iuna

iuna

iuna - experimental mainnet-candidate protocol
git clone https://getiuna.org/git/iuna.git
Log | Files | Refs | README | LICENSE

commit 8ace0ea013212d4821599617c0e8433cb18cca1a
parent 42aa148c30df3aadf3affebc1e2ed2baa6aa49f7
Author: Joris Hartog <jorishartog@hotmail.com>
Date:   Tue, 18 Aug 2026 07:28:25 +0200

Document fee distribution

Diffstat:
Mdocs/protocol.md | 4++--
1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/docs/protocol.md b/docs/protocol.md @@ -52,7 +52,7 @@ Every normal block must include at least one plaintext burn. A blinded transacti This mandatory anchor burn is a liveness rule for the ticket pool, not a fairness rule for ticket distribution. It guarantees that normal block production keeps creating future tickets. Fairness against self-serving finalizers comes from blinded third-party burns. -Wallet-created transfers and burns are not gossiped as plaintext. Their blinded envelopes expose and lock UTXO inputs before reveal, so declared fees are backed by spendable coins. Mine actions are public mempool items, because they do not reveal burn or transfer intent and must be possible without owning coins. The local plaintext anchor burn for finalization is separate from the configured automatic blinded burn per block. When automatic burning is enabled, the configured burn amount enters the network as a blinded envelope like other wallet-created burns. When a blinded payload is revealed and executed, `35%` of its fee goes to the finalizer that originally committed the envelope, up to `35%` goes to the reveal-block finalizer, and `10%` goes to each included explicit signed reveal-list maker. Missing reveal-list shares, missing reveal-finalizer shares, and rounding dust are burned. The local plaintext anchor burn required for block liveness is part of the block reward like other plaintext block items. +Wallet-created transfers and burns are not gossiped as plaintext. Their blinded envelopes expose and lock UTXO inputs before reveal, so declared fees are backed by spendable coins. Mine actions are public mempool items, because they do not reveal burn or transfer intent and must be possible without owning coins. The local plaintext anchor burn for finalization is separate from the configured automatic blinded burn per block. When automatic burning is enabled, the configured burn amount enters the network as a blinded envelope like other wallet-created burns. When a blinded payload is revealed and executed, `35%` of its fee goes to the finalizer that originally committed the envelope, up to `35%` goes to the reveal-block finalizer, and `10%` goes to each included explicit signed reveal-list maker. Even with full reveal participation, at most `90%` of the fee is paid out and the remaining baseline `10%` is burned. Missing reveal-list shares, missing reveal-finalizer shares, and rounding dust are burned as well. The local plaintext anchor burn required for block liveness is part of the block reward like other plaintext block items. ## VDF Timing @@ -196,7 +196,7 @@ Before height `1500`, each attestation hash is the signed reveal-bundle hash for When a valid bundled reveal executes, nodes decrypt the earlier payload, check the commitment and payload hash, and decode the transfer or burn. The decrypted transaction inputs must match the visible inputs locked by the envelope, and the transaction executes against that locked value. If the reveal bitmask says multiple committee bundles contained the same reveal, the reveal is still executed only once. If the decrypted transaction is a burn, it creates burn tickets at the reveal height, not the earlier envelope-commit height. -Fees are paid without inflating the reveal block reward. The decrypted transaction must pay the same fee declared by the blinded envelope. `35%` goes to the envelope committer. Up to `35%` goes to the reveal-block finalizer, scaled by included reveal attestations divided by the available committee slots for that height. Before height `1500`, signed reveal bundles define those attestations. Starting at height `1500`, the denominator is the total available committee size including implicit slot `0` (`3`, `2`, or `1`). The finalizer's implicit slot `0` attestation counts for the scaled reveal-finalizer share for every reveal in the block, so the reveal-block finalizer always receives at least one slot's share when it includes a valid reveal. Slot `0` does not earn the separate reveal-list-maker share. `10%` goes to each included explicit signed reveal-list maker for non-finalizer slots. Missing reveal-list shares, the missing reveal-finalizer share, and rounding dust are burned instead of redistributed. +Fees are paid without inflating the reveal block reward. The decrypted transaction must pay the same fee declared by the blinded envelope. `35%` goes to the envelope committer. Up to `35%` goes to the reveal-block finalizer, scaled by included reveal attestations divided by the available committee slots for that height. Before height `1500`, signed reveal bundles define those attestations. Starting at height `1500`, the denominator is the total available committee size including implicit slot `0` (`3`, `2`, or `1`). The finalizer's implicit slot `0` attestation counts for the scaled reveal-finalizer share for every reveal in the block, so the reveal-block finalizer always receives at least one slot's share when it includes a valid reveal. Slot `0` does not earn the separate reveal-list-maker share. `10%` goes to each included explicit signed reveal-list maker for non-finalizer slots. A fully attributed reveal can therefore pay at most `90%` of the fee (`35% + 35% + 10% + 10%`); the remaining baseline `10%` is burned. Missing reveal-list shares, the missing reveal-finalizer share, and rounding dust are burned instead of redistributed. Starting at height `750`, reveal fee attribution is per reveal mask. A signed reveal-list maker earns the `10%` share for a revealed payload only if that maker's signed bundle actually contained that reveal. The reveal-block finalizer's scaled share is also based on the number of attestations for that reveal, not merely the number of bundle signatures included somewhere in the block. Before height `1500`, those attestations are signed bundles. Starting at height `1500`, slot `0` is counted as attesting to every reveal in the block through the finalizer's block signature, while slots `1` and `2` count only when their signed bundle contained the reveal. Before height `750`, all included signed reveal-list makers are treated as participating in every revealed payload in that block.