Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion Developer/BACK_LOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -32,4 +32,4 @@
| BL-23 | DP / Privacy (cache_model_0) | `clip_scope: global` default paired with an unreviewed `clipping_norm: 1.0` may over-clip real weights | [PR #109](https://github.com/InfiniteZeroFoundation/DevNet/pull/109) (`fix/dp-sensitivity`) correctly ties noise to the clip (`noise_scale = noise_multiplier * clipping_norm`) and defaults `clip_scope` to `global` so the clip actually bounds the combined L2 norm the noise is calibrated against — the sensitivity-calibration fix itself is sound (`per_layer` only bounds the combined norm at `clipping_norm * sqrt(n)`, not `clipping_norm`, so pairing it with the new noise formula would under-noise as tensor count grows). But `cache_model_0/manifest.json`'s `clipping_norm: 1.0` was never revisited: under the old `per_layer` scope it bounded each tensor independently to norm 1.0; under `global` it bounds the *entire model's combined* L2 norm to 1.0, a much tighter constraint for any model with more than one floating tensor (`sqrt(Σ‖tensor_i‖²)` grows with tensor count even if no individual tensor's norm changes). No test in PR #109 exercises this against `cache_model_0`'s real trained `state_dict` (the new tests use synthetic tensors), so it's unverified whether the new default clips — and thus degrades — the reference model's weights far more aggressively than before. Follow-up: run `apply_dp_mechanism`/`clip_state_dict` against `cache_model_0`'s actual trained weights under the new default and retune `clipping_norm` if the combined-norm bound turns out to be destructive. | P3 (verify before/at merge) | PR #109 review, Sep 8, 2026 | 🆕 New — unaddressed; `cache_model_0/manifest.json`'s `clipping_norm` still `1.0`, and `tests/test_cache_client_dp.py` still exercises synthetic tensors (`build_small_state_dict`), not real trained weights |
| BL-24 | DP / Privacy (cache_model_0) | F4 — Laplace noise calibrated against an L2 clip, not the L1 sensitivity it's normally calibrated against | `post_training_laplace`'s `laplace_scale` is scaled by the same `clipping_norm` as the Gaussian mechanisms (`clip_state_dict`'s L2-norm clip), but the Laplace mechanism's textbook privacy guarantee is calibrated against L1 sensitivity, not L2. [PR #109](https://github.com/InfiniteZeroFoundation/DevNet/pull/109) flagged this explicitly rather than silently assuming it's fine (`Documentation/technical/services/clients.md:210-212`: "Laplace noise calibrated against an L2 clip is an open question tracked separately"), and [#99](https://github.com/InfiniteZeroFoundation/DevNet/issues/99)'s F4 (`Documentation/technical/audits/dp-mechanism-review.md` §F4) called the structural mismatch confirmed but left the exact magnitude/severity for a DP specialist's sign-off — explicitly excluded from #99's scope rather than fixed. [#119](https://github.com/InfiniteZeroFoundation/DevNet/pull/119) (which closed #99's remaining F8 items) left F4 untouched, so nothing currently tracks it now that #99 is closed. Needs either a DP specialist's opinion that L2-calibrated Laplace is acceptable as-is (and the open-question note downgraded to an explanation), or a fix (e.g. recalibrating against an actual L1 clip, or reclassifying `post_training_laplace` as experimental alongside F5's `per_layer` treatment) before any ε is claimed for it. | P3/P4 (needs DP specialist input first) | [#99](https://github.com/InfiniteZeroFoundation/DevNet/issues/99) F4 (excluded from scope), `Documentation/technical/audits/dp-mechanism-review.md` §F4, Sep 10, 2026 | 🆕 New — unaddressed; `Documentation/technical/services/clients.md`'s open-question note on L2-calibrated Laplace noise is unchanged since PR #109/#119 |
| BL-25 | Tooling / reference model (cache_model_0) | `cache_model_0/abis/` task-contract artifacts are stale vs. `foundry/src` | `cache_model_0/abis/DINTaskCoordinator.json` and `DINTaskAuditor.json` are full hardhat artifacts (abi + bytecode) last regenerated 2026-06-09, missing 67 ABI entries present in `foundry/src` for the coordinator (104 vs 170) and 96 for the auditor (68 vs 158), with pre-foundry constructors. [PR #171](https://github.com/InfiniteZeroFoundation/DevNet/pull/171) regenerated the six bundled `dincli/abis/` files from `foundry/out` but deliberately left these alone: [cache_model_0/manifest.json](../cache_model_0/manifest.json)'s `task_contracts` block pins each artifact to an IPFS CID, records `"type": "hardhat-artifact"` and a hardhat/cancun/optimizer-off `compilation` block, and carries deployed addresses, and dincli resolves task artifacts by CID. Regenerating the files locally would leave the manifest describing artifacts it no longer points to. Needs one pass: regenerate both from `foundry/out` (with bytecode, e.g. `dincli system dump-abi --bytecode --output cache_model_0/abis`), update the manifest's artifact type and compilation metadata to foundry, re-pin to IPFS and update the CIDs. Addresses only change on a redeploy. | P3/P4 | PR #171 merge (2026-09-26): out of scope for the PR's ABI refresh | 🆕 New — unaddressed |
| BL-26 | Solidity/foundry (task contracts) | Batch-assignment seed lock (H-2) shares BL-11's re-roll residual, plus a new pool-reshaping gap | `DINTaskCoordinator.autoCreateTier1AndTier2`/`createAuditorsBatches` (task_240926_18 Part B, issue #156 H-2 aggregation side) reuse BL-11's future-block-seed + permissionless-lock pattern (`lockAggSeed`/`lockAuditSeed`), so they inherit its residual (2): the model owner can decline to lock a seed they dislike and wait out the ~256-block `blockhash` window for a fresh draw — repeatable, since nothing locks automatically today. A second, distinct gap not present in BL-11's `_assignFreshSubgroup` (which shuffles a fixed pool and only lets an exiting validator drop itself, not re-roll the rest): `_activeAggregatorPool`/`_activeAuditorPool` are evaluated at `autoCreateTier1AndTier2`/`createAuditorsBatches` call time, *after* the seed is already public, and Fisher-Yates re-rolls the whole assignment on any pool-size change — so a validator can unstake between lock and create to reshape everyone else's batch. Cost to the attacker is real but modest (their own Sybils sit out the GI and enter unbonding). Ready-made fix for the pool-reshaping gap: adopt `_assignFreshSubgroup`'s pattern — shuffle the fixed per-GI registration list (`dinAggregators[_GI]` / the auditor equivalent) with the locked seed, then skip inactive validators while filling seats, so an unstake only forfeits the leaver's own seat instead of re-rolling everyone else's. | P3/P4 | [PR #191](https://github.com/InfiniteZeroFoundation/DevNet/pull/191) review, Sep 29, 2026 | 🟡 Partially mitigated — the decline-to-lock re-roll is narrowed by a validator-side lock in dincli, added at the PR #191 merge (`dincli aggregator lock-seed` / `dincli auditor lock-seed`, and automatically in `show-t1-batches`/`show-t2-batches`/`lms-evaluation show-batch` before batches exist): any validator online after the seed block locks it, so the owner only gets a re-roll if nobody else is. A contract-side cap on re-anchors was considered and deferred: with no GI-abort path, a GI capped out would be stuck forever (`endGI` needs `AggregatorsSlashed`, `startGI` needs `GIended`), locking validators' registration slots and the reward pool — it needs a GI-abort design (who may abort, where the reward pool goes) first. Pool-reshaping gap unaddressed. Documented as residuals in the PR (`DINTaskCoordinator.md` §11.1). Sequencer-trust residual (shared with BL-11) tracked in [issue #178](https://github.com/InfiniteZeroFoundation/DevNet/issues/178); the re-roll-by-declining-to-lock and pool-reshaping gaps above have no dedicated issue yet, same as BL-11's own un-issued residual (2) |
| BL-26 | Solidity/foundry (task contracts) | Batch-assignment seed lock (H-2) shares BL-11's re-roll residual, plus a new pool-reshaping gap | `DINTaskCoordinator.autoCreateTier1AndTier2`/`createAuditorsBatches` (task_240926_18 Part B, issue #156 H-2 aggregation side) reuse BL-11's future-block-seed + permissionless-lock pattern (`lockAggSeed`/`lockAuditSeed`), so they inherit its residual (2): the model owner can decline to lock a seed they dislike and wait out the ~256-block `blockhash` window for a fresh draw — repeatable, since nothing locks automatically today. A second, distinct gap not present in BL-11's `_assignFreshSubgroup` (which shuffles a fixed pool and only lets an exiting validator drop itself, not re-roll the rest): `_activeAggregatorPool`/`_activeAuditorPool` are evaluated at `autoCreateTier1AndTier2`/`createAuditorsBatches` call time, *after* the seed is already public, and Fisher-Yates re-rolls the whole assignment on any pool-size change — so a validator can unstake between lock and create to reshape everyone else's batch. Cost to the attacker is real but modest (their own Sybils sit out the GI and enter unbonding). Ready-made fix for the pool-reshaping gap: adopt `_assignFreshSubgroup`'s pattern — shuffle the fixed per-GI registration list (`dinAggregators[_GI]` / the auditor equivalent) with the locked seed, then skip inactive validators while filling seats, so an unstake only forfeits the leaver's own seat instead of re-rolling everyone else's. | P3/P4 | [PR #191](https://github.com/InfiniteZeroFoundation/DevNet/pull/191) review, Sep 29, 2026 | 🟡 Partially mitigated — the decline-to-lock re-roll is narrowed by a validator-side lock in dincli, added at the PR #191 merge (`dincli aggregator lock-seed` / `dincli auditor lock-seed`, and automatically in `show-t1-batches`/`show-t2-batches`/`lms-evaluation show-batch` before batches exist): any validator online after the seed block locks it, so the owner only gets a re-roll if nobody else is. A contract-side cap on re-anchors was considered and deferred: with no GI-abort path, a GI capped out would be stuck forever (`endGI` needs `AggregatorsSlashed`, `startGI` needs `GIended`), locking validators' registration slots and the reward pool — it needs a GI-abort design (who may abort, where the reward pool goes) first. Pool-reshaping gap unaddressed. Documented as residuals in the PR (`DINTaskCoordinator.md` §6.3). Sequencer-trust residual (shared with BL-11) tracked in [issue #178](https://github.com/InfiniteZeroFoundation/DevNet/issues/178); the re-roll-by-declining-to-lock and pool-reshaping gaps above have no dedicated issue yet, same as BL-11's own un-issued residual (2) |
2 changes: 1 addition & 1 deletion Developer/ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -167,7 +167,7 @@ By the end of P4, DIN has an operational daemon capable of autonomous task disco
| P4-9.2 | Daemon | Daemon Release (dind v1.0.0) | Package `dind` binary and Docker image alongside `din-node` · Installation and usage documentation · Release notes · Community onboarding materials | Public release. | P4-9.1 | Critical | Long-term (P4) | | 1 week | | Nov 23–27, 2026 | | Santiago | | 📋 Planned | P4 Week 13. |
| **— P4: Core Protocol / On-chain Indexer (Robbert) —** | | | | | | | | | | | | | | | | |
| P4-IDX1 | Core Protocol / Contracts | On-chain Indexer Design | Choose indexing approach: The Graph Protocol subgraph (preferred — Robbert has production experience) vs. lighter alternative (Ponder, custom event-poller) — document tradeoff · Design entity schema: queryable entities for all 4 platform contract event streams (`ModelRegistered`, `ValidatorSlashed`, `RewardClaimed`, `GIStarted`/`GIEnded`) · Write `subgraph.yaml` and `schema.graphql` · Set up local Graph node against Hardhat local chain for development testing · Design P4 daemon event schema: which events `dind` needs to subscribe to, what current coverage gaps exist (feeds into P4-7.1) | Foundation for replacing RPC-loop call sites in `dincli` with indexer-backed queries. Dynamic data sources for task-level contracts (`DINTaskCoordinator`/`DINTaskAuditor`) are deferred to P5+ (materially harder pattern). | P3-6.3b (stable contract ABIs), P3-PR13 (proxy contracts deployed) | High | Medium-term | | 1 week | | Oct 2026 | | Robbert | | ⚡ In Progress | Implemented in PR [#29](https://github.com/InfiniteZeroFoundation/DevNet/pull/29) (schema, 34 entities) + [#72](https://github.com/InfiniteZeroFoundation/DevNet/pull/72) (P3-staking event wiring, verified byte-for-byte against `DinValidatorStake.sol`), against `feat/din-indexer` — not yet merged to `develop` (no `subgraph/` there today). PR #29 has two small, real blockers: invalid GraphQL syntax at `schema.graphql:412` breaking `graph codegen`, and a broken (non-`CliRunner`) test file; full detail in [discussion #139](https://github.com/InfiniteZeroFoundation/DevNet/discussions/139). Dynamic task-contract indexing, originally deferred to P5+, was reclassified in-scope (Umer, Jul 13) but the underlying contract events it needs (`LocalModelSubmitted`, `T1AggregationSubmitted`, etc.) don't exist anywhere in `foundry/src` yet and have no owner — the one piece of #24 that's unstarted, not just unmerged. |
| P4-IDX2 | Core Protocol / Contracts | On-chain Indexer Implementation | Implement AssemblyScript (or TypeScript for Ponder) mapping handlers for all platform contract events · Deploy subgraph to local Graph node · Verify all event entities index correctly against test transactions · Replace `dincli/cli/dinrep.py` pending-request enumeration loop (~lines 443–467) with indexer-backed query (clearest candidate: `for idx in range(totalModelRequests)`) · Document: setup steps, local run instructions, ≥3 example queries covering validator registry, model registry, and reward history | Converts the most expensive RPC-polling loop to an indexed query. Other candidates for follow-up: `dincli/cli/modelownerd/lms.py` ~56–68 and `aggregation.py` ~76–144. | P4-IDX1 | High | Short-term (P4) | | 2 weeks | | Oct–Nov 2026 | | Robbert | | ⚡ In Progress | Handlers implemented in PR [#29](https://github.com/InfiniteZeroFoundation/DevNet/pull/29)/[#72](https://github.com/InfiniteZeroFoundation/DevNet/pull/72) (31 handlers across 4 data sources, local Graph node via `docker-compose`, 14+ example queries) — `dincli/cli/dinrep.py`'s RPC-loop replacement is done in the PR, just not merged to `develop` yet. Recommended merge order (#29 fixes first, then #72) in [discussion #139](https://github.com/InfiniteZeroFoundation/DevNet/discussions/139). 5 of the 31 handlers are commented out pending the unowned contract-event work noted in P4-IDX1. |
| P4-IDX2 | Core Protocol / Contracts | On-chain Indexer Implementation | Implement AssemblyScript (or TypeScript for Ponder) mapping handlers for all platform contract events · Deploy subgraph to local Graph node · Verify all event entities index correctly against test transactions · Replace the pending-request enumeration loops in `list_pending_requests` (`dincli/cli/dinrep.py`) with indexer-backed query (clearest candidate: `for idx in range(totalModelRequests)`) · Document: setup steps, local run instructions, ≥3 example queries covering validator registry, model registry, and reward history | Converts the most expensive RPC-polling loop to an indexed query. Other candidates for follow-up: `dincli/cli/modelownerd/lms.py` ~56–68 and `aggregation.py` ~76–144. | P4-IDX1 | High | Short-term (P4) | | 2 weeks | | Oct–Nov 2026 | | Robbert | | ⚡ In Progress | Handlers implemented in PR [#29](https://github.com/InfiniteZeroFoundation/DevNet/pull/29)/[#72](https://github.com/InfiniteZeroFoundation/DevNet/pull/72) (31 handlers across 4 data sources, local Graph node via `docker-compose`, 14+ example queries) — `dincli/cli/dinrep.py`'s RPC-loop replacement is done in the PR, just not merged to `develop` yet. Recommended merge order (#29 fixes first, then #72) in [discussion #139](https://github.com/InfiniteZeroFoundation/DevNet/discussions/139). 5 of the 31 handlers are commented out pending the unowned contract-event work noted in P4-IDX1. |
| P4-IDX3 | Core Protocol / Contracts | Indexer Integration + P3 Docs Wrap-up | Wire indexer into `dincli` test suite · Verify replaced RPC-loop call site passes tests against indexed local node · Address any open audit findings requiring contract changes · Finalize any outstanding P3 public documentation · Handoff document: what P4 contract work follows (task-level contract indexing, event schema extensions for `dind`) | Completes contract-side P4 integration and closes all P3 documentation gaps. | P4-IDX2, P3-6.3b | High | Long-term (P4) | | 1 week | | Nov 2026 | | Robbert | | 📋 Planned | Blocked behind P4-IDX1/IDX2 actually merging to `develop` first — neither has, as of Sep 11, 2026. |
| **— P4: Tokenomics / Fair Launch —** | | | | | | | | | | | | | | | | |
| P4-FL1 | Cryptoeconomics / Tokenomics | Fair-Launch Validator Token Distributor (contract slice) | Merkle-drop claim contract (Transparent Proxy, treasury-Safe admin) · Funded once from treasury · Cliff + linear vesting on claim | Abraham's fair-launch vision: no ICO/pre-sale/VC allocation, DIN distributed to validators/active participants only. Resolves the ICO-vs-airdrop fork of [MECHANISM_DESIGN §9 item 14](design/MECHANISM_DESIGN.md#9-consolidated-open-decision-list) in favor of the airdrop path. Was not in this table at all — tracked only via [BL-18](BACK_LOG.md) and [issue #75](https://github.com/InfiniteZeroFoundation/DevNet/issues/75); added here to keep the roadmap matching reality. | — | High | — (ad hoc) | | — | | Aug–Sep 2026 | | Robbert (contract), Umer (eligibility scoping) | | ⚡ In Progress | Contract-only slice merged as [PR #77](https://github.com/InfiniteZeroFoundation/DevNet/pull/77) ([task_050826_9](tasks/task_050826_9.md)). Issue #75 stays open: eligibility computation is deliberately deferred until the on-chain indexer (P4-IDX1/IDX2) exists, since eligibility should be computed off indexed data rather than a raw RPC-log script. |
Expand Down
Loading
Loading