Cardano Modular Restaking

Architecture map

Canonical state boundaries and value flows

No architecture matchesTry another search term.

MVP lifecycle

Release target: every success and rejection must replay through model → UPLC → emulator
1DepositAssets enter a controlled strategy vault.
2DelegatePositions select an operator pool.
3AllocateExposure activates after visible notice.
4Reward / SlashFunded reward or attributable capped loss.
5WithdrawRelease follows every evidence and claim tail.

Evidence-gated delivery, not document-driven completion.

The source-stable model evidence records 90 passing tests across 17 files, 1,084,201 assertions, seven accepted vault/operator actions, and a finite depth-five explorer with 11,550 attempted edges across 2,894 unique state/slot nodes. Its 8,174 expected rejections include 3,375 action-specific single-fault transaction-fact mutations; each rejects exactly without state interference. Selected-source inventories bind ten AllocationManager files and 165 tests, four RewardsCoordinator files and 168 tests, nine permission/pause/upgrade files and 31 tests, and the complete 177-file middleware Solidity tree with 800 named tests. The middleware tests are inventoried, not executed; exact Cardano dispositions remain zero and the core-lock mismatch and semantic/dependency remainder stay open. A separate 27-vector exact-bigint TypeScript oracle plus bounded sweeps executes selected AllocationManager formulas without executing Solidity or selecting Cardano behavior. Complete pre-validator plans keep 60 unresolved or prohibited service, allocation, claim, reward, governance, staking, middleware, key, task, and multichain seams absent and fail closed while their decisions remain open. Controlled staking records the non-ADA/lovelace unit mismatch; middleware records exact service/task/chain domains, integer thresholds, historical key tails, and remote-value exclusion without selecting cryptography or remote trust. No unresolved economics, authority, timing, proof, fee, destination, migration, rollback, recovery, staking, or multichain behavior is admitted. The pinned Catalyst stack passes 26 upstream tests and evaluates two non-protocol UPLC probes. The Aiken Forestry reference corpus passes 47 upstream tests; 14 translated cases match Catalyst. A decoded-proof guard adds 21 matched probes and a canonical codec adds 69 strict arbitrary-Data cases. These 106 evaluator cases are non-protocol primitives; F-001 stays a high-severity blocker pending broader mutable sequences, ledger budgets, reviewed consumers, protocol integration, official V4, refinement, and independent review. Repository-controlled Zig adapters build all 11 packages in the pinned Blaze scope and 63 selected tests pass. Blaze separately constructs, signs, and accepts one deterministic generic ADA transfer containing no restaking datum, redeemer, validator, policy, or state. A same-host clean checkout matches all five deterministic model/formal projections for source revision 4224046219578a8d82eae631a9c6f058ff64f201. The strict release report passes PPA-10 only, fails 12 gates, and records NOT_RELEASED; protocol-transition UPLC/Blaze/Cardano-certificate/cryptographic/remote-finality execution, public-testnet execution, independent reproduction, and release remain open.

The pinned middleware corpus also hash-inventories the complete 177-file Solidity tree: 78 source files, 97 test files, two scripts, 121 normalized source declarations, 618 named source functions, 116 test families, and 800 named tests. Exact per-declaration and per-test Cardano disposition counts remain zero; no upstream Solidity was executed.

Final revision reconciliation is bound to published checkpoint 13de2140279f1cf925db6effc021aec2ef694306: all dependency reports are current, the same-host clean checkout matched five projections in 200,744 ms, and the release gate records 106 non-protocol UPLC evaluations, one generic Blaze acceptance, zero protocol executions, and NOT_RELEASED. This supersedes the earlier revision note above.

REVIEWED 2026-08-06
PhaseStateExit evidencePrimary source

Progress discipline

  1. Resolve value-bearing choices in docs/DECISION_LOG.md before implementing their paths.
  2. Keep every incomplete validator and policy fail-closed.
  3. Advance status only with source-bound, reproducible evidence using the repository vocabulary.
  4. Update this explorer in the same change as architecture, transition, phase, or evidence changes.

Claims stop exactly where the evidence stops.

The project uses a deliberately strict vocabulary so pure models, transaction construction, evaluator execution, emulator acceptance, public-ledger inclusion, formal proofs, and release decisions cannot be conflated.

OPEN RELEASE GATES ↗

Release tiers

  1. Pre-production alpha: generated UPLC and Blaze emulator evidence, explicitly not public-chain execution.
  2. Testnet-executed alpha: named public-testnet transactions, reconstructed state, and exercised operational recovery.
  3. Production: additional soak, independent review, deployed governance controls, monitoring, and budget headroom.