Roadmap
| # | Deliverable | Exit criterion |
|---|---|---|
| S1 | Spike. J as N = 2 UltraHonk recursions versus a ClientIVC fold of two kernel proofs; kernel gate count with 2/2/2/2 arity and 8 envelopes | Numbers in spec/adr/; decision on J's construction |
| W0 | This document to v1.0; kernel relation written out formally; independent review scheduled | Reviewers sign off on §4.3, §5.2, §5.4 relations |
| W1 | Records, bound notes, party and program registries, K, J with N = 1, #[weld::template]/#[weld::choice], Proposal and Escrow | Weld v0.2's golden lifecycle reproduced through Proposal; escrow release/refund race settles exactly one; all four closings' calldata identical |
| W2 | J with N ≤ 2, flows, manifest signing, coordinator SDK, Invoice and DvP | Two-FI DvP lands atomically; abort before submission leaks only statements; policy on each side judges only its fragment |
| W3 | Function privacy padding, encryption-consistency proofs, N ≤ 4, ClientIVC if S1 says so | Escrow and payment transactions have identical calldata; unattended delivery test passes with wrong-key negatives |
| W4 | Indexed nullifier tree by batch proof, fetch, interfaces, program migration flow | A non-consuming read does not conflict with a concurrent consumer; an old-program record migrates under signatory authority |
Deferred: private calls between programs, MPC-backed methods, blob transport, multi-call public effects, asset-issuer and authority policy slots, actor anonymity (§12).