Why the mesh only runs jobs it can replay
Determinism is the load-bearing assumption behind every SLA on this site. A Pi and a laptop must return bit-identical results from the same bytes. When they do not, the network has a problem no clever protocol can fix.
Picture this: two phones in airplane mode take the same job, grind through it, and return different answers. Now someone has to pick a winner. The moment a network starts picking winners by authority, the verifiable part of verifiable compute is gone.
The rule is simple to state and brutal to honor: same bytes in, same bytes out, on any hardware. This is SLA-DET, from docs/sla-and-dod.md in the repo: fewer than 1% of outputs may be unverifiable. The ledger only settles results it can replay and recheck. A result nobody can verify never happened.
Rewind: the chessboard
MossyMesh picked the honest starting point for this problem: a chessboard. Chess is a perfect-information game with discrete state, which makes it the worst possible place to hide non-determinism. MessyMash is the determinism benchmark. Every move is a CRDT (conflict-free replicated data type) operation, every position is a trie root, and the shakmaty engine evaluates identically whether it runs on-device or inside the WASM sandbox.
The speed number attached to that engine is a stated target: an 836-million-nodes-per-second class engine, explicitly a target, not a measurement. If two devices can agree on a chess position, the merge machinery works, and everything more complicated rides on the same rails.
Floating point is the usual suspect
The usual way identical code produces different answers on different chips is floating-point math. A phone and a laptop can disagree in the last bit of a float, and then the trie roots diverge and the replicas fork. MossyMesh answers with static INT8 quantization on the tensor payloads: integers do not disagree. (The quantization scale itself is still a float. INT8 covers the payloads, and the determinism SLA is measured on outputs, not on the absence of floats.)
The sandbox removes the other escape hatches. Every job runs in a cage with a hard 10 MiB guest heap. Ask for one byte more and the runtime kills the job. No swap, no negotiation. A Pi Zero can host a stranger's compute without fearing a memory bomb, and a job cannot smuggle state in through the heap because there is no room to hide it.
The second wall
There is a second wall worth naming. The ten-minute Wesolowski VDF grind keeps fake identities too expensive to mint, and determinism keeps the math honest once a job is inside. Two different threats. Two different walls. Both load-bearing.
The honest status
Not everything here is wired. The native WAMR runtime sits behind a feature flag, and the tests run on a pure-Rust host today. SLA-TO, fewer than 5% job timeouts on unstable RF, is a target; the first real storm of packet loss will grade that one. The determinism guarantee is the part already doing work: the sandbox enforces it, the ledger checks it, the chessboard proved it.
Nobody has measured what the first non-deterministic failure looks like on real radios yet. When it happens, the question that matters is whether the network flags the job itself, before anyone has to trust the node that ran it.