Skip to content

feat(bounty): add owner-activated proportional report rewards - #309

Merged
Mathis (echobt) merged 3 commits into
mainfrom
codex/bounty-proportional-valid-reports
Sep 20, 2026
Merged

Mathis (echobt) merged 3 commits into
mainfrom
codex/bounty-proportional-valid-reports

Conversation

@echobt

@echobt Mathis (echobt) commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Problem and behavior

Bounty currently selects one severity/precision champion, and challenge normalization always spends its full share. Algorithm 2 gives one point per valid published report, rewards all expected authors proportionally, and pays 0.30 * min(total_valid / 10, 1) of subnet emission. Five valid reports pay 15%; ten or more pay 30%. Proof retains 70%; unused, unmapped and quarantined mass burns to UID0.

Counts use cumulative report history at a stable publication revision, restricted to the owner-signed policy's expected metagraph hotkeys. Invalid, duplicate and already-fixed reports contribute zero. Severity remains required publication evidence with no point weighting. Sealed projections expose the algorithm and the effective Bounty allocation.

The owner-signed 3000/7000 profile requires challenge-document version >=2 and algorithm 2 throughout emission, sealing and independent verification. The existing signed 2000/8000 fixture, algorithm 1, frozen encodings and historical seals remain intact. config/challenges-v2.example.toml is explicitly unsigned; code deployment alone changes no rewards.

Validation

  • Ruff format and lint
  • Mypy: 83 source files
  • Offline test suite: 1112 passed
  • scripts/check_repo.py --final
  • Deployment contracts
  • Source distribution and wheel build

Regression coverage includes 0/1/5/9/10/20 reports, multiple authors, independent severity, UID0/unmapped burns, stale activation and signed algorithm downgrades. The real local intake boundary exercises outage rejection without storage, external publication, signed leaves, gateway sealing, sealed: true HTTP retrieval and validator dispatch through fake external providers. Rotation in the same store preserves old bytes and root-addressed archives using retained accepted trust profiles, waits unsealed, seals a new algorithm 2 epoch and survives restart. Archive corruption and challenge-key rotation are covered. The unsigned template cannot be signed until an activation epoch is explicitly chosen.

Public contract

  • Bounty, Proof, validator and operator documentation updated
  • No challenge content, credentials, floating production images or invented digests added
  • Frozen protocol specifications and BASE_*/signature domains preserved

Greptile

  • Greptile reviewed this PR and findings are resolved or answered

Automatic draft/open/push review and status output are configured in .greptile/config.json, using documented field types and preserving the exact file exclusions and review rules. The native folder takes precedence over legacy configuration; required review checks remain enforced.

Risk

This changes consensus only after an offline owner-signed activation. Gateway and submitting validators must support the new profile, drain older pending epochs before rotation, retain journals and signatures, and wait for the first newly sealed completed epoch. Rollback must respect persisted version watermarks; deleting journals or rewriting seals is prohibited. Production activation and on-chain payout are not claimed by these offline checks.

RetriggerConfidence Score: 5/5

Safe to merge.

Summary

This PR adds owner-activated algorithm 2 for proportional Bounty rewards while retaining compatibility with the legacy algorithm 1 profile. It persists accepted trust profiles for historical bundle verification, enforces profile activation and allocation settings, burns ineligible reward mass rather than reallocating it, and updates projections, documentation, and regression coverage.

Reviews (3) · Last reviewed commit: "fix(gateway): retain accepted trust for ..."

@echobt
Mathis (echobt) marked this pull request as ready for review September 20, 2026 08:12
Comment thread config/challenges-v2.example.toml Outdated
@greptile-apps

This comment has been minimized.

@echobt
Mathis (echobt) marked this pull request as draft September 20, 2026 08:20
Preserve verified profile snapshots across rotation without reusing them\nfor current weights. Require an explicit activation epoch in the unsigned\nproportional template and cover archive corruption and signer rotation.

Refs: #309
@echobt

Copy link
Copy Markdown
Contributor Author

Greptile (@greptileai) review

Please review current head bfcbef0.

The gateway now retains accepted trust profiles, including challenge signer keys and participant policies, atomically with monotonic trust watermarks. Historical root lookup verifies the archive against a retained profile, the independently pinned gateway signature, and challenge signatures. Current latest weights never fall back to an archived profile. Missing or corrupt profile snapshots return 503.

The unsigned 3000/7000 template now contains a non-signable activation-epoch placeholder. The operator must select the coordinated integer epoch before signing.

Validation: both reported behaviors reproduced before the fix; 1,112 offline tests pass, including root lookup after rotation/restart, signer rotation, corrupt signatures, invalid JSON/BLOB snapshots, and explicit template signing. Ruff, Mypy, repository/deployment contracts, and source/wheel builds pass.

@echobt
Mathis (echobt) marked this pull request as ready for review September 20, 2026 08:42
@echobt
Mathis (echobt) merged commit 0874160 into main Sep 20, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant