Phase 1 close-out: ratify D3 and D4, complete provenance, close the plan - #12
Merged
Merged
Conversation
D3 (decision by Evan, 2026-07-29): strict rejection of unknown operators is ratified and the softfork guard is declined for v0. Upgrades split by audience: new tapleaf versions for coins created after a fork, reserved conditions for coins already deployed. The reserved-condition rule in MATCHING.md is designated the forward-compatibility mechanism and gets a rule slot there. The ratification record corrects the earlier provisional entry. Probes against the consensus oracle at flags 0 (softfork with an unknown extension id, garbage and raising guarded programs, zero, negative, and over-budget declared costs, live-extension cost mismatch) show old-node softfork is charge-and-nil and never evaluates the guarded program, so the prior claim that the guard's containment machinery must be perfect from v0 was wrong. The guard is declined on redundancy instead. D4 (decision by Evan, 2026-07-29): strict rejection of the pair operator family is ratified. Probes sharpened the record: both oracles reject a proper-list tail in the operator pair, and the sole disagreement is the improper dotted atom tail, which chia-rs ignores and clvm rejects. The divergence table row now states the edge exactly. The grounds: no expressive power, fossil corner semantics both oracles share (((q) 1 2) is nil at cost 91), the dotted-tail edge diverges under any acceptance rule, and grammar continuity with D3, D5, and D7.
The provenance table's two remaining TODOs get their hashes. The clvm 0.9.15 wheel matches Chia-Network/clvm tag 0.9.15 at commit 00c47c9b, the same commit already recorded for the vendored command test corpus, and the chia-rs 0.46.0 wheel matches Chia-Network/chia_rs tag 0.46.0 at commit 7d487907. Both resolved from the tagged releases in the reference clones.
The Phase 1 close-out audit cross-checked every operator in the VM.md table against a COSTS.md row and every constant in python/bitlisp/ against a spec statement, in both directions. One gap: x was the only operator whose cost treatment the spec never stated, and the choice between cost_exceeded and user_raise at the budget boundary is consensus-visible. Probed against both oracles: (x (q . 1)) under budget 20 is cost_exceeded and under 21 is user_raise on all three implementations, confirming x charges only the dispatch cost at identification plus its arguments' own costs, with no charge of its own. The spec now says so and two boundary vectors pin it. No implementation change.
Flip the two remaining Phase 1 checkboxes, both already done in substance (COSTS.md covers every v0 family with the weight mapping stubbed for Phase 3, the vendored Chia corpus and the seeded 10k-program generator run in CI). Record the done-criteria evidence in the plan: fresh-seed verification with seed 20260729 across the unit suite, the vector corpus, the upstream corpus, and both diff harnesses, zero failures. The spec status lines move from in progress to complete, with the PROVISIONAL constants and open section 8 sub-questions explicitly owed to Phase 3.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
Phase 1 ends here. Two design decisions are ratified and recorded, the last provenance TODOs are filled, a cost-table audit gap is closed with boundary vectors, and the execution plan's Phase 1 section is marked done with fresh verification evidence. No implementation behavior changes.
Spec sections
Read the commits in order
Spec: ratify D3 and D4, correct the pair-operator recordSpec: record the oracle wheels' upstream release commitsCosts: state the raise operator's charge order, pin the boundaryDocs: close Phase 1Verify independently
Any fresh seed should also pass the two diff harnesses. The probe claims in the D3 and D4 ratification text (softfork charge-and-nil at flags 0, the pair-operator family map, the raise boundary at budgets 20 and 21) reproduce against the pinned wheels with short scripts over
chia_rs.run_chia_programandclvm.run_program, shapes as described in the spec text.