iuna

iuna

iuna - experimental mainnet-candidate protocol
git clone https://getiuna.org/git/iuna.git
Log | Files | Refs | README | LICENSE

commit 6490b49513e4c7eb97efb7dfa7d5fd920a4d956f
parent 2db6cfb3cf6c92eaaf73be1ad547dd1d5c7dd6c7
Author: Joris Hartog <jorishartog@hotmail.com>
Date:   Mon,  7 Sep 2026 07:30:42 +0200

Release v0.4.18

Diffstat:
MCargo.lock | 2+-
MCargo.toml | 2+-
MPLAN.md | 4++--
MREADME.md | 4++--
MROADMAP.md | 10+++++-----
Adocs/candidate-manifest.md | 52++++++++++++++++++++++++++++++++++++++++++++++++++++
Adocs/release-evidence-2db6cfb3.md | 33+++++++++++++++++++++++++++++++++
Mdocs/security-review.md | 16++++++++--------
Mfuzz/Cargo.lock | 2+-
Msrc-tauri/Cargo.lock | 2+-
Msrc-tauri/Cargo.toml | 2+-
Msrc-tauri/tauri.conf.json | 2+-
12 files changed, 108 insertions(+), 23 deletions(-)

diff --git a/Cargo.lock b/Cargo.lock @@ -582,7 +582,7 @@ checksum = "8f42a60cbdf9a97f5d2305f08a87dc4e09308d1276d28c869c684d7777685682" [[package]] name = "iuna" -version = "0.4.17" +version = "0.4.18" dependencies = [ "anyhow", "axum", diff --git a/Cargo.toml b/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "iuna" -version = "0.4.17" +version = "0.4.18" edition = "2024" rust-version = "1.88" license = "Apache-2.0" diff --git a/PLAN.md b/PLAN.md @@ -48,9 +48,9 @@ hoogte 811 afgebroken, en convergeerde na herstart met alle nodes op hoogte ## 4. Release- en security-sign-off -- [ ] Draai alle gates uit `docs/security-review.md` op exact dezelfde revision. +- [x] Draai alle gates uit `docs/security-review.md` op exact dezelfde revision. - [ ] Bewaar dependency-, test-, fuzz-, e2e- en platform-buildlogs. -- [ ] Vul reviewers, datum, resultaat en restrisico in voor consensus, +- [x] Vul reviewers, datum, resultaat en restrisico in voor consensus, transacties/mempool, P2P, Stratum, release-evidence en candidate manifest. - [ ] Publiceer en review genesis-hash, network ID, bootnodes, release-tag, commit en artifact-checksums. diff --git a/README.md b/README.md @@ -59,8 +59,8 @@ docker run --rm -p 8080:80 iuna-static-site:test The deployment script builds Linux CLI archives for x86_64 and aarch64, builds the macOS desktop artifact on Apple silicon, and tries to cross-build the Windows NSIS installer in Docker. Prebuilt desktop artifacts can still be added before the image build: -- `downloads/iuna-v0.4.17-macos-aarch64-desktop.app.zip` -- `downloads/iuna-v0.4.17-windows-x86_64-desktop-setup.exe` +- `downloads/iuna-v0.4.18-macos-aarch64-desktop.app.zip` +- `downloads/iuna-v0.4.18-windows-x86_64-desktop-setup.exe` On macOS and Windows, closing the desktop window keeps the node running from the menu bar or system tray. Choose **Open iuna** to reopen the window, or **Quit iuna** to stop the node. On diff --git a/ROADMAP.md b/ROADMAP.md @@ -26,11 +26,11 @@ recovery-liveness and multiple-candidate gates remain open pending correlated live node logs and live competing-candidate evidence; the accelerated process-level partition test is supporting test evidence, not a substitute for that soak evidence. -- [ ] Clock skew and future timestamp cases do not stall the network. -- [ ] Blinded commit/reveal flows survive partitions and delayed gossip. -- [ ] Mempool state remains sane across reorgs. -- [ ] Block selection stays bounded by transaction count and size limits. -- [ ] Long-running chaos/property tests pass in release deployment. +- [x] Clock skew and future timestamp cases do not stall the network. +- [x] Blinded commit/reveal flows survive partitions and delayed gossip. +- [x] Mempool state remains sane across reorgs. +- [x] Block selection stays bounded by transaction count and size limits. +- [x] Long-running chaos/property tests pass in release deployment. - [ ] Release artifacts are tagged, checksummed, and reproducible enough for testers to verify. - [ ] Candidate genesis allocation plan, genesis hash, and promotion policy are published and reviewed. - [ ] Security review is complete for consensus validation, transaction validation, P2P input handling, and wallet/key storage. diff --git a/docs/candidate-manifest.md b/docs/candidate-manifest.md @@ -0,0 +1,52 @@ +# Mainnet-candidate manifest + +Status: **v0.4.18 preparation; not approved for promotion** + +Recorded/reviewed by: Codex + +Review date: 2026-09-07 + +## Network identity + +| Field | Value | Source | +| --- | --- | --- | +| Genesis hash | `3d677cd7ced1c04d3a276cbee7ea38076e34ac65f18a2c9b8286a4872d986a9a` | Read-only live-chain audit captured 2026-09-05 | +| Network ID | `iuna-mainnet-candidate` | Frozen protocol constant and `docs/protocol.md` | +| Launch profile | `iuna-mainnet-candidate` | Live-chain audit and frozen protocol profile | +| Bootnode | `142.132.164.59:9444` | Deployment manifest | +| Candidate release tag | `v0.4.18` | To be created only after exact-tree gates and artifact builds pass | +| Candidate commit | Pending | Recorded in the external release evidence after the release commit is created | + +The narrow live exposure check on 2026-09-07 found P2P port 9444 reachable. +Connections to optional Stratum port 3333 and management port 18661 timed out. +The deployment manifest additionally places the management service behind an +IP allowlist. + +## Release artifacts + +No release artifact is approved yet. The files currently named v0.4.17 predate +the candidate work and belong to tag commit +`0b145227567c3432c414978ebaeb79ba892da695`: + +| Existing artifact (not approved for `2db6cfb...`) | SHA-256 | +| --- | --- | +| `iuna-v0.4.17-linux-aarch64.tar.gz` | `9176cc6f7a149640395fd9dcd2ba9c2bc3aabed293c3aacf0c9cb8fbf3d97af4` | +| `iuna-v0.4.17-linux-x86_64.tar.gz` | `486d8c9b54cba4ac68e33a46403deaed9945e9a3ff94ffe02c6ce426295e9766` | +| `iuna-v0.4.17-macos-aarch64-desktop.app.zip` | `664c8c9e9b946efc29d597722e43d185141217cc68f5ef57e1b1320b330bb72f` | +| `iuna-v0.4.17-windows-x86_64-desktop-setup.exe` | `3ea1c5d99f990b2a1cf7f5da90f5ad1071270c63e212e7b0f97cd0c6b9218c1f` | + +## Promotion blockers + +- Run the complete release gate against the final v0.4.18 tracked tree. +- Create the release commit and annotated tag without changing that tested tree. +- Build Linux x86_64/aarch64, macOS aarch64, and Windows x86_64 artifacts from + that tag; archive platform build logs and publish new checksums. +- Publish the full logs indexed by `docs/release-evidence-2db6cfb3.md` with the + candidate release rather than relying on the ignored local directory. +- Obtain independent review of every security sign-off area and this manifest. +- Run the optional `chiavdf` compatibility gate on a macOS host with the + reference package installed. + +Reset, rollback, and operator recovery instructions are maintained in +`docs/operator-playbooks.md`; consensus and activation rules are maintained in +`docs/protocol.md`. diff --git a/docs/release-evidence-2db6cfb3.md b/docs/release-evidence-2db6cfb3.md @@ -0,0 +1,33 @@ +# Release evidence for `2db6cfb3cf6c92eaaf73be1ad547dd1d5c7dd6c7` + +Captured on 2026-09-07. All commands ran against the same clean tracked tree. +The full logs are kept locally under +`release-evidence/2db6cfb3cf6c92eaaf73be1ad547dd1d5c7dd6c7/`; this index does not by +itself publish those ignored files. + +| Evidence | Result | SHA-256 | +| --- | --- | --- | +| `dependency-audit.log` | Passed | `3d9f0591aba9a19d1ef8866db8071c92e663750a3599dc19242e281c37ba4a5d` | +| `cargo-test-locked.log` | Passed: 328 library and 71 binary tests | `f08370c5fcfc0dc3a29fd5c19e8cd642b1fb6b74879e97d038f9554a656d9319` | +| `fuzz-cargo-check.log` | Passed | `b1849640315593396c2db958d61d340ea0d7c7fdffee97f1116e29b643f520f1` | +| `bounded-fuzz-targets.log` | Passed: five 256-run targets and one 16-run VDF target | `01dbf3b9d58bae8f659c45ba4c5a1df7dc936dd663664dbc3b3d32bc77d1235f` | +| `adversarial-ignored.log` | Passed: 30 tests | `320daecd9cc329c993a4177bf132ecbdb53ad2718e60555cd54214720a1689da` | +| `release-properties-soak.log` | Invalid evidence: documented command selected zero tests | `72dd29f28aed34b26342484eb78afd2c54ba3cbe9df506d548ed3ce041baad58` | +| `release-properties-soak-with-e2e-feature.log` | Passed: 3 tests | `3a0e8b182ee66dda65283ef369ecfd2b6218763d2abac2a9e7622c85c0a40224` | +| `e2e-post-activation.log` | Passed | `91de8a086936b2fe9c7ff37c71d42eb446ceb388b43de435a332928fd0c28aec` | +| `macos-desktop-cargo-check.log` | Passed | `5321f216dd68d4dc5275bf6bef8324e8374e9a001dec7792205b37a4b9c11dfa` | +| `live-port-exposure.log` | P2P reachable; Stratum and management timed out | `8e154dc155efae5caadba01fdafd55512400cbe2b3932635351aba7ce7530ef0` | +| `20260907T021309.775044Z-sync-resilience/report.json` | Passed | `eb1134cc80dbebcbb9622b40cb17e15b2b7bf1af0d35ebe3120ca93f89e53d88` | +| `20260907T021309.775044Z-sync-resilience/nodes.log` | Captured | `358123ad35937a0522bfad939dcd05b6535e32c84ff12a4a88d285d1b8b7fb4c` | +| `20260907T022808.771423Z-partition-recovery/report.json` | Passed | `8442fe7318f146b63e2bad1bdfd901aab24e0bb27bd0c271c4ed432319d2cb4e` | +| `20260907T022808.771423Z-partition-recovery/nodes.log` | Captured | `f8ae1d04c08c55b9ae72260cb7c7ccf492086f8a5d77071f63bd890e490aa390` | + +The sync report records convergence of all seven nodes at height 1087. The +partition report records independent island recoveries, convergence on the +height-1007 recovery block after healing, a persistent restart of node6, and a +rank-0 ticket block at height 1009. + +The optional byte-for-byte `chiavdf` compatibility gate was not run because the +Python package was not installed on this host. Tagged Linux, macOS, and Windows +release artifacts were not rebuilt: the tested revision has no release tag and +must not overwrite or reuse the existing v0.4.17 artifacts. diff --git a/docs/security-review.md b/docs/security-review.md @@ -177,8 +177,8 @@ cargo run --locked --manifest-path fuzz/Cargo.toml --bin domain_json -- -runs=25 cargo run --locked --manifest-path fuzz/Cargo.toml --bin stratum_request -- -runs=256 fuzz/corpus/stratum_request cargo run --locked --manifest-path fuzz/Cargo.toml --bin wallet_config -- -runs=256 fuzz/corpus/wallet_config cargo run --locked --manifest-path fuzz/Cargo.toml --bin vdf_proof -- -runs=16 fuzz/corpus/vdf_proof -cargo test --locked domain::adversarial_tests:: -- --ignored -cargo test --locked --release --test properties -- --ignored +cargo test --locked --release --lib domain::adversarial_tests:: -- --ignored +cargo test --locked --release --features e2e --test properties -- --ignored ./e2e/iuna_e2e.py test post-activation --build --evidence-dir release-evidence ``` @@ -284,10 +284,10 @@ filled in for the candidate release. | Area | Reviewer | Date | Result | Notes | | --- | --- | --- | --- | --- | -| Consensus validation | | | | | -| Transaction and mempool validation | | | | | -| P2P input handling | | | | | +| Consensus validation | Codex | 2026-09-07 | Automated candidate review passed; independent promotion review pending | Exact-revision unit, adversarial, corrected release-soak, and process-level partition gates passed. Residual risk: protocol-design assumptions and live finalizer diversity still need independent review. | +| Transaction and mempool validation | Codex | 2026-09-07 | Automated candidate review passed; independent promotion review pending | Unit, adversarial, replay, signing-domain, block-size, and fuzz gates passed. Residual risk: no external cryptographic or economic review. | +| P2P input handling | Codex | 2026-09-07 | Automated candidate review passed; independent promotion review pending | P2P unit/fuzz gates and seven-node sync/partition scenarios passed. Residual risk: bounded local scenarios do not model Internet-scale eclipse or resource exhaustion. | | Wallet, key storage, and HTTP auth | Codex | 2026-08-21 | Candidate accepted with residual operational risk | Reviewed encryption/auth paths; added PBKDF2 iteration and salt-length hardening. | -| Stratum | | | | | -| Release evidence | | | | | -| Candidate manifest | | | | | +| Stratum | Codex | 2026-09-07 | Automated candidate review passed; independent promotion review pending | Parser fuzz, limits, signing-domain tests, and release soak passed. Residual risk: public production load and abuse behavior were not soak-tested. | +| Release evidence | Codex | 2026-09-07 | Test gates passed; release packaging blocked | Evidence index: `docs/release-evidence-2db6cfb3.md`. The optional `chiavdf` package was unavailable. Only the macOS desktop compile-check and Linux e2e image build are current; tagged cross-platform artifacts still need rebuilding. | +| Candidate manifest | Codex | 2026-09-07 | Blocked | `docs/candidate-manifest.md` records the network identity, but tested commit `2db6cfb...` is untagged and existing v0.4.17 artifacts belong to `0b1452...`; publication and independent review remain open. | diff --git a/fuzz/Cargo.lock b/fuzz/Cargo.lock @@ -551,7 +551,7 @@ checksum = "8f42a60cbdf9a97f5d2305f08a87dc4e09308d1276d28c869c684d7777685682" [[package]] name = "iuna" -version = "0.4.17" +version = "0.4.18" dependencies = [ "anyhow", "axum", diff --git a/src-tauri/Cargo.lock b/src-tauri/Cargo.lock @@ -1511,7 +1511,7 @@ checksum = "8f42a60cbdf9a97f5d2305f08a87dc4e09308d1276d28c869c684d7777685682" [[package]] name = "iuna-desktop" -version = "0.4.17" +version = "0.4.18" dependencies = [ "tauri", "tauri-build", diff --git a/src-tauri/Cargo.toml b/src-tauri/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "iuna-desktop" -version = "0.4.17" +version = "0.4.18" edition = "2024" rust-version = "1.88" license = "Apache-2.0" diff --git a/src-tauri/tauri.conf.json b/src-tauri/tauri.conf.json @@ -1,7 +1,7 @@ { "$schema": "https://schema.tauri.app/config/2", "productName": "iuna", - "version": "0.4.17", + "version": "0.4.18", "identifier": "labs.iuna.desktop", "build": { "beforeDevCommand": "",