MVP lifecycle
Release target: every success and rejection must replay through model → UPLC → emulatorEvidence-gated delivery, not document-driven completion.
The source-stable model evidence records 71 passing tests, 1,083,082 assertions, direct register/delegate/delegated-deposit/queue coverage, a 15-vector pinned EigenLayer v1.12.0 vault arithmetic differential, and a finite depth-five one-owner/two-operator explorer with 11,550 attempted edges across 2,894 unique state/slot nodes. Its 8,174 expected rejections include 3,375 action-specific single-fault transaction-fact mutations paired with every planned-success non-create edge; each rejects exactly without state interference and the report explicitly declares that these rejected fact edges never create nodes. The accepted graph still covers 764 registrations, 288 delegations, delegation to either operator, delegated deposit, partial/full queue, and attributed completion paths. A deterministic source-inventory corpus binds ten pinned AllocationManager files, 7 interfaces, 21 errors, 11 structs, 15 events, 51 functions, 28 selected test families with 165 named tests, and 31 named but unexecuted Certora declarations. A separate 27-vector exact-bigint TypeScript oracle plus 821 bounded magnitude/rounding and tail checks executes selected source-derived AllocationManager rules without executing Solidity or selecting Cardano behavior. Ten unresolved local service/set/allocation/exit actions remain absent and fail closed. The pinned Catalyst stack builds, a clean detached checkout passes all 26 upstream tests, and two non-protocol UPLC probes execute with captured inputs, hashes, sizes, outcomes, and testing-cost budgets. Repository-controlled Zig 0.15.2 adapters also build all 11 packages in the exact pinned Blaze emulator scope, three selected outputs match fixed hashes, and all 63 selected upstream emulator tests pass. The integrity-locked published Blaze closure separately constructs, signs, and accepts one deterministic generic ADA transfer twice with identical CBOR and transaction ID; that transfer contains no restaking datum, redeemer, validator, policy, or state. The selected Plutus ledger API exposes only V1–V3; the expected missing-V4 compile diagnostic is preserved and no artifact is labeled V4. The source-bound release report still passes PPA-10 only, fails 12 gates, and records NOT_RELEASED. Independent reproduction, validator implementation, protocol-transition UPLC/Blaze execution, implementation refinement, and public-testnet execution remain open.
| Phase | State | Exit evidence | Primary source |
|---|
Progress discipline
- Resolve value-bearing choices in
docs/DECISION_LOG.mdbefore implementing their paths. - Keep every incomplete validator and policy fail-closed.
- Advance status only with source-bound, reproducible evidence using the repository vocabulary.
- Update this explorer in the same change as architecture, transition, phase, or evidence changes.
Claims stop exactly where the evidence stops.
The project uses a deliberately strict vocabulary so pure models, transaction construction, evaluator execution, emulator acceptance, public-ledger inclusion, formal proofs, and release decisions cannot be conflated.
Release tiers
- Pre-production alpha: generated UPLC and Blaze emulator evidence, explicitly not public-chain execution.
- Testnet-executed alpha: named public-testnet transactions, reconstructed state, and exercised operational recovery.
- Production: additional soak, independent review, deployed governance controls, monitoring, and budget headroom.