Recover 39 RSK direct stales dropped by the defective canonical check - #53
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
A six-agent read-only audit of README, docs/, and docs/chains/ surfaced count drift and factual errors accumulated across the July-August refreshes. This pass applies the verified fixes: Namecoin's full-block blob counts refresh for the 102ba00 upstream pin (323 matched of 1,326 without), three chain notes drop false provenance claims (bitcoin-vault's no-node-first superlative, devcoin's chronologically impossible AuxPoW attribution, crown's stale line citations), per-chain upstream sidecar contributions are measured rather than asserted (Crown 11 rows, Fractal 15), the README's dated refresh narration gives way to current totals with a pointer at the canonical history, the four chain docs owning body-invalid rows cross-reference the overlay, the thin-chain notes name the shared classify entry point, the CHANGELOG records the shared-entry-point refactors and the error-block strand, chain docs converge on the house structure and heading forms, and docs/error-blocks.md documents source_chains as provenance-of-admission rather than a census of observing chains, with the 717,696/Elastos worked example that settles the mechanism.
7064f7f to
808c6b4
Compare
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 808c6b47b3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
808c6b4 to
5e9c576
Compare
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5e9c5764f4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
5e9c576 to
f6c3abb
Compare
|
@codex review |
|
Codex Review: Didn't find any major issues. More of your lovely PRs please. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Four defects in current code, each invisible until someone actually re-ran the RSK pipeline, which had not happened since the error-block module landed. The classifier's VALIDATED_COLS had drifted four child-identity columns behind the committed loader input, so a re-run would have silently rewritten a published CSV with a narrower schema; the columns now come from the shared CHILD_HEADER_FIELDS contract and a new test compares the constant against the committed header rather than against itself, which is how the drift went unnoticed. The classifier's three CSV writers and the strict/weak orphan report writer relied on .gitattributes normalization instead of emitting the explicit LF the evidence contract requires. Identity recovery lost the uncle metadata for error-observation parents when the error-block split moved those rows into the rsk_error_blocks.csv sibling, resolving them block_not_found; the sibling is now a metadata source. And a descendant witness surfaced by a fresh reclassification had no path into the identity work list, because that list derives from the monitor evidence whose descendant rows come from the ledger the ancestry run refuses to publish until the identity exists; load_error_observation_rsk_targets generalizes to load_rsk_ledger_targets and --extra-rsk-targets breaks the cycle. A nominated slot is not an asserted identity: every target is still authenticated against the live RSK node.
The monitor projection emits one classification=stale row per accepted direct stale, so the two surfaces are the same set counted twice, but nothing compared them. A regeneration can therefore rewrite a chain's validated CSV and leave the publication behind, with every other check still passing.
…ve canonical check The May 2026 RSK classification decided canonicality from whether getblockheader succeeded rather than from positive confirmations, so every header Bitcoin Core knew as a side-chain block was silently filed canonical and discarded. Seven other chains were remediated for the same defect over June to August; RSK's bespoke classifier was missed. Reclassifying the archived raw extraction with the current shared active-chain test raises the committed set from 298 to 337 accepted direct stales, with all 298 prior rows byte-identical and every one of the 39 additions already present in the pinned upstream census with a full block body that passes the complete gate profile, including the two coinbase checks RSK itself cannot run. The whole publication surface moves together. The child-identity ledger grows 308 to 348, every row authenticated against the live RSK node. The ancestry publication keeps its 21 parent verdicts and gains RSK's witness of the BTC 941,882 descendant, 32 to 33, with the two prior RSK witnesses repinned to the regenerated inventory and their source classifications corrected to unknown. The monitor publication rebuilds RSK at 343 rows, and its rebuilt error observation export fills the i0coin coinbase outputs the previous build's coordinate join had silently missed. Chronological novelty stays 115: the additions shift first-claim attribution only, taking also-in-upstream from 168 to 207. Per-chain novelty views for elastos, syscoin, fractal and xaya move their affected first-claim rows to rsk. The strict/weak views regenerate against the new publication, which also refreshes four chains whose views had drifted from the committed monitor evidence before this change. The sweep coverage floor and the two descendant-ledger test pins follow the data. Both externally attested body-invalid blocks, 783,426 and 784,121, are among the 39 and keep their accepted status per the body-invalid overlay; each is now witnessed by five chains.
…story Every count that the 298-to-337 reclassification moves: the repo totals (3,729 to 3,768 observations, 2,137 to 2,145 unique headers), the witness ledger 32 to 33, RSK's uncle/canonical split 218/80 to 241/96, its pool-label table, its private-inventory splits, the novelty attributions it takes first-claim on in elastos, syscoin, fractal and xaya, and the child-identity totals. Every figure recomputed from the committed CSVs rather than carried from the plan; dated historical statements deliberately keep their contemporaneous numbers. docs/chains/rsk.md now discloses the canonical-check defect the way emercoin.md long has for its own data, and gains the 2026-09-05 integration history entry recording the reclassification, the fifth 941,882 witness, and the monitor rebuild. Fifteen further chain docs stop describing the superseded any-hit-is-canonical decision model as current: the shared classifier treats a header as canonical only on positive confirmations, and a side-chain hit becomes stale only when its predecessor is on the active chain. argentum keeps the old model as provenance for how its committed rows were actually produced, with its measured zero exposure stated alongside. The body-invalid pair 783426/784121 is recorded as witnessed by five chains. CHANGELOG narrates the reclassification and the pipeline fixes that shipped alongside it.
f6c3abb to
f543b1f
Compare
|
@codex review |
|
Codex Review: Didn't find any major issues. 👍 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Summary
This branch closes out the RSK undercount investigation: the May 2026 RSK classification decided whether a recovered Bitcoin header was canonical by testing whether
getblockheadersucceeded, rather than checking for positive confirmations. Any header Bitcoin Core knew as a side-chain block (which is exactly what a recovered stale looks like to a node that saw it) was silently filed as canonical and discarded. The same defect was found and remediated for seven other chains over June to August 2026, recovering 88 observations, but RSK's bespoke classifier never picked up the shared fix. Reclassifying the archived raw extraction with the current active-chain test raises RSK's accepted direct stales from 298 to 337. All 298 previously published rows come out byte-identical; the 39 additions are all already present in the pinned upstream stale-blocks census, and each one's full block body passes the complete validation profile (including the two coinbase-dependent checks RSK's midstate-compressed proof cannot run on its own).The full publication surface moves together, as the data contract requires: the child-identity ledger grows from 308 to 348 rows (every row authenticated against the live RSK node), the stale-descendant ancestry keeps its 21 parent verdicts and gains RSK's witness of the BTC 941,882 descendant (32 to 33 observations), the monitor publication rebuilds RSK at 343 rows, per-chain novelty views shift first-claim attribution for elastos, syscoin, fractal and xaya (RSK's chronological novelty stays 115 since every addition was already upstream), and the strict/weak orphan views regenerate against the new publication. The rebuilt error-observation export also fills the i0coin coinbase outputs that the previous build's coordinate join silently missed, verified against the sha-pinned source row.
Regenerating for the first time since the error-block module landed surfaced four latent defects in current code, each fixed here with a guarding test where one was missing:
VALIDATED_COLShad drifted four child-identity columns behind the committed loader input (the existing test compared the constant to itself), three CSV writers emitted CRLF instead of the explicit LF the evidence contract requires, identity recovery lost uncle metadata for error-observation parents when the error-block split moved those rows to a sibling file, and a newly surfaced descendant witness had no path into the identity work list (a bootstrapping cycle now broken by--extra-rsk-targets). A new dataset test cross-checks every chain's validated-stales row count against its published stale rows, which is precisely the invariant a piecemeal regeneration would have violated.The branch also carries the 2026-09-04 docs audit fixes (stale Namecoin blob counts, false provenance claims in three chain notes, the shared classify entry point,
source_chainssemantics) and corrects fifteen chain docs that still described the defective pre-fix classification model as current.docs/chains/rsk.mdnow discloses the defect the wayemercoin.mdlong has for its own data, and every count that moved (repo totals 3,729 to 3,768 observations, 2,137 to 2,145 unique headers, the pool table, the uncle/canonical split) was recomputed from the committed CSVs rather than carried from a plan.Context
The two blocks that started the investigation, 783426 and 784121, are the externally attested body-invalid pair (F2Pool, bad-blk-sigops). Four other chains already published them as accepted direct stales; RSK's raw extraction had witnessed both, and the classifier dropped them. Both are among the 39 recovered rows and keep their accepted status per the body-invalid overlay, so each is now witnessed by five chains. Adding the RSK witnesses to bitcoin-data/invalid-blocks#3 is a follow-up once this lands.
Testing
The full suite passes (1439 passed, 5 skipped), along with
just lint,just check-leaks, andjust validate-error-blocks(39 error blocks, 86 observations, unchanged). The reclassification itself was verified three independent ways before installation: a full replay reproduced the historical run's pass-1 counters at every checkpoint and produced 337 with zero regressions, a red-team re-derivation with an independent stdlib-only scanner reached the same 39 rows, and every one of the 39 was validated against its full block body from the upstream archive. The final monitor rebuild reproduced the committed publication byte-for-byte on every unchanged chain (the only content diffs are the RSK payload, its counts/manifest rows, and the verified i0coin enrichment). A local Codex review of the branch converged with zero findings, and the GitHub Codex review loop converged after five rounds on the final head: its two findings (strengthening the new cross-check test from count equality to (height, hash) identity sets, and letting --extra-rsk-targets accept the complete observation ledger rather than only a hand-built delta) are both applied with tests.