under
execution, and developer-registry abuse. 98 checks, 0 failures, 0 node panics.
Two findings filed in the bench-log entry: the mempool admits txs with gas_limit
above B_e (low), and an over-pgas-budget tx is executed natively in full before
being skipped for no fee (medium, griefing).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Safety: X = 1/3 of total weight while honest votes reach every honest node within 41 min of median time; 4/30 = 13.3% across a longer partition, because only the 17/30 floor binds then (2 x 17/30 - 1). Liveness: Y = 17/30 connected and signing, T = P (1 - Y/(2(1 - Y))) + 107 s, 107 s at 2/3, 43 min at 17/30; below the floor finality pauses and the node reports it. Two certificates at one index: no verified lock is ever withdrawn, operators resolve (replaces the 3.5 re-evaluation). Seeds: uncertified checkpoint allowed (O-4.3 decided). Scenarios H (equivocator across a 50/50 split: conflicts at 12 to 16 min with 20%, none at 13%), I (40/40/20), J (signing stops 1, 6, 24 h), K (bought keys worth 20% and 40% against 30% hash), five seeds each. 3.10 rows for the gaps; open items O-3.15 to O-3.19.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/evidence.md and site/evidence.html: 28 public claims with one of five status labels (7 designed, 3 implemented, 18 tested by the team, 0 reproduced externally, 0 reviewed independently), version or commit, the reproducible test, the result with date and machine, and independent verification (none yet for every row). Evidence link in the homepage nav and the generated pages' nav.
docs/benchmarks/proving-e2e.md: replaces the 20-second shard gate with three fixed workloads, job-received-to-accepted-proof latency, cost per proof, the eligible card list with mining and proving reported separately, the verbatim acceptance standard and the three-unrelated-operator protocol.
docs/plans/funding.md: cost, what is funded (founder's means, the client's 1% fee once there is mining), what waits on revenue, what pauses.
docs/analysis/security-budget.md: emission through six halvings at three price inputs, miners and provers separate from burns, the USD 1M floor and the year it is crossed.
docs/design/payment-routes.md: Mermaid flowchart and table of every flow, with operator, app, team and protocol revenue labelled.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
proving/igneum-prove: core (port of igneum-exec at fb33069 as the block statement), program (SP1 v6.8.1 guest),
host (execute, core, compressed; ProofSystem trait with the stub and the SP1 implementation), export (cuts a block
out of igneum_exportSegments and checks every state root against the node's). Fixtures block-78-increment and
block-56-transfers from the 3-node simnet. proving/windows-wsl2: SETUP-PROVER.bat, setup-wsl.sh, PROVE-BLOCK.bat,
make-package.sh. docs/plans/proving-v0.md: the devnet v4 shard plan, what tonight's proof shows and does not, the
morning acceptance line. Mac CPU baseline (block 78: 626 k cycles, core 22.0 s and 7.3 MB, compressed 55.7 s and
1.27 MB, both verified) appended to docs/bench-log.md, left uncommitted because that file carries another agent's
pending changes.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Measured at 375, 768, 1280 and 1680 with headless Chrome. One token set in
all four stylesheets: container 1200 px with a clamp(16px,4vw,32px) gutter,
section rhythm clamp(56px,8vw,96px), cards clamp(18px,3vw,28px) padding and
18 px radius, tiles 18 by 20 px padding and 14 px radius, 24 px card gap and
12 px tile gap, headings h1 clamp(32,5.5vw,56) h2 clamp(28,4.2vw,44) h3
clamp(18,2vw,22), tile values clamp(20,2.2vw,26).
Home: the live strip spans the full hero width with economics-spec tiles;
stat strip and economics tiles share one spec; journey phases and log take
the tile and card boxes; inline padding-top overrides removed, consecutive
dark sections share one gap; every nav anchor lands the heading 11 px under
the sticky bar at every width (padded sections subtract their own padding).
Live: head, strip, cards and gaps on the tokens; four tiles a row, two on
phones; network name no longer clips. Litepaper: real gutter instead of a
fixed 16 px, cover, layout, tables, figures, pull quotes and stat tiles on
the tokens, pager stacks on phones. Engineering log: same tokens, long code
tokens wrap so phones no longer scroll sideways, duplicate h1 hidden.
Copy shortened so no label orphans at any width: stat strip labels, the
economics tiles, the strip tile labels, the litepaper stat tiles, the
mining-program eyebrow. The light-client card block is untouched.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
igneum-seed-1 (Hetzner cx23, fsn1, 188.245.5.161:26611): built on the VM in 1,530 s, synced to the live devnet
(12,204 blocks, same sink as the live node) through a non-mining relay igneumd on the Mac (the live node's addPeer
RPC is refused in safe mode); the live node and the Windows PC learned the seed's address by peer exchange and dialled
it. seeds.txt written. Hetzner prices corrected to USD (pricing API currency) in the plans, READMEs and scripts;
current-generation types per location (cx23 EU, cpx22 sin, cpx21 US) in the cloud-devnet config.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Mac: bundle renamed Igneum Miner.app (network.igneum.miner, 0.1.0, LSMinimumSystemVersion 11.0, igneum.icns),
Terminal title Igneum Miner, seed line in the first-run text, branded DMG (volume icon, background, icon slots via
dmgbuild), dist/Igneum-Miner-0.1.0.dmg at 16.2 MB, tested synced against the live node on 27400/27401.
Windows: packaging/windows with windres .rc files and embed-resources.sh (relink commands for the next cross-build),
Igneum-Miner.iss (Program Files, Start Menu group, firewall rule, uninstall stops the processes, licence, seed line),
BUILD-INSTALLER.bat and build-installer.ps1 for the project lead's PC (winget Inno Setup 6, rcedit fallback for the exe icon).
Icons: brand/icons/make-icons.py makes igneum.icns, igneum.ico, the Inno wizard art and the DMG background.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
site/verify/core.js recomputes every header hash (keyed BLAKE2b, the
node's field order), checks the parent links from the previous locked
checkpoint, hashes each voter's G1 key to its vote_key_hash, verifies the
BLS aggregate over "igneum-vote-v1/" || chain_id || 0 || index_le64 ||
checkpoint under the vote tag with the bitmap's keys, and applies Q3
(2/3 of active, 17/30 of total). verify.js drives it from /api/checkpoint
with @noble/hashes 2.4.0 and @noble/curves 2.4.0 pinned from jsdelivr and
fills the homepage card; the badge says LIVE only after a pass in the tab.
site/api/checkpoint.mjs ships the data: certificate bytes, voter table
with public keys, header chain. tools/observer stores every certificate a
block carries (new table live_certificates, voter table read at the lock,
selected-chain headers back to the previous lock, one-off backfill of the
newest lock on start) and keeps header nonces exact; the FinalityLock
write no longer fails on a missing votes_seen.
Tested on the igneum-devnet-7 test network: checkpoint 95 verifies in
Chrome in 103 ms; a flipped signature bit, a dropped voter, an altered key,
an altered header and a removed header all fail with the reason named.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
tools/harness runs the standard consensus-attack catalogue against a private
test network of our own igneumd nodes (127.0.0.1 ports 27200+, /tmp/igneum-harness,
never the live devnet or the PC node), with a pass criterion per scenario from the
spec and a measured result each. Built on the node fork's own crates
(igneum-harness-sim on kaspa_utils::sim as simpa does; igneum-p2p-probe for the
wire). Scenarios: 1 withholding, 2 timestamp edges and drift, 3 partition and heal,
4 eclipse, 5 malformed and boundary inputs on every p2p and RPC surface, 6 resource
exhaustion, 7 fast-miner flood. Finality and difficulty-controller scenarios are
stubs with their criteria written.
bench-log: one dated entry, a row per scenario (criterion, measured, pass or fail).
First run: 19 of 20 measured rows pass. Findings recorded in the entry: scenario 5
reproduces ledger M15 on HEAD (bogus past-day or DAA headers build a 256 MiB cache
before rejection; the r3-fixes branch removes it); scenario 1 at 45% hash with
burst withholding shows a selfish-mining blue-share gain (50.7% of blues), the one
failing row.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/design/execution-layer.md section 10: what the execution-layer branch implements
(D1 to D10, RPC, differential), the devnet rules fixed there, what is missing, the merge
plan with the finality branch. docs/bench-log.md: the 3-node simnet run with numbers.
tools/evm-smoke: viem 2.57 smoke test (fund, 50 transfers, duplicates in parallel blocks,
contract deploy and call, state roots across nodes, export for igneum-exec-diff) and the
solc build of DeveloperRegistry and the Counter test contract.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
infra/cloud-devnet: hcloud (doctl variant) create, builder-VM provision from a git-archive source tarball,
systemd units for igneumd --devnet-suffix with a sparse --addpeer mesh and a CPU trickle miner per node,
stdlib wRPC client, experiments (latency, partition, hop, collect, observer hookup), README with the command
sequence and the Hetzner API prices of 3 Oct 2026.
infra/gpu-bench: RunPod image recipes (CUDA 12.8, ROCm), bundle, run.sh (vectors gate, 10-min raw, sweep,
inline shortcut ratio, nvcc/NVRTC/OpenCL recompile timings, results row, intake upload), bench-log template.
infra/seed-nodes: create-seed (persistent IPv4, firewall), provision on the VM, health check, addPeer from the
Mac over grpcurl, seeds.txt; igneum-seed-1 created at 188.245.5.161 (Hetzner cx23, fsn1).
docs/plans/cloud-devnet.md and docs/plans/seed-nodes.md.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- docs/fork-divergence.md: "Finality v2" table (every file, risk, merge note), decisions
- docs/spec/03-finality.md: section 3.10 implementation notes, clause by clause
- docs/bench-log.md: test-network results (72 of 72 steady locks, median 0.80 s; equivocation
strip; partition: 0 locks at 39.6% of total with the floor binding, heal in 30 s), follower
- tools/observer: live_checkpoints table, FinalityLock subscription, "checkpoint N locked" events
- site: /api/live adds checkpoints and locked/final flags; /live draws the lock ring and final line
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
packaging/mac: build-dmg.sh assembles Igneum Devnet.app (shell launcher that opens
igneum-devnet.sh in Terminal, stripped ad-hoc-signed copies of igneumd, igneum-miner
and the Metal worker), README.txt, Stop Igneum.command and an Applications link into
dist/igneum-devnet-mac.dmg (17 MB, lzfse). The script starts the node peered to
SEED_PEERS, waits for sync, runs one miner identity mac-<hostname> on the Metal worker,
prints a status line every 30 s, uploads logs every 60 s, keeps the Mac awake and stops
everything in order on Ctrl+C, window close, --stop or the Stop command.
Tested on this Mac from the mounted DMG against a test node on 27310/27311 peered to the
live node: sync in 22 s, 24 accepted blocks, listed on igneum.network/live, clean stop
with no stray process on SIGINT, SIGTERM and Stop Igneum.command.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Pool protocol after Stratum V2 job declaration: member-checked or member-built templates, JSON over TLS, shares at target64 << s on the 32-lane unit, one vote key per operator held by the member, votes relayed and carried by the pool with a chain-only drop test. Light client: trust table, checkpoint-mode bytes per day, pinned seed list, the read-only node API, the homepage card's steps. Phone app: wallet, miner monitor, node card, store rules, build plan on journey.json.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The hero canvas now has a live path fed by the same 2 s fetch as the chain scene (one poller, three subscribers: hero, stats strip, chain scene). When the observer is fresh each dot is one miner seen in the last ten minutes (at most 24, no id drawn), it flashes ember when that miner finds a sampled block, and faint lines reach the miners of the block's parents for a moment. Dots join on a new miner and fade out when one leaves the ten-minute set. The drift, colours and pace are the simulation's; the simulation runs unchanged when the observer is off or stale.
A live stats strip under the hero buttons (miners active, blocks / s, network hash rate, blocks on the devnet) shows only while the observer is fresh and hides again when it goes stale. Two tiles per row at phone width.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
proto-cuda/windows-app/: START-IGNEUM.bat starts igneumd, waits for sync, then runs the
miners; igneum-common.ps1 holds the dashboard, node, chain reader and miner functions once,
dot-sourced by start-igneum.ps1, start-mining.ps1 and start-node.ps1. STOP-IGNEUM.bat stops
everything in order. make-package.sh builds igneum-windows.zip.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
fork-divergence.md: a section for branch r3-fixes (the PoW-before-validation
reorder, the cache-build cap and the per-peer guard), the merge-overlap note for
the finality branch, and the updated "PoW before or after GHOSTDAG" and "Day
seed" open decisions. bench-log.md: the before-and-after attack numbers (50
bogus headers build 50 caches in 10.6 s before, 0 and all rejected in 14 ms
after), one cache builds in about 0.2 s, and the M16 Mac inline-dataset note.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
proto-cuda/windows-node/: START-NODE.bat and start-node.ps1 (igneumd
--devnet with --addpeer to the Mac, status line every 30 s through
igneum-miner watch, keep-awake, random-delay restart, Ctrl+C),
BUILD-NODE.bat and build-node.ps1 (builds on the PC from the src.zip
snapshot; winget for Rustup, LLVM and protoc; MSVC default toolset),
ALLOW-FIREWALL.bat and allow-firewall.ps1, README.txt, cross-build.sh
(the mingw-w64 recipe that built igneumd.exe in 8 min 25 s; the exe
ships with the three mingw runtime DLLs) and make-package.sh.
WINDOWS-MINER.md gains "Run your own node"; bench-log records the
cross-compile and the two-peer sync test on the Mac (ports 27000 and
27010, live node untouched). The mining launcher's NODE_HOST=auto
edit stays uncommitted for the agent that owns start-mining.ps1.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Litepaper Finality: the reorg bound users rely on is the 12-hour finality depth in median time; Kaspa's one-hour merge depth is a merge limit, not a reorganisation bound; first-month sentence and "does not claim" item 4 say the same. Litepaper Speed: emission per block on a schedule keyed to difficulty-adjusted time, reds in the window paid, coins track blocks within the controller's accuracy.
Design 5.5 and D12: the native-execution veto is relative to the carrying block's own selected-parent chain; two-node reorg test added to 8.5.
Ledger P11, F15, E10 statuses and fixes rows 79, 82, 84 updated.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The four public sentences (F18, P13, E11, L7 in site/litepaper.html and site/index.html) were swept into the concurrent commit cd604db; this commit carries the rest.
Spec 02: finality depth (43,200 DAA s, 12 h of median time) named as the reorg bound, merge depth as a merge limit only, simnet reorg test for gate 2; emission follows the code (365.25-day year, 63,115,200-s halving, 31.688 IGN per DAA second, reds inside the DAA window paid to the merger, E paid per block so coins are blocks times E).
Spec 03: W2 and Q1 denominated in past-median time, weight as a share of each 60-s bucket; W6 keys are free, weight is the only Sybil-resistant quantity; 3.8 and 3.9 point exchanges at the finality depth.
Spec 06: O-3.14, the finality simulation with the DAA in the loop under a pulsed rental (gate 3).
Spec 07: shard sortition draws by weight (blue blocks drawn uniformly from the window); proof-record validity is relative to the carrying block's own selected-parent chain; 1-key-versus-1,000-keys test.
Spec 08: release-key chain, rotation signed by the current key, revocation signed by the previous key, both published in a block; policy before the client ships.
Ledger: status lines for F18, P13, E11, L7, P11, F17, F14, M14, F15, E9, E10, G9; P8 cross-reference. Fixes: section 2.2 rows 75 to 88, with M15, M20 and P12 marked code, owner consensus engineer.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Seven reviewers (Kaspa core, RandomX author, Ethereum client, GPU farm,
chip designer, exchange listing, regulator's analyst), three attacks each
against docs/spec, the execution design, the fork code and tonight's devnet.
0 fatal, 18 serious, 8 minor. New ledger entries M14 to M21, F14 to F18,
P11 to P15, E9 to E11, C13, L7, L8, G9, G10, X12; one cross-reference on P8.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>