MVP lifecycle
Release target: every success and rejection must replay through model → UPLC → emulatorEvidence-gated delivery, not document-driven completion.
The source-stable model evidence records 80 passing tests across 14 files, 1,083,478 assertions, seven accepted vault/operator actions, and a finite depth-five explorer with 11,550 attempted edges across 2,894 unique state/slot nodes. Its 8,174 expected rejections include 3,375 action-specific single-fault transaction-fact mutations; each rejects exactly without state interference. Selected-source inventories bind ten AllocationManager files and 165 tests, four RewardsCoordinator files and 168 tests, and nine permission/pause/upgrade files and 31 tests. A separate 27-vector exact-bigint TypeScript oracle plus bounded sweeps executes selected AllocationManager formulas without executing Solidity or selecting Cardano behavior. Complete pre-validator plans keep ten service/allocation/exit actions, five claim actions, five reward actions, two prohibited reward seams, eleven governance/upgrade actions, and four prohibited governance/migration seams absent and fail closed while their decisions remain open. No unresolved economics, authority, timing, proof, fee, destination, migration, rollback, or recovery behavior is admitted. The pinned Catalyst stack passes 26 upstream tests and evaluates two non-protocol UPLC probes. The Aiken Forestry reference corpus passes 47 upstream tests; 14 translated cases match Catalyst. A decoded-proof guard adds 21 matched probes and a canonical codec adds 69 strict arbitrary-Data cases. These 106 evaluator cases are non-protocol primitives; F-001 stays a high-severity blocker pending broader mutable sequences, ledger budgets, reviewed consumers, protocol integration, official V4, refinement, and independent review. Repository-controlled Zig adapters build all 11 packages in the pinned Blaze scope and 63 selected tests pass. Blaze separately constructs, signs, and accepts one deterministic generic ADA transfer containing no restaking datum, redeemer, validator, policy, or state. A same-host clean checkout matches all five deterministic model/formal projections for source revision 58b9e85d8c4129063c55c6154a50ac14d6eba0f2. The strict release report passes PPA-10 only, fails 12 gates, and records NOT_RELEASED; protocol-transition UPLC/Blaze execution, public-testnet execution, independent reproduction, and release remain open.
| Phase | State | Exit evidence | Primary source |
|---|
Progress discipline
- Resolve value-bearing choices in
docs/DECISION_LOG.mdbefore implementing their paths. - Keep every incomplete validator and policy fail-closed.
- Advance status only with source-bound, reproducible evidence using the repository vocabulary.
- Update this explorer in the same change as architecture, transition, phase, or evidence changes.
Claims stop exactly where the evidence stops.
The project uses a deliberately strict vocabulary so pure models, transaction construction, evaluator execution, emulator acceptance, public-ledger inclusion, formal proofs, and release decisions cannot be conflated.
Release tiers
- Pre-production alpha: generated UPLC and Blaze emulator evidence, explicitly not public-chain execution.
- Testnet-executed alpha: named public-testnet transactions, reconstructed state, and exercised operational recovery.
- Production: additional soak, independent review, deployed governance controls, monitoring, and budget headroom.