Skip to content

Releases: cambridgetcg/zerone-core

zerone-dev-1: proposed claim fund settlement v1

Choose a tag to compare

This prerelease prepares knowledge-fund-settlement-v1, knowledge module 10 → 11, proposed for zerone-dev-1 at height 300000. Publishing these files does not activate it. The normal 48-hour SDK governance vote remains unchanged; verify the proposal and applied height on the chain before treating the rules as live.

New ordinary claims and conjectures allocate 55% of their payment to reviewers and retain the remainder as the existing routed fee. An unused reviewer budget returns to the payer. New contradictions and explicit challenges allocate 55% to reviewers and return the remainder at every terminal verdict; with no eligible reviews, the entire deposit returns. Network transaction fees are separate. Timely authenticated dissent shares the fixed review budget without an agreement bonus. Historical claims keep their original terms; this release does not create retroactive refunds, sweep balances or mint rewards.

Source: 5542b221864ca0080e143fa82abbef4cd2064f71 (tree bb41fa89bbf5db36da09f9c1c70a5e626b1649bc). See PR #86 and the fund settlement specification.

Authenticate the downloaded assets against these independently published SHA-256 values before extracting into a new directory:

Asset SHA-256
UPGRADE.json 04f0415a361396e28397155ecb3c0b13d578475ebf1b86c3e2e2b5d533006f75
UPGRADE-RELEASE.json be85503652e9c467e074970c7169c80d5864a2a34fc620db7ca83d0b435d1d2b
Linux amd64 archive ddd41bea901a7f114979d787629874a71a2ea0d806c01c4be53afbf3cf2a43c5
macOS arm64 archive 5bb6cad6d981a3601aa503329f04c36d3d7a49a6b1ed8b3aee3e0098341a6b8b

These are upgrade packages. Their bundled network.json remains the original predecessor descriptor. Existing participants retain their verified original package/home and can continue signing compatible messages; the older decoder omits new funding fields. A fresh full node needs the verified predecessor release plus this package to replay original history and follow the staged boundary. Follow the archive README. Fresh target participant initialization requires a separate descriptor published only after the actual upgrade is observed.

The original genesis, validator identity and single-operator development consensus remain. Test funds have no promised monetary value. Review eligibility proves neither scientific diligence nor Sybil resistance. No independent scientific participation is claimed by release rehearsals.

Validation on this exact source includes 18 successful CI jobs, native macOS and Linux signed governance/bank rehearsals, atomic payment-failure/retry tests, and staged validator/follower plus old-participant compatibility rehearsals. Production signing is intentionally outside this development release.

A fresh zero-power public follower using the final packaged controller replayed the original chain to its tip, matched the block hash, header application hash and full claim-history response at common heights, and restarted cleanly with its original identity and genesis. This is replay/compatibility evidence against the single-operator development chain, not an additional consensus validator or an applied-upgrade claim.

Governance observation at H44552, 2026-09-13 01:19:41 UTC: proposal 1 is in its ordinary voting period, ending 2026-09-15 01:11:00 UTC, and requests height 300000. The operator’s yes vote is committed; knowledge remains10 and no upgrade plan was scheduled at that observation. A vote is not an applied-upgrade receipt.

  • Proposal transaction (H44036, code0): 1DB162BE7B73C80A2BBC54481138FBA77A01D993A966F285C4678DAAC41E07B3.
  • Vote transaction (H44409, code0): F102E2DD7C7FE9126B890B2BAB45A0DAD382F8A592D418A9A00C430C93FC2D8D.
  • The operator spent 10 development ZRN on the governance deposit and 4 ZRN on the two transaction fees. Observed total supply stayed 3,000,000 ZRN. These governance costs are separate from claim-review funding.

zerone-dev-1: shared development network

Choose a tag to compare

@cambridgetcg cambridgetcg released this 12 Sep 13:38
ac5684e

Zerone shared development chain: participant-owned accounts can submit claims, record reasoned commit/reveal reviews, publish counterclaims and inspect their attributed history.

This release is specifically for zerone-dev-1. Development funds have no promised value. One operator initially controls consensus; separate participant addresses do not establish independent reviewers or scientific truth. A reset requires a new chain ID.

The Linux amd64 package contains the exact executable deployed to the development node. The Apple Silicon package was built from the same merged source. Both include the participant client, full-node join runtime, public genesis and network descriptor. They contain no private keys. Python 3.11 or later is required.

Verify archive hashes against the source-pinned public release packet linked from https://zerone.ai/development/ before extracting and running. Keep each new participant home private; the development SDK test keyring is unencrypted. Full-node joining creates a separate node with zero voting power.

Source: ac5684e

Public guide: https://zerone.ai/development/

Public verification on 12 September 2026 confirmed a committed funding grant, agent registration and one operator-owned claim at height 432. A separate zero-power full node reproduced its history, and both the local follower and hosted validator preserved history through restart. This does not stage independent scientific review.

Both macOS and Linux native rehearsals passed the complete 31-transaction claim/review/counterclaim lifecycle. An earlier post-merge CI run refused its second claim submission but discarded the detailed execution receipt. Its exact cause could not be reconstructed; PR85 adds bounded public failure diagnostics and CI retention. The later successful runs do not establish that every future submission will be admitted. No runtime or protocol change was made on an assumed cause.

zerone-1 observer 20260909.2 — experimental Linux amd64

Choose a tag to compare

@cambridgetcg cambridgetcg released this 10 Sep 00:10
60e813c

zerone-1-observer-20260909.2 — experimental legacy observer

Keep your own copy of the existing zerone-1 ledger with a separate Linux amd64 observer. This exact signed package passed fresh sync, retained-home restart, applied-root verification and three transaction-broadcast refusal checks.

Experimental legacy runtime: SDK 0.50 is end of life, and Go 1.25.14 is outside Go's two supported major versions after Go 1.27's release. The dated assessment retains 42 advisory IDs, including 11 exact function-name matches. These are not automatically exploitable findings; absent name matches do not establish safety. No current standard-library advisory was identified in this scan, which does not restore upstream support. The bootstrap window is not a production-security or long-term maintenance promise. A subsequent release needs review and reproduction on a maintained Go baseline.

Use Linux amd64, Python 3.11+, gpgv, local Docker, 2 available CPUs, 6 GiB available memory and 20 GiB free disk for an initial trial. Disk use grows. macOS, ARM and remote Docker are outside the tested platform.

Follow the source-pinned setup guide. Confirm the public authority fingerprint through an already trusted source:

09327B031F8FF2C2EE49B18F2234027FC5B68C19

Use tooling commit ed364bc0afec062612b61a309002f23da85acf2c to verify and unpack the archive, then verify the separate signed rehearsal receipt before init. Use a fresh dedicated home. RPC stays at 127.0.0.1:27657; REST/gRPC are disabled and the nop mempool refuses broadcasts. Raw local check_tx is not promised to be query-only.

Artifact SHA-256
OBSERVER-RELEASE.json 1300f9381d2e290e1468075806734c586fd92e4df7d0ec55e2f7c7a858df7d92
observer-release.tar.gz — 43,975,496 bytes 5d874b4c38427117f1567ea0152fc4782e066e4926f3294f1eb776ff6ce22d08
REHEARSAL-RECEIPT.json c99a1bac24b9ccc71a2769ce10d72f0a947eec8cb4b4afe9df22df2886c0ed0b
REHEARSAL-RECEIPT.json.sig b6c47423166cff29731741b71e9e9a1d5e30820eab93a41c06f26a3fd8b8c56f
Packaged zeroned d6391ea7e500425c898b6b98cb422f76a4262361d45452955182d9b92b743443

New bootstrap expires 2026-09-16 19:19:13 UTC. A successfully synced home can resume afterward with its original authenticated package; a fresh or unsynced home requires a current package.

The executable uses legacy application base 2e37c4c86c31e67515d6aa07b6fd406083e012ea plus the manifest-authenticated dependency patch, CometBFT 0.38.25 and Go 1.25.14. Two fresh-cache builds by the same operator matched. Build provenance remains pinned to 84a1f7304515b52da002ebd7e2da782b5aef1634; v2 changed the helper's empty-startup parsing and added maintenance disclosure. Original build VCS metadata remains absent. The running validator was unchanged.

GitHub's automatic “Source code” archives contain the modern tagged repository/tooling. Reproduce this legacy executable from the authenticated legacy-source.tar.gz and observer-dependencies.patch inside the observer archive, using the pinned build guide. Current main is not a drop-in live binary.

The native trial followed heights 1,262,486–1,262,488 and resumed the same home/identity through 1,262,496–1,262,498. Both phases had zero voting power, unused local signing state, all three nop broadcast refusals and clean exit 0 without OOM. Offline checks matched both applied roots to signed headers at H+1. The phases completed at 2026-09-09 23:28:52 and 23:33:51 UTC; the live executable and authority were checked unchanged at 23:35:17 UTC.

The main-signed receipt remains an operator attestation. These pair checks do not inspect the durable database, prove checkpoint ancestry or establish independent trust. The chain still relies on the disclosed sole validator; signer custody is unresolved and the RPC aliases share one upstream. This release grants no validator membership, account, funds, rewards, transaction admission or upgrade authority.

The release report preserves v1's failed, unpublished startup attempt, exact source/runtime evidence and a separate revalidation of earlier census commitments. Public-download and website checks are recorded separately.