Skip to content

Phase 1 close-out: ratify D3 and D4, complete provenance, close the plan - #12

Merged
EvanWinget merged 4 commits into
mainfrom
phase1-closeout
Jul 29, 2026
Merged

EvanWinget merged 4 commits into
mainfrom
phase1-closeout

Conversation

@EvanWinget

Copy link
Copy Markdown
Owner

What changed

Phase 1 ends here. Two design decisions are ratified and recorded, the last provenance TODOs are filled, a cost-table audit gap is closed with boundary vectors, and the execution plan's Phase 1 section is marked done with fresh verification evidence. No implementation behavior changes.

Spec sections

  • VM.md section 8: D3 and D4 move from provisional to RATIFIED (decisions by Evan, 2026-07-29). The D3 record corrects its own earlier claim about the softfork guard's v0 machinery, based on new oracle probes, and designates reserved conditions as the deployed-coin forward-compatibility mechanism. MATCHING.md gains the corresponding rule 6 slot.
  • VM.md section 6: the D4 row now states the oracle disagreement exactly. Both oracles reject a proper-list tail in the operator pair, and the sole disagreement is the improper dotted atom tail.
  • VM.md section 7: upstream release commits recorded for both pinned wheels (clvm 0.9.15 at 00c47c9b, chia-rs 0.46.0 at 7d487907).
  • COSTS.md section 2: the raise operator's charge order stated, the one operator the cost spec had not covered.

Read the commits in order

  1. Spec: ratify D3 and D4, correct the pair-operator record
  2. Spec: record the oracle wheels' upstream release commits
  3. Costs: state the raise operator's charge order, pin the boundary
  4. Docs: close Phase 1

Verify independently

.venv/bin/pytest python/tests                                  # 76 passed
.venv/bin/python tools/run_vectors.py                          # 460 cases, 0 failures
.venv/bin/python tools/run_upstream.py                         # 832 cases, 0 findings
.venv/bin/python tools/diff_clvm.py --count 10000 --seed 20260729   # 0 failures
.venv/bin/python tools/diff_secp.py --count 40 --seed 20260729      # 0 failures
PATH=".venv/bin:$PATH" ci/lint/lint.sh

Any fresh seed should also pass the two diff harnesses. The probe claims in the D3 and D4 ratification text (softfork charge-and-nil at flags 0, the pair-operator family map, the raise boundary at budgets 20 and 21) reproduce against the pinned wheels with short scripts over chia_rs.run_chia_program and clvm.run_program, shapes as described in the spec text.

D3 (decision by Evan, 2026-07-29): strict rejection of unknown
operators is ratified and the softfork guard is declined for v0.
Upgrades split by audience: new tapleaf versions for coins created
after a fork, reserved conditions for coins already deployed. The
reserved-condition rule in MATCHING.md is designated the
forward-compatibility mechanism and gets a rule slot there.

The ratification record corrects the earlier provisional entry.
Probes against the consensus oracle at flags 0 (softfork with an
unknown extension id, garbage and raising guarded programs, zero,
negative, and over-budget declared costs, live-extension cost
mismatch) show old-node softfork is charge-and-nil and never
evaluates the guarded program, so the prior claim that the guard's
containment machinery must be perfect from v0 was wrong. The guard
is declined on redundancy instead.

D4 (decision by Evan, 2026-07-29): strict rejection of the pair
operator family is ratified. Probes sharpened the record: both
oracles reject a proper-list tail in the operator pair, and the
sole disagreement is the improper dotted atom tail, which chia-rs
ignores and clvm rejects. The divergence table row now states the
edge exactly. The grounds: no expressive power, fossil corner
semantics both oracles share (((q) 1 2) is nil at cost 91), the
dotted-tail edge diverges under any acceptance rule, and grammar
continuity with D3, D5, and D7.
The provenance table's two remaining TODOs get their hashes. The
clvm 0.9.15 wheel matches Chia-Network/clvm tag 0.9.15 at commit
00c47c9b, the same commit already recorded for the vendored command
test corpus, and the chia-rs 0.46.0 wheel matches
Chia-Network/chia_rs tag 0.46.0 at commit 7d487907. Both resolved
from the tagged releases in the reference clones.
The Phase 1 close-out audit cross-checked every operator in the
VM.md table against a COSTS.md row and every constant in
python/bitlisp/ against a spec statement, in both directions. One
gap: x was the only operator whose cost treatment the spec never
stated, and the choice between cost_exceeded and user_raise at the
budget boundary is consensus-visible. Probed against both oracles:
(x (q . 1)) under budget 20 is cost_exceeded and under 21 is
user_raise on all three implementations, confirming x charges only
the dispatch cost at identification plus its arguments' own costs,
with no charge of its own. The spec now says so and two boundary
vectors pin it. No implementation change.
Flip the two remaining Phase 1 checkboxes, both already done in
substance (COSTS.md covers every v0 family with the weight mapping
stubbed for Phase 3, the vendored Chia corpus and the seeded
10k-program generator run in CI). Record the done-criteria evidence
in the plan: fresh-seed verification with seed 20260729 across the
unit suite, the vector corpus, the upstream corpus, and both diff
harnesses, zero failures. The spec status lines move from in
progress to complete, with the PROVISIONAL constants and open
section 8 sub-questions explicitly owed to Phase 3.
@EvanWinget
EvanWinget merged commit cf9d576 into main Jul 29, 2026
2 checks passed
@EvanWinget
EvanWinget deleted the phase1-closeout branch July 29, 2026 18:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant