commit e813905c1e59385f3a4545c20bfa81b129db36ab
parent 71b0447439d4be589d9f348d1e4182617a7e3084
Author: Joris Hartog <jorishartog@hotmail.com>
Date: Wed, 9 Sep 2026 22:41:11 +0200
docs: remove stale release planning artifacts
Diffstat:
9 files changed, 0 insertions(+), 840 deletions(-)
diff --git a/.gitignore b/.gitignore
@@ -4,7 +4,6 @@
/.docker-build
/.iuna
/e2e/.runtime
-/release-evidence
/src-tauri/target
/src-tauri/gen
/src-tauri/binaries/iuna-sidecar-*
diff --git a/PLAN.md b/PLAN.md
@@ -1,80 +0,0 @@
-# Mainnet-candidate vervolgplan
-
-Dit plan zet de resterende promotion-critical werkzaamheden in uitvoerbare
-volgorde. Testbewijs en live bewijs worden apart bijgehouden: een groene lokale
-test is nodig, maar sluit een live-soak gate niet automatisch.
-
-## 1. Procesniveau P2P-partitietest
-
-- [x] Voeg een versnelde echte TCP/P2P-partitietest toe aan de Rust e2e-suite.
-- [x] Splits de zes Docker-nodes fysiek in twee groepen van drie.
-- [x] Laat beide groepen onafhankelijk een recovery-block accepteren.
-- [x] Herstel het netwerk en verifieer dat alle nodes op dezelfde tip convergeren.
-- [x] Herstart een node met zijn bestaande persistente data.
-- [x] Verifieer dat na recovery weer een normaal ticketblock wordt geproduceerd.
-- [x] Neem het scenario op in de verplichte post-activation release-gate.
-- [x] Bewaar bij falen en bij een candidate release de relevante node-logs en
- tip/checkpoint-samenvatting.
-
-## 2. Live recovery-bewijs
-
-- [x] Analyseer de chain-database onder `~/.iuna` uitsluitend read-only.
-- [x] Leg recovery-hoogtes, hashes, voorafgaande stall en eerstvolgende
- ticketblock vast zonder walletmateriaal of secrets te kopiëren.
-- [x] Bepaal welke recovery-gates hiermee objectief gesloten kunnen worden.
-- [x] Laat gates voor meerdere recovery-candidates open tenzij de live historie
- of de procesniveau-partitietest dit daadwerkelijk bewijst.
-
-Resultaat: [de live-chain-audit](docs/live-recovery-evidence.md) vond 12
-recovery-blocks in 8 episodes en na iedere episode hervatte een ticketblock.
-De roadmap-gates blijven bewust open omdat de chainhistorie niet bewijst welke
-finalizers tijdens de stalls offline waren en geen concurrerende live
-recovery-candidates bevat.
-
-## 3. Sync-bewijs
-
-- [x] Test een lege node die zonder handwerk vanaf genesis synchroniseert.
-- [x] Test een stale node vanaf een oud snapshot via range/fork sync.
-- [x] Test onderbreking en herstart tijdens beide sync-paden.
-- [x] Archiveer hoogtes, tip-hashes, doorlooptijden en foutlogs als
- release-evidence.
-
-Resultaat: de versnelde zeven-node `sync-resilience`-gate onderbrak een lege
-bootstrap vóór de eerste persistente snapshot en hervatte tot zeven-node
-convergentie op hoogte 1032. Daarna synchroniseerde dezelfde node vanaf hoogte
-299, werd tijdens actieve range-validatie met een persistente tussenstand op
-hoogte 811 afgebroken, en convergeerde na herstart met alle nodes op hoogte
-1059.
-
-## 4. Release- en security-sign-off
-
-- [x] Draai alle gates uit `docs/security-review.md` op exact dezelfde revision.
-- [ ] Bewaar dependency-, test-, fuzz-, e2e- en platform-buildlogs.
-- [x] Vul reviewers, datum, resultaat en restrisico in voor consensus,
- transacties/mempool, P2P, Stratum, release-evidence en candidate manifest.
-- [ ] Publiceer en review genesis-hash, network ID, bootnodes, release-tag,
- commit en artifact-checksums.
-
-## 5. Promotie en hard-forkproces
-
-- [ ] Leg het besluit vast om de candidate chain wel of niet zonder nieuwe
- genesis te promoveren.
-- [ ] Documenteer protocolversies, activatiehoogtes, compatibiliteitsregels,
- rollout, rollback en noodprocedure voor toekomstige hard forks.
-- [ ] Voer tijdens het launch-window alleen promotion-critical wijzigingen door.
-
-## 6. Atomic BTC swaps
-
-- [ ] Werk protocol, threat model en failure/recovery flows uit zonder de
- bevroren candidate-consensusregels te wijzigen.
-- [ ] Bouw eerst een geïsoleerde testnet/prototype-implementatie.
-- [ ] Plan activatie pas na promotion, security-sign-off en een vastgesteld
- hard-forkproces.
-
-## Eerstvolgende definitie van klaar
-
-Stap 4 is klaar wanneer alle gates uit `docs/security-review.md` op exact
-dezelfde revision zijn gedraaid, de bijbehorende logs zijn gearchiveerd, iedere
-sign-offrij een reviewer, datum, resultaat en restrisico bevat, en het candidate
-manifest met genesis-hash, network ID, bootnodes, release-tag, commit en
-artifact-checksums is gepubliceerd en gereviewd.
diff --git a/README.md b/README.md
@@ -312,7 +312,6 @@ peers.
- [Protocol](docs/protocol.md)
- [Operator failure playbooks](docs/operator-playbooks.md)
-- [Security review checklist](docs/security-review.md)
## Contributing
diff --git a/ROADMAP.md b/ROADMAP.md
@@ -1,158 +0,0 @@
-# Roadmap
-
-iuna is operating a live experimental mainnet-candidate network. This roadmap is the canonical planning document for stabilizing that candidate and, if it stays healthy, promoting the same chain to mainnet.
-
-## Current Phase
-
-Live mainnet-candidate stabilization and promotion evidence.
-
-The current goal is to operate the candidate without unplanned resets, collect live evidence, and close the remaining security, recovery, sync, and promotion gates.
-
-## Mainnet Readiness Checklist
-
-- [x] Protocol rules are frozen for mainnet candidate.
-- [x] Block, transaction, ticket, VDF, recovery, fork-choice, and peer compatibility rules are documented.
-- [x] Long-running testnet has stayed stable with independent nodes for an agreed window.
-- [x] Mainnet-candidate network has launched from a fresh genesis using release artifacts.
-- [x] New nodes can sync from genesis without manual intervention.
-- [x] Stale nodes can reconnect and catch up from old snapshots/range sync.
-- [ ] Post-activation network partitions have an implemented objective checkpoint-based recovery rule; live soak evidence is still required to close this gate.
-- [ ] Recovery blocks restore liveness when selected finalizers disappear.
-- [ ] Multiple recovery candidates converge safely.
-
-The [live recovery audit](docs/live-recovery-evidence.md) records 12 recovery
-blocks across 8 episodes, each followed by resumed ticket production. The
-recovery-liveness and multiple-candidate gates remain open pending correlated
-live node logs and live competing-candidate evidence; the accelerated
-process-level partition test is supporting test evidence, not a substitute for
-that soak evidence.
-- [x] Clock skew and future timestamp cases do not stall the network.
-- [x] Blinded commit/reveal flows survive partitions and delayed gossip.
-- [x] Mempool state remains sane across reorgs.
-- [x] Block selection stays bounded by transaction count and size limits.
-- [x] Long-running chaos/property tests pass in release deployment.
-- [ ] Release artifacts are tagged, checksummed, and reproducible enough for testers to verify.
-- [ ] Candidate genesis allocation plan, genesis hash, and promotion policy are published and reviewed.
-- [ ] Security review is complete for consensus validation, transaction validation, P2P input handling, and wallet/key storage.
-- [x] Upgrade and rollback instructions exist.
-- [x] Basic operational monitoring is available for height, tip hash, peers, last block age, finalizer mode, VDF rounds, mempool, and rejected blocks.
-
-Security review tracking lives in [Security Review Checklist](docs/security-review.md). Do not check the security-review item complete until its sign-off table is filled and the promotion-blocking review items are resolved or explicitly accepted.
-
-## Candidate Launch Test Backlog (Completed)
-
-These items are not protocol rules. They record the attack and reliability work completed before the live mainnet-candidate network was created. If the candidate stays healthy through the agreed window, the same genesis, chain history, UTXOs, and mined coins should be promoted to mainnet instead of being reset again.
-
-### Completed Before Candidate Genesis
-
-- [x] Burn bundle relay cannot import embedded burns before bundle metadata, membership, signature, fee ordering, and size are prechecked.
-- [x] Block validation with burn attestations remains independent of local mempool contents, including empty and conflicting mempools.
-- [x] Post-genesis transactions cannot spend with `genesis` input signatures.
-- [x] From height 1000, previously mined transaction IDs cannot be replayed; in
- particular, spending a mine reward cannot make its inputless proof mint again.
-- [x] P2P envelope item limits reject batches only above their configured boundaries.
-- [x] Stratum endpoint has explicit DoS limits: maximum line size, maximum jobs per session, idle timeout, and connection/session caps.
-- [x] Fork and snapshot adversarial tests cover legacy finality, post-height-1000 objective checkpoints, deterministic conflicting-certificate recovery, same-height leader-quality choice, invalid late snapshot blocks, and pending transaction carry-forward after reorg.
-- [x] Compact snapshot decoder has malformed-input tests for huge lengths, oversized varints, trailing bytes, truncated payloads, invalid tags, and random byte inputs without panics or excessive allocation.
-- [x] Supply invariant tests cover mixed burns, fees, PoW mine actions, reorgs, no replay, and no double spend.
-
-### Should Before Mainnet
-
-- [x] HTTP/auth abuse tests cover CSRF same-origin behavior, lockout/backoff behavior, forwarded-header spoofing from untrusted peers, and session expiry.
-- [x] Multi-node in-memory simulation covers delayed gossip, withheld burn bundles, bundle equivocation, partitions, restarts, persistence reload, and convergence.
-- [x] Long-running release-mode soak test runs with automatic burn/finalization, P2P sync, Stratum-disabled and Stratum-enabled nodes, and periodic node restarts.
-- [x] Operator failure playbooks exist for stalled height, divergent tips, old snapshots, no burn committee signatures, recovery blocks, and corrupted local persistence.
-- [x] Mainnet-candidate release rehearsal includes fresh genesis, published bootnodes, checksums, backup/restore instructions, and a no-reset stability window.
-- [x] Security review checklist exists for consensus validation, transaction validation, P2P input handling, wallet/key storage, Stratum, release evidence, and candidate manifest sign-off.
-
-## Milestones
-
-### M1: Testnet Hardening
-
-Focus: make failure modes boring and observable.
-
-- [x] Add property-style simulations for clock skew.
-- [x] Add property-style simulations for network partitions and reconnect.
-- [x] Add property-style simulations for multiple recovery candidates.
-- [x] Add property-style simulations for late joiners syncing from genesis.
-- [x] Add property-style simulations for future timestamp rejection.
-- [x] Add property-style simulations for reorg mempool preservation.
-- [x] Add property-style simulations for blinded commit/reveal under partition.
-- [x] Add property-style simulations for expired blinded transaction pruning.
-- [x] Add long-running soak chaos test.
-- [x] Keep long-running tests out of normal local test runs.
-- [x] Run long-running tests unconditionally during deployment.
-- [x] Run a multi-day public testnet without manual chain resets.
-- [x] Add or improve operator-facing health metrics.
-- [x] Document common testnet failure/recovery playbooks.
-
-### M2: Live Mainnet Candidate
-
-Focus: operate the live candidate with mainnet-like process and treat it as the chain that can become mainnet if it stays healthy.
-
-- [x] Freeze protocol parameters for the candidate.
-- [x] Create a fresh mainnet-candidate genesis.
-- [x] Publish bootnodes and release artifacts.
-- [x] Publish checksums for every release artifact.
-- [x] Document node setup, backup, restore, and upgrade steps.
-- [ ] Run a candidate network for an agreed stability window.
-- [x] Treat resets as promotion-blocking incidents unless explicitly planned.
-- [ ] Decide and publish whether the candidate ledger is promoted to mainnet without a second genesis.
-
-### M3: Mainnet Launch
-
-Focus: promote the stable candidate ledger. Mainnet launch should not create a second genesis unless the candidate failed and the reset is explicitly announced.
-
-- [ ] Publish the promotion decision, candidate genesis hash, promoted tip height, and promoted tip hash.
-- [ ] Tag the mainnet release from the promoted candidate code line.
-- [ ] Publish release artifacts and checksums.
-- [ ] Upgrade or restart bootnodes on the mainnet release while preserving chain data.
-- [ ] If the P2P network ID changes from `iuna-mainnet-candidate` to `iuna-mainnet-v1`, coordinate the cutover without changing genesis or launch profile rules.
-- [ ] Monitor first blocks and first recovery/fallback events.
-- [ ] Keep feature changes frozen during the launch window.
-- [ ] Document any required hard-fork or emergency procedure before launch.
-
-### M4: Post-Mainnet
-
-Focus: improve usability, tooling, and governance after the base network is stable.
-
-- [ ] Improve wallet UX and backup flows.
-- [ ] Improve block explorer and public network visibility.
-- [ ] Add safer upgrade prompts or update guidance.
-- [ ] Add protocol versioning and hard-fork coordination process.
-- [ ] Explore light client or mobile-friendly modes.
-- [ ] Use observed network data to tune economic and operational assumptions.
-
-## Release Gates
-
-A release intended for deployment must pass:
-
-- `./scripts/check-dependencies.sh`, which audits `Cargo.lock`,
- `fuzz/Cargo.lock`, and `src-tauri/Cargo.lock` and enforces the dependency
- source/license allowlist
-- `cargo test --locked`
-- `cargo check --locked --manifest-path fuzz/Cargo.toml`
-- desktop test/build jobs on Linux, macOS, and Windows
-- fuzz gate runs with `256` iterations each for `p2p_envelope`,
- `compact_snapshot`, `domain_json`, `stratum_request`, and `wallet_config`
-- `cargo test --locked --release --features e2e --test properties -- --ignored`,
- restoring the first objective checkpoint before exercising P2P, Stratum, and restarts
-- `./e2e/iuna_e2e.py test post-activation --build --evidence-dir release-evidence`,
- which crosses height 1000, checks objective finality, restarts all six nodes,
- advances through 1007, interrupts empty and stale node sync, and preserves
- process-level sync and partition recovery evidence
-
-Normal local development may skip ignored long-running property tests and long fuzzing sessions, but deployment must run the release gate smoke checks.
-
-## Decisions
-
-- 2026-08-14: Keep `ROADMAP.md` in the repo as the source of truth.
-- 2026-08-14: Long-running property/soak tests are marked `#[ignore]` for normal local runs and are required in `deployment.sh`.
-- 2026-08-19: The mainnet-candidate chain is intended to be promotable to mainnet without a second genesis if it satisfies the stability window and release gates.
-- 2026-08-20: The agreed independent-node long-running testnet stability window completed without requiring an unplanned chain reset.
-- 2026-09-01: Post-height-1000 operation is the standard integration baseline;
- deployment restores mature checkpoints instead of treating genesis-only runs
- as sufficient release coverage.
-- 2026-09-02: Update project status to reflect that the mainnet-candidate network
- is live. The candidate manifest and promotion decision remain explicit open
- publication gates.
diff --git a/docs/candidate-manifest.md b/docs/candidate-manifest.md
@@ -1,52 +0,0 @@
-# Mainnet-candidate manifest
-
-Status: **v0.4.18 preparation; not approved for promotion**
-
-Recorded/reviewed by: Codex
-
-Review date: 2026-09-07
-
-## Network identity
-
-| Field | Value | Source |
-| --- | --- | --- |
-| Genesis hash | `3d677cd7ced1c04d3a276cbee7ea38076e34ac65f18a2c9b8286a4872d986a9a` | Read-only live-chain audit captured 2026-09-05 |
-| Network ID | `iuna-mainnet-candidate` | Frozen protocol constant and `docs/protocol.md` |
-| Launch profile | `iuna-mainnet-candidate` | Live-chain audit and frozen protocol profile |
-| Bootnode | `142.132.164.59:9444` | Deployment manifest |
-| Candidate release tag | `v0.4.18` | To be created only after exact-tree gates and artifact builds pass |
-| Candidate commit | Pending | Recorded in the external release evidence after the release commit is created |
-
-The narrow live exposure check on 2026-09-07 found P2P port 9444 reachable.
-Connections to optional Stratum port 3333 and management port 18661 timed out.
-The deployment manifest additionally places the management service behind an
-IP allowlist.
-
-## Release artifacts
-
-No release artifact is approved yet. The files currently named v0.4.17 predate
-the candidate work and belong to tag commit
-`0b145227567c3432c414978ebaeb79ba892da695`:
-
-| Existing artifact (not approved for `2db6cfb...`) | SHA-256 |
-| --- | --- |
-| `iuna-v0.4.17-linux-aarch64.tar.gz` | `9176cc6f7a149640395fd9dcd2ba9c2bc3aabed293c3aacf0c9cb8fbf3d97af4` |
-| `iuna-v0.4.17-linux-x86_64.tar.gz` | `486d8c9b54cba4ac68e33a46403deaed9945e9a3ff94ffe02c6ce426295e9766` |
-| `iuna-v0.4.17-macos-aarch64-desktop.app.zip` | `664c8c9e9b946efc29d597722e43d185141217cc68f5ef57e1b1320b330bb72f` |
-| `iuna-v0.4.17-windows-x86_64-desktop-setup.exe` | `3ea1c5d99f990b2a1cf7f5da90f5ad1071270c63e212e7b0f97cd0c6b9218c1f` |
-
-## Promotion blockers
-
-- Run the complete release gate against the final v0.4.18 tracked tree.
-- Create the release commit and annotated tag without changing that tested tree.
-- Build Linux x86_64/aarch64, macOS aarch64, and Windows x86_64 artifacts from
- that tag; archive platform build logs and publish new checksums.
-- Publish the full logs indexed by `docs/release-evidence-2db6cfb3.md` with the
- candidate release rather than relying on the ignored local directory.
-- Obtain independent review of every security sign-off area and this manifest.
-- Run the optional `chiavdf` compatibility gate on a macOS host with the
- reference package installed.
-
-Reset, rollback, and operator recovery instructions are maintained in
-`docs/operator-playbooks.md`; consensus and activation rules are maintained in
-`docs/protocol.md`.
diff --git a/docs/live-recovery-evidence.md b/docs/live-recovery-evidence.md
@@ -1,66 +0,0 @@
-# Live Recovery Evidence
-
-This note records a read-only audit of the local mainnet-candidate chain
-snapshot. It does not contain wallet data, configuration, recovery phrases, or
-private keys.
-
-## Capture
-
-- Captured at: `2026-09-05T17:24:50Z`
-- Profile: `iuna-mainnet-candidate`
-- Height: `1210`
-- Tip: `441f59b34cac6df6253c7f6b2449369ab7c1c3065d065467022f6b52b067eeb8`
-- Genesis: `3d677cd7ced1c04d3a276cbee7ea38076e34ac65f18a2c9b8286a4872d986a9a`
-- Stable database-copy SHA-256:
- `fcf26863853ea51e0a865f330a2292fa2bcac6dc1cfaceb33a0880347a0d168e`
-- Verification marker: valid under the current consensus ruleset
-
-The audit command refuses a source database with a WAL file, copies a stable
-source to a temporary database, decodes only that copy, and removes the copy and
-its SQLite companion files afterward:
-
-```sh
-cargo run --locked --bin iuna-chain-audit -- \
- ~/.iuna/chain.sqlite3 \
- --output release-evidence/live-chain-audit-2026-09-05.json
-```
-
-## Observed recovery history
-
-`parent gap` is the elapsed time from the preceding block to the recovery
-block. `ticket delay` is measured from that recovery block to the first later
-ticket block. Consecutive recovery rows therefore share the same eventual
-ticket where applicable.
-
-| Recovery height | Recovery hash | Parent gap (ms) | Next ticket height/rank | Next ticket hash | Ticket delay (blocks/ms) |
-| ---: | --- | ---: | ---: | --- | ---: |
-| 116 | `31d341ff29c24727ad9926850cc45401fa5f59378894f3d5b40980bc2e785495` | 5684830 | 117 / 0 | `5eafc133241dbc9235c522dab1659ba1b095cf9cede24e762ce1685209dff858` | 1 / 1457218 |
-| 119 | `beba42e65f49fb5bb369920e420d6cfa1d6c8e2cb4051846fd06d2eb4171dd85` | 3600160 | 120 / 0 | `18b2d2be9b3a9f920bf1731bbdcbe064456c219953bbf7d3225c4fedb4c8ca21` | 1 / 2521415 |
-| 134 | `02b9fd07eb39be179070e637c08621cf0342dfbcada20ca6a5b7ccceaedb9b53` | 3600608 | 135 / 0 | `cb2f106d309f6370ca9c3406c560d752f039c43a9493763b7cd4da09dfe5313c` | 1 / 182550 |
-| 150 | `bf0fb179d209d420af7651483d7ac393eadcfdb5580f4a70fa3f8fa870d777ec` | 34350614 | 153 / 1 | `8fc33d01d0b603632c4aeb325bbdc9b587b499297b514fc6f97ec45492cb203b` | 3 / 8402100 |
-| 151 | `1a6002adbfb2cecc95efe52707825dc62a032c9f1633c0fdcfcd7f0fe07544fd` | 3600714 | 153 / 1 | `8fc33d01d0b603632c4aeb325bbdc9b587b499297b514fc6f97ec45492cb203b` | 2 / 4801386 |
-| 152 | `f521b171aff6023a42e0081b4aa2000fd5cabfcc1549aed86cd2cf11d83b380e` | 3600275 | 153 / 1 | `8fc33d01d0b603632c4aeb325bbdc9b587b499297b514fc6f97ec45492cb203b` | 1 / 1201111 |
-| 189 | `7114c1a74d258c73fbe7f1d168c0ecdf628e9f73da529bb30fb3daa494a18e1e` | 3600028 | 190 / 1 | `49d1c9f7bb2aea87d117b9bd669b83839e215340c58d1b9bc297b99d7c5c3d83` | 1 / 1200000 |
-| 232 | `b39c4ce092ad0e7aa1a01f6377895e1113acc5df7942badc6a6b1363903e5690` | 3600946 | 233 / 0 | `0be7c59ae4aafe1e1ef604dbb7f472402701e477662ef30cdd46111c664fbbb0` | 1 / 1034783 |
-| 525 | `7290046cd2dbd18a7ca97ae1b708b92d4bd8bc0459cc206627b97916e965188e` | 3600273 | 528 / 0 | `a753f41a9fc77cc6226b49f06d51ea0e1b2ae5142b368acf8ac58590a48c7e09` | 3 / 16446423 |
-| 526 | `df42e45217fd9e40d9c81709b92b13d0e45a75daf88d3d94dbd2542ab7da4a98` | 11892983 | 528 / 0 | `a753f41a9fc77cc6226b49f06d51ea0e1b2ae5142b368acf8ac58590a48c7e09` | 2 / 4553440 |
-| 527 | `e423061e1075c70b439fb1378389733c8902dbabce79dacad4f4cd346d8c2e71` | 3600497 | 528 / 0 | `a753f41a9fc77cc6226b49f06d51ea0e1b2ae5142b368acf8ac58590a48c7e09` | 1 / 952943 |
-| 788 | `b46bd39f637cfb213d177081a47673da106740edace3f78ce6f0d0f5a971b0be` | 3959212 | 789 / 0 | `61f3921223b84336e6ad84451865b8a1adbca16484fd44f86dbc5cfd788d991a` | 1 / 1845873 |
-
-The 12 recovery blocks form 8 episodes. Every episode is followed by a normal
-ticket block, including the two episodes containing three consecutive recovery
-blocks. This is direct live-chain evidence that the recovery path has restored
-ticket production after observed stalls.
-
-## Gate decision
-
-This capture supports the recovery-liveness gate, but does not close it by
-itself: block history cannot prove that disappearance of the selected
-finalizers caused each stall. Correlated node logs or a controlled live soak are
-still required for that attribution.
-
-The multiple-recovery-candidate convergence gate also remains open. Consecutive
-recovery blocks are not evidence of competing candidates. The process-level
-3-3 partition test proves deterministic convergence in the accelerated e2e
-environment, while live soak evidence is still required for the roadmap's live
-gate.
diff --git a/docs/release-evidence-2db6cfb3.md b/docs/release-evidence-2db6cfb3.md
@@ -1,33 +0,0 @@
-# Release evidence for `2db6cfb3cf6c92eaaf73be1ad547dd1d5c7dd6c7`
-
-Captured on 2026-09-07. All commands ran against the same clean tracked tree.
-The full logs are kept locally under
-`release-evidence/2db6cfb3cf6c92eaaf73be1ad547dd1d5c7dd6c7/`; this index does not by
-itself publish those ignored files.
-
-| Evidence | Result | SHA-256 |
-| --- | --- | --- |
-| `dependency-audit.log` | Passed | `3d9f0591aba9a19d1ef8866db8071c92e663750a3599dc19242e281c37ba4a5d` |
-| `cargo-test-locked.log` | Passed: 328 library and 71 binary tests | `f08370c5fcfc0dc3a29fd5c19e8cd642b1fb6b74879e97d038f9554a656d9319` |
-| `fuzz-cargo-check.log` | Passed | `b1849640315593396c2db958d61d340ea0d7c7fdffee97f1116e29b643f520f1` |
-| `bounded-fuzz-targets.log` | Passed: five 256-run targets and one 16-run VDF target | `01dbf3b9d58bae8f659c45ba4c5a1df7dc936dd663664dbc3b3d32bc77d1235f` |
-| `adversarial-ignored.log` | Passed: 30 tests | `320daecd9cc329c993a4177bf132ecbdb53ad2718e60555cd54214720a1689da` |
-| `release-properties-soak.log` | Invalid evidence: documented command selected zero tests | `72dd29f28aed34b26342484eb78afd2c54ba3cbe9df506d548ed3ce041baad58` |
-| `release-properties-soak-with-e2e-feature.log` | Passed: 3 tests | `3a0e8b182ee66dda65283ef369ecfd2b6218763d2abac2a9e7622c85c0a40224` |
-| `e2e-post-activation.log` | Passed | `91de8a086936b2fe9c7ff37c71d42eb446ceb388b43de435a332928fd0c28aec` |
-| `macos-desktop-cargo-check.log` | Passed | `5321f216dd68d4dc5275bf6bef8324e8374e9a001dec7792205b37a4b9c11dfa` |
-| `live-port-exposure.log` | P2P reachable; Stratum and management timed out | `8e154dc155efae5caadba01fdafd55512400cbe2b3932635351aba7ce7530ef0` |
-| `20260907T021309.775044Z-sync-resilience/report.json` | Passed | `eb1134cc80dbebcbb9622b40cb17e15b2b7bf1af0d35ebe3120ca93f89e53d88` |
-| `20260907T021309.775044Z-sync-resilience/nodes.log` | Captured | `358123ad35937a0522bfad939dcd05b6535e32c84ff12a4a88d285d1b8b7fb4c` |
-| `20260907T022808.771423Z-partition-recovery/report.json` | Passed | `8442fe7318f146b63e2bad1bdfd901aab24e0bb27bd0c271c4ed432319d2cb4e` |
-| `20260907T022808.771423Z-partition-recovery/nodes.log` | Captured | `f8ae1d04c08c55b9ae72260cb7c7ccf492086f8a5d77071f63bd890e490aa390` |
-
-The sync report records convergence of all seven nodes at height 1087. The
-partition report records independent island recoveries, convergence on the
-height-1007 recovery block after healing, a persistent restart of node6, and a
-rank-0 ticket block at height 1009.
-
-The optional byte-for-byte `chiavdf` compatibility gate was not run because the
-Python package was not installed on this host. Tagged Linux, macOS, and Windows
-release artifacts were not rebuilt: the tested revision has no release tag and
-must not overwrite or reuse the existing v0.4.17 artifacts.
diff --git a/docs/security-audit-2026-09-09.md b/docs/security-audit-2026-09-09.md
@@ -1,156 +0,0 @@
-# Pre-mainnet security audit — 2026-09-09
-
-Scope: repository revision `3f9e3c7` before the changes in this report. Testing
-was local-only. The review prioritized attacks with an estimated cash cost below
-EUR 10,000 and covered consensus validation, transaction admission, P2P,
-Stratum, bootstrap trust, wallet storage, and HTTP authentication.
-
-This is a focused implementation audit, not a proof of cryptographic or
-economic security. The custom VDF and the burn/finality mechanism still require
-independent specialist review before promotion.
-
-## Executive result
-
-Two remotely reachable denial-of-service weaknesses were confirmed and patched.
-Two cheap admission/bootstrap risks remain promotion blockers or hardening work.
-No confirmed supply-creation, signature-bypass, or consensus-split defect was
-found in the reviewed validation paths.
-
-| ID | Severity | Estimated attacker cost | Result |
-| --- | --- | ---: | --- |
-| IUNA-2026-001 | High | Effectively EUR 0 from one public IP | Patched |
-| IUNA-2026-002 | High over chain lifetime | A basic host and bandwidth; well below EUR 100/month | Patched |
-| IUNA-2026-003 | High during first sync | Below EUR 10,000 when DNS/routing/bootstrap access is available | Patched |
-| IUNA-2026-004 | Medium | 10,000 minimum-fee transactions; protocol value likely far below EUR 10,000 | Patched |
-
-## IUNA-2026-001 — one source could exhaust every Stratum session
-
-The public Stratum listener used a global 64-permit semaphore but no per-source
-limit. `mining.authorize` is intentionally permissionless, and even an entirely
-silent TCP client retained a permit for up to the 120-second idle timeout. A
-single machine could therefore open 64 connections and prevent all miners from
-connecting. A client that stopped reading responses could retain a task longer
-because response writes had no timeout.
-
-Impact: loss of public mining availability and a practical reduction in PoW
-issuance participation. This does not directly create coins or alter consensus.
-
-Reproduction before the patch: instantiate `StratumSessionLimiter::new(64)` and
-acquire all permits using the same source address; all 64 acquisitions succeed.
-The regression tests now show that only four sessions are accepted for one IPv4
-address or IPv6 /64 while other sources retain capacity:
-
-```sh
-cargo test --locked stratum_session_limiter
-```
-
-Patch:
-
-- enforce four active sessions per IPv4 address or IPv6 /64 in addition to the
- global limit;
-- release both counters through an RAII permit;
-- bound response writes to ten seconds.
-
-Residual risk: sixteen independently routed source groups can still consume the
-global limit. Public deployments should add upstream connection/rate limiting.
-
-## IUNA-2026-002 — invalid mine shares amplified into historical chain scans
-
-Each mine transaction validation called
-`mine_difficulty_bits_for_anchor_height`. That function iterated over every
-retarget window and scanned the complete chain again for each window. At chain
-height `H` the work was approximately `H * floor(H / 10)` block visits per
-share. At height 100,000 that is about one billion predicate visits. Stratum
-performed this work while holding the global node mutex, before rejecting an
-invalid share. Any remote client could authorize with a syntactically valid
-wallet address and repeatedly submit arbitrary nonces.
-
-Impact: growing CPU exhaustion and starvation of block, gossip, wallet, and UI
-operations. Exploit cost is only a network connection and request bandwidth.
-
-Regression test:
-
-```sh
-cargo test --locked applied_window_cache_preserves_retarget_results_for_constant_time_lookup
-```
-
-Patch: maintain the derived difficulty after every completed ten-block window.
-Normal mine validation is now an indexed lookup. Cache updates examine only the
-latest ten blocks and snapshot restoration reconstructs the same cache while
-replaying blocks. A linear compatibility fallback exists only for synthetic or
-migration-created ledgers whose cache is absent.
-
-The patch changes no consensus value or serialized chain format.
-
-## IUNA-2026-003 — first sync trusts an unpinned bootstrap genesis
-
-A setup-placeholder node accepts any self-consistent genesis and launch profile
-served by its selected bootstrap peer. The network ID is checked, but the live
-candidate genesis is not pinned in code or required through an independently
-supplied checkpoint. P2P node identity proves continuity of the peer's
-self-generated key; it does not establish that the key is an authorized
-candidate bootstrap identity.
-
-Impact: a new operator whose DNS, route, configuration, or only bootstrap peer
-is controlled can be placed on a valid but attacker-created chain. Subsequent
-same-genesis validation will keep that node isolated from the real candidate.
-
-The production database and repository manifest both record genesis
-`3d677cd7ced1c04d3a276cbee7ea38076e34ac65f18a2c9b8286a4872d986a9a`, but the
-manifest still describes v0.4.18 while this audit targets v0.4.28.
-
-Patch:
-
-- pin the production genesis in the mainnet-candidate binary;
-- reject a mismatched genesis during direct join, setup-placeholder bootstrap,
- and persisted candidate-chain startup;
-- prevent `--genesis` from creating a second mainnet-candidate chain while
- leaving local testnet genesis creation available.
-
-Residual hardening before promotion: publish and sign an updated candidate
-manifest, pin a finalized checkpoint, and pin bootstrap identities or obtain
-the checkpoint from at least two independently operated sources.
-
-## IUNA-2026-004 — full mempool rejects higher-fee transactions
-
-The mempool accepts any non-zero fee. At 10,000 entries it rejects every new
-transaction before comparing fee rate or evicting lower-value entries. An
-attacker with confirmed funds can create a long sequence of minimum-fee
-transactions and pin admission until blocks drain the pool. The 8 MiB byte cap
-bounds memory, but not admission fairness or repeated validation cost.
-
-Impact: delayed transaction propagation and local CPU load. Consensus remains
-valid and directly connected block producers can still include transactions.
-
-Patch: once the count or byte bound is reached, the lowest-fee-rate independent
-package becomes the dynamic relay floor. A candidate is admitted only when its
-fee rate is strictly higher; eviction removes the package's pending and orphan
-descendants atomically and recalculates both byte counters. Ordinary low-fee
-admission and block consensus remain compatible. Regression tests prove that a
-full pool accepts a higher-fee independent transaction, descendants are removed
-as one package, and the byte/count counters remain exact.
-
-## Verification evidence
-
-The focused regression tests passed:
-
-```text
-stratum_session_limiter: 3 passed
-applied_window_cache_preserves_retarget_results_for_constant_time_lookup: 1 passed
-cargo clippy --locked --all-targets --all-features -- -D warnings: passed
-```
-
-The initial sandboxed run completed 330 tests successfully; its 15 socket-based
-P2P tests could not call `bind(2)`. The suite was then repeated locally with
-loopback permission and passed completely: 432 passed, 0 failed, and 36
-long-running tests were ignored by their existing configuration.
-
-`scripts/check-dependencies.sh` could not refresh RustSec because the sandbox
-made the Cargo advisory database lock path read-only. Dependency audit status is
-therefore not claimed by this report.
-
-## Promotion recommendation
-
-Do not promote to mainnet until the complete release gate is run on the exact
-final revision, the candidate manifest is updated, and the custom VDF plus
-economic finality assumptions receive independent review.
diff --git a/docs/security-review.md b/docs/security-review.md
@@ -1,293 +0,0 @@
-# Security Review Checklist
-
-This document tracks the security review of the live mainnet candidate before a
-mainnet promotion decision. It is a review ledger, not a claim that mainnet is
-safe. Keep the roadmap security-review checkbox open until every
-promotion-blocking item below is resolved or explicitly accepted.
-
-## Review Scope
-
-### Consensus Validation
-
-Review:
-
-- block validation, legacy finality depth, objective finality certificates and
- fork choice, recovery blocks, and VDF checks;
-- burn ticket eligibility, lineage limits, burn-list attestations, and bundle quorum;
-- supply accounting across transfers, burns, fees, mine actions, and reorgs;
-- genesis, snapshot adoption, and candidate-to-mainnet promotion rules.
-
-Primary code:
-
-- `src/domain/ledger_apply.rs`
-- `src/domain/ledger_chain.rs`
-- `src/domain/ledger_consensus.rs`
-- `src/domain/ledger_reveal.rs`
-- `src/domain/ticket.rs`
-- `src/domain/vdf/mod.rs`
-- `src/domain/protocol.rs`
-
-Evidence already in the tree:
-
-- adversarial consensus tests in `src/domain/adversarial_tests.rs`;
-- activation-boundary, quorum, higher-checkpoint, conflicting-certificate, and
- pre-activation-history tests in `src/domain/ledger_reveal.rs` and
- `src/domain/ledger_chain.rs`;
-- release soak test in `tests/properties.rs`;
-- protocol rules documented in `docs/protocol.md`;
-- reset, joining, recovery, and rollback procedures in `docs/operator-playbooks.md`.
-
-### Transaction And Mempool Validation
-
-Review:
-
-- signature validation and canonical transaction IDs;
-- rejection of zero-fee non-genesis transfers and burns;
-- double-spend and replay rejection;
-- transaction count, block byte size, and economic byte-size accounting;
-- block validation independence from local mempool contents;
-- burn bundles cannot make the same burn count both as attested burn-list data
- and as normal block transaction space.
-
-Primary code:
-
-- `src/domain/ledger_ops.rs`
-- `src/domain/ledger_mempool.rs`
-- `src/domain/ledger_prepare.rs`
-- `src/domain/transaction.rs`
-- `src/domain/selection.rs`
-- `src/domain/validation.rs`
-
-Transaction signing automatically switches at height `1000` from the legacy
-format to binary format v1, which commits the launch-profile chain ID and local
-genesis hash for transfers, burns, native mine actions, and Stratum mine actions.
-Historical blocks and genesis allocation outpoints retain their original rules,
-while blocks from the activation height have no legacy fallback. Fixed vectors
-and boundary/replay tests cover pre-activation compatibility, candidate/mainnet/
-testnet IDs, distinct genesis hashes, native and Stratum proofs, and hexadecimal
-casing malleability under format v1.
-
-Chain-wide transaction-ID replay protection activates at the same height.
-Validators maintain an index reconstructed from genesis/snapshots and reject an
-activated block when any transaction ID already exists in its history. This
-closes an issuance bug where an inputless mine proof could be included again
-after its original reward outpoint had been spent, recreating the output. Tests
-cover the activation boundary, the full block-validation path, and index rebuild
-from a persisted snapshot.
-
-Evidence already in the tree:
-
-- focused adversarial tests for zero-fee burns, bundle import ordering,
- duplicate burn handling, mempool-independent block validation, and block
- selection bounds;
-- compact economic-size tests in `src/domain/validation.rs`.
-
-### P2P Input Handling
-
-Review:
-
-- network ID, genesis hash, protocol version, and setup-placeholder handshake
- behavior;
-- inbound session caps and rejected-session metrics;
-- gossip envelope item limits for blocks, transactions, burn bundles, and
- snapshots;
-- snapshot validation before adoption or reorg;
-- malformed compact snapshot and gossip JSON behavior.
-
-Primary code:
-
-- `src/adapters/p2p/handshake.rs`
-- `src/adapters/p2p/line_codec.rs`
-- `src/adapters/p2p/network.rs`
-- `src/adapters/p2p/fetch.rs`
-- `src/adapters/p2p/sync.rs`
-- `src/adapters/chain_store/compact.rs`
-
-Evidence already in the tree:
-
-- P2P tests in `src/adapters/p2p/tests.rs`;
-- compact snapshot malformed-input tests in `src/adapters/chain_store/compact.rs`;
-- compact block-size boundary tests proving that selection and consensus use the
- same current compact snapshot block-body encoder;
-- fuzz targets for `p2p_envelope`, `compact_snapshot`, and `domain_json`.
-
-### Wallet, Key Storage, And HTTP Auth
-
-Review:
-
-- wallet seed encryption, KDF parameters, nonce handling, and authenticated
- encryption;
-- atomic wallet/config/chain writes and crash consistency;
-- password setup, login, session expiry, logout, and password change behavior;
-- CSRF origin checks, forwarded-header handling, and login backoff;
-- operational guidance that the management UI stays local-only.
-
-Primary code:
-
-- `src/adapters/wallet_store.rs`
-- `src/adapters/config_store.rs`
-- `src/adapters/http/request_auth.rs`
-- `src/adapters/http/auth.rs`
-- `src/adapters/http/actions.rs`
-
-Evidence already in the tree:
-
-- HTTP/auth abuse tests for CSRF, lockout/backoff, session expiry, and
- forwarded-header spoofing;
-- wallet/config/chain crash-consistency tests;
-- wallet/config persistence metadata fuzz target;
-- local-only UI guidance in `README.md`.
-
-### Stratum
-
-Review:
-
-- listener disabled by default unless enabled in settings or started with
- `--stratum`;
-- line size, idle timeout, job cache, session, and connection limits;
-- share parsing, worker address validation, and Stratum header validation;
-- operational exposure guidance for public mining endpoints.
-
-Primary code:
-
-- `src/adapters/stratum.rs`
-- `src/domain/stratum.rs`
-- `src/domain/validation.rs`
-- `src/cli.rs`
-- `src/main.rs`
-
-Evidence already in the tree:
-
-- Stratum parser fuzz target;
-- session-limit and request-limit tests;
-- release soak test that exercises Stratum-enabled and Stratum-disabled nodes.
-
-## Required Release Evidence
-
-For every release deployed to the live mainnet-candidate network, attach or
-publish logs for:
-
-```sh
-./scripts/check-dependencies.sh
-cargo test --locked
-cargo check --locked --manifest-path fuzz/Cargo.toml
-cargo run --locked --manifest-path fuzz/Cargo.toml --bin p2p_envelope -- -runs=256 fuzz/corpus/p2p_envelope
-cargo run --locked --manifest-path fuzz/Cargo.toml --bin compact_snapshot -- -runs=256 fuzz/corpus/compact_snapshot
-cargo run --locked --manifest-path fuzz/Cargo.toml --bin domain_json -- -runs=256 fuzz/corpus/domain_json
-cargo run --locked --manifest-path fuzz/Cargo.toml --bin stratum_request -- -runs=256 fuzz/corpus/stratum_request
-cargo run --locked --manifest-path fuzz/Cargo.toml --bin wallet_config -- -runs=256 fuzz/corpus/wallet_config
-cargo run --locked --manifest-path fuzz/Cargo.toml --bin vdf_proof -- -runs=16 fuzz/corpus/vdf_proof
-cargo test --locked --release --lib domain::adversarial_tests:: -- --ignored
-cargo test --locked --release --features e2e --test properties -- --ignored
-./e2e/iuna_e2e.py test post-activation --build --evidence-dir release-evidence
-```
-
-On macOS hosts with the optional Python/C++ `chiavdf` package installed, also
-run the byte-for-byte compatibility test:
-
-```sh
-IUNA_CHIAVDF_PYTHON=/path/to/python cargo test --locked --release domain::vdf::wesolowski::tests::prover_matches_chiavdf_python_binding -- --ignored --nocapture
-```
-
-The deployment script runs these gates for release builds. Keep the exact
-command output with the candidate release notes so independent operators can
-see which revision was tested.
-
-## Promotion-Blocking Review Items
-
-- VDF implementation: `docs/protocol.md` documents the Rust-only,
- Chia-compatible class-group Wesolowski VDF and its
- `classgroup-wesolowski-bqfc-v1` solution encoding. The implementation must not
- depend on GMP, MPIR, or native runtime libraries. On local Apple Silicon, a
- 100,000-round release benchmark with seed `iuna-vdf-prover-benchmark` measured
- about `0.89s` to `0.92s` for the current Rust-only checkpoint prover and about `1.78s`
- for the Rust-only constant-memory prover after moving output squaring, proof
- composition, and proof squaring onto the local custom `Vec<u64>` limb backend
- with reusable division/GCD/reduction scratch buffers, Lehmer-style full and
- partial XGCD batching, x-only extended-GCD paths for call sites that do not
- need the second Bezout coefficient, positive-input left-GCD fast paths,
- mutable Lehmer linear-combination outputs for XGCD batch updates, `u64`
- Lehmer quotient windows, scratch-backed scalar combinations, one-limb scalar
- multiplication into scratch buffers, quotient/remainder-directed
- division outputs, exact power-of-two division fast paths, and owned
- add/sub/shift helpers for formula temporaries, clone-free signed subtraction,
- scratch-backed reduction steps with small-quotient fast paths and quotient
- comparison that avoids temporary doubled limbs,
- tighter add/sub limb loops, one-limb multiplication, small-shift fast paths,
- plus sparse proof buckets that keep empty buckets implicit instead of cloning
- full identity forms or composing identity aggregates, and per-pass incremental
- checkpoint bucket selection with a 100,000-round checkpoint parameter floor of
- `k = 10`, adaptive multi-pass fitting that keeps normal large workloads within
- the fixed checkpoint memory budget instead of selecting the constant-memory
- fallback, release thin-LTO/codegen-unit tuning, and replacement of
- per-checkpoint modular exponentiation with one modular exponentiation plus
- fixed modular steps; an official
- Python/C++ `chiavdf` reference measurement was about `0.673s`. Phase profiling
- measured about `0.78s` to `0.81s` in output squaring and about `0.11s` to `0.12s` in proof
- construction. The limb backend covers signed limb arithmetic, division, full
- and partial XGCD, production NUDUPL/NUCOMP, checkpoint bucket selection, and
- class-group exponentiation.
- Before promotion, keep running fixed vectors, differential VDF tests, fuzz
- targets, release benchmarks, and the optional `chiavdf` compatibility test on
- at least one macOS host. Windows MSVC release benchmarking remains a platform
- readiness item, not a wire-compatibility requirement.
-- Wallet/key handling: reviewed for the mainnet-candidate run. Wallet files use
- versioned JSON. Plaintext seed files are still supported for legacy/setup
- flows, but setting a management password encrypts existing or newly generated
- wallets before normal authenticated use. Encrypted wallets store no plaintext
- seed, use `chacha20poly1305` with a random 16-byte salt, random 12-byte nonce,
- PBKDF2-SHA256 at 210,000 iterations, and bind the ciphertext to the wallet
- address as AEAD associated data. Unlock rejects unsupported algorithms, KDFs,
- unreasonable PBKDF2 iteration counts, wrong salt/nonce lengths, wrong
- passwords, and address/seed mismatches. Wallet writes are atomic and use
- `0600` temporary files on Unix. Management UI password hashes also use
- PBKDF2-SHA256 with bounded iteration counts, login backoff, session expiry,
- `HttpOnly`/`SameSite=Strict` cookies, CSRF same-origin checks, and trusted
- forwarded headers only from loopback proxies. First-run password setup also
- requires an exact loopback Host/Origin/port match and a cryptographically
- random, one-time `HttpOnly` setup capability issued only to the local
- management page. Residual accepted risk for the candidate: PBKDF2 is CPU-hard
- rather than memory-hard, so operators must use strong unique passwords and
- keep the management UI local or otherwise protected.
-- Public exposure: verify bootnodes expose only the intended P2P and optional
- Stratum ports, and that the management UI remains bound to a local or
- otherwise protected address.
-- Candidate manifest: because the candidate is live, release coordination must
- publish and preserve the real genesis hash, network ID, bootnodes, checksums,
- reset and rollback instructions, release tag, and git commit as part of the
- candidate record. The manifest remains a promotion blocker until it is
- published and reviewed. The protocol and operator playbooks are the maintained
- in-tree references.
-- Release evidence: keep successful release-gate logs from the exact tagged
- candidate revision.
-- Desktop dependency security: the project and release builders use Rust 1.88.
- The desktop lockfile pins `quick-xml 0.41.0`, `plist 1.10.0`, and
- `time 0.3.47`, removing RUSTSEC-2026-0194, RUSTSEC-2026-0195, and
- RUSTSEC-2026-0009. `scripts/check-dependencies.sh` audits the root, fuzz, and
- desktop lockfiles without vulnerability ignores and rejects unapproved
- dependency sources or license identifiers. It is mandatory in
- `deployment.sh` and the CI security job. CI also test-builds the desktop crate
- on Linux, macOS, and Windows. RustSec still reports non-vulnerability warnings
- for Tauri's Linux GTK3 stack (unmaintained crates and the `glib::VariantStrIter`
- advisory); iuna does not call that iterator API directly. Reassess this
- transitive stack on every Tauri upgrade and no later than 2026-11-30.
-- Height `1000` activation: the release activates both grinding resistance and
- transaction signing format v1 plus chain-wide transaction-ID replay protection
- automatically. Nodes running pre-activation software cannot follow candidate
- history at or after height `1000`. The activation itself requires no chain-state reset
- or operator migration command, but mixed versions split at height `1000`.
-
-## Sign-Off Table
-
-Do not mark the roadmap security-review item complete until this table is
-filled in for the candidate release.
-
-| Area | Reviewer | Date | Result | Notes |
-| --- | --- | --- | --- | --- |
-| Consensus validation | Codex | 2026-09-07 | Automated candidate review passed; independent promotion review pending | Exact-revision unit, adversarial, corrected release-soak, and process-level partition gates passed. Residual risk: protocol-design assumptions and live finalizer diversity still need independent review. |
-| Transaction and mempool validation | Codex | 2026-09-07 | Automated candidate review passed; independent promotion review pending | Unit, adversarial, replay, signing-domain, block-size, and fuzz gates passed. Residual risk: no external cryptographic or economic review. |
-| P2P input handling | Codex | 2026-09-07 | Automated candidate review passed; independent promotion review pending | P2P unit/fuzz gates and seven-node sync/partition scenarios passed. Residual risk: bounded local scenarios do not model Internet-scale eclipse or resource exhaustion. |
-| Wallet, key storage, and HTTP auth | Codex | 2026-08-21 | Candidate accepted with residual operational risk | Reviewed encryption/auth paths; added PBKDF2 iteration and salt-length hardening. |
-| Stratum | Codex | 2026-09-07 | Automated candidate review passed; independent promotion review pending | Parser fuzz, limits, signing-domain tests, and release soak passed. Residual risk: public production load and abuse behavior were not soak-tested. |
-| Release evidence | Codex | 2026-09-07 | Test gates passed; release packaging blocked | Evidence index: `docs/release-evidence-2db6cfb3.md`. The optional `chiavdf` package was unavailable. Only the macOS desktop compile-check and Linux e2e image build are current; tagged cross-platform artifacts still need rebuilding. |
-| Candidate manifest | Codex | 2026-09-07 | Blocked | `docs/candidate-manifest.md` records the network identity, but tested commit `2db6cfb...` is untagged and existing v0.4.17 artifacts belong to `0b1452...`; publication and independent review remain open. |