PCOC · Docs · Rationale

How you make one

A finished object is a small file. The room of the legs is not in the file.

A public key is thirty-two bytes, and it costs nothing. Anyone can make a million of them before lunch. A key names a secret. It does not spend anything. How a free key fails to make a scarce object is How do you make a digital thing scarce?

A Bitcoin header is also cheap to read. It is already public. The maker did not produce it, cannot choose the next one, and cannot know what it will be. Those two things are the seed. The key is who. The header is the flag that was up when the making began. Mix them and the result is a room: two hundred and fifty-six mebibytes, filled once, held in memory, never written into the file. Same key and same opening flag, same room. Change either one and the room is different.

Bytes copy. What does not copy is a machine holding that room and taking the legs, on a public tick nobody schedules.

Why a key at all

Leave the key out and the work is anonymous labour. A service that later wants this object to belong to this secret has nothing to grab. Leave the work out and the key is free. A crowd of keys is not a crowd of makers.

So the object carries the public key, and the room is grown from it. Produce does not check a signature. Verify does not check a signature. The key is in the seed because the room has to belong to someone. Proving the holder has the matching secret is a later act, at a door, if a door wants it.

Why a clock that is not yours

A maker can always lie about duration. Time is the half of occupancy the maker cannot prove from the file. What supplies that when is How do you prove when the work happened?

In the making, a stage opens under a header and a later, higher header closes it. Eighteen of those stages make a finished hike. The maker does not set the next flag. The stages take their order from a tick they only read.

The room

The room is filled from the seed before the first step. After that it does not change. Later flags do not rebuild it. They only change the mark the leg is under.

Why hold two hundred and fifty-six mebibytes, and why the room stays held between steps, is Why memory, and why a clock? A maker who does not hold the room pays more than one who does. Two hikes at once are two rooms.

The first step

Stage zero opens with a waypoint of thirty-two zeros. The leg starts from zeros too. The public key named the room. It does not aim the first step. The opening flag helped fill the room. It does not aim the first step either.

The leg loads the slot the current state points at, mixes every word, and seals. The room underfoot decides where the next step stands. That is why a second machine cannot usefully split one leg. The next address is the output of this address.

One million of those steps is a leg. A million is this construction's quantity. Eighteen stages. A stage holds at least one leg. When the next header is slow and the machine is fast, a stage can hold more: the room stays, and another leg starts under the same flag. What the file can show later is the legs it wrote. The waiting is the half it cannot prove.

What gets written down

The room is not kept. A log is.

After a leg, two things are written. The leg result is the eight-byte end state of the leg. The checkpoint is one hash of what came before. It has four limbs, in order.

The previous checkpoint, so the legs inside a stage are a chain. A link that does not match fails the object.

The stage waypoint, so this leg is bound to the mark the stage opened with, not to a mark invented later.

A one-mebibyte sample of the room, taken from where this leg began. The sample stays in the room. The checkpoint has seen the room, not only the state of the leg.

The leg result itself, so the cheap bind and the expensive leg agree.

Checking that hash does not repeat the million steps. That is why it exists. The room can be grown again from the seed. A leg can be taken again from the previous checkpoint. The checkpoint is the claim that those two already line up. If they do not, the failure shows up without paying the whole hike.

The next flag

When the leg in hand finishes, the maker looks up.

If the header is still the same, the stage is still open. Another leg can start under the same waypoint.

If the header changed and the height rose, the stage is closed. The flag that just arrived opens the next stage. The next waypoint is computed from the stage just closed: the flag that stage opened under, a slot that flag selects in the room, the waypoint the leg was under, and the checkpoints written. The room does not change. The checkpoint chain of the new stage starts from zeros again. Direction during a leg comes from the room. Direction across stages comes from those checkpoints and from a flag the maker does not own.

Each new mark is folded from the stage just finished. Each checkpoint binds the previous bind, this stage's mark, a piece of the room, and the leg result. Each step takes its next address from the slot it just read. Rebuild from the seed and the log either matches or it does not. A limb that does not match fails the object.

Eighteen, then stop

Eighteen stages, and the log is the object. It is small beside the room. It carries the public key, the opening header, and eighteen stages of marks, leg results, and checkpoints. No room. Anyone who wants the room builds it again from the two things the making started with.

Eighteen is this construction's count. One flag is a moment. Eighteen closings are a pace the maker does not set. The file records the flags and the legs. It does not, by itself, prove the room was occupied for every minute between them. A different construction can pick a different count. This one picked eighteen.

Reading the log

A later reader has the file.

First the file has to be a file: eighteen stages, heights that rise, headers that actually change, one checkpoint and one leg result per leg.

Then the beacons have to be the headers they claim. The reader compares them with the public sequence. That comparison is not a question to the maker.

Then the room is grown again from the seed. The waypoints have to be the waypoints this construction would have computed. Every checkpoint hash has to be the hash of its four limbs, sample included. Those checks do not repeat the million steps.

Then the expensive part, still cheap next to the making: the check re-does only the legs it asks for, and demands that those leg results match what the file wrote down. That replay is not a wait for the next header. If one of those leg results does not match, the object fails.

That is the fact. The object matches the construction, or it does not. Whether the fact is enough is Why can saying no be cheap when saying yes cannot?

What the file does not decide

Two questions are not in the bytes.

One question is whether the binding is tight enough for a particular door. Eighteen stages is the construction. How many of those beacons must sit on a chain the operator trusts, and how old a finished object may be, is the operator's rule.

Another is whether the making was dense enough for that door. One machine can take a long time over a million steps. Another can finish several legs inside one header. The file records the legs. It does not grade the machine, and it does not prove the idle time. A floor on steps, or a ceiling on idle, is no longer a question about whether the log matches. It is a question about whether this making is good enough for that door.

The object does not carry that line. If it did, every door would be stuck with one rule.

A door can also ask for a signature. That is how it finds out the presenter holds the secret that matches the public key in the seed. The hike did not do that work. The hike made an object that can be bound. The challenge is a later sentence.

What this costs

Copying the file is free. Making a second one is not a discount on the first. Why that cost refuses to divide is What kind of cost refuses to divide? The payment is not a fee to an office. It is occupancy already spent. Why that finished file is still worth carrying is Why carry the cost forward?

A derived cost for v1.35, on two-channel desktop-class hosts as of 2026-10-07, has two figures: about $0.19 per accepted hike for an honest producer, and an adversary floor of about $0.13, the cheapest cost per accepted hike any packing reaches; see PCOC at scale. The file either rebuilds or it does not.

Why a lazy file fails

A lazy file fails the cheap checks first: wrong shape, a beacon that was never that header, a waypoint that does not follow from the last stage, a checkpoint that does not hash its four limbs. Why a refusal can be cheap, and a confirmation cannot, is Why can saying no be cheap when saying yes cannot?

What remains is a file that claims leg results for a route through a room grown from this key and this opening flag. Inventing those results without taking the route means inventing the end of a path that cannot be looked ahead on.

A faster box, or a long wait between headers, changes the shape of the bill. It does not give a free object.

The recipe

Start with a key the maker controls and a Bitcoin flag the maker does not.

Grow a room from both. Hold it.

Take a million steps. The room chooses the next step. Write the leg result. Bind it to the last bind, to this stage's mark, to a piece of the room, and to the leg result.

When a new flag goes up, close the stage. Compute the next mark from the stage just closed. Take the next leg.

Do that eighteen times. Stop. The log is the object.

Anyone can grow the room again and ask whether the log is still true. If any limb is false, the object fails. If the chain holds, the file is bound to a name and to public time, made by holding a room across that order. What to do with the file is not the making.