220 KiB
Counter ASIC 3.0: status
Started 6 October 2026, 07:15 UTC, on the project lead's order "run it all"; closed 09:5x UTC with every item measured on the Mac and the 5090 and every AMD row owed (PC 1 not released). Final tree: ca3-coord, 45 commits over the base, no-conflict-markers.sh clean, observer tests 10 of 10, igneum-pow 96 of 96 with the pinned v2 and v3 packs byte for byte. Coordinator worktree igneum-wt-ca3-coord, branch ca3-coord from 50df751 (ca2-coord 9206aea merged with master ddfcdac). The plan: docs/plans/counter-asic-3.md. The audit behind it: docs/analysis/asic-resistance-history.md. The 2.0 record: docs/plans/counter-asic-2-status.md, docs/bench-log.md "Counter ASIC 2.0, the numbers", docs/analysis/chip-model-v3.md. Class v3 is live on the devnet since DAA 154,800 (crossing 03:51:42Z, verdict PASS 05:21:48Z). Nothing in this run publishes to the devnet; what passes is a class v4 candidate behind program_class_v4_activation_daa under the six gates and the two-publish rollout of 2.0.
The test every result is judged against (the project lead, 6 October): a chip maker must have to build a better GPU than NVIDIA to launch an ASIC, the way Bitmain's Antminer X5 reached CPU parity per joule only at many times the price. The binding rule from 2.0: the hash stays bound by dependent random memory reads.
1. Machines and rules in force today
| Machine | State | Rule |
|---|---|---|
| Mac M5 Max | mining paused; Metal worker free | measurements under with-lock.sh measure only |
| PC 2 (1ccfe586, RTX 5090) | HELD for the 0.3.14 shipper's Rust suite from 17:5x UK (main): nothing of 3.0 goes to PC 2 until the shipper reports the suite done (the P2 G6 run waits on it). Earlier: RELEASED at 08:43:24Z after the three jobs (derive 08:26 to 08:29Z, shadow 08:29 to 08:41Z, family 08:41 to 08:43Z, all exit 0; prover ON, app untouched); then the prover-floor agent, then the 0.3.12 release engineer's build. Before that: CLEAR at 08:24:27Z (the clear file carries the proving agent's constraints: prover left ON, no quit or restart, /opt/igneum, /opt/igneum-segal and settings.json untouched); the three 3.0 jobs run one at a time through the mkdir lock (items 8, 2, 6); "PC 2 released" to the proving agent after the last; the prover-floor agent next. Before that: the proving agent's jobs segments-pc2-pv1 runs b and c (run b claimed nothing on a PowerShell key bug; run c from about 07:53Z); "PC 2 clear" expected about 08:35Z; then three 3.0 jobs one at a time (items 2, 6, 8); the prover-floor agent queues after "PC 2 released" |
nothing published until "PC 2 clear"; one job at a time (/tmp/igneum-devnet/pc2-ca3.lock); released by message when done |
| PC 1 (ae432dc7, RTX 5090 + RTX 4070 + RX 9070 XT) | FREE at 18:01:05Z after the queue (reset, family runs a to e, G2, derive, the 4070 ladder, the watts job that failed and left the 9070 XT off, the restore and the flag job); handed to main for the project lead's 0.3.14 click and the Ember window. Earlier: the project lead's desk; the AMD queue opens on "Ember closed" (reset, family, G2, derive, the 4070, watts, about 25 min), then the Ember agent's 6-minute window, then the 0.3.14 update on the project lead's click (after the last job, not between jobs: an update wipes the jobs folder and the kits) | not used today; every AMD row OWED |
Standing rule from main (17:5x UTC; CLAUDE.md on master 630b537, docs/plans/build-server.md): from the next build, every Linux and Windows cargo build and every Linux test suite from the 3.0 lanes runs on igneum-build-1 through tools/build-remote.sh and tools/cross-remote.sh from the worktree's crate directory (artefacts in target-remote/, IGNEUM_AGENT=ca3-<lane>, one slot, a 2 h cap; the clean node build 87 s there against 9 to 18 min on the Mac). PC 2 keeps only GPU and Windows-runtime jobs (G6's engine test on the card stays a PC job; the crate suites move). Passed to the node lane, the hash lane and the PC 1 worker.
2. The items
| # | Item | Worker branch | State | Close |
|---|---|---|---|---|
| 1 | Partial-store chip and the time-memory curve | ca3-analysis | CLOSED, merged (71df794) | verdict OVER 2x: the f = 1 chip (the dataset stored in DRAM, nothing recomputed) is 5.1x per joule on GDDR7 and 7.5x to 9.2x on HBM3 in the model, 2.1x to 4.8x by the Ethash precedent, $2.8 per MH/s against the 5090's $14.7; the curve is monotone toward f = 1, so the partial-store chip is never built; the mixer and item 2 do not touch it; chip-model-v3.md section 5 |
| 2 | Per-day item-derivation program (reserve entry, verifier gate, daily build) | ca3-derive | CLOSED, merged (acb96ee, dd5041b, bdc07d3, 54bc188); 5090 job run-ca3-derive-pc2-20261006 exit 0 in 126 s | GO as reserve R0; NO-GO for genesis-live at dr736 (verifier 4.9 ms per unit on one M5 Max core, about 12 ms on a 2019-class core by the 2.5x rule, over the gate; dr368 2.69 ms passes both); urgency LOW after item 1 (the stored-dataset chip derives no item) |
| 4 + 5 | Share-pattern detector, trigger rules, FPGA lane, layer 9 against 7 | ca3-detector | CLOSED, merged (c0642af, merge ed06814) | detector.mjs + 7 of 7 tests + one observer hook, dry run quiet on the devnet (max correlation 0.53 against the 0.8 edge; excess spread 0 to 5.2 percent); funding.md rule 5: bounty escrowed and benchmark live before daily issuance crosses USD 20,000 a day; epoch-length.md sections 11 and 12: signal trigger M = 6 windows; FPGA soft overlay 0.30x to 0.39x per watt on the measured basis, 0.7x to 1.9x at the bank-bound ceiling (unmeasured); layer 9 ranks above layer 7. The live observer is NOT restarted yet: the write path is untested; one restart after item 7's hook merges, then the first live detector row is recorded here |
| 3 | Cryptanalysis brief in funding.md | ca3-crypto-brief | CLOSED, merged (43c3ead) | funding.md line item USD 80k to 160k, reviewer shortlist, ranked break list; verdict GO to commission (no outreach, no spend) |
| 6 + 7 | Reserve order with step costs, vendor-share metric | ca3-reserve | CLOSED, merged (b85f0f1, merge 820f4d4); 5090 job run-ca3-family-pc2-20261006 exit 0 in 36 s, the card to itself | proposed reserve order R1 byte permute, R2 popcount and clz, R3 indexed shuffle, R4 bit-field extract, R5 variable shifts, R6 select, R7 andn, R8 mm8 (docs/plans/counter-asic-3-reserve.md, a decision for the project lead, not in the spec); vendor-share.mjs with tests and one observer hook; repro.md carried from repro-bench (dda9fa3) with section 8: today's devnet NVIDIA 0.986 of blue blocks, Intel 0.014, coverage 1.00 at 135.8 MH/s with PC 1 off |
| 8 (added by item 1's finding, coordinator 08:xx UTC) | Program work in the latency shadow: the hash rate, watts and verifier cost at N = 50,000, 100,000, 200,000 ops per hash on the M5 Max and the 5090; the 5090 power-cap rows | ca3-shadow | CLOSED, merged (70eaf06, merge 12d8a93); 5090 job run-ca3-shadow-pc2-20261006 (lock 08:29:22 to 08:41:03Z), the card empty | GO as a class v4 candidate at mx8+sh256x27 (100,000 ops per hash): the chip's per-joule edge over the 5090 falls from 5.6x to 2.1x at k = 1 for 0.2 percent of the 5090's rate and 1.5 percent of the Mac's; NO-GO above 130,000 ops or a block over 256 instructions; the chip question is decided by k, the chip core's energy per op against the 5090's measured 11 pJ: over 2x only at k under 0.5 |
3. Measured numbers
Item 1 (analysis, no new measurement; every chip figure is arithmetic on cited memory figures, approximate where marked)
| Row | Rate against the 5090's 136.1 MH/s | Per joule against 2.40 microjoules per hash | $ per MH/s | Binding |
|---|---|---|---|---|
| f = 0 on-die recompute chip (sections 1 to 3; 9,360 ops per item hoisted, 10,512 unhoisted) | 0.31x bare, 0.92x with the 3x factor (0.27x / 0.82x unhoisted) | 1.86x (1.75x unhoisted; 1.3x to 2.4x over the on-die read energy) | $16.8 | compute |
| f = 1 on GDDR7 (the 5090's own memory system, 21.3 G reads/s activate ceiling) | 1.22x | 5.1x | $2.8 | memory |
| f = 1 on one HBM3 stack | 0.61x | 7.5x | $6.6 | memory |
| f = 1 on eight HBM3 stacks | 4.9x | 9.2x | $4.0 | memory |
| f = 0.25 to 0.75, both memories | between the ends and worse than both on $ per MH/s |
The whole case for the f = 1 chip: the 5090's memory system draws about 55 W of its 326 at the hash (17 percent, approximate); the rest is the GPU spinning on loads at 0.15 percent of its integer budget. The op count per mixer application, counted from memhard.rs: 144 as written, 128 with the RC and rk adds hoisted; 72 x 128 + 144 = 9,360 per item, which is the spec's "about 130" x 72 exactly; the chip model's rows stand at 9,360 and are given at 10,512 beside them.
What moves the f = 1 rows (chip-model-v3.md section 5.7): not the dataset size (one HBM3 stack holds 24 GB, the schedule reaches 4 GiB at year 4), not the read width (the decision to stay at 4 B stands), not the chain length; only (a) the honest card's watts at the hash (a 5090 holding 136 MH/s at a 250 W cap reads 3.9x on GDDR7, at 200 W 3.2x) and (b) program work in the latency shadow (the card hides 512 ops per hash behind 128 reads and could hide about 330,000 before compute binds; at N = 330,000 the model reads 1.85x at a chip core as efficient as the GPU's ALU, 2.5x at 1.5x worse), which is the design item this run adds (item 8 below) and the one that answers the project lead's test directly: a chip must carry the memory system AND the ALU budget.
Item 2, the Mac rows (interim, ca3-derive dd5041b; measure lock, load average 4.5 to 5.3; the 5090 rows queued on PC 2; the 9070 XT OWED)
| Class | Ops per item (chip, RC + rk hoisted / GPU as written / multiplies) | Verifier ms per unit, one M5 Max core (worst cold) | 2019-class core, 2.5x rule, approximate | Metal 1 GiB build | Hash rate, M5 Max | Bit-exact | Chip row (bare / at a 1.2x / 1.5x allowance; the 3x no longer applies) |
|---|---|---|---|---|---|---|---|
| v2 (x1) | 1,152 / 1,296 / 144 | 0.598 | 1.5 | 2.45x | |||
| v3 (x8), live | 9,216 / 10,368 / 1,152 (the acceptance floors) | 2.061 to 2.063 | 5.2 | 22.1 ms | 27.1 MH/s | yes | 0.31x / 0.92x with the 3x factor |
| dr368 (9 x 368 instructions) | about half of dr736 | 2.69 | 6.7, passes | ||||
| dr736 (9 x 736 instructions, the genesis-day draw: 9,992 / 10,659 / 1,461) | 4.875 to 4.944 (5.241) | 12, over the gate | 29.0 ms | 27.1 MH/s (equal) | yes (Metal and Apple OpenCL, fingerprint 50e3eaa779da4f1e) | 0.29x / 0.34x / 0.43x |
Verifier headroom under the 10 ms gate (bdc07d3, the budget item 8's shadow ops may spend; steady / worst cold): on this M5 Max core x8 7.9 / 7.8 ms, dr368 7.3 / 7.1, dr736 5.1 / 4.8; on the approximate 2019-class core x8 4.8 / 4.6, dr368 3.3 / 2.8, dr736 none (over by 2.2 / 3.1). cargo test -p igneum-pow on acb96ee under the build lock: 95 passed, 0 failed; the pinned v2 and v3 packs regenerate byte for byte.
The 5090 rows (job run-ca3-derive-pc2-20261006, 08:26:43 to 08:28:49Z, exit 0; the card was LOADED: the miner stayed up because the job posted the settings key without the device index, see corrections; ratios valid, absolutes not): bit-exact on CUDA for both dr736 packs (64 samples, 96 lanes, fingerprints 50e3eaa779da4f1e and 9553f6d5c667205a equal to the Mac's); 1 GiB build 42 / 32 ms against x8 40 and v2 46; rates 61 to 62 MH/s on every pack (the v2 control 62.3 against 136 unloaded); NVRTC compile 1,266 ms against x8's 164 ms, +1.1 s per pack because memhard.h's item function sits inside every hash-kernel and race-variant compile, so a once-a-day derivation module is a requirement of the class, not an option. Prover left ON, app untouched.
The RX 9070 XT rows (PC 1 job run-ca3-pc1-amd-derive-20261006, 17:23:56 to 17:29:13Z, exit 0, beside the miners so the absolutes are loaded-card figures and the ratios stand): bit-exact on AMD OpenCL for both dr736 packs (fingerprints 9553f6d5c667205a and 50e3eaa779da4f1e equal to the Mac's and the 5090's, two passes each, self-tests PASS); the OpenCL compile 2,070 to 2,092 ms per dr736 pack against 41 ms for mx8 (+2.0 s per pack, the AMD twin of NVRTC's +1.1 s: the once-a-day derivation module is a requirement on every vendor, and on a one-click AMD miner the shadow-free x8 pack compiles in 0.04 s where the derivation pack takes 2.1); the 1 GiB daily build 168 to 189 ms against 205 to 273 for mx8 in the same loaded session (a build the same size or smaller, inside the noise); the rate ratio to mx8 0.982 and 1.006 (no hash-rate cost). With these the derivation's bit-exactness is on all three vendors and its hash-rate cost is zero on all three.
Consequence: the derivation costs no hash rate on any card and 7 ms a day of build on the Mac (29 against 22 ms; the 5090 and the 9070 XT rows owed, the loaded-iGPU tier is the one to watch); it costs the verifier, and the verifier budget is shared with item 8's shadow ops under the one 10 ms gate, so the class v4 candidate is the pairing that fits, not either lever alone (both workers told).
Item 8, the Mac rows (interim, ca3-shadow a050a54; knob d4b7300; docs/analysis/latency-shadow-2026-10-06.md; Metal packbench, IOReport GPU + DRAM watts without root; the 5090 rows queued on PC 2; the 9070 XT OWED)
| N, shadow ops per hash | M5 Max MH/s (against the control 27.07 to 27.10) | Watts (GPU + DRAM) | Microjoules per hash | Verifier per warp, one M5 Max core | Reading |
|---|---|---|---|---|---|
| 512 (class v3 today) | 27.1 | 21 | 0.78 | 2.06 ms | the honest best per joule we own: 3x better than the 5090's 2.34 at 290 W |
| about 100,000 | -1.5 percent | 37 | 1.40 | 2.06 + 0.32 | still latency-bound |
| about 130,000 | -5 percent | the 2.0 rule's edge on this card | |||
| 151,000 | -7.3 percent | ||||
| 200,000 | -10 percent | compute binds | |||
| 331,000 | -21 percent | 40 | 1.88 | 2.06 + 0.56 (about 1.4 ms more on a 2019-class core) |
The verifier is not the constraint: 3.2 microseconds per 1,000 shadow instructions per warp, so no pairing of item 2's class with any N binds the gate before the cards do; the cards bind. Block size on Apple: a 64-instruction block +2.5 percent, 256 holds, 1,024 costs 17 percent at the same N. Marginal ALU energy on the Mac 6.9 pJ per counted op at N = 100,000. Chip side at N = 100,000 and a chip core equal to the GPU's ALU (k = 1): 1.4x over the M5 Max per joule, 2.7x over the 5090 on the model watts (5.0x today at 290 W with the shadow empty); k decides it. Power caps: the 5 October sweep re-used (floor 400 W, the cap never binds), no -pl steps; the PC 2 job carries the N ladder and -lgc clock rows at the four Ember caps (OWED if refused).
Consequence per tier (interim): the M5 Max at 21 W is the per-joule best honest miner we own (0.78 against the 5090's 2.34 microjoules), so against Apple silicon the stored-dataset chip of item 1 reads 1.7x per joule on GDDR7 (0.47 against 0.78) and 2.4x on one HBM3 stack, inside the "1 to 2x" band on GDDR7; per pound the Mac stays the worst tier (list price against 27 MH/s). Filling the shadow to about 100,000 ops costs an Apple miner 16 W more for 1.5 percent of rate (0.78 to 1.40 microjoules) and buys 1.4x against a chip at k = 1; the N the project can pick without any card we own losing over 5 percent is set by the Mac at about 130,000 until the 5090 and 9070 XT rows land. An NVIDIA owner's number is the PC 2 job; an AMD owner's is owed.
Item 8, the 5090 rows and the chip side (ca3-shadow 70eaf06; job run-ca3-shadow-pc2-20261006, the card confirmed empty by nvidia-smi compute-apps and the process list, the installed worker's --bench, nvidia-smi at 1 Hz, the app's 431 W cap; every pack bit-exact on Metal, CUDA, clang emulation and Apple OpenCL)
| N ops per hash | M5 Max MH/s (delta) | M5 Max W, microjoules | RTX 5090 MH/s (delta) | 5090 W, SM MHz, microjoules | Verifier ms per warp, one M5 Max core |
|---|---|---|---|---|---|
| 930 (class v3 today: 512 instructions, 384 ALU, about 1.83 counted ops each) | 27.08 | 21.0, 0.78 | 132.2 | 350, 3,040, 2.65 | 2.06 |
| 49,700 | 26.75 (-1.2%; a 64-instruction block +2.5%) | 31.1, 1.16 | 132.3 (+0.1%; 64-block +3.5%) | 425, 3,034, 3.21 | 2.21 |
102,100 (sh256x27, the candidate) |
26.67 (-1.5%) | 37.2, 1.40 | 131.95 (-0.2%) | 431 cap, 2,824, 3.27 | 2.23 |
| 150,800 | 25.10 (-7.3%) | 36.7, 1.46 | 131.75 (-0.3%) | 431, 2,427, 3.27 | 2.33 |
| 199,600 | 24.25 (-10.4%) | 38.2, 1.58 | 128.67 (-2.7%) | 431, 1,753, 3.35 | 2.43 |
| 330,700 | 21.39 (-21%) | 40.1, 1.88 | 86.39 (-35%, compute-bound at the capped clock, 28.6 T op/s) | 431, 1,834, 4.99 | 2.62 (worst cold 2.77) |
Where each card leaves the latency bound (the 5 percent rule): M5 Max about 130,000 ops; RTX 5090 about 210,000 at its 431 W cap (the cap binds from 102,100 ops and the governor lowers the clock); RX 9070 XT OWED. The verifier's law: 2.06 ms + 3.2 microseconds per 1,000 shadow instructions per warp, so 330,700 ops add 0.56 ms (about 1.4 ms on a 2019-class core): it fits every pairing's headroom (x8 7.8 / 4.6 ms, dr368 7.1 / 2.8, dr736 5.1 / none), and the node never binds before the cards. The verifier on a SLOWER core, measured 7 October 08:46 UK by the node lane on igneum-build-1 (an EPYC 9454P core at 3.66 GHz under schedutil, the measure hold, load 6.1; the ladder worktree's igneum-pow 59ae70cf; 50 warps averaged, the cold warp beside it) for the testnet's latency ladder (its rungs are item 8's shadow packs): rung 2 = 199,566 counted ops (the sh256x53 pack) 8.99 ms loaded (9.25 cold), ADMISSIBLE under the 10 ms gate; rung 3 = 330,740 ops (sh256x88) 5.95 ms alone (9.04 cold), 10.11 ms with the sibling loaded (10.85 cold), OVER the gate by 0.85 ms, so the testnet freezes that rung FALSE. Reading against the M5 Max's law (2.06 ms + 3.2 microseconds per 1,000 shadow instructions: 2.62 ms at 330,700): the server core is 2.3x slower alone and 3.9x loaded, so the 2.5x rule's "about 6.5 ms" for a slower core was right alone and short under load; the candidate at 100,000 ops sits well inside the gate on this core by the same ratios (about 5.3 ms loaded, approximate, not measured), and the 2019-class laptop core (O-1.14) stays the owed row. Consequence per tier: a pool core or a node on a server-class CPU verifies the candidate class inside the gate with room; the ladder's top rung is out for any core slower than an M5 Max under load, which is why the testnet ships it false.
Marginal ALU energy per counted op: the 5090 10 to 13 pJ at its shipping clock (twice the 5.5 pJ the item 1 model assumed), the M5 Max 6.9 pJ. Power caps: -pl below 400 W cannot be set, the 5 October sweep rows re-used (302 to 316 W at every cap); the clock rows are OWED (nvidia-smi refused -lgc without rights; the job did not ask; an elevated job is a decision for the project lead, section 6). Item 1's denominator: the 5090 at the hash is 290 W in the app and 350 W in the bench, not 326; the f = 1 rows move 2 to 11 percent.
Chip side (approximate: the f = 1 stored-dataset chip of item 1 plus an ALU core at k times the 5090's measured 11 pJ per op): at N = 100,000 its per-joule edge over the 5090 falls from 5.6x (shadow empty, 350 W) to 2.1x on GDDR7 and 2.3x on one HBM3 stack at k = 1, 1.5x at k = 1.5, 3.2x at k = 0.5, 4.1x at k = 0.3; over the M5 Max from 1.6x to 0.9x at k = 1. The chip needs a 14,000-lane ALU array (about 30 mm^2 at N5, 150 W at k = 1) at 100,000 ops and 22,600 lanes (60 to 100 mm^2, 500 W) at 331,000; at 28 nm the array is reticle-class. That is the project lead's test as a number: with the shadow filled the chip must carry the memory system and a GPU-class datapath, and its edge is the ratio k of its datapath's energy per op to the GPU's.
Consequences per tier at N = 100,000: an Apple miner loses 1.5 percent of rate and pays 16 W more (0.56x per watt, per pound unchanged); a 5090 loses 0.2 percent and goes from 350 to 431 W (0.81x per watt), so a 5090 rig pays about 23 percent more electricity for the same blocks; a pool user sees nothing; a small NVIDIA card (4060 class) binds near 100,000 by its ALU budget (model, owed); AMD holds by its budget (owed); every verifier tier is untouched (+0.17 ms per warp).
Item 8, the RTX 4070 rows (PC 1 job run-ca3-pc1-4070-shadow-20261006, 17:36:05 to 17:48:10Z, exit 0; the 4070 alone through api/cards, the installed CUDA worker's --bench, nvidia-smi at 1 Hz with 12 of 12 idle samples carrying power; the card at its Ember tune point: a 1,860 MHz core lock and the 160 W cap, memory 10,251 MHz; the 5090 and 9070 XT mining beside it; every pack's fingerprint equal to the Mac's)
| N ops per hash | Pack | 4070 MH/s (delta) | Watts (min to max) | Microjoules per hash | SM MHz | Reading |
|---|---|---|---|---|---|---|
| 930 (class v3) | mx8-devnet-epoch0, twice | 30.95 | 79.3 to 79.8 | 2.56 to 2.58 | 1,860 | the control: 2.5x the M5 Max's energy per hash, a third more than the 5090's at the hash |
| 49,700 | sh256x13 | 31.08 (+0.4%) | 93.5 | 3.01 | 1,860 | |
| 49,700, 64-instruction block | sh64x52 | 32.09 (+3.7%) | 92.6 | 2.89 | 1,860 | the 64-block gain seen on the Mac and the 5090 |
| 102,100 (the candidate) | sh256x27 | 31.08 (+0.4%) | 109.0 | 3.51 | 1,860 | latency-bound; +30 W for no rate |
| 199,600 | sh256x53 | 31.07 (+0.4%) | 138.2 | 4.45 | 1,860 | still latency-bound |
| 330,700 | sh256x88 | 27.14 (-12.3%) | 159.9 (the cap) | 5.89 | 1,846 | the 160 W cap binds; compute-bound under it |
Reading: the model's "a small NVIDIA card binds near 100,000" is replaced by the measurement: the 4070 holds its rate to about 200,000 ops per hash at its tune point and binds only at 330,700 when its power cap does. Consequence per tier (main's reading, 17:5x UTC): class v4's 100,000 ops per hash costs the 12 GB NVIDIA tier nothing in rate, and the shadow has 2x headroom on that card; the 4070 owner pays 30 W more (79 to 109, 0.73x per watt); the N no card we own loses 5 percent at stays set by the M5 Max (about 130,000), not by the small card. One line to check: the restore printed "no entry was enabled before this job" and waited for no worker, while the card had been mining at 28.8 MH/s before it; the card's state after the job is read from the intake below.
Item 8, the RX 9070 XT rows (PC 1 job run-ca3-pc1-amd-g1-shadow-20261006, 15:46:27 to 15:56:54Z, exit 0; the 9070 XT alone through api/cards in every key form (amd:3:gfx1201 is the installed key today), confirmed by the process list, restored in finally and mining again 15 s later; the 5090 and 4070 mining beside it, the 5090 probably clock-locked at about 2,781 MHz from the aborted Ember step; AMD OpenCL 3683.0, device-event time, 2^24 per dispatch)
| N ops per hash | Pack | 9070 XT MH/s (window s) | OpenCL build ms / dataset ms | Watts | Fingerprint = the Mac's |
|---|---|---|---|---|---|
| 930 (class v3) | mx8-devnet-epoch0 | 18.92 (82), 18.92 again at the end | 41 to 51 / 74 | OWED (the ADLX helper ran, 0 samples parsed) | yes |
| 49,700 | sh256x13 | 19.31 (80) | 429 / 74 | OWED | yes |
| 49,700, 64-instruction block | sh64x52 | 19.07 (81) | 342 / 74 | OWED | yes |
| 102,100 (the candidate) | sh256x27 | 19.29 (80) | 428 / 74 | OWED | yes |
| 199,600 | sh256x53 | 19.11 (71) | 424 / 74 | OWED | yes |
| 330,700 | sh256x88 | 19.60 (53) | 418 / 70 | OWED | yes |
Reading: the AMD card never leaves the latency bound on this ladder (its ALU budget is about 650,000 ops per hash); the +2 to 4 percent with the shadow is inside its clock and noise band. Consequence per tier: an AMD RDNA 4 owner loses nothing at the candidate and nothing at 330,700; the N the project can pick stays set by the M5 Max (about 130,000) and the capped 5090 (about 210,000); the one-click AMD miner pays 0.42 s of OpenCL compile per pack at the boundary against 0.05 on class v3, under half a second; the daily build is unchanged at 74 ms. The AMD per-joule row (item 1) and MH per W stay OWED until the sampler reads watts.
Item 6, the 5090 rows (ca3-reserve b85f0f1; job run-ca3-family-pc2-20261006, 08:42:27 to 08:43:03Z, exit 0, the card quiet, prover off and back on; nvcc 12.8 sm_120; best of 3 runs; every row bit-exact)
| Family | M5 Max, Metal (ratio to the alu chain, 881 G steps/s) | RTX 5090, CUDA (ratio to the alu chain, 7,941 G steps/s) | RX 9070 XT | Native or emulated |
|---|---|---|---|---|
| rotr (live) | 1.13 | 1.32 | OWED | native everywhere |
| shflx (live shuffle) | 0.86 | 1.49 | OWED | native |
| variable shifts shl / shr | 0.85 / 0.86 | 1.27 / 1.28 | OWED | native |
| bfe (bit-field extract) | 0.77 | 1.54 (a two-instruction sequence on NVIDIA) | OWED | native on Apple and AMD, sequence on NVIDIA |
| andn | 0.75 | 1.26 | OWED | native |
| perm (byte permute) | 1.13, EMULATED | 1.30 (prmt) |
OWED | emulated on Apple |
| popc / clz | 0.87 / 1.01 | 1.50 / 1.63 | OWED | native |
| sel | 0.76 | 1.32 | OWED | native |
| shfla (lane + delta) | 1.91 (2.2x the xor shuffle) | 1.53 | OWED | native; the 32-lane crossbar is the chip's cost (about 6x the xor butterfly, approximate) |
| dot4 (comparison) | 1.60 unsigned / 4.73 signed, emulated | 1.16 | 1.06 (5 October) | |
| mm8 (comparison, R8) | OWED (Metal 4 matmul2d) | 2.43 (mma.m8n8k16.u8, bit-exact) |
OWED | the licensable block |
The RX 9070 XT column (PC 1 job run-ca3-pc1-amd-family-20261006-e, 17:31:57 to 17:34:47Z, exit 0; the card ALONE: every gfx1201 entry posted off, its worker pid 19788 gone, three runs at 17:32:11 / 15 / 19Z with card_state=alone, every entry restored with its own flag and identities and the card mining again 20 s later under pid 13040; the gfx1036 and old-platform columns run after the restore beside the miners; AMD OpenCL 3683.0, gfx1201, 32 CUs; the range below is over the three runs' best-of-3): alu 1,074 to 1,186 G steps/s (ratio 1.00); rotr 0.99 to 1.13; shflx (xor shuffle, ds_bpermute) 0.82 to 1.21; shl 1.00 to 1.02; shr 0.91 to 1.02; bfe 1.00 to 1.09 NATIVE (amd_bfe); andn 0.91 to 1.01; perm 1.73 to 1.93 EMULATED (no byte-permute path in AMD's OpenCL C); popc 0.91 to 1.01; clz 1.19 to 1.30; sel 0.90 to 1.01; shfla (lane + delta, ds_bpermute) 0.75 to 0.84 NATIVE; dot4 1.00 to 1.11 NATIVE (sudot4); mm8 1.68 to 1.83 NATIVE (the WMMA iu8 builtin reaches gfx12; exact UNVERIFIED: the fragment layout is not in any source at hand, so the CPU reference was not attempted rather than guessed). The AMD column of item 6 is CLOSED. Reading: on RDNA 4 every 32-bit datapath family sits within 0.75x to 1.30x of the alu chain, the shuffles cheaper than it (an LDS operation overlapping the dependent chain), so the ds_bpermute number that could have moved R3 leaves the order as proposed; the two dear rows on AMD are the same two as on Apple and NVIDIA, the byte permute and mm8.
Reading: against the live rotr every candidate is 0.95x to 1.23x on NVIDIA; on Apple only perm (emulated) and shfla cost more than rotr; the 8x emulation bound of 1.13.2 holds everywhere by 4x or more; the 5 percent hash-rate bound at W_new = 4 is argued from the step cost (under 1 percent of ALU time on a read-bound hash), not measured, since no reserve family is live. Proposed order R1 perm, R2 popc and clz, R3 shfla, R4 bfe, R5 shifts, R6 sel, R7 andn, R8 mm8, W_new = 4 each, family n at era n (mm8's era-4 unlock kept as a named exception or moved to era 8: the project lead's call); the full proposed 1.13.2 text with edge vectors per family is docs/plans/counter-asic-3-reserve.md section 6. Consequence per tier: an Apple miner pays the emulated perm at 1.13x a step and shfla at 1.91x, under 1 percent of its hash rate at W_new = 4 (argued); an NVIDIA miner pays nothing measurable; an AMD miner's row is owed and its ds_bpermute_b32 cost is the one number that could move R3; a chip pays a barrel shifter, a byte crossbar, a popcount tree and a 32-lane crossbar per lane, which is the point.
Item 6, the Mac rows (interim, ca3-reserve 192a683; the 5090 job waits on PC 2)
Step cost per family on the M5 Max as a ratio to the add-xor-rotate chain (881 G steps/s; best of 3; load average 7.64; all bit-exact): shl 0.85, shr 0.86, bfe 0.77, andn 0.75, byte permute 1.13 (emulated on Apple), popcount 0.87, clz 1.01, select 0.76, indexed shuffle 1.91 (2.2x the xor shuffle), live rotr 1.13, dot4 unsigned 1.60, dot4 signed 4.73. Every 32-bit datapath family costs an Apple lane under 1.2x a step, inside the 8x emulation bound of 1.13.2 with room; the matrix family is the only one past 1.6x. The rows feed item 8's ALU pricing. The full table with consequences lands at item 6's close.
Items 4 and 7 on the live tables (dry mode, read-only, 09:2x UTC; the live observer still runs master's code)
| Module | Reading | Consequence |
|---|---|---|
| Detector (window epochs 41 to 46, tip DAA 171,165, 20 ids) | network 125 to 152 MH/s per epoch, settled; bands from the fleet log 5090 99.4 / 115.6 / 123 MH/s (n 849), M5 Max 26.5 / 27.4 / 28.5 (n 586), Intel UHD 1.7 / 1.8 / 2.2 (n 758); correlation pairs 6, max r 0.94, edges 1 (the two 5090 ids, PC 1 back since 07:2x), groups none; alert inactive, held 0 of 6; events none | quiet on the devnet; two findings sent to the detector worker: two honest same-model cards cross the 0.8 edge (the group rule of 3 or more ids is what keeps the alert off; the edge may be a network-estimate artefact), and each 5090 id reads about 50 MH/s on chain against the 115 MH/s band (a factor of two to explain before an unknown miner is banded). ANSWERED (ca3-detector 9c7838e, merged): the r 0.94 edge was an artefact of the epoch common factor (the mean over every present id let the paused-and-resumed Mac push the other residuals together); the factor is now the median over the steady core ids, and the same window reads max r 0.10, no edge, tests 7 of 7, the fabricated design still alerts. The factor of two is identities=2 on PC 2's worker (2 x 50.4 = 100.8 MH/s on chain against the 115.6 band, 0.87x, the ratio the whole network shows: reds, pending blocks, template latency); the key count joins the coinbase tag with the card model (owed, 0.3.12). The devnet's max pairwise r over the windows run is 0.10 to 0.53 against the 0.8 edge; the alert stands as a trigger with the 3-id group rule |
| Vendor share (10-minute window, network 253 MH/s) | fleet-reported: NVIDIA 241.7 MH/s (2 workers, 0.920), AMD 18.8 (1, 0.072), Intel 2.2 (1, 0.008), Apple 0 (the Mac paused); chain-attributed: NVIDIA 0.914 (529 of 579 blue blocks, 10 ids), AMD 0.078 (45 blocks, 8 ids), Intel 0.009, unknown 0 (every id maps to a fleet key, 30 mapped) | the two readings agree within 1 percent; the devnet is a one-vendor fleet at 91 percent NVIDIA, which is what the metric is for: an AMD owner's share of income is 0.078 for 1 of 4 cards, an Apple owner's 0 while paused; the public testnet's number is the one that matters |
The live observer runs the shared checkout, which autosync fast-forwards from origin/master; new code reaches it only through a push to master, which is the project lead's call (CLAUDE.md: push only when the project lead asks). So the one restart main asked for waits on that push; the dry rows above are the evidence until then.
Consequences per tier (item 1)
| Tier | Meaning | Being done |
|---|---|---|
| Home miner, 8 or 12 GB card | Nothing today (no chip exists; a 28 nm controller project is $5M to $30M and about 32 months by the Ethash precedent); when one lands it runs 0.3 to 0.5 microjoules per hash against 10 to 20 for this tier (approximate), the first tier out | the power-cap rows and the item 8 measurement; the detector (item 4) is what tells this miner a chip has arrived |
| 16 GB AMD (9070 XT) | 7x worse per joule than the 5090 and 30x worse than the chip (approximate); a chip ends AMD home mining first | vendor-share metric (item 7); nothing in the hash fixes AMD's 2.4 G dependent reads/s |
| 24 or 32 GB (5090, M5 Max) | the honest best at 2.40 microjoules; 5x to 9x behind the chip in the model, 2x to 5x by the precedent | a 200 W cap on the 5090, if the rate holds, halves the gap |
| Rig | per joule it is its cards; at $2.8 against $14.7 per MH/s a chip fleet is cheaper per dollar too | the issuance trigger: bounty and benchmark live before daily issuance crosses about $50K (item 4b) |
| Pool user | a chip fleet is a few operators; Monero's was found at 85 percent by its share pattern | the detector, before the public testnet |
| The public claim "under 2x" | held for the recompute chip at the op budget; per joule and against the stored-dataset chip the model reads over 2x on both memories and the precedent reads 2.1x to 4.8x; NOT SAFE TO PUBLISH as worded | decision for the project lead (section 6); nothing on the site or the devnet changes from this run |
3a. Corrections found by the run
| Found by | What was wrong | Fixed |
|---|---|---|
| item 3 (43c3ead) | spec 01 section 1.13.1's era table and docs/plans/mixer-x4.md section 2 still said mixer_mult = 4; the code (LoadClass::MX8, V3_CLASS) and spec 1.8.5 say 8 |
both lines corrected on ca3-coord, 6 October 2026 |
| PC 1 job 2 (family, run-ca3-pc1-amd-family-20261006, 16:56 to 16:59Z) | the probe ran on device 0, the integrated gfx1036, not the 9070 XT (device 1): every row dev=0 name= empty, alu 40.59 G steps/s (a one-CU figure); the rows are RDNA 2 iGPU ratios (shifts 1.15, bfe 1.15 native, andn 1.16, popc 1.55, clz 1.75, sel 1.81, shfla and shflx 1.89 through ds_bpermute, perm 2.43 and dot4 2.57 emulated, mm8 none: AMD's OpenCL C compiles no byte-permute, dot4 or WMMA builtin) and the 9070 XT column stays owed |
the probe picks the device by name (gfx1201 on the newest AMD platform) and prints it in every row; re-run in the next PC 1 slot |
| the watts job (run-ca3-pc1-amd-watts-20261006, 17:49:46 to 17:52:54Z, FAILED exit 1) | the sampler proved itself (12 of 12 9070 XT watts lines), the 90 s app-state window ran (the card mining at 18.87 MH/s, 203 W, identities 8 before it), every gfx1201 entry was posted off, the card went quiet and the sh256x27 bench started; then the script exited with no APPROW, no LADDER, no watts error= and NO RESTORE line in any upload (no enabled=True post, no card_workers_after): a finally that did not run or did not print, so the 9070 XT may have been left OFF |
CONFIRMED and restored: api/state at 17:55:10Z read the card enabled false, state off, 23 W idle; the identities job run d posted it back and at 17:57:10Z it mined under pid 3436 at 18.9 MH/s, 195 W, identities 8; the entry amd:1:gfx1201 was set back to enabled at 17:59:05Z (job run-ca3-pc1-amd-flag-amd1-20261006) with the card mining through it (18.86 MH/s, 200 W); PC 1 free at 18:01:05Z; the AMD watts row stays OWED; the cause and a fixed script (an unconditional finally with its own first line, no exit inside the try, the device dumps out of the report) with the script worker before any re-run |
| the 4070 ladder's restore line | "no entry was enabled before this job" and no wait for the worker, while the card had mined at 28.8 MH/s before it | the intake shows the 4070's worker restarted 15 s after the restore and racing at 30.9 MH/s: the card came back; the script's settings read, not the card, was wrong |
PC 1 family run d (run-ca3-pc1-amd-family-20261006-d, 17:17 to 17:20Z, exit 0; run b had failed because the script's probe parameter was named $args, PowerShell's automatic variable, so the splat was empty: renamed, with a rule added to tools/ci/ps-drive-ref-check.sh that fires on the old signature and stays quiet on the new) |
the probe chose the 9070 XT by name (gfx1201, 32 CUs); every variant built on it: mm8 NATIVE through the WMMA builtin on gfx12 (exact unverified), dot4 native (sudot4), bfe native, the shuffles native (ds_bpermute, ds_swizzle), the byte permute EMULATED (no amd_perm path in AMD's OpenCL C). The step costs are unusable: the card was mining beside the probe, the alu chain read 226 then 195 G steps/s and the ratios swung from 5.9 to 11.8x (run 1) to 0.17 to 1.3x (run 2), the loaded card's scheduler | the 9070 XT column is taken with the card alone (run e, job 1's switch path), after the G2 job |
| the identities job, first run (run-ca3-pc1-amd-identities-20261006, 17:02:10Z, failed in 0 s) | my own script: "... under $appDir: nothing posted" is a PowerShell 5.1 parse error ($appDir: reads as a drive-qualified variable), so the script never started; the script worker checks this shape by hand, CI did not |
${appDir}:; the class guard tools/ci/ps-drive-ref-check.sh added to ci.yml (67 .ps1 files clean; a backtick-escaped $ in a bash-generating here-string is ignored); the job republished as -b |
| the identities job, run c (run-ca3-pc1-amd-identities-20261006-c, 17:05:53 to 17:07:53Z, done) | the 9070 XT's live entry amd:gfx1201 read identities 2 at 18.91 MH/s and 203 W before; the one POST (the app's cards-array shape) and a 120 s settle; after: identities 8, mining under a new worker pid, 18.9 MH/s (avg 18.77), 199 W. The identities count moves no rate (18.92 at 2 was the number to beat). Run b of the same job had failed on the flat body shape (400) | closed: PC 1's 9070 XT runs as it did before job 1 |
| the reset job (16:55Z) | the 9070 XT's ADLX state read factory 0 after Ember run 6 (offsets zero, the flag cleared by the engine's set of 0); the app runs the card under amd:gfx1201 with identities 2 where it ran 8 before job 1's restore | the reset to factory 1 applied and read back; the one POST api/cards back to 8 identities running as its own job, the rate before and after recorded |
| item 2's PC 2 job | the settings.json card key is nvidia:0:NVIDIA GeForce RTX 5090 (with the device index); the 5 October job scripts posted the state's key without the index, so POST api/cards switched nothing and the miner stayed up through the 90 s wait: the job's 5090 rows are loaded-card figures |
items 6 and 8 told to post both key forms and confirm by the process list; the class fix (one key form everywhere, a check that fails a job script posting a card key without the index) is owed to the job tooling |
| the coordinator's merge of ca3-shadow | git add -A docs staged docs/bench-log.md with its conflict markers inside (a conflicted path is marked resolved by git add), so 45f3019 carried markers into HEAD; found at the ca3-reserve merge as nested markers |
the three 6 October entries kept in order with every marker removed (fcce185); the class guard already exists, tools/ci/no-conflict-markers.sh in CI, and it would have failed the push; it passes on the merged tree |
| the merge of ca3-derive and ca3-shadow | both added a field to LoadClass (derive_len, shadow); resolved as the union, every other literal spreads ..; cargo test -p igneum-pow on the merged tree (cargo 1.99 at ~/.cargo/bin; the Homebrew 1.69 on PATH cannot read the lock file): 59 + 7 + 4 + 19 + 7 = 96 passed, 0 failed, the pinned v2 and v3 packs byte for byte |
merged 09:10 UTC |
| item 3 | the mixer's op count: 144 integer ops per application as written in memhard.rs (128 with RC and rk hoisted) against the 130 the chip model prices (chip-model-v3.md section 1, from spec 1.8.4) |
items 1 and 2 asked to state which figure their rows use and why; the status close carries the answer |
4. The chip model, before and after
Every chip figure is arithmetic on cited memory and logic figures and is approximate; every GPU figure is measured and names its entry. "Per chip" is rate per chip against the 5090's rate; "per joule" is energy per hash, the Ethash chips' metric.
| Chip | Before 3.0 (the 2.0 record, 5 October) | After 3.0 (6 October) | Source |
|---|---|---|---|
| On-die 256 MiB cache recompute chip (f = 0), class v3 | 0.31x bare, 0.92x with the 3x fixed-function factor per chip; per joule not priced; the public claim "under 2x" rested on this row | per chip unchanged; per joule 1.86x (1.3x to 2.4x over the on-die read energy); with the per-day derivation (item 2, dr736) the 3x factor goes: 0.29x bare, 0.34x at a 1.2x allowance, 0.43x at 1.5x | chip-model-v3.md sections 2, 5.4, 6 |
| Stored-dataset memory-controller chip (f = 1), the Ethash class | not priced (O-1.6 open, the curve never drawn) | per chip 1.22x on GDDR7, 0.61x on one HBM3 stack, 4.9x on eight; per joule 5.1x (GDDR7) to 9.2x (eight HBM3 stacks) at the 326 W denominator, 5.6x at the measured 350 W bench control; $2.8 per MH/s against the 5090's $14.7; the Ethash precedent for this class 2.1x to 4.8x per joule; the curve is monotone toward f = 1 so the partial-store chip is never built; the mixer, item 2 and x16 do not touch it | chip-model-v3.md section 5; history rows 3 and 4 |
The same chip with the latency shadow filled (item 8, N = 100,000 ops per hash, class v4 candidate mx8+sh256x27) |
not a lever anyone had priced | per joule over the 5090 2.1x (GDDR7) and 2.3x (HBM3) at k = 1, 1.5x at k = 1.5, 3.2x at k = 0.5; over the M5 Max 0.9x at k = 1; the chip needs a 14,000-lane ALU array, about 30 mm^2 at N5 and 150 W at k = 1, reticle-class at 28 nm; k, the chip core's energy per op against the 5090's measured 11 pJ, decides it, and 2x is crossed only at k under 0.5 | latency-shadow-2026-10-06.md sections 6 and 8 |
| The honest denominators | the 5090 at 136.1 MH/s and 326 W (a peak with the prover on) | the 5090 at 290 W in the app and 350 W in the bench (2.34 to 2.65 microjoules per hash), cap floor 400 W so no power cap binds; the M5 Max at 21 W GPU plus DRAM (0.78 microjoules), three times better per joule than the 5090 and the honest best we own | item 8; miner-eff's 4 October log |
What 3.0 did to the model in one line: the chip that matters is not the one 2.0 priced; it is the Ethash-class memory-controller chip, over 2x per joule today; the lever that answers it is program work in the latency shadow, which makes the chip carry a GPU-class datapath, and the measured candidate takes its edge from 5.6x to 2.1x at a chip core no better than the GPU's, for 0.2 percent of the 5090's rate.
5. What passes as class v4
Judged on measurements against the six gates of docs/plans/counter-asic-2-rollout.md section 7. Nothing is published; nothing is cut.
| Candidate | Measured | The six gates | Verdict |
|---|---|---|---|
mx8+sh256x27: class v3 plus a 256-instruction ALU block run 27 times per iteration, about 100,000 ops per hash (item 8) |
hash rate -0.2 percent on the 5090, -1.5 percent on the M5 Max, under the 5 percent rule; verifier +0.17 ms per warp (2.23 ms, gate 10 ms, 2019-class core about 5.6 ms); bit-exact on Metal, CUDA, clang emulation and Apple OpenCL; the 5090 at 431 W (its cap) from 350; the 9070 XT owed | G1 bit-exact: NVIDIA and Apple GREEN, the AMD vendor NOT RUN (gfx1036 or the 9070 XT); G2 (1,000 random hashes per card re-hashed on the CPU): NOT RUN; G3 (crate suite green: 96 of 96; the Metal fuzz, edge and stats runs on the class): NOT RUN; G4 (the fast-time 3-node network across a v4 activation): NOT RUN; G5, G6: NOT RUN | READY FOR THE GATE RUN as THE class v4 candidate, on the project lead's word; not ready for a cut. Two design decisions ride with it: the acceptance rule does not yet interpret the block (cost stated in the analysis), and the block stays at 64 to 256 instructions |
dr368 or dr736: the per-day derivation (item 2) |
dr736 verifier 4.9 ms per unit on the M5 Max core, about 12 ms on a 2019-class core (over the gate); dr368 2.69 ms, passes both; bit-exact on Metal, Apple OpenCL and CUDA; build +7 ms a day on the Mac, +2 ms on the 5090; NVRTC +1.1 s per pack (a once-a-day module is a requirement) | not a v4 candidate: a reserve entry | GO as reserve R0 (proposed text, counter-asic-3-derivation.md section 6); NO-GO genesis-live at dr736 until O-1.14; urgency LOW (the f = 1 chip derives no item) |
| The reserve order R1 to R8 (item 6) | step costs on two cards, every family under 1.91x a step, bit-exact | a spec ordering, no activation | GO for the order as proposed; a decision for the project lead |
| Layer 9 (epoch length) ranked above layer 7 (mm8) (item 5) | FPGA soft overlay 0.30x to 0.39x per watt on the measured basis, 0.7x to 1.9x at the unmeasured bank-bound ceiling | reserve ranking | GO for the ranking; the rented FPGA hour owed |
So: one class v4 candidate, mx8+sh256x27, defined and measured on the hash's own numbers, with gates G1 (AMD), G2, G3 (Metal runs), G4, G5 and G6 still to run before any publish, by the two-publish rollout of 2.0 and a program_class_v4_activation_daa at tip + 14,400.
5a. The gate run (the project lead, 16:50 UTC: "3.0 run it now"; opened 16:5x UTC)
No publish, no manifest, nothing on the live devnet; PC 2 one job at a time with the installed app untouched; the Mac's miner stays paused. Two lanes: the hash side (branch ca3-v4-hash: G1 Metal, Apple OpenCL and CUDA, G2, G3 and the verifier benchmark; one PC 2 job first) and the node side (branch ca3-v4-node and the fork worktree igneum-node-ca3v4 from release-0.3.13-node: the v4 switch through igneum-pow, the fork, the workers, the miner and the app, then G4, G4b, G6 with --features igneum-pow, G5; its PC 2 jobs after the hash lane's). G1 AMD rides in PC 1 job 1 on "go PC 1 AMD". Evidence lands in docs/plans/counter-asic-3-gate/.
| Gate | What | State | Evidence (full lines in docs/plans/counter-asic-3-gate/hash-gates.md and node-gates.md, JSON per run beside them) |
|---|---|---|---|
| G1 | bit-exact v4 on every vendor against the Mac reference (2^24 fingerprint, self-test) | GREEN on all three vendors | Apple (Metal and Apple OpenCL, 15:49 to 15:50Z) and NVIDIA (the 5090, PC 2 job, 15:52Z): eight packs, three harnesses, one fingerprint per pack; AMD (PC 1 job run-ca3-pc1-amd-g1-shadow-20261006, 15:46 to 15:56Z): 7 of 7 packs equal to the Mac's on gfx1201 (sh256x27 3d2e8245cc084d07) |
| G2 | the CPU verifier exact on 1,024 random hashes per card | GREEN on all three vendors | AMD (PC 1 job run-ca3-pc1-amd-g2-20261006, 17:22Z, the kit worker's serve mode on gfx1201 through the class=v3 and class=v4 tokens, beside the miners): 1,024 of 1,024 found and distinct on the control mx8-devnet-epoch0 (digest 2a1824a2...) and on the generator-4 candidate v4-devnet-epoch0 (435b976a...), both re-hashed on the Mac through tools/ca3-v4/g2-recheck.sh --digest: MATCH 1,024 of 1,024 each. The first kit's sh256x27 is a string-seed pack the worker's job protocol refuses, so G2 ran the chain-seed packs the 5090 and the Mac ran |
| G3 | the soundness suite green on the class | GREEN | the crate suite 96 of 96 (97 on the merged tree at 17:17Z, cargo 1.99); the Metal fuzz 200 of 200 and 50 of 50; Apple OpenCL 20 of 20 and 5 of 5; 4 of 4 CPU tests on the class and on the era-composed class |
| Verifier benchmark | ms per warp on one M5 Max core, v2 / x8 / v4 in one session, gate 10 ms | GREEN | 2.33 ms on the candidate (x8 2.06), about 5.8 ms on a 2019-class core by the 2.5x rule (approximate); the 2019-class core itself still unmeasured (O-1.14) |
| G4 | the fast-time 3-node network across a v4 activation, plus the known-failed case | GREEN (and GREEN again on the id fix with the id assertion and its failed case, 491131a) | run 1 (15:54 to 15:59Z, class-v4.mjs, activation 150 rounded to epoch 3 at DAA 180, the v3 switch at 60): 3 of 3 switch lines, templates class 2 / 3 / 4 by epoch, 181 blocks before and 128 after DAA 180, program ids agree on all three miners and no v2 or v3 id reappears under v4, rejected 0/0/0, one sink at 308/308/308, one digest; the first v4 epoch's cache ready in 2 ms (the v3 day cache reused across the boundary); run 2 the known-failed case (the switch at never: no v4 epoch reported) |
| G4b | a real Metal miner across a v4 boundary through --prepare-packs | GREEN | run 3 (16:02 to 16:07Z, igneum-bench from the committed tree): 5 PREPARE lines 5 to 6 DAA before each boundary, three class=v4 era=<hex>, the worker's prepared lines (430 ms the first with the v4 day built on the GPU, 139 and 175 ms with the day resident; a v3 prepare 62 ms), every swap with no pause, 301 blocks accepted on the Metal miner (123 after the switch) all re-checked on the CPU mismatched 0, need 0, no mismatch or out-of-date line, no exit 42 or 44 |
| G5 | the PC-built Windows workers and the Mac workers from the same commit | GREEN, one gap named (re-done from the fix 7c22d0d: cuda.exe 3bc8ad8f..., opencl.exe 16ef0154..., igneum-bench f9ca4b07...) | the Windows workers cross-built on the Mac from a522d04 as 0.3.11's G5 did (the build job has no worker unit: a tooling gap): igneum-worker-cuda.exe e563126e... (1,536,512 bytes), igneum-worker-opencl.exe 7fce1249... (478,208), both with the resource block, mingw not bit-reproducible (a link-time stamp); the Mac igneum-bench 30c70754... from the same tree, the binary G4b mined with; the node and app from PC 2 job build-20261006-155958, every sha256 verified |
| G6 | the node suites on PC 2 with --features igneum-pow, from a fork branch off the current release tip | GREEN | fork ca3-v4-node 5f7e0543 on release-0.3.13-node; PC 2 job build-20261006-155958 (15:59 to 16:08Z under the lock, the app untouched, the prover on): every stage ok in 392 s; kaspa-consensus 98 (2.0's flake did not recur), consensus-core 109 + 7 (override_params_carry_the_program_class_v4_activation), kaspa-pow 15 with the v4 engine test under the feature, p2p-flows 33, igneum-app 112 + 26 + 8 |
BLOCKER before any cut (found by the hash lane, 17:0x UTC): program_id(3, seed, attempt) is class-independent, so all seven v4 packs carry the same program id as the v3 control of their seed (73bcbfe8ccf988f1), and a stale worker across the activation would see no id mismatch (2.0's G4 id check cannot fire on it; G4's per-epoch ids differ only because each epoch has its own seed). The fix is on the v4 seam, assigned to the node lane: a generator-4 stamp in the id so a v3 and a v4 program of one seed differ, v2 and v3 ids byte-identical, the packs re-exported (fingerprints unchanged, ids moved), G4's id assertion and the fuzz re-run. FIX MERGED (ca3-v4-node 7c22d0d, 17:3x UTC): the trap was the CLI's --era path (stamp_era stamped generator 3 on any class), not the chain seam (the fork already stamped generator 4 and its kaspa-pow test asserts the same-seed v3 and v4 ids differ); now generate_era and the CLI stamp the generator from the class, the shadow block marks class v4 in packcheck.rs, packfile.h and main.swift (a generator-3 pack with a shadow block is refused as "a v4 program stamped v3", a generator-4 pack without one refused; the ladder packs stay loadable); v2 and v3 ids byte-identical; the crate suite 97 of 97 on the merged tree; the seven gate packs re-exported with generator 4, class "v4" and program id c120d7963abdcd96 (the v3 control keeps 73bcbfe8ccf988f1), only the generator, id, class and comment lines changed, the kernels and vectors byte-identical. The hash lane's re-run on the fix is GREEN (ca3-v4-hash ca61dec, merged; hash-gates.md "Follow-up 1"): the crate suite 97 of 97; the seven packs re-exported here equal the tree's (0 differing files); the fingerprints unchanged on the rebuilt Metal and Apple OpenCL harnesses (all eight); Mac G2 through the class=v4 token 1,024 of 1,024 on all eight packs, both harnesses; the fuzz 200 programs and 800 units, stats, edge and determinism 4 of 4 on the class and 4 of 4 era-composed, the same-seed v3 and v4 ids now differ (assert_ne). The node lane's re-run on the fix is GREEN (ca3-v4-node 491131a, merged): G4 re-run 16:32 to 16:38Z on igneumd and igneum-miner rebuilt on the fixed crate, SUMMARY PASS, 181 / 125 blocks across DAA 180, rejected 0/0/0 and 0/0/0, one sink at 305/305/305, and the id assertion: every v4 epoch's id on all three miners equals the CLI's class v4 id for that seed and era and differs from the same-seed v3 id (e3 30544487d1289d6e against 1ae1c9f0eda0cef5, e4 53e36801cc6fafcf against af81f6e844959460, e5 876e155e3fb59983 against b4f25c4678496a78); the assertion's own failed case (--id-check-against v4) reports exactly FAILED CHECK v4_ids_differ_from_the_same_seed_v3_id, exit 1. The seven re-exported packs' Metal fingerprints by packbench equal the table (only the ids moved). G5 re-done from 7c22d0d because packfile.h and main.swift moved: igneum-worker-cuda.exe 3bc8ad8f..., igneum-worker-opencl.exe 16ef0154... (resource block verified), igneum-bench f9ca4b07...; kaspa-pow with the feature 15 of 15 on the rebuilt fork. THE BLOCKER IS CLOSED: the gate table is green on the hash and on the cut, with AMD G2 and the AMD watts the owed rows (queued on PC 1). Two conditions ride with the fix: every kit sent to a PC carries the re-exported packs (the AMD G2 kit is being rebuilt from the merged tree), and the mixer.rs harness change rides with any merge of 7c22d0d (it does, on ca3-coord). The PC 1 AMD rows taken on the old-id packs stand: the id is not an input to the hash.
The per-tier cost line of the candidate (item 8, measured): the 5090 -0.2 percent of rate at 350 to 431 W (a rig about 23 percent more electricity), the M5 Max -1.5 percent at 21 to 37 W, pool users nothing, the verifier +0.17 ms per warp; the 9070 XT and the 4070 rows land with the PC 1 jobs. Owed before the cut, besides the blocker: the AMD watts (the sampler fix is in; the re-run queued), the 2019-class core (O-1.14; the US laptop's CPU could answer it with a Windows igneum-pow build, a proposal), the G2 found-lines file and digest and the 200 KB report cap (tooling, in hand on ca3-v4-hash).
Two preconditions on the cut, from main (17:0x UTC, both from today's incident), assigned to the node lane:
| # | Precondition | What passes it | State |
|---|---|---|---|
| P1 | The cut rehearses first on the rented fleet as a staging network (the fleet agent owns the boxes; the node lane supplies the v4 override object and the rehearsal plan docs/plans/counter-asic-3-rehearsal.md) |
a fleet-only chain crosses the v4 activation with every box switched: zero rejected blocks, blocks on both sides, the G4 id assertion live on every box, one sink, one digest; the stale-box case refused at the handshake with no fork | PASSED 19:33Z (the run's record in section 5a's P1 cell below the table and docs/plans/counter-asic-3-rehearsal.md). PLAN WRITTEN (ca3-v4-node f39a8eb, merged): fleet-only chain igneum-devnet-400 from its own genesis state, 12 or more mining boxes, a seed box, one stale 0.3.13 box; the signal flip at DAA 7,200 (the first full 3,600-DAA window) with the floor at 14,400 not reached; ten steps, the report fields and pass rules; the id assertion from the boxes' miner lines. Two objects as files in docs/plans/counter-asic-3-gate/: the publish object (the live 13 fields plus program_class_v4_activation_daa = N6, the floor, tip + 14,400 rounded up, 219,600 at the 16:57Z DAA of 202,919, and program_class_v4_signal_window_daa = 86,400; digest ac8e60ce...) and the rehearsal object (every earlier switch at 0, window 3,600, floor 14,400; digest bc2142b1...); the no-file devnet digest on this binary 7f2e49be... (3c505021 superseded: the window field joined the digest). THE RUN STARTED 18:22Z (the fleet agent): igneum-devnet-400 from the devnet genesis with the re-cut 1-block/s object override-v4-rehearsal-1bps.json (600-DAA epochs, lead 100, window 600, the flip at epoch 2 = DAA 1,200, the floor at 2,400; node digest d23394e7...; the file written byte for byte on every box) and the signalling fork's Linux binaries from PC 2 job build-20261006-174823 (igneumd 847ddfd1..., igneum-miner 37178aeb..., verified on the Mac and every box); the seed on the RunPod pod dn2-seed (public p2p 213.173.110.229:11927, no miner); 15 mining boxes beside their live-devnet nodes on separate ports with fresh appdirs and 1-thread CPU miners (dn2-1, dn2-2, dn2-3, hub-1, 3080, 4070, 4090, 5090, A5000, 3090-2, 3090-3, 4070-1, 4090-1b, 4090-3, the 8x 4090 rig); the stale box p2-3090-4 on 0.3.13's igneumd d6350586 with the same file and no miner, started last; the 38 wave pods join about 18:50Z. The clock from the seed's genesis at about 18:23Z: the window full 18:41Z, the flip about 18:43Z, the floor about 19:03Z (run to the floor so its line is exercised). A sampler on every box every 5 minutes; the id lines go to the node lane for the CLI check; the report in section 4's table plus rehearsal- |
| P2 | No fixed-height activation on the live devnet again: miner signalling for class changes as the v4 seam's activation rule (the block carries the miner's object version; the class flips at the first epoch boundary after 95 percent of mining weight over a window signals the new object, with a floor height after which it flips regardless), PROPOSED spec text in counter-asic-3-node.md, implemented behind the override, with the fast-time harness test (67 percent does not flip; 100 percent flips at the next boundary; nobody signals and the floor flips it; each with its failed case) and G6 again on PC 2 |
the three harness runs PASS with their failed cases; G6 green on the fork change | GREEN (ca3-v4-node 0635c04 and 3892035, fork 0562a7f2 on 5f7e0543; PROPOSED text in counter-asic-3-node.md section 6: the header version's high byte carries the node's object version, the low byte stays the block version so later objects pass the version check; weight = blue blocks by the finality walk over the window ending at each epoch's seed block; 95 percent = 9,500 bps; window 86,400 DAA in the file and the digest, 0 = off; monotone, memoised per seed block; the fixed height stays as the floor; IGNEUM_CLASS_SIGNAL lowers a node's byte on devnet and simnet only; RPC fields 20 to 23). The fast-time gate infra/fast-time/class-v4-signal.mjs (three CPU miners, window 120, v3 from 60): two of three signalling PASS with no v4 epoch over epochs 0 to 7 (share 6,166 to 7,583 bps, 0 rejected, one sink 424/424/424); all three PASS with the flip at epoch 3, the first full window, 10,000 bps, 3 of 3 switch lines, 181 / 124 blocks, 0 rejected, one sink, the id assertion on epochs 3 to 5 (e3 e48e6be7c6699824 against the v3 6847355c88e8215f); nobody with the floor at 300 PASS, 0 bps, the flip at epoch 5 by the floor and not before; the failed case (two of three told to expect a flip) FAIL on eight checks. G6 on the signalling fork: three PC 2 jobs under the lock, prover on, app untouched (build-20261006-173017 hit 2.0's flake, 97 of 98; build-20261006-174027 kaspa-consensus alone exit 0; build-20261006-174823 the five crates exit 0 in 35 s with consensus-core 110 + 7, igneum-exec 18, kaspa-pow 15 with the v4 engine and the signal-rule tests, igneum-miner 18, p2p-flows 33, and the app 112 + 26 + 8 exit 0; its closing line "upload incomplete" is the relay blob fault after both test stages closed exit 0). Owed and named: a class-signal witness in the pruning-proof format (a proof-synced node falls back to the floor rule for epochs whose window reaches below its pruning point and logs it), the same class as the era witness |
Facts for the cut from the node lane (docs/plans/counter-asic-3-node.md): the devnet digest moves (c562d70e... to 3c505021...), so the cut is a one-sweep binary rollout and a 0.3.13 node is refused at the handshake afterwards (intended, fleet-wide); a 0.3.13 miner reads the v4 height as never (an optional proto field), so miners and nodes move together; infra/fast-time/override-60x.json as committed carried the proving-v1 block twice and lacked four 0.3.12 and 0.3.13 fields (the node refused the file; fixed, with a new CI check override-json-check.sh); the 48 GiB target clone vendor/igneum-node-ca3v4/target-ca3v4 can go after the cut.
THE ONE LINE FOR [user]: class v4 (mx8+sh256x27, 100,000 ops per hash in the latency shadow) has passed every gate on the fixed tree (the program-id blocker closed with its own failed case) and P1 HAS PASSED (the fleet rehearsal, 19:33Z: the flip by miner signal on 52 nodes, one program id per epoch on every box for three epochs, zero rejected, the stale box refused, the floor crossed with v4 in force), so class v4 is ready for the cut ON [user]'S GO, in the order publish 1 the 0.3.15 binary with no handshake split under the digest-compat rule, publish 2 the sixteen-field object as the one sweep once every NODE AND EVERY WORKER in the fleet is 0.3.15's (the shipped 0.3.14 worker refuses a generator-4 pack, so a box whose worker lags stops at the flip), its digest read on the fixed 0.3.15 binary: P2, miner-signalled activation (95 percent of blue-block weight over a one-day window, the floor height after which it flips regardless), is designed, implemented and GREEN on the fast-time gate with its failed case and on G6; P1, the rehearsal on the rented fleet as a staging network, has its plan and objects written and waits for the fleet agent's run; the clean-day wait removed by the project lead ("can we run the v4 class now?", 18:2x UTC): the P1 rehearsal runs NOW on the fleet (15 prover boxes plus the four Devnet 2 boxes, the wave joining about 18:50Z) and the 0.3.15 cut (class v4 plus the fourteenth field, one digest move, miners first, hands last) goes tonight on the project lead's go the minute P1 passes; its cost is the 5090 at 431 W instead of 350 for 0.2 percent less rate (a rig pays about 23 percent more electricity), the M5 Max at 37 W instead of 21 for 1.5 percent, the 9070 XT no rate at all (its watts pending), the verifier +0.27 ms per warp; what it buys is the stored-dataset chip's per-joule edge over the 5090 falling from 5.6x to 2.1x at a chip core equal to the GPU's; proposed for a day when no other cut is in flight, not tonight (0.3.14 and the fleet night come first).
6. Decisions for the project lead
- The public claim. "Under 2x" is true of the recompute chip per chip at the op budget and false of the stored-dataset chip per joule (item 1). Nothing on the site or in the litepaper changes from this run; the two drafts below are for the project lead's decision, with the rows that bound them.
| Row | Per chip (rate) | Per joule | Source |
|---|---|---|---|
| On-die recompute chip, class v3 (f = 0) | 0.92x with the 3x factor (0.31x bare) | 1.86x (1.3x to 2.4x over the on-die read energy) | chip-model-v3.md sections 2 and 5.4, model |
| Stored-dataset memory-controller chip, GDDR7 (f = 1) | 1.22x | 5.1x | chip-model-v3.md 5.4, model |
| Stored-dataset chip, HBM3 one stack / eight stacks | 0.61x / 4.9x | 7.5x / 9.2x | chip-model-v3.md 5.4, model |
| Ethash precedent, the same chip class: Linzhi Phoenix 2020, Antminer E9 2022, Jasminer X4 2021 | 2.1x / 2.9x / 4.8x per joule | asic-resistance-history.md rows 3 and 4 | |
| With the latency shadow filled (item 8, model until measured) | 1.22x | 1.85x at N = 330,000 and a chip core equal to the GPU's ALU; 2.5x at 1.5x worse | chip-model-v3.md 5.7 |
Draft (a), scoped: "The strongest recompute chip we can price, holding the whole 256 MiB cache on-die, reaches under 1x per chip against an RTX 5090. A memory-controller chip that stores the whole dataset reaches 1.2x per chip and, in our model, 5x to 9x per joule; the Ethash chips of this class reached 2.1x to 4.8x. The lever against it, program work in the latency shadow, is being measured (Counter ASIC 3.0 item 8)."
Draft (b), the measured fact only: "An RTX 5090 mines this hash at 136 MH/s and 17.5 billion dependent 4-byte reads a second, 82 percent of its memory's random-read ceiling, with its integer units at 0.15 percent of their budget. A chip beats it only by reading per watt what a 512-bit GDDR7 board reads, and the gap is the card's own idle logic."
Either replaces "under 2x" on the site and in the litepaper once the project lead chooses; until then the claim stays as it is and this file records that it is not safe as worded.
- The class v4 candidate: run the six gates on
mx8+sh256x27(100,000 ops per hash) and, if green, cut it by the 2.0 rollout shape. Cost to the tiers: the 5090 goes from 350 to 431 W for the same blocks (a rig pays about 23 percent more electricity), the M5 Max from 21 to 37 W for 1.5 percent of rate; the verifier +0.17 ms per warp. Gain: the stored-dataset chip's per-joule edge over the 5090 falls from 5.6x to 2.1x at a chip core equal to the GPU's. Alternative: wait for the 9070 XT and the 4060-class rows (both owed) before the gates, since a small card binds near 100,000 by its ALU budget (model). - The reserve order R1 perm, R2 popc and clz, R3 shfla, R4 bfe, R5 shifts, R6 sel, R7 andn, R8 mm8 (W_new = 4 each; mm8's era-4 unlock kept as the named exception or moved to era 8), and R0 the per-day derivation as a reserve family (dr368 the safe draw; dr736 after O-1.14).
- Commission the mixer cryptanalysis: USD 80,000 to 160,000, the brief and the reviewer shortlist in funding.md (item 3); it should name random ARX programs (item 2's class) beside M_r. No outreach has been made.
- The bounty trigger: escrowed and the benchmark live before daily issuance crosses USD 20,000 a day (funding.md rule 5); the detector is the clock (quiet on the devnet, max pairwise r 0.10 to 0.53 against the 0.8 edge).
- The live observer: the detector and the vendor-share hooks reach it only through a push to master (autosync); the project lead's word on the push, then one restart and the first live rows into this file.
- The 5090 clock rows (
-lgcat 2,781 / 2,472 / 2,163 / 1,854 MHz): an elevated job on PC 2 would ask for administrator rights at the keyboard (the 5 October prompt class); not run without the project lead's word. - PC 1: the 9070 XT rows for items 2, 6 and 8, the detector's band and the FPGA ranking's AMD line are all owed on PC 1's release.
- The job tooling: one card-key form everywhere (the settings.json key carries the device index) and a CI check that fails a job script posting a key without it (the class fix for item 2's loaded-card run).
Main's decisions on section 6 (18:0x UTC, 6 October 2026)
| # | Decision | Record |
|---|---|---|
| 1 | The public claim: the sentence deployed on the hero at 16:21Z ("In our public model the strongest chip reaches 5x to 9x per joule against an RTX 5090 today, about 2x once the lever now in its gates ships") plus the litepaper's long form; "under 2x" nowhere | docs/evidence.md row 17 (the claim, its sources, draft (a) of this file chosen); the review finding behind it: docs/review/round-4-reddit-2026-10-06.md item 3 (Serious), flipped by the measured fact |
| 2 | The cut: yes, after P1's rehearsal passes and 0.3.14 has run a clean day; the fleet agent owns P1's run | section 5a |
| 3 | R0 (the per-day derivation, dr368 the safe draw) and the reserve order R1 perm to R8 mm8: GO as proposed, with the once-a-day item module recorded as a requirement on every vendor (NVRTC +1.1 s, AMD OpenCL +2.0 s per pack) | counter-asic-3-derivation.md, counter-asic-3-reserve.md |
| 4 | The cryptanalysis spend, USD 80,000 to 160,000: AWAITING [user] (his money decision; put to him with the brief on a quieter day, not tonight) | funding.md |
| 5 | Push: ca3-coord merged into master through CI (nothing activates: v4 sits behind the override; the detector and vendor-share hooks go live on the observer's next restart) | the merge commit and the CI run, below |
| 6 | The AMD watts: on the runner's --cards-off mechanism, next cut |
section 6a |
| 7 | The 2019-class core (O-1.14): a Windows igneum-pow job on the US laptop when it next appears on the relay | owed list |
6a. A rule from the run (main, 17:5x UTC, from the watts job's failure)
A script never switches the installed app's cards: a POST of enabled false to /api/cards from a script is the same class as /api/pause from a script (a script that dies leaves the box degraded, unattended). A job that needs a card alone asks the runner for it: the runner's --stop-miners grows a --cards-off <keys> that posts the exact settings entries off before the script and restores them with their own flags and identities on ANY exit, as it restarts miners; tools/ci/playbook-quit-check gains the api/cards enabled-false pattern so the shape fails CI. Both land tonight (the PC 1 worker, branch ca3-pc1-amd); the four PC 1 scripts that carry the shape move to the flag; the AMD watts row re-runs only on the runner mechanism, after the app that carries it is installed (owed to the next cut).
7. Unverified and owed
| Item | Owed | Why |
|---|---|---|
| 1 | the 5090's watts at the hash alone: LANDED from Ember Tune run 5 (job ember-tune-pc1-5, PC 1, 15:30 to 15:38Z, elevated, nvidia-smi -pl set directly, the clock unlocked at 2,850 MHz core and 13,801 MHz memory, 75 s a step, MH/s wall from the worker's STATUS lines): 575 W cap 127.38 MH/s at 309.9 W (0.411 MH per W); 518 W 99.32 at 313.6 (a stall inside the hold); 460 W 123.11 at 312.2; 403 W 127.38 at 310.9; 400 W (the floor) 127.38 at 311.3; 64 to 65 C. The cap never binds on this hash (310 to 314 W under every limit), the power knob is flat at 0.41 MH per W, 2.44 microjoules per hash in the app on PC 1 beside two other cards; the clock caps were not measured (the watchdog ended the run at the first clock step, fixed on ember-tune 5e4ef43) and the card was left clock-locked at about 2,781 MHz until a reset (not a card under test in the PC 1 AMD jobs). The earlier state: the run of 07:21 to 07:56Z produced no 5090 step (its second engine never mined; re-run pending the project lead); the 4 October PC 1 log (miner-eff record, run win-ae432dc7-20261004-164723) gives p95 290 W at 124 MH/s in the app under a 460 W limit, and the card's cap floor is 400 W, so a power cap CANNOT bind on this kernel: item 1's 326 W denominator is a peak with the prover on, the hash alone is about 290 W (2.34 microjoules at 124 MH/s), and the lever that can move the watts is the core clock, now in item 8's PC 2 job (-lgc steps at 2,781 / 2,472 / 2,163 / 1,854 MHz); every DRAM energy figure is a streaming figure applied to random reads; the 9070 XT rows |
PC 1 not released; no chip measured |
| 4 | the 9070 XT rate band for the detector; the coinbase card-model tag (0.3.12) so the chain-attributed band needs no fleet log; the public testnet's first-week baseline (history check 2) | PC 1 not released; a miner change |
| 5 | a rented FPGA hour (the soft-overlay reads-in-flight number is a model on cited HBM figures) | no FPGA in the fleet |
| 6 | the 9070 XT step costs | PC 1 not released |
| 4 + 7 | the live observer restart with both hooks, and the first live detector and vendor-share rows | needs a push to master (the project lead's word) |
| 2 | the 2019-class core (O-1.14), which decides dr736 against dr368; the once-a-day NVRTC module for the item function (required before any activation); cryptanalysis of random ARX programs; the loaded-iGPU tier's build with the day program; the 5090 absolutes re-run with the card quiet (ratios stand) | unmeasured; unimplemented |
| 8 | the 9070 XT and 4060-class rows (where a small card binds); the 5090 clock rows (an elevated job); the 5090 at a 575 W cap (model only); the Mac package watts (IOReport gives GPU + DRAM, Ember's 38 W approximate); the chip side's k, lane area and 28 nm scaling; the Metal fuzz, edge and stats runs and gates G2, G4 to G6 on the class; the acceptance rule's reading of the block | PC 1 not released; no elevated job; the gates are the next step on the project lead's word |
| 6 | mm8 as a chain on Apple (Metal 4 matmul2d; the Mac's Swift toolchain has no tensor API); mm8's exactness on AMD (the gfx12 WMMA fragment layout; an empirical layout probe would settle it in one job); the 5 percent rule per family with the family live (argued only); the RDNA ISA guides unread (mnemonics from LLVM's tables). The 9070 XT step costs themselves are CLOSED (run e) | |
| 1 | the DRAM energy figures are streaming figures applied to random 32-byte reads; the GDDR7 burst and HBM3 tFAW are behind the JEDEC paywall; no chip has been built or torn down | |
| all | every AMD RDNA 4 number in this run | PC 1 is the project lead's desk today. 16:0x UTC: the RX 9070 XT is back on PC 1 (amd:gfx1201, 16,304 MiB) beside the 5090 and an RTX 4070; main has asked for the PC 1 jobs to be PREPARED, not published: (1) G1 AMD plus item 8's ladder on the 9070 XT (about 15 min, the card alone), (2) item 6's family step costs on AMD (about 3 min), (3) item 2's dr736 build and compile on AMD (about 3 min), (4) optional: the 4070 ladder (about 10 min); branch ca3-pc1-amd (1f33cc6, e054ed7, merged): the four scripts pass every CI check, the kit zip sha256 a70fce5b... verified, the AMD watts readback is igneum-gpu-telemetry.exe (ADLX board watts); the commands and the row map in tools/ca3-pc1-amd/README.md; published one at a time on "go PC 1 AMD" after the 0.3.13 update and the Ember table run, about 33 min of PC 1 in all |
The 0.3.15 cut (class v4), in flight (the shipper, with the node lane)
| Step | State |
|---|---|
| The node: the signalling fork 0562a7f2 merged onto 0.3.14's node tip 4c6b129d = f86a33c0 | merged; the header processor byte-identical between 0562a7f2 and f86a33c0 (the class signal read after the cheap checks, as before) |
| The suite on igneum-build-1 | one test, cheap_checks_run_before_the_pow_engine, failed at its LAST assertion (the genesis-day hint), not the four cheap-check assertions: a test race on two process-wide things (the engine captured at consensus construction inside the test's install window; the live day length another test can swap) that the box's 96 test threads hit and PC 2's 24 never did; the fix is tests only, fork commit 791ff22c on ca3-v4-order-fix from f86a33c0 (an install_engine_lock in kaspa-pow held across the window by both installing tests; the day assertion made the processor's own promise), with the shipper at 18:5xZ; the single test 1 of 1 on the box (43 s); the full kaspa-consensus run from the fix worktree on the box, its line pending |
| The order, with the shipper's measurement on the 0.3.15 Mac binary (fork f86a33c0, no suffix, no peers) | THE DIGEST MOVES AT PUBLISH 1: on the live thirteen-field file 0.3.15 reads c09c3e48... where 0.3.14 reads b18ed271... (the two v4 fields fold into the digest at never when absent), so publish 1 (binaries only) is itself the one-sweep handshake split and every node moves inside one window there, miners first, the hand nodes and the seeds last; publish 2: the SIXTEEN-field object (the live thirteen plus 0.3.14's exec_restart_state_root, the floor 226,800 from DAA 209,458 at a 19:47Z publish, the window 86,400; digest 2c1162e2... on 0.3.15; the node's lines "Program class v4 from the override file: active from epoch 63 (DAA 226800)" and the 86,400 window at 9,500 bps) only once every node reports 0.3.15; a 0.3.14 node given it exits at parse ("unknown field program_class_v4_activation_daa"), confirmed on the Mac binary as the rehearsal found. The node lane's tests-only fix 791ff22c merges into the release node. MAIN'S RULING (19:0x UTC): publish 1 must not be a handshake split. The node lane adds to ca3-v4-order-fix a digest-compat change: an ABSENT optional field contributes nothing to the digest, so 0.3.15 on the thirteen-field file prints b18ed271... and peers with 0.3.14; the binary rolls out with no window; the sixteen-field file at publish 2 is the one sweep (miners first, the hand nodes and the seeds last, only when every node reports 0.3.15); the sixteen-field digest is re-read on the fixed binary before publish 2. IMPLEMENTED (fork ca3-v4-order-fix 713ef876, with the shipper): the two v4 fields enter the digest only once set, the window's default 0 on every network, the no-file devnet digest back to c562d70e...; the box's suite on 713ef876 kaspa-consensus 98 and consensus-core 111 + 7, 0 failed; pinned in a new test: the thirteen-field live file b18ed271... (0.3.14's value), fourteen fields 23e76936..., sixteen fields (the pin, floor 219,600, window 86,400) 1dddfa55...; the rehearsal unaffected by construction (its object sets both fields, so a15db4f0 on devnet-400 stands); the two harness lines on real nodes both PASS (the fixed Mac binary of 713ef876 against the 0.3.14 binary, 18:58Z, infra/fast-time/digest-compat.mjs, the P3 row on ca3-v4-node 38ac2a3): COMPAT, a fixed node and a 0.3.14 node on the live thirteen-field file print one digest and peer; REFUSAL, the fixed node on the sixteen-field file prints another and is refused with the handshake's own "consensus params digest mismatch" line on both sides; on the devnet id the sixteen-field object re-reads 1dddfa55... (the pinned value), the thirteen-field file b18ed271..., no file c562d70e.... The rehearsal's flip (about 19:01Z) and floor (about 19:21Z) are the PASS clock main holds the project lead to |
| The fork's final tree for 0.3.15 (ca3-v4-order-fix, four commits) | 791ff22c the order-test race (tests only); 713ef876 the digest once-set rule; 17c60367 the signal stamp and read gated on both v4 fields (header version 2 on the live file, 1026 only with publish 2's object); 7961c5f1 a sync request below a pruned node's retention answered as SyncManagerError::BlockBelowRetention to the peer, never an unwrap (the hub's 19:57Z panic: a remote crash vector against every pruned node since the first one). The shipper built 0.3.15 from 7961c5f1 on all three platforms, the digests unchanged, the six-crate suite green. The node-compat gate (ca3-v4-node 4d7e677, infra/fast-time/node-compat.mjs, 20:19Z): a mining new node beside a 0.3.14 node on the live object PASS (one digest on five nodes, the new miner's 75 blocks accepted by the old hub, header versions 2 only, 195 blocks on every node including the clean join through the old hub, the old node served from genesis by the new one, the new node restarted and re-synced); the canary binary 713ef876 on the same gate FAILS with the fleet's exact reject lines (the known-failed case). Ledger rows N1 and N2 (security, conceded, dated, with the fixes) in docs/fud-ledger.md. The audit pass landed (fork ca3-v4-deps f8f0f1df from 7961c5f1, Cargo.lock only, the shipper's 0.3.15.1 node change): h2 0.4.20, quinn-proto 0.11.19, rustls 0.23.45, crossbeam-epoch 0.9.21, ruint 1.20.1; cargo audit on the box 6 vulnerabilities and 16 warnings before, 1 and 16 after (the one left tracing-subscriber 0.2.25 pinned through ark-groth16, a major bump, named and not taken); the six-crate suite green on the new lock (99 / 111 + 7 / 20 / 15 / 18 / 33); row P5 on ca3-v4-node 536e084. The receive-side fix f1ea7a38 (fork ca3-v4-order-fix on 7961c5f1, 21:39 UK, to the shipper 21:46 UK; the box line kaspa-consensus 99, consensus-core 111 + 7, rc 0): with the window or the floor absent, a header's version must be exactly 2 (0.3.14's rule), so a 1026 header is refused before the engine with WrongBlockVersion(1026, 2) and never relayed; with publish 2's object both bytes are read as designed; the test inside cheap_checks_run_before_the_pow_engine; the gate re-run with a poisoned peer in the topology (a 713ef876 node mining 1026 blocks into the new node, 20:42 to 20:45Z) PASS: 12 refusals with 0.3.14's exact line, none relayed, the old hub's chain holding version-2 headers only, every clean node at 180; stale blocks on the live devnet: a 0.3.14 node holding them is disconnected by its 0.3.14 peers by their own rule, new nodes are immune, the fleet wipes the poisoned datadirs; ledger N1 extended; the shipper rebuilds once on f1ea7a38. The node lane's further queue (the peer-driven unwrap class with a sync-request fuzz gate, the 7-window signalling rule, the Horizon items, the stale-block nuisance-peer case) reports to main: it is the cut's and the ledger's, not this file's |
| the project lead's go | given in advance for tonight; publish 1 on the 0.3.15 canary line, publish 2 once every online node and worker reads 0.3.15 |
| PUBLISH 2 LIVE AND READ BACK (22:43Z, the shipper) | the sixteen-field object (the live thirteen, the exec pin, program_class_v4_activation_daa 831,600, program_class_v4_signal_window_daa 86,400), digest eada4bda8aa8368c2b2c3d17744bc7a70a0ff0e996dad681884d3ac5de1207eb on igneumd/2.1.0-f1ea7a38, on the fleet's 14 standing boxes, both PCs, the hands and the seed; every node prints "active from epoch 231" and the 86,400 window at 9500 bps; THE VOTE OPENED at DAA 223,667. Two facts from the way there: 0.3.15's node gained two gates beyond the signalling fork (the stamp AND the header-version rule both gated on publish 2's object: 17c60367, f1ea7a38) after the live canary found a 0.3.15 node writing version 1026 on the thirteen-field file and then accepting one from a poisoned peer; and the floor sits a week past the publish (831,600) because the floor flips unconditionally on this node (the 0.3.17 P2 rule applied early). The rehearsal chain igneum-devnet-400 ends on this line (the fleet agent told) |
| A FAULT SINCE PUBLISH 2, fixed (the node lane, 03:03 UK, fork ca3-v4-0317-fix 90aaf38e on 02d15a87, with the shipper) | protocol/flows/src/ibd/flow.rs sync_and_validate_pruning_proof compared the syncer's relay block's WHOLE header version with the block version (upstream's guard) while the consensus rule reads the low byte when the signals are active, so a fresh node on the headers-proof IBD path with the window object refused every legal 1026 relay block; the live f1ea7a38 has the same line, so no fresh node joined through that path since the window opened at 22:43Z (nodes syncing without a proof, under 419 headers, were unaffected, which is why the hands moved). The fix: one shared reading, igneum::header_version_acceptable, at both sites; the known-failed unit test first (1026 against 2 legal with the signals, refused without); consensus-core 123, the header tests, p2p-flows 34 green on the box. Owed: the two-daemon integration test with the window object over relay and IBD (next on the 0318 tree). It alters no consensus outcome and the digest is untouched. MAIN'S DECISION: 0.3.17 is a node-only hotfix on the 0.3.16 app tree (the fresh-join fix, node b3c228fa), taken by the canary, then the Mac, PC 1 and PC 2 by update-now on the shipper's line; the feature tree becomes 0.3.18 and decimals 0.3.19 |
7a. The two fast-forwards to master (decision 5)
| Push | Commit | ci | windows-ci |
|---|---|---|---|
| 1 | 88f5026 (ca3-coord merged with master: Counter ASIC 3.0 complete, the two CI check fixes, the close) | GREEN (37508680115) | red on "payload inputs (payload-inputs.zip from the downloads host ...)", red since 630b537 at 17:51Z, the shipper's 0.3.14 payload on the downloads host; the last green windows-ci 2cf8851 at 15:53Z; untouched by this branch |
| 2 | 0396580 (35776fe: the runner's --cards-off with the restore on any exit, the quit-check's rule 2 with the dated allow list, the stripped PC 1 scripts; plus the executable bit on the quit-check) |
GREEN (37509530709) | cancelled (37509530516): superseded by the build-server fix 3e6a488 pushed to master minutes later; the payload-inputs step is the shipper's to turn green with 0.3.15's payload |
7b. The final row: the P1 rehearsal PASSED (6 October 2026, 19:33Z)
| Check | Result |
|---|---|
| The flip by miner signal | the identical line on all 52 signalling nodes at epoch 2: 10,000 bps over 600 DAA, 599 of 599 blue blocks, one seed block |
| One program id per epoch across the boxes, equal to the CLI's class v4 id, differing from the v3 id | epochs 2, 3 and 4: 24304f0788ea9408, cc266b4f5dbc3447, 634018bab5e5f283 (the v3 ids d8927052c764f00b, de3a34f1f2130228, 170e3aa4b2f69d60); the pre-flip epoch 1 generator 3, id b237a661a3c7f7c1 |
| Rejected | 0 PoW rejected on all 16 nodes over the run; every miner mismatched 0, rejected 0 |
| The stale old-binary box | refused by digest at every connect (11 refusals, 22 mismatch lines), never a peer; on the full file refuses at parse and exits |
| Blocks on v4 | on every box from the 19:15:47Z resume on the generator-4 worker; about 1.6 blocks/s |
| The floor | crossed at DAA 2,400 with v4 already in force; the chain mined through it; one chain, no fork at the 19:34:54Z sweep |
| G2 serve mode on the epoch-2 v4 pack | 1,024 of 1,024, digest 7bf77506..., the Mac recheck MATCH line for line |
| Cut-critical | an old worker refuses a generator-4 pack, so publish 2 waits on every node and every worker; a 0.3.13 node exits at parse on the file; publish 1 carries no handshake split |
the project lead gave the go in advance for tonight: the shipper runs publish 1 on the 0.3.15 canary line, then publish 2 once every online node and worker reads 0.3.15, miners first, hands last; the rehearsal chain ends on the line that publish 2's digest is read back on every node (its miners off, the boxes to the standing roster or run A). The evidence folder's last entry: counter-asic-3-gate/class-v4-20261006-rehearsal-PASS.json. The public bench-log entry (numbers only, no box names): docs/bench-log.md "6 October 2026, Counter ASIC 3.0: the class v4 rehearsal". The 3.0 lane is closed.
7c. Reopened on the v4 seam, 7 October 2026 (morning): AP-F8-1, the item read map's skew
| Item | State |
|---|---|
The finding (the attack-pass lane, F8 phase D, one class v4 program, 2^26 nonces; docs/analysis/attack-pass/f8-uniform.md on branch attack-pass) |
the top 0.1 percent of items take 0.520 percent of reads against 0.115 uniform (4.05x); the top 1 percent 2.49 (1.37x); one item 0xca5b92 takes 78,479 reads, 153x the mean; read site 15 feeds 6.37 percent of its reads into the top 0.1 percent in all 8 iterations; the excess grows with N. The ask: a generator fix on the v4 seam with the gate "top 0.1 percent within 1.2x of uniform over 2^26 nonces on 64 seeds"; the attack-pass lane re-gates with tools/attack/f8-uniform |
| The lane's framing | class v4's item map is not designed to be uniform per program: layer 8's per-site windows (k_off = below(3): the whole dataset, a half or a quarter per site, under the era stride and interleave) concentrate a quarter-window site 4x on its quarter, which is the 4.05x; the null is the window model from the program's own 16 draws; the 153x item is the number to explain (coinciding windows under the era mapping with a stated tail, or a low-entropy source at site 15, a fault); the chip consequence a 1.7 MB hot-set cache serving 0.5 percent of reads, under one percent of rate |
| The cut consequence | v4 is on the live devnet's vote and the class lives in the binary: any generator change to v4 is a class change (new vectors, the six gates) that must reach every node before the flip or the chain splits; unless F8's phase E census shows a fault beyond the window model, the answer is the documented null and, for a tighter tail, an acceptance bound in the next class, not in v4; a fault beyond the model is main's and the shipper's decision (a class amendment before the flip, or the flip held by the floor) |
| Who | the hash lane, branch ca3-v4-uniform from master: the model, the reproduction with F8's harness on the v4 packs and the mixer harness's 200 programs, the census, the re-priced row; a fix only on a fault |
THE ANALYSIS (the hash lane, ca3-v4-uniform 095f84a7, docs/analysis/ca3-v4-uniform.md, the tool on igneum-build-1) |
the window model moves the null from 0.115 to 0.160 percent (1.39x, not 4.05x); the rest is a FAULT beyond it: site 15 reads a register last written by or r6, r4, so all-ones recurs at (3/4)^32 per read and the era map sends it to F8's hottest item exactly (the popcount model predicts 77,348 all-ones reads against 78,479; the top-0.1-percent share 0.58 against 0.52); it passes the acceptance rule because part (a) takes any write as a fresh source and part (c) counts saturation on final values only. The census of 1,024 chain-shaped v4 programs: 96.6 percent carry a lossy-sourced load (or, mul, mulhi as the last writer), 48.5 percent an or-sourced one (0.30 percent of all reads per site), 4.9 percent an or-of-or chain (4.6 percent of all reads on 0.1 percent of items); F8's 1.2x gate fails 96.6 percent of today's programs. Worth to a chip: 1.07 MB of SRAM ($0.25) serving 0.52 percent of a typical program's reads and 4.6 percent of the worst class's, at most 1.005x and 1.048x in rate; the ceiling under rule (c)'s 120-of-128 floor one site repeating its item in all 8 iterations, 6.25 percent of reads, 1.067x in 64 bytes; the 2x margin stands; the public line says "bounded at 1.067x", not "uniform" (the public text corrected) |
| The two options, priced, STOPPED at the coordinator for the project lead's word | A: a 0.3.19 class amendment before the flip (the generator draws a load's source from the registers whose last writer injects): a new program stream, new vectors, the seven gate packs re-exported, the six gates again (G1 to G3 and the verifier about an hour on the Mac and PC 2; G4 to G6 the node lane), every node before the flip under the one-box-at-a-time rule; the risk a node that misses the build splits the chain at the flip. B: hold the flip at the floor with v4 as it is; the bound documented; the source rule to class v5: a hot set worth up to 1.005x on about half the hours and 1.05x on 5 percent, 1.067x at the ceiling; no chain risk. The number: 1.067x at the ceiling against the 2x margin. The lane recommends B |
| The v5 bound (sent to the v5 lane) | H = W_0.1 (the window term, 0.115 to 0.251 percent) + the sum over load sites of h(last writer) (or 0.30 percent, an or chain 4.5, mul 0.067, mulhi 0.049, an injecting op or a rotate 0), H at or under 1.2 x W_0.1, which is the static rule "every load's source was last written by an injecting op or a rotate"; as a rejection it costs 96.6 percent of candidates (about 30 attempts per seed), as a generator draw nothing; gate F8's 64-seed census with the saturated-source count |
| [user]'S WORD (15:2x UK, 7 October): OPTION A, "do this but limit the testing, get it pushed" | the class v4 amendment: a load's source drawn only from registers whose last writer injects or is a rotate (the v5 rule applied now), a new program stream and vectors, the seven gate packs re-exported, the amended class with its own generator stamp; rides 0.3.20, the feature node (release-0.3.20-node = dc141409; 0.3.19 is an app-only cut with nothing of ours), on the shipper's line. The rollout arithmetic for the flip clock (the shipper): the standing fleet's one-box-at-a-time rollout took 32 minutes for 14 boxes (04:56 to 05:28Z, 7 October), the hands and the seed about 3 minutes after the miners, the Mac and the PCs within minutes of the publish; every 0.3.20 worker must accept the amended stamp before any flip. Owners: the hash lane (ca3-v4-amend: the generator, the vectors, the packs, the pairing on the box, one G1 run on PC 2, the ledger row), the node lane (release-0.3.20-node: the stamp agreed with the hash lane, the split-protection mechanism and the earliest flip time, the digest test, the mixed-version Devnet 2 gate), the attack-pass lane (the F8 census at 2^24 on the new stream, the gate 1.2x of the window model over 64 seeds), the shipper (the cut, the rollout order that sets the earliest flip). Testing limited to what prevents a split and proves the fix; G2, G3, the ladder re-measure and the rest of G4 to G6 OWED. THE STAMP agreed (the node and hash lanes, 7 October afternoon): generator 4 with sub-version 1 inside igneum-pow's id function, so the amended v4's program id for a seed differs from the old v4's (the old devnet epoch-0 id c120d7963abdcd96 pinned as the must-differ vector in kaspa-pow's test). SPLIT PROTECTION SETTLED (the node lane, plan section 6.6, ca3-v4-node fa5bc9e6; the node side on release-0.3.20-node): a fresh object byte. CLASS_SIGNAL_V4 is 5; the amended binary stamps 5 and the tally counts a block only at byte 5 or above; object 4 was stamped only by the unpublished dc141409 canary, so no published block carries it and a byte-4 block never counts; a node of the 6 October stream that sees byte 5 counts it as v4 (its rule is at least 4), flips to its own stream at the same epoch and forks ALONE (its blocks fail the amended id check, generator 4 sub-version 1 inside every id; the amended blocks fail its own), ours to upgrade in the sweep; object 6 is class v5's; the two holds already in the rule keep the window shut until every node is on 0.3.20 (a node stamps and tallies only with both v4 fields in its file; the fields publish only after the one-sweep rollout); a lagging worker refuses the amended pack at packcheck and mines nothing after the flip, costing that box, never the chain; no extra window hold: seven full day-windows are the hold. THE EARLIEST FLIP (approximate, measured 09:40Z: DAA 270,659, 1.095 DAA/s over 25 hours, 1.165 over 4; epoch 3,600, lead 600; seven windows 604,800 DAA wholly after the sweep's end D_s = T + about 40 minutes; the flip epoch the first e with 3600 e - 600 >= D_s + 604,800): T + 6 days 10 hours to T + 6 days 11 hours UK; for a publish at 12:00 UK on 7 October, 13 October between 22:20 and 23:10 UK (about 13:00 UK if the 4-hour rate holds). The floor as it stands (831,600, about 13 October 09:00 UK) would fire before any seven-window signal from a publish today completes, so it moves by the 0.3.16 rule to the publish DAA + 604,800 rounded up to the epoch boundary (882,000 for a 12:00 UK publish), firing about 30 minutes before the earliest signal flip: either way about 6 days 10 hours after the publish, never before every node has had the sweep plus a week. THE CLOCK (the node lane, 11:3x UK, after a Mac reboot moved its runs to the box): the 0.3.20 node line (dc141409 plus the proof archive aea0ca5c plus the amended v4 at object byte 5, igneum-pow at the hash lane's a0aaca92 beside the fork on the box) tested on the box, committed on release-0.3.20-node, pushed to the mirror and origin, igneumd and igneum-miner built, the tip to the shipper: about 12:00 UK; the mixed-version Devnet 2 gate (node-compat.mjs on the box, the amended node beside the 5899f603 pair for ten minutes) and the digest test (digest-compat.mjs): about 12:45 UK; the object-byte pin 5 unless the v5 lane answers both lanes with another assignment (v5 at 6 proposed). THE HASH SIDE on ca3-v4-amend (tip 8c728ca3, read from the branch 14:0x UK; the hash lane's own report pending): 1748fd1d the PC 2 G1-only playbook; e1f48d63 the fud-ledger entry AP-F8-1 (the fault, the project lead's ruling, the amendment, the split protection, the owed tests); d8859522 the G1 line (the eight fingerprints equal on the RTX 5090, self-test PASS) and the node lane's signal byte 5; 4aa0c665 the v4 unit test following the amendment; 965d9e96 igneum-pow taken from release-0.3.20's 3f1652bf (the ladder's chain_program_shadow with the reps argument, never on master) with the amendment re-applied, the seven packs re-exporting byte-identical; 8c728ca3 the source rule keyed on the class with the shadow's pass count set aside, so every ladder rung draws under it (the fork's ladder test). The shipper took this igneum-pow tree into release-0.3.20 (00249643, byte-equal); nothing after 8c728ca3 touches igneum-pow. THE VECTORS AND THE PACKS (read from the branch and its ledger entry, 14:1x UK): the seven amended v4 packs (v4-devnet-epoch0, v4-era-0 to 5) carry generator 4, sub-version 1, one program id 1a4230699a6b9c60 (the 2.0 one-id-per-seed rule across the eras; the old c120d7963abdcd96 pinned as must-differ); the v3 control mx8-devnet-epoch0 untouched (73bcbfe8ccf988f1, fingerprint 90f794dd556f7a3b); the seven 2^24 fingerprints, Metal equal to Apple OpenCL: 867dbc45cfb36b4d, 2146ecacc8c75a8e, fe52602393f6d3d4, 3b206471a13912b4, c3f03c4a5d7333aa, f1dfd7209f15bb97, 8c194da64fadf31d; the zip of the eight packs sha256 889ec99976d2728b4b5035bfa476032e5b6a13b928968fc45236d5f25084aa39; the per-pack vectors.json sha256 prefixes 756301bf (devnet epoch 0), 1b5f4568, d430cadc, 1a1b21d8, 460fff9e, 4a85d49d, f83a1196 (eras 0 to 5). G1 on the RTX 5090 (PC 2 job run-ca3-v4-amend-g1-pc2-20261007, 09:41:07 to 09:41:28Z, exit 0, the installed worker): every fingerprint equal to the Mac's (the seven above and the control), NVRTC 188 to 332 ms per pack, the 1 GiB build 38 to 49 ms. hash-gates.md's older table still lists the pre-amendment fingerprints (f410c731... and the eras), which no longer apply to the amended packs; the ledger entry is the record. THE FIRST GREEN (11:31 UK, the box): the kaspa-pow suite on release-0.3.20-node (dc141409 plus the proof archive aea0ca5c plus the object-5 change) against the hash lane's igneum-pow 8c728ca3: 17 passed, 0 failed; the amended devnet epoch-0 id 1a4230699a6b9c60 pinned equal and c120d7963abdcd96 differing, the ladder's rung test green under the rekeyed rule, the v3 control unchanged; the consensus-core and exec RPC suites follow, then the node line (commit, push, box build, the tip to the shipper), then the digest and mixed-version gates. CLOCK RE-CUT (the node lane, 13:0x UK): the node line now carries, beside the object-5 change and the vector test, the lane's 0.3.20 fixes from the day (isSynced from the hook's stamp, the lazy template snapshot, the weight-table cache, the submit path returning after the block task, the watchdog, the RPC fields), about 13:30 UK if the box suites are green; the shipper's fresh-join canary 60 to 100 minutes after the cut; PC 1 as its first machine about 16:00 UK at the earliest, approximate until the shipper names the cut; the earliest flip about 6 days 10 hours after the publish. BUILD-2 LINES (12:28 to 12:33 UK): consensus-core 123 passed (the 60x file test green with the ladder window and activation pinned), the behind test green, kaspa-pow 17 passed (the amended vectors, earlier on build-1), the exec RPC suite green, the flows and rpc-service checks green with the submit-path change; the 24-requester latency test's first run tripped an unrelated flapping-fork double insert (24 equal forks from one parent; the test now builds on the sink as a real miner does; the double insert owed to a small fork harness before it is called a bug); THE NODE LINE COMMITTED (13:1x UK): release-0.3.20-node = 8097d600 (dc141409 + the proof archive aea0ca5c + one commit) on the mirror, pairing igneum-pow 8c728ca3, the hash with the shipper; in it the amended class v4 as object 5 (CLASS_SIGNAL_V4 = 5, byte 4 never counts, the kaspa-pow vector test pinning 1a4230699a6b9c60 equal and c120d7963abdcd96 differing, the daemon's window line naming object 5 and sub-version 1) beside the day's fixes (isSynced from the hook's stamp, the weight-table cache, the lazy snapshot, the submit path, the 100 ms template wait); the suites green on build-2 (consensus-core 123, the exec RPC suite, the four finality tests including 24 requesters under 200 ms: the worst template 100 ms, the worst submit 102 ms) and kaspa-pow 17 on build-1. Next: igneumd and igneum-miner building from 8097d600 on build-1, then the two gate lines (the mixed-version Devnet 2 gate: the 8097d600 node mining beside the 5899f603 pair for ten minutes on the live file without the v4 fields, the old node accepting every block; the digest test: the thirteen-field file b18ed271 unchanged, the sixteen-field object re-read on the 8097d600 binary), expected about 13:30 UK; the shipper picks the cut point. THE DATE FIXED (the node lane, from the hub's live file, 13:3x UK): publish 2 of 6 October (22:49:45Z, digest eada4bda) already put BOTH v4 fields on the live devnet (floor 831,600, window 86,400), so the 0.3.17 fleet has stamped object byte 4 since 7 October 00:2x UK and the floor is live at about 13 October 09:00 UK, before any seven-window signal completes; a 0.3.17 node left on that file flips to the OLD v4 stream at epoch 231 whatever anyone signals, a 0.3.20 node to the amended stream at the same epoch, and the two never share an id, so each straggler forks alone there. REQUIREMENT for the 0.3.20 publish (with the shipper and main): a new file with the floor at the publish DAA + 604,800 rounded up (about 882,000 for a publish today), the digest moving, the one-sweep rollout replacing every 0.3.17 node before 13 October 09:00 UK; any node that misses the sweep is alone then; the earliest flip after that about 6 days 10 hours past the publish; plan section 6.6 amended today. IN THE 0.3.20 PLAN (the shipper, 13:4x UK): both requirements; the node pin by main's rule is the node lane's second commit (the claim floor, the listener watchdog, the claim RPCs, on top of 8097d600) if its suites, both gates and the fleet's 12 GB prover line are green by 15:30 UK, else 8097d600; igneum-pow 8c728ca3 either way; the digest read on whichever binary pins. THE LINE AT 13:5x UK: three commits on release-0.3.20-node, 8097d600 (the object-5 amended class v4 and the day's fixes), 6b94c823 (test-only: the stale PC 1 test from 500ddd66 inverted by the isSynced ruling; the FALLBACK pin, code byte-identical to 8097d600, so the module reads green whole) and 6a3432a3 (the app lane's key methods, the observer's claims, the settled claim floor, the listener watchdog); suites on build-2 on 6a3432a3's code (the whole finality module 25, the exec suite 29 with the watchdog test, the kaspad, flows and rpc-service checks; consensus-core 123 and kaspa-pow 17 earlier); the cut 6a3432a3 if its gates and the fleet's 12 GB settled-claim line are green by 15:30 UK, else 6b94c823; both binaries building on build-1, the two gates (the digest gate, then the ten-minute mixed-version gate beside the 5899f603 pair) on the 8097d600 build, lines about 14:05 UK. GATE NEWS (13:53 UK): on 6a3432a3's own digest gate the listener watchdog counted a bind failure (the four harness nodes share one exec JSON-RPC port) as a listener death and exited three of four nodes at 20 s, where 0.3.17 and 8097d600 only warn and live without the exec RPC; the digest facts came out first and stand (the thirteen-field file a89be8a7 on both binaries, the compat case; the sixteen-field object db9a85f9 refused with the mismatch line, the refusal case); the ten-minute gate on 6a3432a3 stopped as void for the same cause. The fix: a bind failure is a retry every poll, one line a minute, no death counted and never an exit, with a second watchdog test whose known-failed shape is the old rule's exit on a held port; the third commit and its build about 14:15 UK, its gates about 14:35 UK; the fallback 6b94c823's gates on build-1 on their own binary (no watchdog there), lines about 14:20 UK; ledger row N12 for the bind-failure class. A ROLL BLOCKER on every kept datadir (the node lane, 14:1x UK, ledger N13): the fleet started 6a3432a3 on a kept 0.3.17 datadir (pool-1's copy) and it died at start (virtual_state.rs:250, DeserializationError(UnexpectedEof)); the cause 10db4b61 on the 0.3.16 feature line added silent: bool to BlockRewardData under serde(default), which bincode ignores, so every build from 10db4b61 on (dc141409, 8097d600, 6b94c823, 6a3432a3, 09124180) reads a 0.3.17 node's virtual-state row short; no canary saw it because every canary wiped, and a one-box roll keeps datadirs, so it blocks the roll on every standing box, the hands and the hub whatever the pin. The fix on the line: the store reads the current layout first and on a deserialization error decodes the row as a v1 mirror, converts with silent false and rewrites it under the same key, with the known-failed test first; the fourth commit and build about 14:40 UK, the fleet's kept-datadir start on the fixed binary about 14:50 UK, its gates after. THE RULE IT ADDS for every node cut from now: a kept-datadir restart gate on a standing box's datadir copy beside the wiped canary. THE CANDIDATE PIN (14:2x UK): b7cc37e7 (8097d600, 6b94c823, 6a3432a3, 09124180, b7cc37e7; igneum-pow 8c728ca3): the N13 fix with its test green on build-2 at 14:04 UK and the kaspad check green, the build on build-1; the fallback 6b94c823 is no longer a pin for the one-box roll (it dies on a kept datadir like every build since 10db4b61): if b7cc37e7's gates are not green by 15:30 UK the honest fallback is 0.3.17's 5899f603 staying live. In flight on build-1: the earlier commits' gates, then b7cc37e7's own digest and ten-minute mixed-version gates on its binary with the read-back, lines about 15:05 UK; on the fleet the kept-datadir start on b7cc37e7 about 14:50 UK and the 12 GB settled-claim line 14:50 to 15:00 UK. Plan section 6.6 amended with the hard date (ca3-v4-node 9d763edd, merged to master); N12 and N13 on the ledger. THE GATES ON THE FALLBACK'S OWN BINARY (6b94c823, sha b1b7d47b, 13:56 to 14:08 UK; code byte-identical to 8097d600, so the amendment's node side): the digest gate, the thirteen-field file a89be8a7 on both binaries (the compat case, n0 peering n1 and n2) and the sixteen-field object db9a85f9 refused with the mismatch line (the refusal case); the mixed-version gate, ten minutes, one digest b0afb2ee on all five nodes, the 5899f603 hub accepting every block the amended node mined (146 new, 246 old, 0 rejected), plain header version 2 on the thirteen-field file, counts equal on all five through the two clean joins and the restart. Two FAILED checks, both the harness's own and fixed (36d3efdc): a refused peer's count read 1 with the reconnect in flight (now the minimum of five), and six address-in-use panics in the two old nodes because the second gate reused the first's ports the second they were sent SIGTERM (a 20 s gap now). CLOCK CORRECTION (the node lane, 12:12Z = 13:12 BST): every "UK" stamp it sent today was the box's CEST, an hour fast of BST; its lines read UTC from now. Restated: b7cc37e7's build about 12:15Z, its digest and mixed-version gates on that binary with the sha and string about 12:32Z (13:32 BST), the fleet's kept-datadir start on it about 12:25Z, its 12 GB settled-claim line 12:50 to 13:00Z; the shipper's checkpoint 14:30Z (15:30 BST), two hours of room. The 13 October date stands (derived from UTC DAA rates): the floor 831,600 about 08:00Z, 09:00 BST. b7cc37e7'S OWN LINES (binary sha256 bc28331abf21f4d5, the string read back on build-1 and on the fleet's pod): the digest gate 12:14:39Z to 12:16:18Z SUMMARY PASS (thirteen fields a89be8a7 on both binaries with the peers as the gate wants them; the sixteen-field object db9a85f9 refused with the line and no peer; the live file's digest eada4bda on the binary, unmoved); the kept-datadir start on the fleet's copy of pool-1's 0.3.17 datadir: the first start 12:17:12Z reads the v1 row through the mirror and rewrites it ("1 mergeset rewards"), the finality blob converts (1,747 locks), the node comes up on its ports with no panic; the second start 12:18:53Z reads first-try with no rewrite line and no panic; 6a3432a3's death on the same copy is the known-failed shape. The ten-minute mixed-version gate beside the 5899f603 pair runs on the same binary since 12:16:39Z, its line about 12:28Z; then the only line outstanding for the shipper's 14:30Z rule is the fleet's 12 GB settled-claim line, 12:50 to 13:00Z. AP-F8-1 RESIDUAL CLASS ON THE AMENDED STREAM (attack-pass lane 12:18Z on igneum-pow 8c728ca3, sub-version 1). F9 over 1,000,000 seeds: programs flagged (hot share at least 1 percent or 7 constant address bits) 1,871 (0.19 percent) against 11,696 (1.17 percent) unamended; worst hot share 9.66 percent against 17.3; mean 0.011 against 0.063 percent; 84 percent of the flagged programs and the whole or-saturation tail gone. F8 at 30 of 64 seeds: nine over 1.2x of the window model (p31 29.3x, p11 5.5x, p19 3.3x, p6 3.1x, p23 2.0x, the rest 1.3x to 1.6x); the 64-seed 1.2x gate is heading to FAIL on sub-version 1. Mechanism, confirmed on the two worst seeds: an all-ones load source (image 0x0ca59e4c under the era map) delivered through a writer the source rule counts as entropy-keeping, a rotate (rotl and rotr map all-ones to itself) or a load whose own source was saturated, with the saturation made one or more writes upstream by or. The rule looks one writer back; it must look through saturation-preserving writers or test the source's values. The ceiling has not moved: rule (c)'s 120-of-128 floor still caps any program at one saturated site, 6.25 percent of reads, a chip edge of at most 1.067x, and the residual (worst seed two sites at 0.53 and 0.56) sits inside it. THE SENTENCE "no lossy-sourced load by construction" IS HELD: it goes in no plan row and no ledger entry as true; sub-version 1 removes the or-source class and bounds the rest. MAIN'S RULING (13:2x UK): 0.3.20 ships object byte 5 on sub-version 1 as it stands, strictly better than the old stream the live floor flips to on 13 October; the fix is sub-version 2 on ca3-v4-amend (object byte 6 or whatever the v5 alignment leaves free) with both fixes: (F1) the static rule made transitive (rotates do not keep entropy; a load keeps entropy only if its own source did; one draw change, no attempts lost) and (F2) the dynamic source check (saturated load SOURCE values counted per site over the 64 units' 16,384 evaluations, rejected above 163 of 16,384, the same 1 percent the final-value rule uses; costs attempts on about 0.2 percent of seeds; rides with F1 because an or-written source is all-ones only (3/4)^32 of the time). Gate before sub-version 2 is proposed, run by the attack-pass lane and not by the hash lane: the full 64-seed census under 1.2x on every seed and the hot-set census. Hash lane's estimate about an hour its side (implement, re-export seven packs, vectors, crate suite, pairing, one G1 on PC 2) plus the node lane's vector re-pin and the attack-pass re-gate. The flip floor for sub-version 1 is expected to move (the project lead's word) so the chain never flips to a stream that fails this gate. Also recorded: the crate suite at 8c728ca3 100 of 100 on the box (rc 0, 77 s); the pairing against the fork at dc141409 compiled and ran 15 of 16, the one failure the fork's own pre-amendment assertion (base equals v3's, igneum.rs:972), which 8097d600 on the release-0.3.20-node line turns into assert_ne; the pairing re-runs at b7cc37e7, its line to follow. CORRECTION (the attack-pass lane's own retraction, 13:3x UK): the F9 hot-set figures above (1,871 of 1,000,000, worst 9.66 percent, 84 percent removed, the two or-then-rotate listings) are WITHDRAWN: F9's harness draws through candidate_class with its own era class, outside candidate_from_words_class where the source rule lives, so it measured the old stream (the 8c728ca3 binary prints the identical program to the sub-version-0 binary for its worst seed). F8's 64-seed census on the chain path (pairing verified on 1a4230699a6b9c60) is the valid re-gate and STANDS: at 30 of 64 seeds, nine over 1.2x of the window model (p31 29.3x, p11 5.5x, p19 3.3x, p6 3.1x, p23 2.0x, p4 1.6x, p10 1.5x, p26 1.3x, p25 1.3x). The residual mechanism on the amended stream: a load-after-load chain (a saturated source reads one fixed word, which is the next load's address), admitted because a load injects; and the rotate-preserves-saturation path (generator.rs sets entropy_kept true for a rotate whatever it rotated), correct in code and a second admitted path if it occurs on the chain stream. Sub-version 2 must close both: dataflow freshness per register (a load fresh only if its source was fresh; add, sub, xor, mad, shfl fresh if either operand was; rotates only if the operand was; or, mul, mulhi never) plus the (c') count of saturated load sources per site as the backstop. The STOP holds on F8's evidence alone; the options and the 1.067x ceiling are unchanged. The sentence "no lossy-sourced load by construction" waits on the sub-version 2 census verdict and stays out of every public text until then. SUB-VERSION 2 IN BUILD (the hash lane, ca3-v4-amend, on the coordinator's direction, 13:4x UK): F1 (dataflow freshness per register, keyed on the class v4 shape on every draw path, era or not, so the candidate_class path and the chain path draw one stream) plus F2 (the (c') count of saturated load source values per site over the 64 units' 16,384 evaluations, rejected above 163, keyed on the same shape so v2 and v3 verdicts do not move); PROGRAM_SUBVERSION_V4 = 2, new ids, the seven packs re-exported, recheck.rs with 1a4230699a6b9c60 and c120d7963abdcd96 as the must-differ pair. Clock (UTC): the commit on the branch by 13:30; the crate suite on box 2 and the pairing against b7cc37e7 by about 13:50 (the pairing's vector test fails on the fork's sub-version-1 pin until the node lane re-pins; the compile and the other 15 are the pairing evidence); the G1 job on PC 2 under --cards-off by about 14:10, lock permitting; then the attack-pass lane's full 64-seed census and hot-set census on the chain path. Two consequences stated in the commit: the rule on every draw path moves the no-era sh256xN ladder packs' stream (packs-ca3-shadow's seven 256-block packs re-export with new fingerprints; the measured rates stand as the old stream's), and the class v5 lane's pinned string-seed packs move when it merges sub-version 2, so it re-exports them then. 0.3.20's sub-version-1 packs, ids and fingerprints untouched. OBJECT BYTES SETTLED (main, 13:5x UK): byte 5 = class v4 sub-version 1 (0.3.20), byte 6 = class v5 (pinned: class-v5 16afd0a0, class-v5-node 699db5a2, the flip case passed on 6,6,6; the v5 lane stopped), byte 7 = class v4 sub-version 2; the node and hash lanes told. b7cc37e7's MIXED-VERSION GATE: FAIL, the binary not the harness (12:16:39Z to 12:27:21Z, sha256 bc28331abf21f4d5, the string read back). Before the restart step everything held: one digest b0afb2ee on all five nodes, 268 new and 392 old blocks accepted, 0 rejected, header versions plain 2, counts equal on all five at 324 and 502 through both clean joins. At the new node's restart (12:24:19Z) it died at once on its own datadir ("IO error: While lock file: .../datadir/meta/LOCK: Resource temporarily unavailable", conn_builder.rs:167): the previous process was still shutting down, because the listener watchdog added on 6a3432a3 sleeps its whole 10 s poll before checking shutdown, so every node on the line since then takes up to 10 s longer to stop than 0.3.17 (the fleet saw the same shape as "a 12-second timeout does not stop the node"). Three of the four failed checks follow from that one death (counts, the restarted node's resync, the node it served frozen at 502). The fix on the line, one rule: the poll in 250 ms steps returning the moment shutdown is set, with a test that a shutdown returns within a second (the 10 s loop the known-failed shape); the exec suite on build-2, the fifth commit and its build about 12:45Z, its digest and ten-minute gates about 12:50 to 13:05Z, inside 14:30Z. b7cc37e7 is NOT the pin. The node-side re-pin for sub-version 2 (byte 7) once the hash lane's commit lands: the beside-the-fork igneum-pow copy archived from the commit, the two pinned ids moved in the kaspa-pow vector test (sub-version-2's epoch-0 id must-equal; sub-version-1's joins c120d7963abdcd96 as must-differ), CLASS_SIGNAL and tests for byte 7, the daemon's window line: about 20 minutes of edits plus one kaspa-pow suite run on build-2 (about 2 minutes). THE FIFTH COMMIT c4459193 on release-0.3.20-node (b7cc37e7's child, the watchdog poll returning on shutdown; the diff is the poll loop in rpc.rs alone), pairing igneum-pow 8c728ca3; its build on build-1 started 12:30:13Z, sha256 and string to follow. Line A, the shutdown test: rpc::watchdog_tests::a_shutdown_returns_within_a_second_whatever_the_poll green on build-2 at 12:29Z in the exec suite's 31 passed, beside the two other watchdog tests; its known-failed shape the old loop's 10 s stop. Line B, the kept-datadir start: b7cc37e7's fleet read carries to c4459193 since the store code is byte-identical between the two commits; the fleet re-reads on the c4459193 binary only if the shipper's rule wants the string on that line too. The digest gate and the ten-minute mixed-version gate on c4459193's own binary follow its build. THE SHIPPER'S CARRY RULING (14:1x UK): b7cc37e7's kept-datadir read stands as evidence that the store fix is right (the store code byte-identical) but is not the gate line for the pin, because the rule reads the binary, not the diff, and the binary changed (rpc.rs); the gate line is the kept read on c4459193's own binary with its string, which the fleet's canary already runs on c18-1 (wipe, then the kept read, then the restart) before the canary's restart step, at no extra cost; no re-read on p12-vast. THE PIN IS c4459193 pairing 8c728ca3 (object byte 5, sub-version 1); sub-version 2 (byte 7) is 0.3.21's, not 0.3.20's. The shipper's reading of main's F8 ruling: 0.3.20 ships object 5 as it stands because the live floor otherwise flips every node to the OLD stream on 13 October, and the 16:00 BST report tells the project lead the floor move is now RECOMMENDED rather than optional, so the chain never flips to a stream that fails the 1.2x gate before sub-version 2 lands. THE FLEET'S CLOCK ON c4459193 (the fleet lane, 12:5x UTC): the kept read on pool-1's 0.3.17 datadir copy and the restart (the old process's stop time on the line) run on c18-1 before the wipe, a few minutes each, so both lines land before 14:30Z; the wipe canary (IBD from the pruning-point proof, 98 minutes on this pod class) starts when c18-1 is free of the 0.3.20 cases (about 13:00Z) and the binary is in hand, so its synced line lands about 14:40Z at the earliest, PAST the 14:30Z checkpoint; the 12 GB settled-claim line: c4459193 starts on p12-vast's kept copy of pool-1's datadir beside the 6a3432a3 IBD node on alternate ports the moment the binary lands, catches up from 129,398 blocks (15 to 20 minutes) and the 12 GB prover claims against it, the line on c4459193 itself. The binary not yet in the fleet's hand (build-1 building since 12:30:13Z); a wait armed on the sha and string, a report by 13:10Z if nothing. THE SHIPPER'S CALL ON THE CLOCK (14:2x UK): the wipe canary is the decisive read by the deploy rule; the pin never cuts without it and b7cc37e7's lineage does not stand in (the binary changed). The fleet rents a second one-shot pod of c18-1's class now and starts the wipe canary on c4459193's binary the moment the build lands, synced line about 14:15Z (15:15 BST), inside the checkpoint; c18-1 keeps the 0.3.20 cases and the pool window. If the wipe line slips past 15:30 BST the pin holds to it and main hears the clock (a slip is a report, not a cut). The set: the node lane's digest and mixed-version gates (12:50 to 13:05Z), the kept read and restart on the new pod, the wipe line on the new pod, the 12 GB settled-claim line on p12-vast. c4459193's BINARY IN THE FLEET'S HAND (12:34:54Z from build-1): igneumd sha256 45be9b02d1b002f5486d0f0108571c3b6042094113ad9da6f3d3d9ffc0072bba with the string c4459193 read back from the file, igneum-miner c7cfc40bc8b0e357. The wipe pod c19-1 (RunPod wpuke4tfu0vr49, RTX 3070 community, c18-1's class, USD 0.13/h, rented 12:37:03Z, one-shot; the day at USD 124 of work plus the 248 leak, 37 percent of the ceiling): the canary form (wipe, IBD from the pruning-point proof, synced, ten minutes mining with the exec poller, the hub read, the restart read) starts the moment the pod answers ssh; the kept read on pool-1's 0.3.17 copy armed behind its synced line on the same pod; the IBD start stamp its own line; synced about 14:20Z if the pod answers by 12:42Z (ten minutes inside the checkpoint), a slip reported the moment a poll shows it. CASES END on c18-1 at 12:37:18Z rc 0 (the relay and poison lines to the shipper); c18-1 and the two case pods destroyed by the run; the ten-member pool window rented its ten at 12:37:36Z. The 12 GB settled-claim line on p12-vast runs against a c4459193 node on the pod's kept copy, up since 12:36:35Z first-try, catching up. THE WIPE CANARY ON c19-1 STARTED: IBD at 12:38:55Z on c4459193 (sha256 45be9b02... asserted on the Mac before the put; the node's own line igneumd/2.1.0-c4459193 and digest eada4bda8aa8368c read back on the pod; a wiped datadir; IBD from the pruning-point proof with 4 peers at 12:39:26Z); synced about 14:17Z by the 98-minute class, thirteen minutes inside the checkpoint; the mining read, hub read, restart and kept read follow on the same pod, each its own line. c4459193's GATE LINES (the node lane): the binary built on build-1 at 12:33Z (1 m 07 s), sha256 45be9b02d1b002f5, the string read back from the binary (strings, two hits) and the worktree HEAD; igneum-miner beside it at /srv/builds/igneum-wt-ca3-v4-node/vendor/igneum-node-0318-release/target/release/. THE DIGEST GATE 12:33:27Z to 12:35:05Z SUMMARY PASS: the thirteen-field object a89be8a7 on both binaries, n0 peering n1 and n2 and the old node peering the new (the compat case); the sixteen-field object db9a85f9, n3 with no peer and the refusal line "consensus params digest mismatch, local db9a… remote a89b…" (the refusal case); the live file's digest on this binary eada4bda, as 5899f603 reads it. THE MIXED-VERSION GATE 12:35:26Z to 12:45:39Z SUMMARY PASS, beside the 5899f603 pair: one digest b0afb2ee on all five nodes; the 5899f603 hub accepted every block the c4459193 node mined, 215 new and 314 old, 0 rejected, no reject line in any log; header versions plain 2 on the thirteen-field file; counts equal on all five at 312 after mining, 441 after the clean join through the old hub and the clean join served by the new node, 529 at the end; the restart step passed: the new node restarted at 12:43:08Z on its own datadir and resynced to 529 with the others (where b7cc37e7 died on the database lock); no panic in any node log; every check green. The node side of the set is complete; the fleet's wipe, kept read, restart and settled-claim lines remain. A SLIP (the fleet lane, 12:5x UTC): the 0.3.20 cases rerun on c4459193 lands about 15:10Z, not 14:20Z: its target c20-1 catches up from pool-1's kept 1026 copy, 22,000 blocks behind a tip the line reaches headers-first (headers 137,405, blocks 129,398 at 12:50Z; the morning's poison pod on the same copy took 50 minutes before its blocks moved), synced about 13:50Z, the 79-minute form after; no faster path exists on a kept copy. The wipe canary on c19-1 holds its clock (29 percent of the headers at 12:47Z on dc141409's curve): synced about 14:17Z, the mining and hub reads to about 14:30Z, the restart and the kept read after; the 12 GB settled-claim line on p12-vast about 14:00 to 14:10Z. The kept read on the pinned binary is already in hand from c20-1's own start at 12:45:46Z (the rewrite line, no panic, sha 45be9b02 and the string read back), with the shipper. MAIN'S RULING WITH THE SHIPPER (14:5x UK): the cases rerun on the pin's own binary gates the cut; the cut word about 15:15Z (16:15 UK) on CASES END, the publish on green right after, the sweep from then with PC 1 first; 5899f603 the fallback until the word. The shipper's reason: the cases are a named gate and the morning's run was on dc141409 (the diff from dc141409 to c4459193 touches the class signal byte, in the cases' territory); the 16:00 BST report carries the clock and the full cut set; everything else staged so the publish is one step at that moment; nothing changes on the pods. AP-F8-1 RE-GATE VERDICT ON SUB-VERSION 1 (the attack-pass lane, census ended 12:55:55Z; igneum-pow 8c728ca3 paired with release-0.3.20-node 8097d600, pairing id 1a4230699a6b9c60 verified by the harness; 64 seeds p2 to p65 at 2^24 nonces each, chain path with era, window-model control, box 2; log /srv/builds/igneum-wt-attack-regate/attack-f8-regate/log/regate-census-64x2e24.log): FAIL the pass line, 53 of 64 PASS, 11 FAIL. |
| Seed | Ratio to the window model | Hottest item's predicted source |
|---|---|---|
| p31 | 29.27x | 0x74e2b8, 5,365,527 reads, site 4 r4 all-ones, last writer rotl at 3 |
| p11 | 5.45x | 0x0eec66, site 1 r7 all-ones, last writer or at 63 of the previous iteration |
| p45 | 4.55x | 0x400000, site 1 r4 zero, last writer mulhi at 59 |
| p19 | 3.32x | 0x400000, site 37 r5 zero, last writer load at 32 |
| p6 | 3.11x | 0x3bf40d, site 13 r0 all-ones, last writer load at 12 |
| p23 | 2.04x | site 16 r7 all-ones, last writer load at 14 |
| p4 | 1.57x | |
| p34 | 1.51x | 0x400000, site 23 r6 zero, last writer rotr at 12 |
| p10 | 1.50x | |
| p26 | 1.30x | 0x000000, site 10 r1 zero, last writer rotl at 2 |
| p25 | 1.28x | |
| the 53 passing | 0.9915x to 1.16x | no predicted source |
Three residual classes, all a constant delivered through a writer the rule admits: (1) saturation or zero preserved through rotl, rotr, load or mad (p31, p6, p23, p26, p34); (2) zero from mulhi (p45) and zero preserved by rotates; (3) the iteration boundary, the rule's writer state starting fresh at instruction 0 so an or at 63 feeds a load at 1 (p11). Sub-version 2's dataflow-freshness rule closes all three IF the freshness is computed as a fixpoint over the loop (the state after instruction 63 feeds instruction 0 of the next iteration), with the dynamic (c') count on load sources as the backstop; sent to the hash lane. "No lossy-sourced load by construction" is not true of sub-version 1 and stays held. Chip consequence on sub-version 1 by the 1.4 arithmetic: the hot set is still one item at one site, under 1 percent of rate for a chip caching it, so the ship is safe on the rate side; the auditor's flag is what sub-version 2 removes. F9's hot-set harness cannot be the second re-gate (its metric counts the era's designed half and quarter windows as hot; its chain-path 8.3 percent on sub-version 1 is the window model, verified on its worst seed); F8's census is the single re-gate instrument, re-run on sub-version 2 within the hour of its commit. SUB-VERSION 2 COMMITTED: ca3-v4-amend 07a809a7, 13:01Z (origin and build), the string with the attack-pass lane. The loop fixpoint is in as rule (a') in accept.rs (the freshness run to its fixpoint over base then shadow block; every load's source fresh in the steady state, else the candidate rejected and the next attempt drawn; it closes the iteration boundary the draw's fallback cannot see); (c') counts zero and all-ones alike (v == 0 or v == MAX) per load site over the 16,384 evaluations, rejected at 164 or more; both and the draw rule keyed on the class v4 shape on every draw path, so v2 and v3 do not move; mulhi never fresh. Epoch-0 id a788661687db4bb3 (the devnet seed's attempt 0 rejected by the new rules, attempt 1 accepted); must-differ c120d7963abdcd96 and 1a4230699a6b9c60 pinned; object byte 7 in recheck.rs. The seven fingerprints (Metal = Apple OpenCL on the M5 Max, 13:01:17 to 13:01:49Z, the control 90f794dd556f7a3b unchanged):
| Pack | Fingerprint |
|---|---|
| v4-devnet-epoch0 | e370fb2080b7dbb1 |
| era-0 | b7237555d31fc3cf |
| era-1 | b6b167fa15dfe2c9 |
| era-2 | 28bdf65eff33f2c4 |
| era-3 | e26d38c46f3f1b16 |
| era-4 | dd8fdf6ff4f59eed |
| era-5 | 8bf40f5cb858d835 |
Packs zip (eight packs, packs-ca3-v4-sub2) sha256 69c36772cd79e44e2ddd589466d9c64a94a13c9e970e9f27bd76feabb9b4581b. The suite re-runs through master's build-remote on box 2 (the worktree's own script predates --box; the first run died on the flag), line to follow; G1 on PC 2 under --cards-off after it. The sub-version-2 pairing waits on the node lane's re-pin to a788661687db4bb3 and byte 7. For the record, sub-version 1's pairing: igneum-pow 8c728ca3 against b7cc37e7 (8097d600's assert_ne in) 17 passed, 0 failed, rc 0, 12:21Z. 0.3.20's CUT SET AS IT STANDS (the shipper, 14:1x UK): pin c4459193, igneum-pow 8c728ca3 at object byte 5 (sub-version 1), the floor-moved file publishing with it (the project lead's word; the floor from the live DAA at the publish plus 604,800, the digest read on c4459193), publish about 15:15Z (16:15 BST) on CASES END, the sweep from then with PC 1 first. 0.3.21's clock tonight: the node lane stages release-0.3.21-node at the shipper's sweep-end word (about 15:45Z, 16:45 BST) with the sub-version-2 re-pin (07a809a7, byte 7, id a788661687db4bb3) as its own commit, held pending the F8 census on 07a809a7; the census's clock about 14:00Z (15:00 BST) by the attack-pass lane's within-the-hour line from 13:01Z; the pass line every one of the 64 seeds under 1.2x of the window model on the chain path. If the census fails or slips past 19:00Z (20:00 BST), main's standing ruling applies (nothing on sub-version 2 is proposed until the census is green): 0.3.21's node ships byte 5 again with the re-pin dropped and the rest of its line kept. CI NOTE (13:1x UTC): master's ci runs since 12dc5c97 (nineteen of mine) sit queued behind one self-hosted runner (igneum-build-1, busy; 31 queued across branches, one in progress); the last completed master runs (439a233f to 5f990a09) are success; no red exists, the conclusions are unread until the queue drains. MAIN'S WORD (14:2x UK): the floor move is the project lead's word already and ships with 0.3.20 at the cut; the CI lever is a second self-hosted runner on build-2 plus ubuntu-latest for docs-only pushes, ordered to the CI lane; the rule reads "own a red when the conclusion lands", never holding pushes; the census verdict about 14:00Z (15:00 UK) decides 0.3.21's byte. SUB-VERSION 2's STATIC CENSUS (the hash lane, tools/ca3-v4-uniform on box 2, 13:12Z, 1,024 chain-shaped seeds plus F8's p1 to p3): 0 lossy-sourced load sites of 16,432 (14,329 injecting, 2,103 bijective); 0 programs with an or-, mul- or mulhi-sourced load; the no-era draw path gives the devnet epoch-0 seed the pack's own id a788661687db4bb3, so every draw path reads one stream. Cost of (a') and (c'): 1.99 attempts per seed on average against 0.05 before (p2's seed five), about 2 ms of generation per rejected attempt on one core; nothing a miner or node notices. Ledger entry 715f14be. Master 36e08c80 merged into ca3-v4-amend as f5244ad7 (igneum-pow untouched, re-export 0 differing files), pushed with the gate GREEN, its CI runs queued; the box-2 suite runs through the merged tools (the first attempt died on test initialisers missing the (c') field, fixed in the same push; library and packs unaffected). G1 BLOCKED: PC 2 has not picked up fetch-ca3-v4-sub2-20261007 and run-ca3-v4-sub2-g1-pc2-20261007 (published 13:04:02Z, signature OK); the intake shows nothing from 1ccfe586 since job-update-now-0319 at 10:34:21Z; the PC 2 lock releases when the job closes or in 30 minutes; the run is republished when the app reports. PC 2 READS SILENT on the console (the shipper, 14:4x UK): last seen 2 h ago, app 0.3.19 on node 5899f603, its last line the 0.3.19 update-now at 10:34:21Z; the app went down or stopped polling on that update (the UI lane's update-now; PC 1 took the same update and reports). The build-server lane's PC 2 kept-datadir job (run-20261007-125433, published 12:54Z) is unpicked for the same reason, and it is the Windows kept-datadir gate for 0.3.20's PC 1 step. The sweep cannot bring PC 2 back (the app's poller applies updates; a silent app does not poll); a Windows restart of the app is a hand action, the project lead's or by main's word; the shipper has asked main. The hash lane's G1 and the Windows kept-datadir line wait on that answer; the PC 2 lock stays. SUB-VERSION 2's SUITE LINE (the hash lane): ca3-v4-amend 526fa757 (the code; the ledger tip f0fbd9da), box 2 through the merged tools, route line "13:15:07 build-remote: box 2 (build@142.132.249.238) for class suite, priority normal", rc 0, 66 s: 61 lib + 7 derive + 4 mixer + 19 packs + 2 recheck + 7 scratch = 100 passed, 0 failed; the pinned v2 and v3 packs byte-identical; the three v4 ids as pinned (a788661687db4bb3 equal; c120d7963abdcd96 and 1a4230699a6b9c60 differ). The two commits between 07a809a7 and 526fa757 touch tests only (the (c') field in the accept.rs initialisers; the two generator unit tests follow the amended facts); the library, the packs, the id and the seven fingerprints are unchanged from 07a809a7, so the attack-pass re-gate on 07a809a7 stands for 526fa757. CI: the merge commit's run cancelled by the next push (superseded, not red); 526fa757's run queued (37626985216), its conclusion owned by the hash lane. The 0.3.21 re-pin commit is therefore 526fa757 (or the branch tip at the node lane's archive, code-identical). MAIN'S WORD ON PC 2 (15:0x UK): the hand restart of PC 2's app is asked of the project lead. If PC 2 has not polled by 15:00Z (16:00 UK), "go PC 1": the sub-version 2 G1 on PC 1 under the runner's --cards-off after the 0.3.20 sweep step lands there, one job, read back, nothing else on PC 1. The PC 1 job publishes only after the shipper's line "PC 1 on 0.3.20" (app 0.3.20, node 2.1.0-c4459193, the published file's digest, synced, the sweep step closed with its lock line), about 15:30 to 15:40Z by the clock, and only if PC 2 is still silent; The PC 1 variant is on ca3-v4-amend at a2714d43 (tools/ca3-v4-amend/pc1-v4-sub2-g1.ps1; CI checks pass; no api/quit, pause, resume or cards call in the script): the RTX 5090 on PC 1 (ae432dc7) by its index-free key nvidia:NVIDIA GeForce RTX 5090 on the runner's --cards-off, restored by the runner after; the AMD card and the Intel Arc not named and mining on; the card confirmed quiet by the process list (90 s wait) and nvidia-smi's compute-apps; the installed worker's --bench on the eight packs (the v3 control and the seven sub-version 2 packs) for the 2^24 fingerprint and self-test, rates a reference only; the kit the same zip (69c36772...), as fetch-ca3-v4-sub2-pc1-20261007 immediately before run-ca3-v4-sub2-g1-pc1-20261007 (--timeout-minutes 20, --expires-hours 12); published only on the go-PC-1 line. AP-F8-2 ON SUB-VERSION 2 (the attack-pass lane, 15:1x UK, before anything is proposed): a chain-shaped epoch seed can exhaust all 32 draw attempts under rule (a'), and the generator treats exhaustion as a consensus fault (panic): seed igneum-f9/331672, "32 consecutive candidates rejected, last: (a') load at 16 reads r6, not fresh by dataflow in the loop's steady state". One such seed in the first 331,672 chain-shaped seeds (300,000 drew clean), a rate of order 10^-6 to 10^-5 per epoch seed; the 10^6-seed measurement with the attempts distribution runs on box 2. Meaning: an exhausted epoch seed is an epoch no node can draw a program for, a liveness halt, the era and epoch seeds being VDF outputs nobody can steer; at one epoch an hour, one halt per 11 to 40 years at the bracketed rate, which the firms would compute from the rule as written and file. Sub-version 1 had 0 exhausted in 10^6 chain-shaped seeds. The fix (to the hash lane): the draw enforces the freshness fixpoint itself so (a') never fires (no exhaustion by construction), or MAX_ATTEMPTS sized to the measured rate with the exhaustion probability stated in the spec. The 64-seed hot-set gate on sub-version 2 is separate: 13 of 64 seeds read, none over 1.2x so far. Sub-version 2 is NOT GREEN until both are settled. MAIN'S RULING ON AP-F8-2 (15:2x UK): the draw must be total and no consensus path may panic; preferred fix a deterministic repair instead of rejection (the draw rewrites the offending load's source to the nearest fresh register, or inserts a fresh mix, so every seed yields a program on the first attempt and (a') becomes a check that can never fire); if the repair changes the stream's statistics, the fallback is a stated attempt bound with a deterministic last-resort draw after it, never a panic, the probability in the spec and the ledger; either way a test walking seed igneum-f9/331672 and the exhausting class, the 10^6-seed exhaustion count at zero, and the 64-seed hot-set gate re-run on the fixed commit; the hash lane builds it now on the coordinator's direction; 0.3.21 ships byte 5 if not green by 19:00Z (20:00 UK). The 07a809a7 kit is not published to any PC.
AP-F8-2 FIXED (the hash lane, ca3-v4-amend 8bdcbdd8, 13:31:10Z, origin and build, gate GREEN): sub-version number unchanged at 2 because the stream is unchanged for every non-exhausting seed (re-export diff 0 on v4-devnet-epoch0, v4-era-0 and v4-era-5; the id a788661687db4bb3 and the seven fingerprints stand; the packs zip sha256 69c36772... holds), so the attack-pass census at 13 of 64 continues on it. The route: the deterministic repair would have rewritten every seed whose attempt 0 fails (a'), about two thirds of seeds, a new stream and a restarted census against the 19:00Z line, so the second route main allowed was taken. The bound: MAX_ATTEMPTS_V4 = 256 for the class v4 shape (v2 and v3 keep 32, keyed on the shape); at the measured rejection rate of about two thirds per attempt, 32 attempts exhaust at about 2e-6 per epoch seed (one undrawable epoch every few decades at one an hour), 256 at under 1e-45, the worst-case draw about half a second on one core. After the cap the draw is total: the seed takes the last-resort program, deterministic and accepted as drawn, the candidate at attempt 256 with every or, mul and mulhi of the base program and the shadow block rewritten to xor, so every register stays fresh from the init words on and (a') holds by construction; no consensus path panics for the v4 shape. The test class_v4_draw_is_total_with_the_last_resort (the last resort on real (a')-rejected candidates, every load fresh after it, no lossy op left, the chain path over 64 seeds without a panic, the cap per class asserted) green on the Mac, the box-2 suite running; the hash lane's 4,096-seed census with the attempt histogram on box 2; the attack-pass lane's 10^6 count is the control; the string with the attack-pass lane with seed igneum-f9/331672 named. CI: 526fa757 success; 8bdcbdd8 queued. The spec and ledger text for the bound and the probability in the ledger entry. The PC 1 variant and fetch job carry 8bdcbdd8's packs (byte-identical to 07a809a7's); the PC 2 kit published at 13:04Z is the same packs. Per tier: a miner never sees the draw (the node draws once an hour, half a second at worst); a chip maker gains nothing from the last resort (a 1e-45 event); the auditor reads the bound and its probability in the spec. SUITE LINE AT 8bdcbdd8: box 2, route line "13:31:21 build-remote: box 2 (build@142.132.249.238) for class suite, priority normal", rc 0, 80 s, 62 lib + 7 derive + 4 mixer + 19 packs + 2 recheck + 7 scratch = 101 passed, 0 failed, the total-draw test included; ledger entry 32e96c9a; CI on 526fa757 success, the newest push's run queued and owned by the hash lane.
THE 12 GB SETTLED-CLAIM LINE ON c4459193 (the fleet lane, 13:27Z): the floor reads right and the card proves, THE NODE REFUSES. p12-vast on c4459193 (sha 45be9b02, string read back) synced 13:22:47Z on the kept copy; first claim 13:23:01Z "segment 164198..164205 (8 shards, fresh) margin=414 tip=287564 settledNumber=0x28185 settledDaa=0x46317 settledBy=finality candidates=5"; proof complete 13:25:19Z on the 3060 (8 of 8 shards, 135.9 s, peak 8,487 MiB); submission refused "statement differs from the node's at hex offset 472 (lengths 616 vs 616); ours ...2b1a81cb413236cf... node ...0000". The node's start line on this binary reads "proving v1: ... shard program id unknown, aggregator id unknown" where 5899f603 on the same override file reads the ids; the statement is built with zeros and every proof fails its check. This blocks the paid line on any card and, after the sweep, every standing prover; with the node lane (the fix) and the shipper (the cut) since 13:27Z; the pod and proof files held for the node lane's read. The cut set is therefore NOT complete on c4459193. THE CAUSE (the node lane, 13:4xZ): no commit on the line lost the ids and the binary is not the difference; on every build including 5899f603 the statement's ids come from the override object's two fields (absent on the live sixteen-field file), else IGNEUM_PROOF_PROGRAM_IDS, else the verifier host's --mode id when IGNEUM_PROOF_VERIFIER is set. hub-1 runs with IGNEUM_PROOF_VERIFIER=/opt/igneum-floor/bin/igneum-prove-host in its process environment, so the host hands it the ids; the pod's c4459193 node was started bare for the kept-datadir read, so program_ids answered None and the statement carried zeros; a bare 5899f603 reads "unknown" too. The start environment, not the binary. What the child commit fixes anyway: the binary embeds the verifying keys it verifies carried proofs with, so it knows the ids it expects; the child resolves them in that order and last from the embedded keys, with a test whose known-failed shape is the bare node's None and the zero-id statement; the diff two files (resolve_program_ids in igneum/exec/src/proving.rs and its call in kaspad/src/daemon.rs; nothing in acceptance, the version check, relay or peer handling); its exec suite running, the string and sha256 about 13:52Z. Gate carry: the digest and mixed-version gates are outside the diff's territory and carry from c4459193, but rule 4a runs every gate on every candidate from its build, so both run again on the child's binary and the fleet's set with them; the re-run that bears on the diff is the 12 GB line itself, the pod's already-proved claim submitted against a node that names the ids. Per tier: a solo miner on a bare node never proves, so feels nothing; a standing prover beside hub-1's environment was never affected; a prover on a bare node could not be paid on any build until the child. THE CONTROL (the fleet lane, p12-vast): the same c4459193 (sha256 45be9b02d1b002f5, string read back) on the same kept copy, killed and restarted 13:30:28Z with IGNEUM_PROOF_VERIFIER=/opt/igneum-floor/bin-0317/igneum-prove-host (sha 71bc2438) and HOME on the floor: the start line reads "proving v1: ... shard program id 0x2b1a81cb413236cf..., aggregator id 0x474678f3...", no panic, synced 13:31:49Z (155,725 blocks, 4 peers); the bare start of the same binary on the same copy at 12:36:11Z read "unknown". The ids are the start environment on the pinned build, not the binary. The submission verdict against the ids-naming node: the prover restarted 13:31:56Z and claims fresh (the 13:23Z proof held as evidence, past its margin), the first chain proof about 2.5 minutes on the 3060, the verdict line about 13:36Z; the bare-child line runs the minute the child's string and sha land (about 13:52Z). THE CONTROL'S VERDICT (13:33:56Z): against c4459193 restarted with the verifier set, the 3060's first proof "RESULT seg 164286 chain ... 8 shard records, chain_len 8, proof 1272909 bytes, shards 44.9 s, aggregation 39.7 s, wall 110.6 s, peak 8423 MiB", "shards accepted 8 of 8", no "FAILED: statement": the statement check passes, so the zero-id refusal at 13:25Z was the bare start's environment and nothing in the binary, the pin included. The submission then read "segment_refused ... segment already paid; end to end 113.1 s": the claim race (a 24 GB box proved the same fresh segment inside the 3060's 113 s, the shape of p2-4070-1 this morning); the settled floor does not reserve a claim per key, so a 12 GB prover on the open devnet wins only when no faster box picks its segment; the prover runs on (claim 164342..164349, settledNumber 0x28208 by finality, margin 470) and the paid line goes out the minute a race is won, minutes to tens of minutes of races, not the floor. Per tier: a 12 GB card proves and verifies on the pin; whether it is paid on the open devnet is the race against bigger cards, which is the settled floor's design today and a question for the claim rule, not this cut. THE PROVING-IDS CHILD: 55768f88 on release-0.3.20-node (c4459193's child; resolve_program_ids reads the override's fields, then the env or the host, then the embedded verifying keys; one call in the daemon), pairing igneum-pow 8c728ca3 at byte 5; the exec suite 32 passed at 13:29Z with a_bare_node_resolves_its_program_ids_from_the_embedded_keys (known failed first: the bare node's None and the zero-id statement), kaspad check green 13:33Z; igneumd and igneum-miner built on build-1 at 13:35Z, sha256 279b1b690e854fc9, the string read back; the node lane's digest and mixed-version gates on it from 13:37Z (lines about 13:52Z); the fleet has the path, sha and string for its full set from the same minute; ledger N14 on ca3-v4-node. MAIN'S WORD THROUGH THE SHIPPER (15:5x UK): THE PIN IS c4459193 (the control showed the environment names the ids on it; the ids commit 55768f88 is 0.3.21's first node commit, with the ids gate on every candidate from then); the publish about 14:55Z (15:55 BST) on CASES END. PC 1 is offline for the project lead's cable work, out of the sweep's waves; its app updates on its poller when it returns; the "PC 1 on 0.3.20" line comes after the cable work, not at the publish. PC 2 still silent. The sub-version 2 G1 waits for whichever PC returns first; nothing on either before the shipper's line. 0.3.21's node line stages tonight on 55768f88 with the re-pin held for the census. MAIN'S RULING ON 0.3.21's BYTE (16:0x UK): neither PC is needed for the CUDA half; G1 for 8bdcbdd8 runs on a fleet 5090 now (p1-5090 or a one-shot 5090 pod through the fleet lane; the Linux CUDA worker's 2^24 fingerprints and self-test against the Mac's seven; no --cards-off on a pod; ordered to the fleet lane with the kit's sha256 and the pass line). If that G1, the attack-pass lane's two gates on 8bdcbdd8 and the node lane's re-pin and pairing are all green by 19:00Z (20:00 UK), byte 7 ships in 0.3.21 with the Windows G1 owed and run on the first PC that returns (a Windows-only CUDA mismatch would be a 0.3.22 re-pin; nothing flips before the moved floor); if any is not green by then, byte 5 ships and the re-pin stages for 0.3.22. THE FLEET G1 PACKAGE (the hash lane to the fleet lane, 13:4xZ): the kit packs-ca3-v4-sub2-20261007.zip on the dl host (sha256 69c36772...), the eight packs; the worker proto-cuda/nvrtc/worker.cpp built for Linux by infra/cross/build-workers-linux.sh (dlopens libcuda and libnvrtc, compiles each pack's own text; any 0.3.20-tree build is the right binary, its string from --help); the bench igneum-worker-cuda --bench --pack <dir> --batches 5 --batch-log2 24 --block-warps 1, the pass per pack self-test PASS plus the fingerprint equal; the eight expected fingerprints. THE PC 2 RUN JOB WITHDRAWN: run-ca3-v4-sub2-g1-pc2-20261007 had been live in the signed file since 13:04Z and would have fired the moment PC 2's app polled, before any sweep step; removed and deployed 13:39:54Z, the file verified; the fetch kit stays; the PC 1 variant never published; the PC 2 lock released 13:39:22Z. PC 2 BACK (the shipper, 13:4xZ): polling since 13:38:32Z, app 0.3.19, non-elevated, node synced; the silence from 10:46Z was the whole PC losing power (Kernel-Power 41, no bugcheck), not the update; the build-server lane's kept-datadir job ran on it at 13:38:32Z and passed; PC 2 takes 0.3.20 on its poller in wave 1 at the publish. The Windows G1 on PC 2 ordered now under the PC 2 lock with --cards-off on the 5090, the 0.3.19 worker (nvrtc compiles each pack's text), to close well before the 14:55Z publish (a job under an app relaunch is the shape that killed the 9070 XT on 6 October); if it cannot start by 14:20Z it waits for the shipper's line that PC 2 reads 0.3.20. The fleet 5090 G1 runs regardless. THE LINUX CUDA G1 FOR SUB-VERSION 2: PASS (the fleet lane, p1-5090, the fleet's standing RTX 5090, no rent, 13:43:22Z to 13:44:07Z; kit sha256 69c36772... asserted; the box's igneum-worker-cuda 1.0 of 4 October 2026, sha256 97e036e23f4ace66; --batches 5 --batch-log2 24 --block-warps 1).
| Pack | Fingerprint on the 5090 | Equal to the Mac |
|---|---|---|
| mx8-devnet-epoch0 (the v3 control) | 90f794dd556f7a3b | yes |
| v4-devnet-epoch0 | e370fb2080b7dbb1 | yes |
| v4-era-0 | b7237555d31fc3cf | yes |
| v4-era-1 | b6b167fa15dfe2c9 | yes |
| v4-era-2 | 28bdf65eff33f2c4 | yes |
| v4-era-3 | e26d38c46f3f1b16 | yes |
| v4-era-4 | dd8fdf6ff4f59eed | yes |
| v4-era-5 | 8bf40f5cb858d835 | yes |
Self-test PASS on each (FNV-1a 448274a57f508cbc); rates 120 to 142 MH/s with the box's miner loop sharing the card, a reference only; p1-5090's node untouched, its supervisor restarted after. The CUDA half of G1 is green. THE WINDOWS G1 ON PC 2: GREEN (job run-ca3-v4-sub2-g1-pc2-20261007b, published 13:46:33Z under the PC 2 lock taken 13:45:03Z, the runner's --cards-off on the 5090, 15-minute timeout, nothing of the proving lane's running; start 13:46:36Z, end 13:46:50Z, exit 0; lock released 13:47:18Z; app 0.3.19, the installed worker sha256 14b6637e..., the card off before the script and restored on exit, igneum-worker-cuda 0 before and after, the prover untouched).
| Pack | Fingerprint on PC 2's 5090 | MH/s (card alone, 5 batches) | Equal to the Mac and the fleet 5090 |
|---|---|---|---|
| mx8-devnet-epoch0 (the v3 control) | 90f794dd556f7a3b | 118.1 | yes |
| v4-devnet-epoch0 | e370fb2080b7dbb1 | 119.3 | yes |
| v4-era-0 | b7237555d31fc3cf | 115.8 | yes |
| v4-era-1 | b6b167fa15dfe2c9 | 116.7 | yes |
| v4-era-2 | 28bdf65eff33f2c4 | 119.3 | yes |
| v4-era-3 | e26d38c46f3f1b16 | 129.5 | yes |
| v4-era-4 | dd8fdf6ff4f59eed | 115.2 | yes |
| v4-era-5 | 8bf40f5cb858d835 | 117.1 | yes |
Self-test PASS on every pack (cache FNV 448274a57f508cbc); both rows in the ledger entry 43c5bf5b. G1 FOR SUB-VERSION 2 IS COMPLETE on three platforms (Metal, Linux CUDA, Windows CUDA), nothing owed. Per tier: the 5090 rate on sub-version 2 is the same band as sub-version 1 (115 to 130 MH/s), so a miner's rate does not move with the class amendment. The lines left for byte 7 by 19:00Z: the attack-pass lane's two gates and 10^6 count on 8bdcbdd8, the node lane's re-pin and the pairing. THE 64-SEED GATE ON SUB-VERSION 2 IS HEADING TO FAIL (the attack-pass lane, 13:55Z; its earlier "none over 1.2x at 13 of 64" was not read from the log and is withdrawn): 39 of 64 seeds read, 8 over 1.2x of the window model, worst p23 at 4.82x; 44 minutes for 39 seeds, the finish about 14:25Z; the eight seeds' hottest items and predicted sources being read (a residual constant through a writer the freshness rule still admits, or the window model's tail). The 10^6 exhaustion count at 8bdcbdd8: 630,000 drawn, finish about 14:05Z; the 07a809a7 control 880,000 drawn, finish about 13:59Z; the exhaustion and past-31 counts with the ends. The hot-set gate is F8's 64-seed census alone (F9's table serves the attempt histogram and the exhaustion count only). Sub-version 2 is NOT GREEN. THE EIGHT SEEDS (the attack-pass lane, 14:0xZ): three are the window model's own tail at 2^24 nonces with no predicted source (p4 1.22x, p8 1.38x, p10 1.50x); five are constants the freshness rule cannot see because it tracks lineage, not value: p23 4.82x (zero from xor of a register with itself at instruction 0, item 0x000000 at 41,727 reads), p34 1.25x (sub of a register with itself), p15 2.57x (zero through rotl at 0), p18 2.50x and p19 3.32x (a load whose address is constant delivers one word to the next load; p19 byte for byte the sub-version 1 program, untouched by the rule). (c') cannot catch them: its 164-of-16,384 per-site bound (1 percent) is about fifty times coarser than the gate (p23's item is 0.002 percent of all reads and still 4.8x at the top 0.1 percent). Chip side unchanged: one item at one site, nothing to a chip; it is the auditor's uniformity test that fails. THE EXHAUSTION HALF (AP-F8-2) at 8bdcbdd8: 0 exhausted and 0 panics in 650,000 chain-shaped seeds (the 10^6 finishes about 14:05Z), max attempt 35, nobody at the last resort, past attempt 31 about 3.2e-6 (5 in 1.55 million draws, inside the (2/3)^32 estimate), per-attempt rejection 0.67, mean 2 attempts; seed 331672 accepts at attempt 32; the 07a809a7 control's clean evidence one exhaustion in 331,672 (its later chunks contaminated by a rebuild on the same path, not used); FIXED-AND-PASSED at the 10^6 end if the count stays 0. THE GATE QUESTION (the hash lane to the attack-pass lane): three of the eight are the null's own tail at 2^24 nonces, so a 1.2x-on-every-seed threshold sits below the null's spread and no rule can pass it on 64 seeds; the threshold must be set from the null's measured 64-seed quantile or the nonce count raised; the attack-pass lane asked to state that quantile. SUB-VERSION 3 (the fix shape, the hash lane; new ids, packs, fingerprints, the G1s and the census again): (1) the draw forbids a self-operand on xor, sub and mad (dst == src) in the base program and the shadow block; (2) (c') becomes a per-site bound on the MOST REPEATED source value, any value, over the 16,384 evaluations, set from the gate's sensitivity (a uniform source repeats a value two or three times by chance; a bound of 8 is 0.05 percent of a site's reads, 0.003 percent of all reads, 1.02x at the top 0.1 percent), catching the load-after-load constant, the rotated zero and anything a static rule misses; (a') stays for the or, mul and mulhi classes; (3) the attempt cap and the last resort stay, the last resort's rewrite gaining the self-operand guard (a lossy op with src equal to dst becomes add with the immediate). Clock (UTC): build, re-export, Mac fingerprints and the census by about 14:50; the fleet and PC G1s by about 15:20; the attack-pass 64-seed re-gate about 1.5 hours after the string, green by about 16:45 if the threshold question is settled; inside 19:00Z with no slack for a second miss. CORRECTION (the hash lane, from igneum-pow show on p23, p15 and p18 at 8bdcbdd8): the draw already forbids src == dst on every ALU op, so the self-operand ban (1) is void; p23's instruction 0 is xor r2 ^= r1 and site 1 reads r2, so the zero means r2 equals r1 at the start of most iterations, which only the shadow block arranges (a pair of ORs between two registers makes them equal; lossy ops are free in the shadow because only load sources are ruled); p15's rotated zero and p18's load-to-load constant are the same class, a value equality or a constant made upstream that lineage cannot see. The only fix that closes the class is the dynamic bound (2), whose reach the acceptance sample sets: a uniform source repeats a value three times with probability about 4e-8; p23's zero at 3e-4 of its site's reads shows up about five times in 16,384, so "no value three times at a site" catches p23 with about 88 percent probability and misses rarer constants; catching a constant at 1e-4 of a site's reads reliably needs 256 units instead of 64 (four times the draw cost per attempt, about 8 ms), a bigger consensus change. THE COORDINATOR'S PLAN (15:1x UK, to main): 0.3.21 stages on byte 5 (sub-version 1, what 0.3.20 carries); byte 7 goes in only if a sub-version 3 reads green on both gates by 19:00Z; otherwise sub-version 3 is 0.3.22's, built against a gate defined in numbers. The attack-pass lane asked for the gate's three numbers by 14:30Z (the ratio's formula; the single-item read count at 2^24 that still passes 1.2x; the null's 64-seed tail and a threshold defendable to an auditor, or a higher nonce count); the hash lane prepares sub-version 3 uncommitted (the bound and the sample size as parameters, the test with p23, p15 and p18 as the known-failed shapes, the draw-cost line per sample size) and commits on the coordinator's one line once the numbers land; if they do not land by 14:30Z or the census would pass 18:00Z, sub-version 3 is 0.3.22's. THE GATE IN NUMBERS (the attack-pass lane, 14:2xZ, from tools/attack/f8-uniform/src/main.rs lines 289 to 290 and 1240 to 1252). (1) The ratio: the items are the 2^22 dataset items; a census counts reads per item over 2^24 nonces x 128 loads = 2^31 reads; S_f is the share of all reads on the top f of items by measured count (f = 0.1 percent = 4,194 items); W_f the same statistic on a windowed control (a simulated read map from the program's own 16 window draws under the era map, Poisson, no program structure); ratio_w = S_f / W_f, the gate ratio_w at f = 0.1 percent under 1.2; the flat ratio against a uniform map reported beside it; X_f = S_f minus W_f the excess share. (2) The reach: on a typical seed W_0.1 is 0.14 to 0.16 percent of all reads, so 1.2x is an excess of about 0.03 percent, 640,000 reads of 2^31; a single item trips the gate alone only at about 640,000 reads (0.48 percent of its site's 2^27, 78 repeats per 16,384 evaluations), which a per-site most-repeated-value bound sees; the five constants are the tops of low-entropy BANDS: a site whose index has k bits of entropy over its window spreads 2^27 reads over 2^k items, ratio about 45x at k = 12, 6.7x at 15, 2.4x at 17, about 1.2x at 18 (512 reads per item, the uniform level); so the reach is a per-site index entropy of about 18.5 bits of the window's 20 to 22, and the matching dynamic statistic is the count of DISTINCT source values per site, not the most repeated (at 16,384 evaluations every k above 14 reads about 16,380 distinct and is invisible; at 2^20 evaluations a k = 18 site reads about 2^18 distinct against 2^20 uniform). The bound: distinct index values per site over 2^20 evaluations at least 2^19.5 (about 740,000), run once on the chosen candidate (about 10 s per candidate), with the most-repeated-value bound at 16,384 beside it. (3) The null's tail: the Poisson spread of ratio_w at 2^24 nonces is about 0.2 percent, so a seed at 1.22x is hundreds of sigma from the sampling null and a higher nonce count tightens nothing; sub-version 1's 53 clean seeds median 1.004x, p75 1.051x, max 1.156x (p17), then 1.103 and 1.080, the window model's own error, not noise; sub-version 2's three no-source seeds are reproducible under a re-draw (p10 1.5048x on sub-version 1 and 1.5036x on sub-version 2 with the identical program; p4 1.57x to 1.22x with the rule; p8 1.38x): structure the predictor does not name (near-zero or low-entropy sources whose images sit in the 0x40xxxx band), not tail. Defendable to an auditor: 1.2x sits just above the window model's measured error (1.04x over the clean maximum, 1.15x over the clean p75) and far above the sampling null; a seed over it with no named source is reported as unattributed and chased, never absorbed; neither the threshold nor the nonce count moves. Also: F6 closed PASS at 13:57Z (the worst of 10^5 programs 8.708 ms on the half-core proxy); the 64-seed census on sub-version 2 at 46 of 64, 8 over, finish about 14:40Z. THE LINE FOR SUB-VERSION 3 (the coordinator to the hash lane, 15:3x UK): commit now with the dynamic rule in two parts keyed on the class v4 shape: (A) per load site the count of distinct index values over 2^20 evaluations of the chosen candidate at least 2^19.5, run once on the candidate that passed (a') and the repeat bound, a failing candidate rejected and the next attempt drawn under the same 256 cap and last resort; (B) the most-repeated-value bound at 16,384 evaluations at 8 beside it; the threshold stays 1.2x; new ids, packs and fingerprints; the string to the attack-pass and fleet lanes; nothing to any PC. The 0.3.21 re-pin target moves from 8bdcbdd8 to sub-version 3's commit, on the coordinator's word after both gates, before 19:00Z or not at all for 0.3.21. MAIN'S WORD (15:4x UK): the plan accepted as written: 0.3.21 stages on byte 5; byte 7 only if sub-version 3 reads green on both gates by 19:00Z with the gate defined in numbers; otherwise sub-version 3 is 0.3.22's, read green before it is proposed; do not force the clock. AP-F8-2's EXHAUSTION HALF CLOSED: 10^6 chain-shaped seeds at 8bdcbdd8 through the chain path, 0 exhausted, 0 panics, max attempt 35, 4 seeds past attempt 31 (4e-6, inside the (2/3)^32 estimate), none at the last resort, r = 0.67, mean 2.0 attempts; final 14:03:53Z; FIXED-AND-PASSED in the pass record. The hash lane's sub-version 3 commit waits on its known-failed test's result on box 2, then the re-export, fingerprints, suite, census and the three strings. A SEPARATE FINDING ON THE 0.3.20 LINE (the node lane from the fleet's per-node read at 14:05Z, ledger N15 on ca3-v4-node): the exec layer's chain block number is the node's own record index (seeded from genesis, the restart pin or a snapshot, extended one per chain block the follower appends), not a canonical index of the DAG; seven standing provers number the same DAG block 2 to 46 higher than the hub and the five paid boxes, constant since some past follower event, so their segment records name block ranges the carriers refuse ("is not chain block N on this chain"; p1-5090's record for the worked example carried seven times and refused seven times while p1-4090's for the same DAG blocks was paid); a prover on a drifted node is never paid whatever the card or the claim rule. Nothing on chain is wrong and the pin's gates stand; the fleet scans the two worst nodes for the drift point; the fix direction (the number canonical by construction from the pin plus the selected-parent distance, a continuity check at every append, a drift self-check at start, the carrier resolving a record's segment by the block hash it names) in 0.3.21 if the scan names the event in time, else 0.3.22. Per tier: the hub and the five paid boxes are right; seven standing provers earn nothing until their node is restarted on a clean number or the fix lands; a solo miner is untouched. AP-F8-3, THE ROOT OF THE RESIDUAL CLASSES (the hash lane, 15:5x UK; in the attack-pass record c2203b55): accept.rs never runs the latency-shadow block. Its interpreter run_unit was written for class v2 and v3 and executes the 64 base instructions per iteration and nothing after instruction 63, while the hash (verify.rs, the GPU kernels) runs the shadow block 27 times at the end of every iteration. So every dynamic acceptance test on a class v4 program, (c), (c') and the (A) and (B) bounds, judged a program the chain never hashes: the forced equalities and constants that make F8's bands are produced by the shadow's lossy pairs (or r2 |= r1 then or r1 |= r2, the xor swap), which the acceptance never executed. Confirmed on the prepared bounds: p23 at attempt 4 passes (B) at 16,384 and (A) at 2^20 evaluations (492 ms on one box-2 core) because in the shadow-less run its registers are uniform. (c)'s own v4 figures (saturation, bias, distinct addresses) were measured on the wrong program, harmless only because the base program alone is a well-formed v3 program. THE FIX (sub-version 3): run_unit executes the shadow block after instruction 63 of every iteration, reps times with the iteration's sel, exactly as verify.rs does (the shadow holds no load, so its instructions take the same arms); then (B) at 8 repeats over the 16,384 (c) evaluations and (A) the distinct-index floor of 2^19.5 over 2^20 evaluations, both keyed on the v4 shape; (a'), the 256 cap and the last resort unchanged; a new stream and a new acceptance verdict for v4 (new ids and packs), v2 and v3 untouched (their shadow is empty). The known-failed test on p23, p15 and p18 re-runs on box 2 with the shadow executed; its result and the draw-cost line at 2^20 (492 ms per chosen candidate before the shadow, more with it) decide the commit. The attack-pass lane ships a class check beside the fix (the acceptance's program equal to the hash's). Per tier: nothing on the live chain changes (sub-version 1's acceptance is the same shadow-less check and its programs hash exactly as published); the auditor's finding is that class v4's acceptance was checking the wrong program since 6 October, closed in sub-version 3. THE SUB-VERSION 3 BUILD RESULT (the hash lane, box 2, 14:09Z): run_unit now executes the shadow block as the hash does and the test acceptance_executes_the_shadow_block_as_the_verifier_does is green (the acceptance's execution and verify.rs agree on the output bit counts over the 64 units for the devnet epoch-0 program and the six test eras, 8 x 256 x 27 shadow instructions per hash; the same program with its shadow stripped gives different counts, so the two paths cannot diverge silently again). But (A) and (B) do not reach the class even with the shadow executed: F8's exact p23 candidate (attempt 4, id 06263572197875d2, measured at 4.82x) passes (B) at 8 repeats over 16,384 and (A) the 2^19.5 distinct-index floor over 2^20 evaluations (2.08 s on one box-2 core), no low-entropy site. The acceptance now runs the whole program, so the remaining difference from the census is the dataset (the acceptance's seed-keyed closed-form words against the chain's memory-hard items) or the census's consecutive nonces; a band that exists only under the real dataset is outside the reach of any in-acceptance rule unless the acceptance builds the real dataset (a 256 MiB cache fill and a 1 GiB day per candidate: seconds to minutes per attempt). The attack-pass lane localises p23's zero (which iteration, which registers, whether it reproduces on the closed-form dataset; the register history at instruction 38 on the memory-hard day, the closed-form words and random against consecutive nonces), which decides whether the rule is nonce-aware, dataset-aware or structural; neither is a 19:00Z build with a 75-minute census behind it. THE DECISION (the coordinator under main's accepted plan, 16:1x UK): 0.3.21 ships byte 5; sub-version 3 is 0.3.22's. The hash lane commits the shadow fix with the agreement test as sub-version 3's first commit (a new stream, new ids, byte 7 unchanged; AP-F8-2's exhaustion half FIXED-AND-PASSED at 8bdcbdd8 and AP-F8-3 fixed in the ledger entry); (A) and (B) held uncommitted until the localisation lands, with the cost of each form on one line (the dataset-aware form's cache fill per attempt decides it). The node lane and the shipper told: no re-pin and no CLASS_SIGNAL change in 0.3.21; byte 7 reserved for sub-version 3, byte 6 for class v5. Per tier: no miner, pool or chip consequence tonight; the auditor's record carries sub-version 1's 11 of 64, sub-version 2's 8 of 56, AP-F8-2 closed and AP-F8-3 found and fixed, with the uniformity rule open as a named item. THE N15 DRIFT FIX DONE (the node lane, 14:13Z): rides 0.3.21 as two commits after f95178a1, branch numbering-fix on the mirror at d8bceca5 (a6864e36: the chain path's continuity rule, the orphans above the fork point handed to the reorg unwind; d8bceca5: the start-time self-check from the restart pin against the DAG's selected parents, the first break unwound and re-walked, and recordsContinuous and continuityBreak on the status RPCs so a prover claims only on true); the scans named both events (p1-5090's short reorg path at 15:51Z on 6 October, p2-3090-3's inherited snapshot at 21:09Z); two unit tests known-failed first, the exec suite 35 passed, the kaspad check green on build-2 at 14:13Z; the live line is the fleet's restart of the two drifted boxes on the 0.3.21 candidate. Plan 6.9 reads byte 5 with igneum-pow 8c728ca3, no CLASS_SIGNAL change. SUB-VERSION 2's FINAL VERDICT (the attack-pass lane; the 64 seeds p2 to p65 at 2^24 nonces, chain path, window-model control, box 2, 13:10:15Z to about 14:40Z; pairing id a788661687db4bb3): FAIL, 55 of 64 PASS (0.9915x to 1.144x), 9 FAIL.
| Seed | Ratio | Hottest item, reads | Site, instruction, share of the site's reads in the top 0.1 percent | Source |
|---|---|---|---|---|
| p23 | 4.82x | 0x000000, 41,727 | site 7, instruction 38, 9.43 percent | or-then-xor same-operand mask over a mulhi (r6 and not r4) |
| p19 | 3.32x | 0x400000, 28,114 | site 15, instruction 62, 6.64 percent | unchanged from sub-version 1 |
| p15 | 2.57x | 0x000000, 12,313 | site 2, instruction 12, 4.49 percent | |
| p18 | 2.50x | 0x75f0fd, 13,866 | site 6, instruction 30, 5.55 percent | |
| p56 | 2.01x | 0xbeb53c, 6,091 | site 2, instruction 10, 3.34 percent | unattributed |
| p10 | 1.50x | site 8, 2.04 percent | unattributed, identical to sub-version 1 | |
| p8 | 1.38x | site 14, 1.42 percent | unattributed | |
| p34 | 1.25x | site 1, 1.35 percent | ||
| p4 | 1.22x | site 1, 1.45 percent | unattributed, 1.57x on sub-version 1 |
Every failing seed is ONE low-entropy load site; the mechanism is lineage-blind (AP-F8-1's residual) and the acceptance could not see it because it never ran the shadow block (AP-F8-3). SUB-VERSION 3's FIRST COMMIT: ca3-v4-amend ddacfbd3, 14:20:37Z (origin and build, gate GREEN): the acceptance executes the shadow block as the hash does, the test pins it to verify.rs on the seven v4 programs; PROGRAM_SUBVERSION_V4 = 3; byte 7; (A) and (B) held in a stash. Epoch-0 id a785001687d8688a (must-differ c120d7963abdcd96, 1a4230699a6b9c60, a788661687db4bb3; the devnet seed still accepts at attempt 1, so its program is sub-version 2's under the new id); the seven fingerprints unchanged from sub-version 2 for the same reason (e370fb2080b7dbb1, b7237555d31fc3cf, b6b167fa15dfe2c9, 28bdf65eff33f2c4, e26d38c46f3f1b16, dd8fdf6ff4f59eed, 8bf40f5cb858d835; control 90f794dd556f7a3b; Metal = Apple OpenCL 14:18:41 to 14:19:13Z), so the fleet and PC 2 G1s already read them and the G1 on sub-version 3's packs is a re-run of a known result; packs zip packs-ca3-v4-sub3 sha256 4f2445c50c58d76a5544023492d8b858d0b07c5e372d31f9c90c4ce51f829154; the ledger entry carries AP-F8-2's exhaustion half FIXED-AND-PASSED at 8bdcbdd8 and AP-F8-3 fixed here; the suite and the 4,096-seed census at ddacfbd3 on box 2. THE LOCALISATION (the hash lane): p23's band is dataset- and nonce-independent and reproduces in the acceptance's own execution: site 7 (instruction 38) reads r6 after 25 mulhi, 31 or r6 |= r4, 35 xor r6 ^= r4, which is r6 and not r4, an AND mask the lineage rule counts as fresh because the xor's operand is the or's; over 2^20 evaluations on the closed-form words site 7 reads 874,953 distinct word indices against about 1,046,500 at every other site (0.84 of uniform, 2.2 s on one box-2 core); over 2^24, 8,979,203 against about 16,260,000 (0.55, 35 s). THE COST LINES FOR THE SECOND COMMIT (0.3.22): structural (an abstract value class tracking shared operands) 0 s per attempt, this idiom only; the distinct-index ratio at 2^20 2.2 s per chosen candidate; at 2^24 35 s; no dataset-aware form needed (no cache fill). The hash lane's recommendation: the ratio at 2^20 with the threshold set from the clean seeds' per-site spread (p23's site 0.84; every clean site 0.995 to 1.000), plus the structural rule for the idiom so the ratio is a never-firing check on it. The attack-pass lane's verdict: sub-version 3 is the stream to gate and cannot read green by 19:00Z; byte 5 for 0.3.21 stands on its evidence. THE THRESHOLD NUMBERS FOR SUB-VERSION 3's SECOND COMMIT (the hash lane, box 2, the per-site distinct-index ratio over 2^20 evaluations against the window expectation N minus N^2 / 2W, on the 64 F8 programs as ddacfbd3 draws them, 2.8 s per seed on one core, all sixteen sites): the 55 clean seeds' per-seed minimum 0.9962 to 1.0000 (median 0.9999); over all 880 clean site rows min 0.9960, p1 0.9990, p5 1.0000, median 1.0000. The nine failing seeds' minimum site: p23 0.8361 (site 7), p18 0.9274 (site 6), p19 0.9335 (site 15), p15 0.9432 (site 2), p56 0.9654 (site 2); then p34 0.9927, p4 0.9961, p8 0.9963, p10 0.9963. A threshold of 0.98 sits 0.016 under the clean minimum and 0.015 over the strong five's maximum and rejects exactly those five; the weak four (1.22x to 1.50x in F8's gate) sit inside the clean spread at 2^20 and no threshold reaches them without rejecting clean seeds; a 2^24 run (35 s per candidate) on the weak four, p23 and five clean seeds measures whether they separate there (p23 went 0.84 to 0.55). The structural rule is in and bites where the band was: with the shared-operand relation tracked in the draw and in (a'), p23's attempt 1 draws site 7 from r5 instead of r6 (the or-then-xor on r4 marked r6 lossy); the devnet seed still accepts at attempt 1 (id unchanged); the (a') fixpoint carries the relation. THE COORDINATOR'S LINE: decide by the 2^24 lines: if they separate the weak four from the clean seeds with a gap at least the 2^20 gap, commit (iii), the 2^20 ratio at 0.98 always plus the 2^24 ratio only when the 2^20 per-seed minimum sits under a band edge set from the clean p1 with margin (0.999 fires it on about 1 percent of clean candidates, 35 s once an hour on a node); otherwise commit (i), the 2^20 ratio at 0.98, and name the weak four (p4, p8, p10, p34) as the open tail in the ledger and the commit, unattributed-and-chased, not absorbed. SUB-VERSION 3's SECOND COMMIT: ca3-v4-amend 017e7037 (017e70376489251e18564c0abce7e466e606c8b3; origin and build; gate GREEN; CI run 37639406567 queued), choice (i) by the 2^24 lines: 2^24 does not separate the weak four from the clean seeds (weak p34 0.9181, p4 0.9614, p8 0.9630, p10 0.9612; clean p44 0.9612, p52 0.9613, p3 0.9971, p2 1.0004, p5 1.0004; p23's chain attempt 1 1.0004), two clean seeds sitting on the weak four's value, so any 2^24 floor that reaches them rejects clean seeds. Committed: the per-site distinct-index ratio at 0.98 over 2^20 alone (ACCEPT_UNITS_DISTINCT_V4 = 4096, MIN_DISTINCT_RATIO_V4 = 0.98; expectation per site N minus N^2/2W, window 2^28 >> min(win, 2), the shadow executed), no 2^24 stage, (B) unwired; the structural shared-operand rule in the draw and in (a'); the open tail named in the ledger and the commit: p4, p8, p10, p34 (0.9927 to 0.9963 at 2^20), unattributed and chased.
| Threshold line | Value |
|---|---|
| Floor at 2^20 | 0.98 |
| Clean minimum over the 55 clean seeds' 880 site rows | 0.9960 (p1 0.9990, median 1.0000) |
| Strong five | p23 0.8361, p18 0.9274, p19 0.9335, p15 0.9432, p56 0.9654 |
| Margin | 0.015 to each side |
| Cost per chosen candidate | one 2^20 pass, 2.1 to 2.2 s on one box-2 core, once an hour on a node |
Known-failed test class_v4_distinct_ratio_rejects_the_low_entropy_band green on box 2 (12.95 s): p15 attempt 3 (52638ea2e8b0fd68) site 2 at 0.943; p18 attempt 2 (9a37e9489d8ba698) site 6 at 0.927; p19 attempt 0 (79d7441de0689223) site 15 at 0.933; p56 attempt 2 (486a8ad2701ec3b5) site 2 at 0.965; p23 attempt 1 (d65122675f16a1c7) draws site 7 from r5 and passes, and with r6 put back is refused by (a') UnfreshLoadSource and, run anyway, by the ratio at 0.836. Stream unchanged from ddacfbd3 (re-export diff 0 on all eight packs): id a785001687d8688a, the seven fingerprints and the packs zip sha256 4f2445c5... as recorded. THE SUITE AT 017e7037 on box 2: 103 of 103 (64 lib + 7 derive + 4 mixer + 19 packs + 2 recheck + 7 scratch, 3 diag ignored), rc 0; the lib tests 140.8 s against the 41 s whole-suite line at ddacfbd3, because every class v4 draw in the tests pays the 2^20 ratio pass on its chosen candidate (2.2 s each): a CI-time cost, not a node cost (one pass per epoch draw). CI run 37639406567 on 017e7037 success. THE CENSUS AT 017e7037 (box 2, 4,096 chain-shaped seeds plus F8's p1 to p3, draws in parallel across the cores; tools/ca3-v4-uniform now draws across available_parallelism since the serial run became a four-hour job): 4,099 programs, 0 lossy-sourced load sites of 65,584 (57,322 injecting, 8,262 bijective), 0 exhaustions; attempt histogram 0:1297 1:899 2:609 3:416 4:298 5:197 6:125 7:92 8:54 9:46 10:21 11:14 12:13 13:9 14:6 16:2 17:1, mean 2.086, max 17 (ddacfbd3 read 1328/917/622/409/284..., mean 1.998, max 17): the ratio refuses about 4 percent of candidates that pass every other test, one extra attempt on about one seed in twelve, the worst case unchanged at 17; devnet epoch-0 at attempt 1, id a785001687d8688a; F8's p2 attempt 5, p3 attempt 1. The attack-pass lane's class check: ddacfbd3's shadow-executed verdicts against 8bdcbdd8 on 598,678 chain-shaped seeds move 11,990 (2.0 percent) to a different attempt, 0 exhausted, max 32; on 017e7037 the pairing holds and the 64-seed gate at 2^24 plus the 10^6 exhaustion count run to about 16:05Z. The hash lane's ledger lines 2a111fb1 on origin and build (the GitHub 500s cleared on their own), CI run 37642582140 success at 15:25Z; the hash lane has nothing in flight. Nothing on the hash side stops a cut of sub-version 3 at 017e7037 for 0.3.22; then the attack-pass lane's 64-seed gate at 2^24 and 10^6 exhaustion count. Owed as before: G2, G3, the ladder re-measure, AMD (PC 1), the 2019-class core, the fleet and PC 2 G1 on the sub-version 3 packs (a re-run of a known result). release-0.3.21-node STAGED (the node lane, 16:0xZ): 96161037 on the mirror, at the shipper's sweep-end word, in the final order on 55768f88 (c631c64b, 52e96c94, f067f7c1, b0444f51, 437f0438, 2e32d5f6, f95178a1 cherry-picked, a6864e36 and d8bceca5), pairing igneum-pow 8c728ca3 at byte 5, no re-pin. The whole set on the tip green: consensus-core 126, the consensus crate whole (lib 120, both integration targets), igneum-miner 25, kaspa-pow 17, igneum-exec 36, the three checks, 15:49 to 15:57Z on build-2. Binary built on build-1 at 15:58Z, igneumd sha256 f99340b3cf4ce32e, the string read back; the digest eada4bda on the previous live object and 4bbbe816 on the published floor file (so the 0.3.20 floor file is published), as the pin reads them. The node lane's digest and mixed-version gates on it from 16:00Z; the fleet's set from the same minute; plan 6.9 carries the steps and the two box-input rules the staging added. THE 0.3.20 RECORD (the shipper, UTC). Cases: the dc141409 run on c18-1 CASES END rc 0 at 12:37:18Z (both halves PASS); the c4459193 run on c20-1 CASES END rc 0 at 14:54:02Z with its relay half void (one RunPod host, no hairpin) and the poison half PASS (13 rejected, 0 accepted); main's (b): the publish on the dc141409 cases plus the diff argument (the class byte the only touch in the cases' territory) and c19-1's tip-following, with the separate-host relay re-run on c19-1 on the live digest as the halt condition and the Discord card's gate (CASES END about 16:25Z). PUBLISH 14:54:17Z (15:54 BST): manifest 0.3.20, mac DMG sha256 73796c5f..., Windows installer 45b2f3fb..., the hive tar d9dd12df... on the public alias. THE FLOOR FILE: program_class_v4_activation_daa 900,000 (the live DAA 294,073 at 14:51Z; 294,073 + 604,800 = 898,873 rounded up to the 3,600 boundary), window 86,400 unchanged, file sha256 294f1f80...; the digest 4bbbe8162ea9fff277aa5b16b4ffad9e2262ba5e6a5acac7b697ff77211e7328 read on c4459193's binary before the cut and on the hub's handshake line after. The pin c4459193, igneum-pow 8c728ca3, byte 5; the sweep's node pair a80ed39c / 70a5180f (the build-server lane's native build of the same tree). THE SWEEP complete 15:39Z (16:39 BST): wave 1 the hands (observer-node, node1 at 14:57Z), the Mac (15:23Z on its poller, interface 1.0.1), the hub, pool-1 and the eight heaviest voters (15:04 to 15:21Z); wave 2 the four lighter voters (15:23 to 15:26Z); wave 3 Devnet 2's four pods and bps-seed (digest 4a0b8726 unmoved); the first new-side lock 9313 at 15:28:08Z after a 23-minute split; every lock line "sweep complete before 13 October 09:00 UK (the margin; the floor is now DAA 900,000)". 0.3.17 nodes remaining: PC 1 and PC 2 (offline for the project lead's cable work; their apps update on their pollers on return) and the three testnet seeds (on the testnet, not on the devnet's floor); no devnet node of the fleet, the hands or the Mac on 0.3.17. EARLIEST FLIP: the floor at DAA 900,000 is about 7.0 days of DAA from the publish (605,927 DAA at about one a second), so about 14 October 23:00Z (15 October 00:00 BST) at the earliest, and only once the seven 86,400-DAA windows read 95 percent of blue weight signalling byte 5; the live floor of 831,600 (13 Oct 08:00Z) is replaced by the published file on every swept node, so the chain never flips to the 6 October stream. Per tier: a solo miner on the Mac or a swept box mines on; a PC miner on 0.3.17 is refused by digest when it next connects until its app updates (its poller does this on return; nothing by hand); the pool and the hub are on the pin; the auditor reads one object, one digest, one floor.
SUB-VERSION 3 PASSES BOTH GATES (the attack-pass lane, the close line dated 7 October 2026): class v4 sub-version 3, commit 017e70376489251e18564c0abce7e466e606c8b3 on ca3-v4-amend, pairing id a785001687d8688a (verified by the harness). F8's 64-seed census (p2 to p65) at 2^24 nonces each, chain path, window-model control, box 2, 14:51Z to 16:00:20Z: PASS, 60 of 64 under 1.2x (0.9915x to 1.144x); the only four over are the named tail, unattributed and chased: p10 1.5036x (identical to sub-versions 1 and 2, hottest item 0x4004da at 362 reads, no predicted source), p8 1.3776x (0x837de4, 420 reads), p34 1.2505x (0x800010, 541 reads, the one-bit value through sub at 5), p4 1.2167x (0x4000e7, 355 reads); every strong seed gone (p23 4.82x, p19 3.32x, p15 2.57x, p18 2.50x, p56 2.01x all under 1.2x); the worst ratio on the stream 1.50x; the tail's hottest items carry 355 to 541 reads of 2^31 (one to two per 2^22 items above the mean), no chip consequence. The exhaustion gate as it is: the chain-path count on 017e7037 runs slowly (the draw evaluates (c'') at 2^20 per candidate: 20,532 seeds in 59 minutes, 0 exhausted, 0 panics, max attempt 29), so a 10^6 count is two days away and is not waited on; the substance is met by construction (the 256 cap and the last resort unchanged from 8bdcbdd8, 0 of 10^6 there) and by measurement at 017e7037 on 24,631 seeds (0 exhausted, max 29; r about 0.68); the count runs on as a strengthening line. The node's epoch draw now costs about 2 attempts at 2.2 s each, 4 to 5 s per epoch on slower cores, once an hour. The hash lane's ledger at 6941da1d. SUB-VERSION 3 AT 017e7037 IS THE FROZEN GENERATOR FOR 0.3.22 (byte 7), THE TAIL RULED (main, 18:1x UK): the four seeds (p10 1.5036x with its hottest item at 362 reads, p8 1.3776x at 420, p34 1.2505x at 541, p4 1.2167x at 355, of 2^31 reads) are accepted as the window model's unattributed residue at 1.22x to 1.50x with nil chip consequence; the AP-F8-1 row CLOSES with that wording and the hottest-item counts beside it; the 10^6 count on 017e7037 runs on as the strengthening line. The attack-pass plan's start 15 October or the morning after. 0.3.21's FIRST CANDIDATE 96161037 (sha256 f99340b3cf4ce32e, string read back) passed the node lane's two gates on its own binary: the digest gate 15:59:54Z to 16:01:32Z PASS (a89be8a7 with the peers right; db9a85f9 refused, no peer); the mixed-version gate 16:01:53Z to 16:12:05Z PASS (one digest b0afb2ee on five; 252 new and 352 old accepted, 0 rejected; counts equal at 316, 493 and 604 through both clean joins and the restart step; no panic); the node side complete; the fleet's set on the same binary (the kept start with the ids gate, the wipe canary, the cases rerun, the 12 GB line, N15's restarts of p1-5090 and p2-3090-3) is what the shipper's pin word waits on; byte 5 throughout, nothing on the class v4 seam moved. DEVNET 3 NOW (the project lead through main, 17:3x BST): 0.3.22 is the Devnet 3 release (a fresh network object igneum-devnet-3 with every activation at 0 and no override file, the era VDF fork, class v4 sub-version 3 at byte 7 from genesis), the node building on build-1, genesis by 17:30Z (18:30 BST). THE HANDOFF (17:3x BST, inside the 17:40 BST line, to the shipper and the node lane): igneum-pow 017e70376489251e18564c0abce7e466e606c8b3 (the audit-freeze-2026-10-07 tag; 2a111fb1 and 6941da1d above it docs only), object byte 7, PROGRAM_SUBVERSION_V4 = 3, devnet epoch-0 program id a785001687d8688a (must-differ c120d7963abdcd96, 1a4230699a6b9c60, a788661687db4bb3), kit packs-ca3-v4-sub3 zip sha256 4f2445c50c58d76a5544023492d8b858d0b07c5e372d31f9c90c4ce51f829154, the eight fingerprints as recorded (equal on Metal, Apple OpenCL, the fleet 5090 and PC 2's 5090), both attack-pass gates GREEN, suite 103 of 103, CI success; the open items stated as open: the four-seed tail under main's ruling (the attribution for 0.3.23), the 10^6 count as a strengthening line, the 4 to 5 s epoch draw, the owed measurements that do not gate Devnet 3. NO FURTHER HASH CHANGE RIDES ON 0.3.22; anything from the tail goes to 0.3.23. The node lane stages the re-pin on the 0.3.21 tip as its own commit (the fork commit and the kaspa-pow suite line owed to this record); the hash lane's sub-version 3 pairing follows it. THE PUBLIC CHIP TEXT REWRITTEN LAUNCH-FIRST (the project lead: "I thought we were making it 2.1 from launch?"; master 9b996d06, docs/plans/counter-asic-3-public-text-2026-10-07.md): the testnet and mainnet objects set program_class_v4_activation_daa 0, so class v4 is live from genesis and the launch number is 2.1x to 3.9x on day one; the three texts and evidence row 17 lead with that (labels kept), then class v5, then the 5x to 9x only as the class v3 baseline the work started from, the devnet's activation height a devnet fact only; no em dashes, no prize mention, eight columns; with the site lane to apply in the same deploy as the padding sweep (its commit and deploy time owed to this record). STOP-THE-LINE ON MASTER's POW SUITE (main through the CI steward, 18:4x BST): red since 16:31 BST (runs a4eaf76 and 1210158d; program_ids_differ_between_class_v3_and_class_v4_of_one_seed and cpu_recheck_equals_the_worker_reference_for_class_v3_and_class_v4 fail on packs-ca3-v4/v4-devnet-epoch0) because era-vdf's merge 0e2d6b1c put the sub-version 1 line's generator on master against tests/recheck.rs's pins, never CI-run. Ruling: the hash lane merges ca3-v4-amend's tip 6941da1d to master through merge-to-master.sh within 15 minutes, provided its epoch-0 id equals the frozen object's; the coordinator verified the condition (6941da1d's igneum-pow byte-identical to 017e7037; recheck pins 0xa785_0016_87d8_688a with the three must-differ ids; PROGRAM_SUBVERSION_V4 = 3), so no revert; master is the 0.3.23 line after this, 0.3.22 keeps its pin at 017e7037. EXECUTED: ca3-v4-amend on master as merge cf7d6ccb (pushed 16:45:48Z through merge-to-master.sh, try 1; the branch gate GREEN, 55 checks in 317 s on 874e945d; master ac8ed2f1 merged into the branch first with docs/fud-ledger.md keeping both sides and igneum-pow taken wholesale from 6941da1d, byte-identical to 017e7037); master's CI run 37654633279 on cf7d6ccb in progress from 16:46:10Z, the pow job's conclusion owed. Master's igneum-pow is now the frozen sub-version 3 generator. THE 0.3.22 RE-PIN STAGED (the node lane, 16:38Z): fork commit bd710a36 on release-0.3.22-node (igneum-pow 017e7037 archived beside the fork as igneum-pow-amend, byte 7, epoch-0 id a785001687d8688a must-equal, the three must-differ ids, PROGRAM_SUBVERSION_V4 read as 3); the line's candidate fa7f854f (the re-pin, the era VDF merge f2ecf452, the igneum-devnet-3 object with program_class_v4_activation_daa 0 and a one-day signal window, so byte 7 is stamped and hashed from genesis); the kaspa-pow suite on build-2 from 16:38Z, its line owed; the hash lane has the commit for its pairing run. THE kaspa-pow SUITE ON THE 0.3.22 CANDIDATE 21d8f454 (build-2, 16:47:10Z): GREEN 17 of 17; the pairing test reads PROGRAM_SUBVERSION_V4 = 3, epoch-0 id a785001687d8688a, the three must-differ ids hold, the chain draw at attempt 1 against class v3's 0 on the test header; the candidate's digest for igneum-devnet-3 ab9af79f...ed23; the node stamps object 7 (block version 1794) from genesis. MASTER GREEN ON THE POW FIX: CI run 37654633279 on cf7d6ccb success at 16:54:51Z, the igneum-pow job success; master's igneum-pow the frozen 017e7037 byte for byte; build-1's amend checkout synced to 874e945d (its packs-ca3-v4 carries the sub-version 3 kit). THE CHIP TEXTS LIVE (the site lane, site-ui-5): sections 1 to 4 applied verbatim in b34d1932, master cc593483, live on igneum.network at 16:47Z (home row 03 "under class v4 from the first block"; /litepaper#chip-model the new paragraph and the reordered table with the class v3 row last; /miner the new line; /evidence row 17 "2.1x (k = 1) to 3.9x" in eight columns); the litepaper's abstract rewritten launch-first too; tools/ci/ledger-text-check.mjs X35 asserts the launch-first sentence on the home page and "so the launch number is the class v4 row" on the litepaper; no prize mention. /claims (the litepaper's limits section) rewritten launch-first by the coordinator in the litepaper's chip bullet (2.1x to 3.9x under class v4 from the first block with its labels, class v5, then the class v3 baseline "never the launch state", the recompute chip under 1x, the X9 history), /claims rebuilt from it, the ledger text check 61 of 61, the padding and overlap sweeps green in the 56-check gate, master 0a999646 at 17:01:47Z. DEVNET 3's FIRST GO (the fleet lane): dn3-g1 on 21d8f454 up 16:50:21Z from an empty datadir, digest ab9af79f matching the build-1 read, genesis a6fa348e executed (chain id 4463), object 7 / block version 1794, era VDF from DAA 0, no override file, mining from 16:50:42Z; the dn3_ observer running since 16:38:29Z; DN3_GO_DATE=2026-10-07 in /srv/hands/dn3/dn3.env, the hash-origin timer's first dn3_ report 8 October 08:30Z. BUT NO BLOCK ACCEPTED: dn3-g1 refuses every block its miner finds with "the block timestamp is too far into the future: block timestamp is 1791417600001 but maximum timestamp allowed is 1791392281213" (16:57:51Z): 1791417600001 ms = 2026-10-08T00:00:00.001Z, the template stamping genesis + 1 ms, so the igneum-devnet-3 genesis object carries 8 October 00:00Z, one day after the intended 7 October 00:00Z; every block is seven hours in the future and refused before PoW on any node with any miner or pack; the pack is not the suspect (the node draws the epoch's program under its own igneum-pow and hands the pack to the worker; the exported kit is for G1 and recheck only). The fix is the node lane's (a past genesis timestamp, moving the genesis hash and the digest) and a rebuild; the fleet reruns the go within the minute of the new pair; if the corrected build lands by about 17:20Z the pair lock is about 17:35Z (18:35 BST). Spend at 17:00Z about USD 410 of 1,000. GITHUB SUSPENDED (17:0xZ): every push to origin refused with "Your account is suspended" (403); the API reads 404 for the user igneum-labs and the repo (the shape of a suspended account, not a revoked token); with the project lead (the ticket route given by main); until GitHub answers, every lane pushes to the build-1 mirror (/srv/igneum.git over ssh) and the mirror is the record, merges landing through the box gate stamp under the shipper's exception window. This branch is on the mirror at a33a7859 (17:09Z); master's last origin landing 0a999646 (17:01:47Z). DEVNET 3 MINES (the fleet lane, 17:08Z): dn3-g1 on the corrected candidate 69d1b56e (genesis 7 October 00:00Z, hash 4020cb43..., digest 83eb50cdf2eda4cb...) accepted its first block at 17:06:19.920Z, 3 blocks by 17:06:44Z, 0 rejected; dn3-g2 joining, the pair's first common lock about 17:15Z (18:15 BST), then the late joiner and the canary's ten minutes; the hands pair for 69d1b56e landed 17:05:54Z, the shipper ruling whether the genesis bytes are the node lane's or the hands'. Per tier: the first chain that hashes class v4 sub-version 3 (byte 7) from genesis is live on the fleet; the launch-first chip texts describe it exactly. DEVNET 3's EPOCH-0 PROGRAM ID (the node lane): fce15bf61030be57 on igneum-devnet-3 (genesis 4020cb43...b925), read in the 0.3.22 miner's "cache ready" line on build-1 at 17:10:39Z and on dn3-g1 at 17:12Z, the node accepting 85 of 85 GPU blocks; a785001687d8688a stays the shared devnet's epoch-0 id (genesis edc4fa84) and the kaspa-pow pairing pin; the pairing is unchanged, the id follows the seed; the fleet's pack-id gate reads fce15bf61030be57 at epoch 0 and the node's per-epoch value after; the exported kit's eight packs are the shared devnet's seeds, so a Devnet 3 kit, if the hive wants one, is a re-export over 4020cb43's seeds (the hash lane's, on request). DEVNET 3's PAIR AGREES (the fleet lane, 17:19Z): dn3-g2 up 17:17:58Z on the same bytes, digest and genesis, synced from dn3-g1 and mining from 17:18:15Z; the pair agrees on every determined finality checkpoint (20, 21, 22 on identical blocks in both logs); 702 blocks, 0 rejected on either, by 17:19:08Z. The first LOCK lands about 19:10Z (20:10 BST): the object's finality window is 7,200 DAA ("window filling, 681 of 7200") at about 1 block/s, the object as cut, nothing wrong. Two independent nodes agree on the chain since 17:18Z; finality signatures start two hours in; the hash-origin daily (dn3_ tables, DN3_GO_DATE 2026-10-07) counts from today once the observer units are enabled on the shipper's go. The shipper rules whether the genesis is declared on the pair's agreement or on the first lock; the late joiner, the empty-datadir canary (ten minutes) and the spare placing on the hands pair; the standing boxes' second nodes after the joiners on the shipper's word. Spend 17:20Z about USD 412 of 1,000. GITHUB RULE (main through the shipper, 18:02 BST): no push, fetch or poll of GitHub from this lane or its sub-lanes, not even a retry; the box mirror on build-1 and build-2 is origin and the box gate stamp the verdict until it lifts. DEVNET 3's EPOCH-0 PACK EXPORTED (the hash lane): program.json 0xfce15bf61030be57, attempt 0, sub_version 3 (dn3-g1 drew the export path's seed); igneum-pow at 874e945d (byte-identical to 017e7037 and master's), --epoch-hex and --era-hex the genesis 4020cb43...b925, class mx8-eraaf3a9139+sh256x27, day bytes "igneum-day/" || le64(20733) (the chain's rule day = timestamp_ms / 86,400,000; the program and id day-independent, the dataset and fingerprint rolling with the UTC day); Metal fingerprint e510ad92b4d24846 at 2^24 from base 0, Apple OpenCL equal, vectors 3 of 3; on build-1 /srv/artefacts/packs/v4-devnet3-epoch0/ and .zip sha256 e025750f71175ed14d6e2a24e387ebbf1979b1cd0faee9139c41a7671165b334, the sub3 kit zip beside it (4f2445c5...); in the 0.3.22 hive package order with the kit. [user]'S THREE ORDERS (through main, 18:3x BST), with his correction (18:4x BST: everything in-house, nothing external): (1) BUILD CLASS V5 NOW on the 0.3.23 line (program class v5, its own activation height, object byte 6): the generator and verifier in igneum-pow (+0.2 ms per warp against the 10 ms gate), the node side (the state commitment into the dataset derivation, the stateless/stale-chip rule known-failed first on a stale dataset), the hot-set, weak-day and shadow-redundancy rules routed to this class, the attack-pass families re-run on v5, the kit for Metal, CUDA, OpenCL/AMD and Intel with fingerprints equal, the crossing on Devnet 3 by height after its gate, miner cost rows per card; the v5 lane resumed with the order, owing tonight the design-to-code gap in one list and a UTC clock for the first v5 pack. (2) CRYPTANALYSIS IN-HOUSE: no outside firms, no paid lots, no briefs to anyone; the three targets (the mixer M_r, the chained cache, the acceptance rule) attacked by three adversarial lanes that have never worked on the hash code, each given only an outsider's inputs (the public kit, the frozen object, the spec, the attack-pass harnesses), a written attack plan first, a budget of box hours, a report in the attack-pass shape (the claimed break or the bound reached, reproducible); the Counter ASIC lane the defender, main ruling disputes; plans within two hours, first results by tomorrow evening; a coordinator lane spawned for it (docs/plans/cryptanalysis/in-house-pass.md, funding.md's lots rewritten to the internal pass). The served sentence "the cryptanalysis plan buys three external lots" rewritten on the litepaper, /claims and evidence row 17 to the internal adversarial pass, labelled internal, the one outside check staged on its escrow and the publish word (the served text never names the prize or the project lead, by the forbidden-strings gate). (3) OWED MEASUREMENTS on PC 1: released tonight after the shipper's 0.3.21 host build (the line "PC 1 released" about 18:05Z, the window to 17:30Z on 8 October, an elevated job allowed under the standing rules); the hash lane prepares the three job files on the sub-version 3 kit (the 9070 XT G1 and ladder rows, item 6's step costs on AMD, the 5090 clock rows elevated, dr736 if it fits), published one at a time on the coordinator's relay of the line, --cards-off on the measured card alone, the desk left usable; the rows land in the public table with their labels. Nothing in (1) or (3) reaches outside the fleet, the boxes and the PCs. DEVNET 3's PROOF WINDOW OPENED 17:57:05Z (the fleet lane): coverage from 17:44:23Z (dn3-x1, an RTX 3060 12 GB, the sm_86 SP1 floor, from DAA 0; the first segment 1024..1031 submitted 17:45:49Z, 86.1 s end to end); the first records PAID by dn3-x1's key, segments 1256..1263 (0.7036 IGN) and 1272..1279 (1.5993 IGN) in block 1403, paidShards 10 at 17:57Z; the 24 hours run to 17:57Z on 8 October; sizing: a 3060 proves a segment in 84 to 86 s (about 42 an hour) against 450 segments an hour at 1 block/s, 11 cards for a share of one, 15 placed (14 more 3060 12 GB pods on distinct Vast machines, USD 1.07/h together); a runbook rule found: a Devnet 3 block builder carries a proof record only after its own node verified it, so every Devnet 3 miner node needs IGNEUM_PROOF_VERIFIER on the host verifier (the four miners ran bare for 11 minutes, 72 records pending and 0 carried; dn3-j1 restarted with it at 17:54:37Z and carried the first). THE UTILISATION TABLE (the fleet lane, 18:00Z, for the project lead): 36 rented boxes plus the Hetzner seed, 37 GPUs, USD 197 a day at this size, today's total about USD 432 of 1,000; idle in the hour 12 by the letter, 9 of them Devnet 3 boxes rented in the last 15 minutes and syncing, 3 the 0.3.21 warm set standing between windows; the fleet's recommendation: stop Devnet 2's four boxes (USD 59.76 a day; Devnet 3 is now the staging chain) on the shipper's word, fold the 0.3.21 warm set (USD 12.72 a day) into Devnet 3's relay trio when 0.3.21's last line closes. THE PUBLIC BENCH TABLE (main's order): /miners now carries every measured card, 37 rows, with watts, MH per watt, the class v4 cost per card and the tuned state (the 5090 stock 136.1 MH/s at 350 W and tuned 127.71 at 226.8 W; the 4070 at its tune point; the 9070 XT, the M5 Max (no lever), the 5060 Ti, the Arc B580, and the fleet's rented-card sweep of 7 October: the 5080 71.16 at 143.4 W, the H100 248.70 at 385.6 W, the B200 416.35 at 855.6 W, the 4090 hands row 52.25 at 183.1 W, down to the 4060 Ti 20.10 at 77.5 W; every fleet row stock, bench only, labelled measured by the fleet or reported by the fleet). CLASS V5's DESIGN-TO-CODE GAP (the v5 lane, 19:00 UK; section 13 of docs/design/class-v5-stored-state.md at c17bc04b): igneum-pow's class v5 rebased onto the frozen sub-version 3 (v5 and its rungs draw under (a'), (c''), the shared-operand rule, the 256 cap and the last resort by merge); the fork rebased onto release-0.3.23-node with class v5 pinned to object byte 6 counted EXACTLY (byte 7 is v4 sub-version 3; the bytes are no longer ordered by class); the gap about 40 agent hours (17 the v5 lane's): the +0.2 ms per warp on the Mac (1 h), the AP-F4-1 and AP-F1-1 rules with their known-failed cases (3 h each), the attack-pass families on the v5 stream (4 h), the kits (Metal and CUDA hosts uploading leaves.bin, 2 h each; OpenCL/AMD and Intel 3 h), G1 on the 5090 and the Mac (2 h), the Devnet 3 crossing by height (3 h), the miner cost rows (3 h), the snapshot wire's day streams (3 h), the pool's per-epoch state fetch (2 h), the proof witness (4 h), the spec text (2 h); the first v5 pack's clock (Devnet 3's genesis as epoch and era seed, day 20,733) follows the suite and the day-stream bin. THE IN-HOUSE ADVERSARIAL PASS (the crypto lane, 19:05 UK): crypto-engage deb0011e on the mirror; docs/plans/cryptanalysis/in-house-pass.md (outsider inputs and withheld files, the three lanes, the budget 8 box-hours each and 24 total with a ceiling of 48 on the coordinator's word, the review roles, the clock, the label rule); funding.md's lots rewritten to the internal pass with no cash row and every firm name removed; the three lanes adv-mixer, adv-cache and adv-accept spawned 19:1x UK with outsider-only inputs, plans due 21:10 UK, first results by 18:00 UK on 8 October; the Devnet 3 epoch-0 pack added to their inputs. THE PC 1 QUEUE PREPARED (the hash lane, c1a1f1d7, nothing published): the kit fetch (zip sha256 1d441f5a..., the 8 sub-version 3 packs plus the ladder packs sh256x13/27/53/88 and sh64x52); the class v4 efficiency pass on the 5090 (elevated, --cards-off, a 17-step clock-lock grid from unlocked to 1,400 MHz with the four Ember caps on it, v4 then v3 at each step for about 60 s, the fingerprint on every step, nvidia-smi at 1 Hz, -rgc in finally; nvidia-smi has no voltage-offset lever, the lock walks the driver's V/F curve; about 40 minutes; the owed 5090 clock rows subsumed); the same on the 5080 (its unlocked row the stock point against the fleet's 71.16 MH/s); G1 on the 13 packs and the AMD ladder rows on the 9070 XT (the ladder packs' Mac fingerprints sh256x13 ff8f707210659eb1, sh256x27 892b6d55a7ddcfcb, sh256x53 663c73c61f62cc54, sh256x88 ec7ca430a061fa59, sh64x52 9dd010f79d8ca9f4); item 6's step costs on AMD (run e); the 5080 full Ember Tune (not elevated, the Power Helper carries the rights); the 9070 XT tune pass (the tune_line before and after on RESULT lines); dr736 not in the queue (its packs are not in this tree). The protocol: each exit line to the shipper, the next published on its ack, the shipper's "PC 1 released" line (after the 0.3.21 window host build) opens the queue. [user]'S STANDING RULE (through main, 19:1x UK): no gaps between tasks, the builders run continuously, no lane idle while another has queued work; the Counter lane reports exceptions and clock readings only. [user]'S WORD ON CLASS V5 AND THE CRYPTANALYSIS (19:2x UK): push both tonight. Class v5 split across six parallel lanes: (a) the v5 lane, the generator and verifier with the verifier cost against the 10 ms gate (the first v5 pack cut 18:06:39Z on build-1 under igneum-pow b4059975: Devnet 3's genesis as epoch and era seed, day 20,733, the genesis state's 11 leaves under state root 7e37a9fb19b154d32daf5bf30a50d339a75029fbc9eec9ea20e95439dba5a311, generator 5 attempt 0, program id e5a4ac5978462156, Metal fingerprint 82b19cbde8557ea5 at 2^24 from base 0 on the M5 Max at 18:07Z, the three vector warps bit-exact, the cache FNV 7334fa46e5d972eb, 70 unit tests green, the v5 chain draw equal to the amended v4's instruction for instruction; the pack proto-cuda/packs-ca3-v5/v5-dn3-epoch0 with state.igsd1 and leaves.bin); (b) the node lane, the state commitment into the dataset derivation and the stale-dataset test known-failed first, the digest-compat fields, the day streams, the proof witness; (c) a new kits lane, Metal, CUDA, OpenCL/AMD and Intel with fingerprints equal and a kit zip on build-1; (d) the attack-pass lane, F1, F4, F8 at 2^24 and F9 on the v5 stream on both boxes (held for main's own line to it, since it takes tasking from main only); (e) a new fast-time lane, the ladder climb plus the v5 crossing with a stale node, the digest-compat and the restart cases; (f) the shipper and the node lane, the Devnet 3 crossing as class v5 by activation height on the 0.3.23 node with the apps' kits in the same release, every gate kept; the target the v5 crossing on Devnet 3 tonight, the clock a reading when (b)'s fork draws e5a4ac5978462156 for Devnet 3's epoch 0 and (e)'s cases pass. The cryptanalysis: the lanes tripled (three per target on different question classes), CPU and GPU pods rented within the fleet's ceiling through the fleet's warm-pod shape, the sweeps back to back, first results by 23:00Z (00:00 BST) with the box-hours and pod-hours spent and the bound reached stated honestly (the crypto lane's rule set at crypto-engage 921ea607 carries the no-gaps rule). THE EVENING's EXCEPTIONS AND PLACEMENT (19:2x to 19:5x UK): build-2's mirror master was stale (a4bca198, without the pow fix) until the hash lane fast-forwarded it to build-1's 001e32ec at 18:25:42Z; the three adversarial branches cut from the stale tip are ordered to merge build-1's master before any run or report (master's igneum-pow 017e7037 byte for byte on both mirrors). the project lead's read: build-1 at 11 percent CPU, build-2 at 56; the word both to near max, the lease pool to about 88 cores a box; the cryptanalysis sweeps, the attack-pass family runs on v5 and the v5 kit builds placed on build-1 explicitly, back to back, both boxes above 80 percent until the queues empty. The cryptanalysis tripled: seven of nine lanes running (the three originals re-scoped to one question class each, plus mixer day-key, mixer statistical distinguisher, cache hot-set, acceptance header-grinding); adv-cache-3 (chain-break) and adv-accept-3 (draw exhaustion) blocked by the session's 20-concurrent-subagent cap (only the project lead raises CLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS), re-spawned as slots free; plans by 20:25 and 21:10 BST, first results by 00:00 BST; the sweep queue on build-2 live. Pods: no CPU-only pod type exists, and the fleet lane rents none for the pass until the project lead's word reaches it on its own channel; the boxes' idle cores at nice 10 carry the sweeps; adv-accept-2's GPU locality row stays an analytic bound tonight. MAIN's RULINGS (20:0x UK): pods cleared, the fleet lane holding the project lead's word with a USD 200 cap for the pass tonight, each request as purpose, lane, hours and pod type, adv-accept-2's GPU locality row first; the 20-concurrent cap stays (the Mac crashed under agent load this morning; the standing rule keeps running agents near ten), the two unspawned lanes take slots as they free and their questions queue as sweeps on the boxes meanwhile. PC 1: released 18:04:37Z, the kit fetch landed 18:16:36Z, the MSVC host built and off; main's word 19:5x UK: publish the class v4 efficiency pass this minute, then the queue in order. A SHARED-DEVNET FACT FROM THE FLEET (not this lane's, with the shipper and the infra lane): the Hetzner live seed 188.245.5.161:26611 is still on the old override object (digest eada4bda) 1 h 40 min after the 0.3.20 sweep (the fleet never touches Hetzner nodes, so it was outside the sweep); the 0.3.21 wipe canary c22-1 took five digest-mismatch rejects from it; an app with the packaged peers is refused at the seed and syncs through node1 and the hub only, a fresh joiner with only the seed cannot join, the 14 voters and the hub are unaffected; the owner puts the floor file ov16-floor-900000.json (sha 294f1f80) and the c4459193 pin on it. 0.3.21's STAGING (the node lane): the order dry-merges onto 55768f88 with nothing moving to 0.3.22; the late-join fix is 52e96c94 (70e4601e rebased onto 55768f88, exec suite 33 green with both new tests); f067f7c1, b0444f51 and 437f0438 merge clean in order; 2e32d5f6's one conflict (DST_ADDRESS beside pool-finish's DST_BINDING in consensus/core/src/finality.rs) kept both; the live-file digest eada4bda after each (every switch at never); the staging waits on the shipper's sweep-end word; the re-pin held. PC 2 DOWN AGAIN (main, 16:5x UK): the project lead takes PC 2 down for cable work (PC 1 back but his desk); both PCs out of the sweep's waves, each updates on its poller on return; no PC job to PC 1; the Windows G1 completed before the outage, nothing reruns. 0.3.21's SECOND GATE LINE on 55768f88 (sha256 279b1b690e854fc9): the ten-minute mixed-version gate beside the 5899f603 pair, 13:37:40Z to 13:47:52Z, SUMMARY PASS (one digest b0afb2ee on five nodes; 223 new and 381 old blocks accepted by the old hub, 0 rejected; counts equal at 319, 486 and 604 through both clean joins and the restart step at 13:45:22Z; no panic); the node lane's two lines on 0.3.21's first candidate complete, in plan 6.9 on ca3-v4-node; the fleet's set on it (the bare-child 12 GB line, the wipe, the kept read, the cases) is the fleet's. 0.3.21's FIRST GATE LINE on 55768f88 (sha256 279b1b690e854fc9, the string read back; pairing igneum-pow 8c728ca3 at byte 5): the digest gate 13:35:41Z to 13:37:19Z SUMMARY PASS (a89be8a7 on both binaries with the peers; db9a85f9 refused, no peer; the live file's eada4bda unmoved); the ten-minute mixed-version gate from 13:37:40Z, line about 13:50Z. The 0.3.21 order as the shipper sent it: 55768f88; f067f7c1 and 70e4601e; b0444f51; 6eb21fc9; db28d331; then the re-pin from 8bdcbdd8 on the coordinator's word; suites between, the digest read after every one; the mirror's release-0.3.20-node back at the pin c4459193, release-0.3.21-node open at 55768f88. THE LATE-JOIN COMMIT (N9's second half, the node lane): 70e4601e on the box mirror as branch proof-hold-fix, from c4459193, two files (igneum/exec/src/proving.rs, protocol/flows/src/v10/proving.rs); the gap was the fetch side on the joiner (the served record ran the native check against the joiner's trailing exec state before anything was stored, the check refused it, the proof was never held, the body rule read "not held" for 20 s and failed the IBD); the fix holds the proof by hash before the checks (the pool entry still needs them) and the serve side says when it holds fewer than asked; the exec suite 32 passed at 13:26Z with the known-failed shape first, the flows check green 13:28Z, igneumd on build-1 at the 0321 worktree path built 13:32Z, sha256 17649eeb2f7d1290, string read back; with the testnet lane (the resume form, B alone); it joins the 0.3.21 staging as its own commit. THE WIPE CANARY ON c19-1, c4459193 (sha 45be9b02d1b002f5, string read back): FORM END rc 0 at 13:50:53Z. Wipe synced 13:35:50Z (57 minutes, inside the 98-minute class); mining 13:36:00Z to 13:47:07Z, 66 mined, 66 accepted, 0 rejected, isSynced true at the tip throughout; the hub holds 41 of its blocks in its last 700 with 0 rejects (13:47:09Z); the restart on its kept datadir at 13:47:15Z: the old process stopped at once (the new process's first lock line seven seconds after the marker; the watchdog held nothing, the b7cc37e7 fault closed), synced again at 13:48:39Z after 84 s, 109 templates read with max 3,432 ms and 0 timeouts; the kept read on pool-1's 0.3.17 copy on the same pod passed at 13:38Z (the rewrite line once, a clean second start). The pin's set on c4459193: the digest gate PASS, the mixed-version gate PASS, the wipe canary PASS, the kept read PASS, the restart PASS, the 12 GB line proves and verifies (paid is a race, not a gate); CASES END from c20-1 (about 14:50Z) is the last pin line. THE INTEROP FACT stands from the void run: the 5899f603 hub accepted 235 object-byte-5 blocks from the 8097d600 node with 0 rejected, one digest on all five nodes on the live sixteen-field file. The gates: the digest test and the kaspa-pow vector test (the amended devnet epoch-0 id 1a4230699a6b9c60 must equal, c120d7963abdcd96 must differ, the v3 control unchanged) on the box; the mixed-version Devnet 2 gate (the amended 0.3.20 node beside a 5899f603 node for ten minutes on the live file without the v4 fields) after the Mac build; the fresh-join canary the 0.3.20 cut's | | Main's rulings (7 October, morning) | no generator change to v4 on the live devnet; the record's null is the window model with numbers, sent by the hash lane to the attack-pass lane so AP-F8-1 re-gates against it; a fault beyond the model (a low-entropy source at site 15) stops at the coordinator with the two options priced (a 0.3.19 class amendment before the flip, or the flip held at the floor), nothing shipping without the project lead's word; the tighter tail, an acceptance bound on the hot-set share, is a CLASS V5 item (sent to the v5 lane a6410f3b8abefb762 with the 64-seed census as its gate; the bound's number follows from the model) |
AP-F4-1, the weak-day MUL draw (the attack-pass lane, 7 October, morning): PASS against v4, a class v5 rule
The cryptanalysis brief's rank-3 question (a weak-key class in the day's rotation and multiplier draws, MEMHARD's untested all-equal ROT draw) is now measured: docs/analysis/attack-pass/f4-weakday.md (branch attack-pass). No weak class: the cheap days are the tail of a sum (the exact convolution predicts the census to 0.6 percent). Against the DSP-bound datapath (M2) PASS, 0 of 2^28 days over 1.1x. On the LUT-adder metric (M1, every multiply in adders, census median 231 adders per mixer application) 5,476 of 2^24 days over 1.1x (3.26e-4, 342x the 2^-20 gate); the worst in 2^24 1.173x; the worst in the public calendar's first 100 years chain day 29,337 at 1.121x (M2 1.000x). Priced: a per-day LUT-recompute FPGA gets at most 12.1 percent more hash rate on that day (reads and shadow untouched), 12 days a century, 0.004 percent of a century's hashes; 0 for a stored-dataset FPGA or any chip; one bitstream a day under USD 3 compiled ahead on the public calendar. Consequence per tier: nothing for any GPU miner or pool; the chip model is unmoved. The rule for the NEXT class (sent to the v5 lane with F4's harness as the gate; v4 untouched): reject a MUL block with NAF sum under 163, NAF weight at least 4 per word, at least 4 distinct ROT amounts, redraw from the next stream values, 6.1e-4 rejection per day, the first calendar redraw day 22,633; no devnet or testnet pack changes.
AP-F1-1, the shadow redundancy bound (the attack-pass lane, 7 October, 12:3x UK): PASS against v4, a class v5 rule
Over 100,000 class v4 programs the shadow block's peephole-removable instructions (a register written twice from one source with no write between) average 0.62 percent of the 256 per pass, maximum 5.078 percent, 1 in 100,000 over 5 percent; nothing crosses a pass; clang -O3 removes the same instructions from the honest kernel, so it is a bound on the shadow's useful work, not a chip shortcut (docs/analysis/attack-pass/f1-shadow.md). Consequence per tier: nothing for any miner or chip; the chip model is unmoved. The rule for the next class (sent to the v5 lane with F1's harness on 64 seeds as the gate; v4 untouched): the generator refuses a shadow block whose honest-compiler simplification exceeds 3.0 percent (the v5 lane's fraction, 4af21977: the bins from 3.0 percent up hold 384 of 100,000 draws, about 4e-3, under one attempt lost per 250 seeds, inside the 2.0 rule's bounds) and redraws from the next stream values; it lands in generator.rs behind the v5 class once ca3-v4-amend is merged into class-v5.
8. Close
Closed 6 October 2026, 18:1x UTC. The lanes: item 1 (ca3-analysis), item 2 (ca3-derive), items 4 and 5 (ca3-detector), item 3 (ca3-crypto-brief), items 6 and 7 (ca3-reserve), item 8 (ca3-shadow), the PC 1 AMD jobs (ca3-pc1-amd), the hash gates (ca3-v4-hash) and the node gates with both preconditions (ca3-v4-node and the fork): thank you, every one of you, for the numbers and for the faults you found in your own work and in mine before they reached a cut.