Skip to content

CacheCoin (CCCN) 0.1.1 for Windows

Choose a tag to compare

@triplecN triplecN released this 04 Oct 10:13
· 22 commits to main since this release

CacheCoin (CCCN) 0.1.1 for Windows

This is the second portable Windows package of CacheCoin: cachecoind.exe and
cachecoin-cli.exe from the tagged tree, the PowerShell launcher, the
documentation and a bundled Tor Expert Bundle.

The binaries are unsigned and this build is not reproducible. Read the whole
note before running.

Version history (why 0.1.1 exists)

0.1.0 was the first Windows package. While it was being hardened on its first
day it was rebuilt and re-uploaded several times: the first build had a launcher
bug that broke the normal double-click start, and later rounds fixed the wallet
backup check, the mining gate, process cleanup and the configuration rewrite.
Each time, the signed tag was moved to the corrected commit so that the tag, the
source and the ZIP stayed consistent. That is why an early 0.1.0 download can
have a different ZIP hash than the final one.

Rewriting the files of a published version is bad practice: two people who both
downloaded "0.1.0" can hold different bytes and have no way to tell. So that
stops here. 0.1.0 is frozen as published; 0.1.1 is the same code as the final
0.1.0 build (commit 025c328), published under a new number instead of
rewriting 0.1.0 again. If your 0.1.0 ZIP matches the hash on the 0.1.0 release
page, you already have this build and 0.1.1 changes nothing functional for you.

The consensus patch series did not change at any point: its fingerprint is the
same in every build (6a89aa14..., see Provenance). What changed during 0.1.0
was the Windows launcher and the package around it, not the node.

What changed from the first 0.1.0 build

  • The launcher starts correctly on a normal double-click.
  • The wallet identity check hashes stable descriptor strings, so the backup
    confirmation survives address generation and mining; a replaced wallet still
    invalidates the old confirmation.
  • The mining gate no longer mistakes an old-but-synced tip for a sync in
    progress, and it pauses when the clock is off.
  • The opt-in "help other nodes connect" setting binds only to loopback.
  • The logon task re-registers when the package folder moves, and -EnableAutostart
    / -DisableAutostart manage it directly.
  • Config rewriting understands [sections], UTF-16 and BOM files, and never
    duplicates keys.
  • BACKUP.txt now includes a restore procedure that was tested
    (restorewallet, and importdescriptors with the .descriptors array).
  • version.json must list the program files before the launcher trusts it.

An adversarial audit of the consensus patch series found no inflation, split or
balance-theft path; the accepted findings are recorded in
doc/consensus-audit-notes.md.

Files

  • CacheCoin-Windows-0.1.1.zip
    sha256: 080ea0491a87df0bc855573afcf950320b215ac7be2371e54ff6d5ec6694819c
  • SHA256SUMS.windows.txt (sha256 of every file in the package)
  • SHA256SUMS.windows.txt.asc (detached GPG signature of the checksum file)
  • version.json (inside the package: pins, patch fingerprint, per-file sha256)

Signing key fingerprint:
7D85B6F364CC47BA9209BB54F750900C7C911728
(CacheCoin (CCCN) Releases releases@cachecoin.org; public key also in the
repository as release-key.asc and in doc/release.md).

Provenance

  • Base pins: Bitcoin Core v31.1, commit
    9be056a8a72b624dae9623b2f7bded92c2a21c91; RandomX commit
    7607fb2faed24d5a679e139a9828d194bbc644a4.
  • Patch fingerprint: 6a89aa144620ea2c019f2678ea80ae8b2de45544bc64d871cd3bb2fefcf1ddda
    (cat patches/*.patch | sha256sum). Compare it with doc/verification.md.
  • The release tag windows-0.1.1 is a signed Git tag; verify it with
    git tag -v windows-0.1.1 after importing release-key.asc.
  • Tor Expert Bundle 15.0.24 (tor 0.4.9.13); its files are hashed in
    version.json. The bundle's sha256 was checked against the Tor Project's
    published sha256sums-signed-build.txt.

Verify before running

Get-FileHash CacheCoin-Windows-0.1.1.zip -Algorithm SHA256

Unpack it, then:

gpg --import release-key.asc          # from the repository or the release page
gpg --verify SHA256SUMS.windows.txt.asc SHA256SUMS.windows.txt
sha256sum -c SHA256SUMS.windows.txt

The gpg --verify output must name the fingerprint above. The sha256 values
prove the files arrived unchanged; the signature proves the checksum file came
from that key. Neither proves the binaries can be rebuilt from source.

What this is

A portable Windows package. The node is Tor-only; the launcher starts a bundled
Tor if none is running. Data lives in %APPDATA%\CacheCoin, not ~/.cachecoin.
Double-click CacheCoin.cmd to start. There is no GUI and no daemon mode.

Honest limits

  • Not reproducible. The sha256 values prove only that the files arrived
    unchanged in transit; the GPG signature proves the checksum file came from
    the CacheCoin release key. Nobody can yet rebuild the exact bytes.
  • The executables are unsigned at the OS level (no Authenticode).
  • SmartScreen. Windows will show "Windows protected your PC" on first launch;
    choose More info, then Run anyway, after checking the sha256.
  • Outside the suites. The Windows .exe files are not covered by the
    repository's automated test suites. CI starts the node in regtest, verifies
    the genesis and mines one block; on this package the node was also run against
    mainnet, synced to the live tip and connected to a peer over Tor.
  • No daemon mode. cachecoind -daemon does not exist on Windows (MinGW has
    no fork()); run it in a window or under Task Scheduler.
  • Mining is a lottery. Expect weeks without a block; it may never pay. The
    PER ticket system shares fees only when fees exist. Mining costs electricity
    whether or not it pays.
  • No financial advice. This is open-source software provided as is under the
    MIT license; nothing here is financial advice, an offer or a promise of return.