Skip to content

CacheCoin (CCCN) 0.1.2 for Windows

Choose a tag to compare

@triplecN triplecN released this 04 Oct 12:15
· 21 commits to main since this release

CacheCoin (CCCN) 0.1.2 for Windows

This is the third portable Windows package of CacheCoin: cachecoind.exe and
cachecoin-cli.exe from the tagged tree, the PowerShell launcher, the
documentation and a bundled Tor Expert Bundle.

The binaries are unsigned and this build is not reproducible. Read the whole
note before running.

Why 0.1.2 exists

0.1.1 was audited again after publication and one High bug was found and
reproduced in the launcher:

  • -Stop could restart the node instead of stopping it. In Windows
    PowerShell 5.1, a process started with redirected output can report a null
    ExitCode. The supervisor read "null exit code" as a crash and restarted the
    node, so a stop request turned into a restart loop. This only affects how the
    launcher stops; it cannot affect consensus, balances or mining.

The launcher fix has two parts: the process handle is now cached so a clean exit
reads as exit code 0, and -Stop writes a stop marker that the running launcher
consumes and exits on, with the marker removed on every path. The fix was tested
end-to-end on the packaged binaries: node-only start, -Stop, node and launcher
exit, no restart, launcher exit code 0.

0.1.1 is frozen as published; the fix ships as 0.1.2 instead of rewriting it.

The consensus patch series did not change: its fingerprint is the same in every
build (6a89aa14..., see Provenance). Nothing in this release changes the node.

What changed in 0.1.2

  • -Stop no longer restarts the node (the High bug above); the launcher also
    exits correctly when the node stops by itself with a clean exit code.
  • An existing cachecoin.conf that enables listening (listen=1 or
    listenonion=1, e.g. written by an older launcher) is now enforced with
    loopback-only bind= lines and a torcontrol= setting on every start, not
    only on first install. A custom bind= line is kept and warned about.
  • The mining clock gate is corroborated with the chain: mining pauses only when
    peers report the local clock ahead and the tip is older than 5 minutes.
    A single peer can no longer pause mining. A peers-report-behind case is a
    warning, not a pause.
  • The wallet descriptor list is retried once; if it still does not answer while
    mining, the backup confirmation is dropped and mining stays paused instead of
    proceeding on an unverified wallet.
  • node-out.log no longer grows: the node runs with -printtoconsole=0.
    Errors still land in node-err.log and are shown in the launcher log.
  • The autostart task check no longer uses wildcard matching, so package paths
    containing [ or ] do not cause a re-register loop.
  • The cloud-folder warning also covers My Drive (Google Drive for desktop).
  • BACKUP.txt has a corrected, tested restore procedure (node-only mode first,
    createwallet before importdescriptors, UTF-8 output encoding).
  • CI only: the test suites reserve the fixed ports they use (29333/29334 and
    39xxx) against ephemeral-port collisions, print node diagnostics on a failed
    start, and wait for the Tor peer handshake before the Shunko rotation check.
    These are test/build changes and are not part of the shipped binaries.

Files

  • CacheCoin-Windows-0.1.2.zip
    sha256: 90ecf2df8fdb131e0f189de19303b12fc5b30c58d176c276ad8be0d9a715ae9d
  • SHA256SUMS.windows.txt (sha256 of every file in the package)
  • SHA256SUMS.windows.txt.asc (detached GPG signature of the checksum file)
  • version.json (inside the package: pins, patch fingerprint, per-file sha256)

Signing key fingerprint:
7D85B6F364CC47BA9209BB54F750900C7C911728
(CacheCoin (CCCN) Releases releases@cachecoin.org; public key also in the
repository as release-key.asc and in doc/release.md).

Provenance

  • Base pins: Bitcoin Core v31.1, commit
    9be056a8a72b624dae9623b2f7bded92c2a21c91; RandomX commit
    7607fb2faed24d5a679e139a9828d194bbc644a4.
  • Patch fingerprint: 6a89aa144620ea2c019f2678ea80ae8b2de45544bc64d871cd3bb2fefcf1ddda
    (cat patches/*.patch | sha256sum). Compare it with doc/verification.md.
  • The release tag windows-0.1.2 is a signed Git tag; verify it with
    git tag -v windows-0.1.2 after importing release-key.asc.
  • Tor Expert Bundle 15.0.24 (tor 0.4.9.13); its files are hashed in
    version.json. The bundle's sha256 was checked against the Tor Project's
    published sha256sums-signed-build.txt.

Verify before running

Get-FileHash CacheCoin-Windows-0.1.2.zip -Algorithm SHA256

Unpack it, then:

gpg --import release-key.asc          # from the repository or the release page
gpg --verify SHA256SUMS.windows.txt.asc SHA256SUMS.windows.txt
sha256sum -c SHA256SUMS.windows.txt

The gpg --verify output must name the fingerprint above. The sha256 values
prove the files arrived unchanged; the signature proves the checksum file came
from that key. Neither proves the binaries can be rebuilt from source.

What this is

A portable Windows package. The node is Tor-only; the launcher starts a bundled
Tor if none is running. Data lives in %APPDATA%\CacheCoin, not ~/.cachecoin.
Double-click CacheCoin.cmd to start. There is no GUI and no daemon mode.

Honest limits

  • Not reproducible. The sha256 values prove only that the files arrived
    unchanged in transit; the GPG signature proves the checksum file came from
    the CacheCoin release key. Nobody can yet rebuild the exact bytes.
  • The executables are unsigned at the OS level (no Authenticode).
  • SmartScreen. Windows will show "Windows protected your PC" on first launch;
    choose More info, then Run anyway, after checking the sha256.
  • Outside the suites. The Windows .exe files are not covered by the
    repository's automated test suites. CI starts the node in regtest, verifies
    the genesis and mines one block; on this package the node was also run against
    mainnet, synced to the live tip and connected to a peer over Tor.
  • No daemon mode. cachecoind -daemon does not exist on Windows (MinGW has
    no fork()); run it in a window or under Task Scheduler.
  • Mining is a lottery. Expect weeks without a block; it may never pay. The
    PER ticket system shares fees only when fees exist. Mining costs electricity
    whether or not it pays.
  • No financial advice. This is open-source software provided as is under the
    MIT license; nothing here is financial advice, an offer or a promise of return.