Marcin Pawlowski 15e876e90a
Correctness pass: derive rho in code, and the absolute vs-1.0 test
Two findings from re-reviewing the fine-delay section.

1. The rho values I put in s3.2a were wrong. The report derives
   rho = f*D_vis with D_vis = hops*delta_max/2 + (hops+1)*ell_mean from
   a MEASURED ell_mean (1.211 slots at N=1000/degree=6), not from the
   link_latency_mean parameter (0.5). Hand-substituting a guessed 1.5
   inflated every value by ~0.04: the band is rho 0.21-0.41, not
   0.25-0.45.

   To stop that recurring, graph_ell_mean moves out of
   rho_boundary_analysis.py into figures_pernode.py, joined by a new
   rho_for() that both scripts and any future quotation go through;
   plot_fine_delay.py now prints the derived rho per delay.

   This also exposed an inconsistency in the existing s3.2 table, which
   rounded delta_max=4 to "rho ~ 0.4" while s3.2a called the same cell
   0.36 and prose elsewhere already used 0.56 for delta_max=8. The s3.2
   column now carries the derived values (0.36/0.56/0.96/1.76).

2. Testing each cell against the exact target 1.0 -- the same question
   the gap test asks, without reference to the other model --
   corroborates the first-fork onset independently. Unrestricted: 1/15
   cells below 1 (t=-2.09, chance). Countable: 4/15, and not scattered
   -- delta_max=4 at U=1, and ALL THREE caps at delta_max=5 (-0.0012 to
   -0.0019, t=-2.5..-3.7). A shortfall appearing at every cap at once,
   only at the top of the band, only under the restricted model, is the
   first-fork cost seen absolutely.

   That makes "one uncle slot is sufficient -- not approximately,
   exactly" too strong as I had written it. s3.2a now states the
   residual (0.1-0.2% at the top of the band, zero below delta_max=3),
   reconciles it with the s1 headline, and notes that since all three
   caps show the same shortfall the residual is not a capacity limit.
   The bound quoted in s1 moves from "below 0.15%" to "<= 0.2%".

Also adds the new run directories to s9's canonical list, which covered
every other study but not these.

Tests: 209 passed. ruff clean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-05 10:34:33 +02:00
..

Total-Stake-Inference parameter selection

Per-node network simulation of Cryptarchia Total Stake Inference (TSI). Simulator: tsi-sim-pernode. All runs at the true security parameter k = 2160 unless noted; latency is in slots and 1 slot = 1 s.

This report selects and justifies the TSI parameters for Cryptarchia from a per-node network simulation. It is split into four cohesive parts; section numbers (§1§9, AC) are stable identifiers preserved across the set.

Uncle references. The model analysed throughout is the countable one: counting-only references, deduplicated by slot, drawn from first-fork blocks only, within a window derived as w_u = W_abs/f. An unrestricted baseline — any orphan in the window at any fork depth — is measured alongside it for comparison. The two are indistinguishable in the design regime ρ < 1 and diverge only under overload. See the model note at the top of Part 1, the mechanism in §2.1, the comparison in §3.2§3.2a, and the reproduction notes in §9.

Parts

  1. Overview and recommendations — the executive summary, the per-knob parameter reference (§7), and the safest selection with residual risks and the recommendation-vs-spec deltas (§8).
  2. Accuracy and design — the model and counting rule (§2), the seven findings and their evidence (§3), the design equations and selection algorithm (§4), and the caveats and regime of validity (§5).
  3. Robustness and incentives — jitter, grinding, withholding, selfish mining, the reward design, fork/reorg depth, and organic churn (§6).
  4. Reproducibility and appendices — how to re-run every study (§9), the residual f-rounding offset (App A), the per-epoch noise floor (App B), and consensus detail (App C).

Headline recommendation

Cryptarchia baseline f = 1/30. Two design choices are foundational: count uncles per occupied slot, not per block — the density-bug fix that lands the estimate at exactly D (§2.1, §8.5) — and make genesis a single protocol constant, identical at every node, never client-configurable, since a per-node divergence is never self-corrected (§8.1 row 7). The settings: security k = 2160, uncle window W = 300 slots, uncle cap U ≥ ⌈ρ⌉ + 1 (2 at the Blend target; the protocol's MAX_UNCLES = 4 sits safely above it), learning rate β = 1, on-chain f at 10⁻⁶ precision, peering degree ≥ 6 at scale, soft uncle rewards with w_u + w_n < 1, and operate at load ρ = f·D_vis < 1. The full recommended-configuration table and rationale are in Part 1 →.

Figures

Figures are embedded from report-figures/ via relative links and are versioned here alongside the report. They are produced by the simulator's plotting scripts (scripts/*.py and tsi_sim.plotting) in tsi-sim-pernode; that simulation folder does not commit its own generated figures — the copies checked in here are the report's figures of record.

Reproducing the results

The simulation code, configs, and run data live in tools/simulators/tsi/tsi-sim-pernode. Every study's exact command is listed in Part 4 — Reproducibility (§9). In short, from the simulator directory: make install, then make <config> to run a sweep (results land under runs/<timestamp>_<label>/), and the per-figure generators under scripts/ render the figures. Regenerated figures must be copied into report-figures/ to update this report.