A 6-lens hostile panel with adversarial verification confirmed 17 attacks that
would hold in a public takedown. All repaired: the MI contract now carries the
two base-fee floor-lapse windows (12,978,617-13,087,959 and
13,596,033-13,596,141) as explicit ruleset validation exceptions, so a stranger
implementing the written rules no longer halts where our own follower did; the
honesty boundary now states the full record of reject-on-disagreement including
the windows, and why the fact stays load-bearing; the independence claim is
bounded (upstream skeletons yes, AERE ruleset has one author in both forks, so
a common-author bug passes any differential gate by construction); the harness
verdict claims only what it measures, records engine identity via
web3_clientVersion on every run, refuses same-URL endpoint pairs, and prints
its NOT MEASURED block on every run; stage 4 names the live engine (upstream
parallel processing enabled by default, idling on empty blocks) and its
oracle's model limits; 'governed registry' became 'owner-controlled' with the
single-key fact stated. The panel also confirmed the import-proof doc claimed
a two-month validation history where six days is the truth; fixed.
Block-STM enters the kernel through the MachineInterface seam, not beside it. The
one guarantee, stated as a contract and proven: parallel execution produces the
byte-identical state root that serial execution produces, or the kernel refuses
it. The feared failure mode is a silent state divergence under contention, and
that is exactly what the negative control plants.
Run 2026-08-15 (WSL, Rust release build of parallel-executor):
- positive: harness reports 0 mismatches, parallel Block-STM == sequential on
all profiles, seeds, and thread counts 4/8/16.
- negative control: disable the validation phase (the mechanism that catches a
stale read and forces re-execution) and the harness reports MISMATCH on every
contended profile. So the oracle is load-bearing, not applause.
No throughput number is claimed; 8-10x is proven capacity while chain 2800
blocks are empty. Parallel execution is not put on mainnet in this stage; the
equality that would make that safe is proven, so the switch becomes a measured
decision. One coordinated activation if it ever changes an observable, the
discipline proven at block 14,050,000.