Roadmap
| # | Deliverable | Exit criterion |
|---|---|---|
| S0 | Spikes (week one). (a) Recursive UltraHonk verification of a witnessed VK in Noir with the pinned bb, gate count measured, constant proof size confirmed. (b) A minimal comptime attribute that walks a function body and extracts string literals. | Both numbers and both feasibility answers written into spec/adr/. If (a) is prohibitive, decide on three phase-specialized VK_Ws before M1. |
| M0 | Spec, schema files, domain table, golden world definition, leakage profile as a test fixture | Reference crate builds all four context regions and emits vectors; Poseidon2 vectors agree across Rust, Noir, TS |
| M1 | Protocol libs + the five main circuits + no-op policy + hand-written corridor mains | Golden lifecycle (initiate → accept, initiate → reject, initiate → reclaim) proves end to end under nargo + bb; pool verifies on a local devnet; accept and reject calldata diff is empty |
| M2 | Wrapper W with witnessed phase, params, state, attestation publics, possession proofs | Wrapped no-op at every phase; the hand-written corridor proves and lands; a replay under another FI index is rejected |
| M3 | Framework library + attributes; corridor rebuilt on the framework | Example builds to three packages with zero hand-written main; type-level phase restrictions verified by compile-fail tests; Either composes |
| M4 | CLI: build, manifest, test (satisfiability, weld coverage, sensitivity, negatives, budget), codegen | weld test catches a deliberately unwelded, a deliberately no-op, and a deliberately bricking policy |
| M5 | Registry CLI, TS/Rust SDKs, two-FI e2e, outsourced proving | Params change lands without VK rotation; velocity rule enforces across two payments; a relayer proves W from an FI signature alone |
| M6 | Rule catalog, attestations, docs site, template registry | Ten catalog rules with negatives; a recipient rule requires a sender attestation |
Deferred by design: authority, asset-issuer, and unshield policy slots (each
is one more leaf/VK slot and one more Ctx phase; the framework model is
unchanged), keyed state maps, sender settle callback, proof aggregation
across FIs, path-mode context openings, no-code editor. The programmable
workflow layer (spec/workflows.md) replaces the initiate, resolve, and
reclaim circuits in a later protocol version and turns the hold into a
library template; its milestones start after M5.