Skip to content

Commit 47fc513

Browse files
committed
Docs: D-CC2 addendum for the sentinel decision and vector exception
Records the 2026-07-31 decisions by Evan carried into the CREATE_COIN_TAPROOT PR: the empty-root sentinel for key-path-only outputs (separate opcode and outright decline both considered and declined), the two rejection branches unreachable by any constructible vector and pinned by contrived-scalar unit tests instead (a recorded exception to the every-error-path-is-a-vector rule), and the BIP341 wallet test vectors as the vendored tweak-derivation oracle. Also ticks the Phase 2 tx-model checkbox in the execution plan, housekeeping owed since PR #20 landed python/bitlisp/tx.py.
1 parent 3e124fe commit 47fc513

2 files changed

Lines changed: 26 additions & 1 deletion

File tree

‎docs/condition-record.md‎

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -36,6 +36,14 @@ Section 4 registers the rules that have no external reference at all.
3636
is acceptable, and which precedent prices tx-scoped
3737
SEND_MESSAGE and RECV_MESSAGE (the CHIP-0049 precedent is split,
3838
see `docs/execution-plan.md` Phase 2 notes).
39+
- **BIP341 wallet test vectors** are vendored as data into
40+
`vectors/upstream/bip341/` with a provenance sibling, and are the
41+
primary tweak-derivation oracle for CREATE_OUTPUT_TAPROOT. The
42+
vendored Bitcoin Core test framework carries no named taproot
43+
constructor, but its generic tagged-hash and x-only tweak
44+
primitives compose into a second runnable oracle, and the test
45+
suite runs the derivation differentially against that composition
46+
alongside the official vector pins.
3947
- **bllsh** (AJ Towns' introspection Lisp) was cloned into
4048
git-ignored `references/` on 2026-07-29 and read for the
4149
CREATE_COIN_TAPROOT evaluation, under the reading guardrails
@@ -105,6 +113,23 @@ Section 4 registers the rules that have no external reference at all.
105113
signature verification."
106114
The condition enters the v0 vocabulary in its own PR immediately
107115
after the opening one. Its commit discloses the bllsh reading.
116+
117+
Addendum (2026-07-31, decisions by Evan, landed with the
118+
CREATE_OUTPUT_TAPROOT PR). Key-path-only handling uses the
119+
empty-root sentinel: one opcode, `merkle_root` exactly 0 or 32
120+
bytes, the empty atom committing to no script tree. A separate
121+
key-only opcode and declining key-path-only entirely were both
122+
considered and declined. The sentinel is unambiguous because a
123+
real root is always exactly 32 bytes, and it keeps one BIP341
124+
concept in one vocabulary entry. Two of the entry's rejection
125+
branches, a tweak scalar at or above the group order and a
126+
tweaked point at infinity, are unreachable by any constructible
127+
vector because both require hash-preimage control, roughly a
128+
2^-128 event. They are pinned by contrived-scalar unit tests
129+
through the implementation's application-step seam. This is a
130+
recorded exception to "every error path is a vector," accepted so
131+
the corpus gap is deliberate rather than an oversight. The tweak
132+
oracle provenance is recorded in section 2.
108133
4. **Rule 1 equality-only matching.** RATIFIED (decision by Evan,
109134
2026-07-29, as part of the rule 1 draft). Claims match slots by
110135
exact content equality only, which collapses injective matching

‎docs/execution-plan.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -86,7 +86,7 @@
8686
**Goal:** the executable spec for the only consensus component that exists nowhere else.
8787

8888
- [ ] `CONDITIONS.md` v0 vocabulary: ported set (CREATE_COIN, secp AGG_SIG family with program-composed messages, ASSERT_HEIGHT/SECONDS abs/rel, ASSERT_MY_* family, SEND/RECV_MESSAGE tx-scoped, RESERVE_FEE) + universal asserts (ASSERT_OUTPUT_COUNT, ASSERT_FEE_LE) + explicit curation notes per obligation 4.
89-
- [ ] Minimal Bitcoin tx model in Python (inputs w/ outpoint+amount+leaf, outputs w/ scriptPubKey+amount, locktime/sequence) — enough to validate against, no networking.
89+
- [x] Minimal Bitcoin tx model in Python (inputs w/ outpoint+amount+leaf, outputs w/ scriptPubKey+amount, locktime/sequence) — enough to validate against, no networking.
9090
- [ ] `MATCHING.md` + implementation, in this order (novelty-first):
9191
1. **Injective multiset output matching** — k identical CREATE_COINs consume k distinct output slots.
9292
2. **Mixed-transaction rule** — every condition finds a distinct satisfier; unmatched outputs permitted (plain-taproot coexistence).

0 commit comments

Comments
 (0)