Skip to content

CacheCoin (CCCN) 0.1.3 for Windows

Choose a tag to compare

@triplecN triplecN released this 04 Oct 13:11
· 20 commits to main since this release

CacheCoin (CCCN) 0.1.3 for Windows

This is the fourth portable Windows package of CacheCoin: cachecoind.exe and
cachecoin-cli.exe from the tagged tree, the PowerShell launcher, the
documentation and a bundled Tor Expert Bundle.

The binaries are unsigned and this build is not reproducible. Read the whole
note before running.

Why 0.1.3 exists

A third audit round on 0.1.2 found no High issue, but it confirmed one Medium
availability problem and two documentation mistakes:

  • A single peer's clock could pause mining for every Windows miner. The
    launcher paused mining when peers reported that the local clock was ahead by
    more than 5 minutes, and the chain tip was older than 5 minutes. On this
    chain the tip is often older than that, so one peer with a slow clock (for
    example a seed without NTP, or a malicious peer) could stop all launcher
    miners - exactly when the chain most needs them. Verified in regtest with the
    real binaries: one peer at -1 hour produced timeoffset=-3605,
    MiningGated=True.
  • BACKUP.txt step 2 used ren "%APPDATA%\...", which does not work in
    PowerShell, and step 6 promised that mining resumes after a restore, while the
    saved mode stays node and mining does not start.
  • 0.1.2 is frozen as published; these fixes ship as 0.1.3.

The consensus patch series did not change: its fingerprint is the same in every
build (6a89aa14..., see Provenance). Nothing in this release changes the node.

What changed in 0.1.3

  • Clock differences are now warnings only. Mining no longer pauses because
    of a clock disagreement, in either direction. Why this is safe:
    Bitcoin Core adjusts time by the median peer offset, and a block found with a
    genuinely wrong clock is simply rejected by the network - only the reward is
    lost, never funds. The real gates remain: node not answering, still syncing,
    or zero peers. The launcher logs one clear warning per run and tells the user
    to fix Windows time if it is wrong.
  • BACKUP.txt is now PowerShell-only and tested as written:
    • step 2: Rename-Item "$env:APPDATA\CacheCoin\wallets" wallets.old
    • step 6: CacheCoin.cmd -Mode mining (the saved mode is restored to mining
      by that one start; after that a normal double-click mines again)
  • New docs/BEGINNER_GUIDE.md, a step-by-step English guide for people who do
    not code. It covers: node-only vs mining mode; how the wallet creates its own
    modern SegWit address (cccn1q...) so nothing has to be typed; the mandatory
    backup before mining with hard warnings to keep the files offline or on a USB
    stick; how to print private keys (listdescriptors true) with the same
    warnings; how to stop the node; and how to check status, including the
    optional local block explorer at http://127.0.0.1:8080 (the repository's
    explorer/app.py, which needs Python 3 and is not bundled in the ZIP).
  • docs/START_HERE.txt now points to the beginner guide first.

Deliberately not changed (Low findings from the same audit, deferred to avoid
launcher churn): a repeated "custom bind" warning for the launcher's own lines;
listen=1 # comment parsing; the saved backup-confirmation state after a
transient listdescriptors failure; CI diagnostic collection for nine suites;
two cosmetic phrases in BACKUP.txt. None of these touch funds or consensus.

Files

  • CacheCoin-Windows-0.1.3.zip
    sha256: 634fe000f393aa7c8bbd1cd4d96c84702e25db942612cb525c75fb10e80443e2
  • SHA256SUMS.windows.txt (sha256 of every file in the package)
  • SHA256SUMS.windows.txt.asc (detached GPG signature of the checksum file)
  • version.json (inside the package: pins, patch fingerprint, per-file sha256)

Signing key fingerprint:
7D85B6F364CC47BA9209BB54F750900C7C911728
(CacheCoin (CCCN) Releases releases@cachecoin.org; public key also in the
repository as release-key.asc and in doc/release.md).

Provenance

  • Base pins: Bitcoin Core v31.1, commit
    9be056a8a72b624dae9623b2f7bded92c2a21c91; RandomX commit
    7607fb2faed24d5a679e139a9828d194bbc644a4.
  • Patch fingerprint: 6a89aa144620ea2c019f2678ea80ae8b2de45544bc64d871cd3bb2fefcf1ddda
    (cat patches/*.patch | sha256sum). Compare it with doc/verification.md.
  • The release tag windows-0.1.3 is a signed Git tag; verify it with
    git tag -v windows-0.1.3 after importing release-key.asc.
  • Tor Expert Bundle 15.0.24 (tor 0.4.9.13); its files are hashed in
    version.json. The bundle's sha256 was checked against the Tor Project's
    published sha256sums-signed-build.txt.

Verify before running

Get-FileHash CacheCoin-Windows-0.1.3.zip -Algorithm SHA256

Unpack it, then:

gpg --import release-key.asc          # from the repository or the release page
gpg --verify SHA256SUMS.windows.txt.asc SHA256SUMS.windows.txt
sha256sum -c SHA256SUMS.windows.txt

The gpg --verify output must name the fingerprint above. The sha256 values
prove the files arrived unchanged; the signature proves the checksum file came
from that key. Neither proves the binaries can be rebuilt from source.

What this is

A portable Windows package. The node is Tor-only; the launcher starts a bundled
Tor if none is running. Data lives in %APPDATA%\CacheCoin, not ~/.cachecoin.
Double-click CacheCoin.cmd to start. New users should read
docs\BEGINNER_GUIDE.md. There is no GUI and no daemon mode.

Honest limits

  • Not reproducible. The sha256 values prove only that the files arrived
    unchanged in transit; the GPG signature proves the checksum file came from
    the CacheCoin release key. Nobody can yet rebuild the exact bytes.
  • The executables are unsigned at the OS level (no Authenticode).
  • SmartScreen. Windows will show "Windows protected your PC" on first launch;
    choose More info, then Run anyway, after checking the sha256.
  • Outside the suites. The Windows .exe files are not covered by the
    repository's automated test suites. CI starts the node in regtest, verifies
    the genesis and mines one block; on this package the node was also run against
    mainnet, synced to the live tip and connected to a peer over Tor.
  • No daemon mode. cachecoind -daemon does not exist on Windows (MinGW has
    no fork()); run it in a window or under Task Scheduler.
  • Mining is a lottery. Expect weeks without a block; it may never pay. The
    PER ticket system shares fees only when fees exist. Mining costs electricity
    whether or not it pays.
  • No financial advice. This is open-source software provided as is under the
    MIT license; nothing here is financial advice, an offer or a promise of return.