Verdict count: 11 confirmed / 4 disputed / 1 unconfirmed (16 findings total).
refs/tags/v0.2.5 → commit c99ff8ce86a7c5d2ad343d62232c843f627c9d0cbork/proof/20260930T111822-73c2b9 — check this branch out or apply enclosed patch file to refs/tags/v0.2.5to run every repro on the tree the findings were proved on. The target implementation is unchanged; the branch adds only proof files under per-finding namespaces.Skipped, mocked, parked or unrun tests were never treated as conformance: the parked ZEC/XMR CI tests, the unwired guide-contract scripts and the un-run standalone-sequencer harness count only as what the pass rows attest — presence of an artifact, not evidence of a passing run.
refs/tags/v0.2.5The first pass’s trace, copied as written, joined to the merged finding statuses. Toolchain: pinned Rust workspace built with cargo --locked; the CI gate lives in .github/workflows/ci.yml driving scripts/run-ci-quality-gates.sh.
Legend: pass = concrete implementation plus test evidence at the described boundary; finding N = diverges, see finding N below; unresolved = no verifiable evidence either way in a static checkout (not a pass). Rows marked pass* pass at the cited layer but inherit a filed cross-cutting finding.
| ID | Requirement | Implementation evidence | Tests | Status |
|---|---|---|---|---|
| F1 | No central server; advertisement over Logos Delivery, coordination over Logos Chat | crates/node-common/src/run_local_delivery.rs:40 (LIP-23 content topic), crates/node-common/src/logos_chat_gateway.rs:1-6, apps/basecamp/README.md:12,72 (pinned Logos Chat 0.2.2 / Delivery 0.2.x) |
node e2e (deploy/scripts/node-e2e.py) |
pass* — no central service anywhere; but the network transport lives only in the Basecamp apps, see finding 13 (confirmed) |
| F2 | LEZ–BTC via BIP-340 adaptor sigs + Taproot; cooperative claim is a key-path spend; refund pre-signed key-path or script-path CSV tapleaf | claim key-path: crates/btc-swap-sdk/src/transaction.rs:152-155,224; shape enforced crates/btc-core-adapter/src/evidence.rs:507-520; CSV tapleaf crates/btc-swap-sdk/src/p2tr.rs:234-247; MuSig2/adaptor crates/adaptor-signature/src/lib.rs:820-869 |
e2e assertion deploy/scripts/node-e2e.py:377-401 |
pass (construction). Justification staleness is finding 8 (disputed) |
| F3 | LEZ–XMR via adaptor sigs + cross-curve DLEQ (h4sh3d/COMIT); atomicity by spend-key-share transfer, no on-chain scripting | crates/xmr-swap-sdk/src/shared_spend.rs:209-268 (spend key from extracted adaptor scalar), crates/xmr-swap-sdk/src/cross_curve.rs:148-220 (sigma_fun cross-curve DLEQ); event-gated maker recovery crates/swap-core/src/lib.rs:249-259 |
SDK crate tests; no node-level e2e | pass* at SDK layer (crate itself disclaims production acceptance, crates/xmr-swap-sdk/src/lib.rs:10); unreachable from the shipped product, see finding 2 (confirmed) |
| F4 | LEZ–ZEC via BIP-199 HTLC; Zcash refund deadline strictly succeeds LEZ deadline by a documented margin | script crates/zec-swap-sdk/src/lib.rs:187-247 (exact BIP-199 layout); ordering crates/swap-core/src/lib.rs:208-241,301-306; margin values crates/zec-swap-sdk/src/profile.rs:80-99 matching docs/milestone-1/parameter-profiles.md:70-71 |
SDK crate tests; ZEC lane parked in CI | pass (contract layer); unreachable from the shipped product, see finding 2 (confirmed) |
| F5 | Risc0 LEZ escrow locks per-chain proof-contingent funds; refund after timelock | guest compat/lez-v0.2-provisional/escrow/methods/guest/src/bin/zec_escrow_v02.rs; three claim authorities compat/lez-v0.2-provisional/escrow/src/lib.rs:30-52; claim window ..refund_at, refund window refund_at.. compat/lez-v0.2-provisional/escrow/src/lib.rs:817,1021 |
escrow guest tests, cycle drift-guard | pass for BTC/ZEC authorities; the XMR variant’s punish path violates the refund clause, see finding 16 (confirmed, raised by second pass) |
| F6 | Both legs atomic; no state where one party receives funds and the other does not | crates/swap-core/src/lib.rs:1143-1207 guards; bypass via reorg detour crates/swap-core/src/lib.rs:993-999,1358-1367; stale maker flag crates/swap-core/src/lib.rs:1098-1141 |
failing proof tests on the proof branch | finding 4 (confirmed), finding 15 (confirmed, raised by second pass), finding 16 (confirmed, raised by second pass) |
| F7 | Native LEZ token and custom tokens via ATAs | escrow+SDK implement it (compat/lez-v0.2-provisional/escrow/src/lib.rs:279-289,1242,1288; crates/btc-swap-sdk/src/asset_sdk.rs:46-55) but no product surface reaches it and XMR/ZEC have no token path |
escrow-layer tests only | finding 9 (confirmed) |
| F8 | Two pricing modes (local static; Logos-module C API), pluggable sources | trait crates/maker-node/src/price_source.rs:75-119; C-ABI adapter crates/logos-price-c-api/src/lib.rs + include/lez_logos_price_api.h; per-route selection crates/maker-node/src/lib.rs:1553-1585; CLI static prices crates/maker-node/src/bin/lez-maker-cli.rs:62-75 |
maker-node tests | pass (static prices settable via CLI; the spec’s “config file or CLI” is satisfied by the CLI path) |
| F9 | Headless maker daemon covering config, pricing, advertisement, execution, monitoring; fully CLI-operable without GUI | daemon crates/maker-node/src/bin/lez-maker-node.rs; but network liquidity advertisement requires the Basecamp GUI runtime |
operator journey tests (local Delivery only) | finding 13 (confirmed) |
| ID | Requirement | Implementation evidence | Tests | Status |
|---|---|---|---|---|
| U1 | Per-pair SDK exposing full lifecycle (discovery, negotiation, escrow, claim, refund) | lifecycle surfaces for all three (crates/btc-swap-sdk/src/sdk.rs:819-1523, crates/xmr-swap-sdk/src/sdk.rs:432-615, crates/zec-swap-sdk/src/sdk.rs:100-1944); discovery/negotiation are injected ports |
SDK tests and examples | finding 11 (disputed — second examiner: dependency-injected transports are a valid SDK surface) |
| U2 | Maker daemon + systemd unit + documented installation steps | unit packaging/systemd/lez-maker-node.service; installer scripts/install-maker-node-service.sh; no installation documentation anywhere |
none for the docs clause | finding 3 (confirmed) |
| U3 | Maker CLI: pairs/prices config, start/stop, history, manual claim/refund over IPC/RPC | crates/maker-node/src/bin/lez-maker-cli.rs:39-179; systemctl-backed control crates/node-common/src/service_control.rs:27-28,197-240 |
crates/maker-node/tests/operator_journey.rs:61,423 |
pass |
| U4 | Taker CLI: discovery, initiation, monitoring, claim, refund | crates/taker-node/src/bin/lez-taker-cli.rs:88-111,212-235 |
taker-node tests | pass* — XMR/ZEC lifecycle feature-gated off by default, see finding 2 (confirmed) |
| U5 | Maker Basecamp mini-app: configure pairs and prices, monitor, history | app exists (apps/basecamp/maker/) but is hardwired to LEZ–BTC |
package-contract check (BTC scope only) | finding 10 (confirmed) |
| U6 | Taker Basecamp mini-app as primary taker interface | app exists (apps/basecamp/taker/) but pair list is ["Bitcoin"] and ZEC shield-after-swap guidance was removed |
package-contract check (BTC scope only) | finding 10 (confirmed) |
| U7 | SPEL-framework IDL for the escrow program(s) | compat/lez-v0.2-provisional/escrow/src/lib.rs:1947-1990 (__program_idl() + tests), compat/spel-zec-escrow/tests/generated_client.rs:44, build-time client generation compat/lez-v0.2-provisional/build.rs:5 |
IDL tests, generated-client test | pass |
| U8 | bitcoind testnet setup doc: config, wallet, funds, self-hosted + public | docs/bitcoin-testnet4-setup.md:76,179,192,238 |
CI-enforced (scripts/run-ci-quality-gates.sh:86) |
pass |
| U9 | monerod stagenet setup doc incl. monero-wallet-rpc and funds, self-hosted + public | docs/monero-stagenet-setup.md does not exist; the repo’s own guard scripts/test-monero-stagenet-guide-contract.sh:6,15 fails |
guard exists but fails and is unwired | finding 1 (confirmed) |
| U10 | zcashd/zebrad testnet setup doc incl. transparent wallet and funds, self-hosted + public | docs/zcash-testnet-setup.md exists but fails its own contract (scripts/test-zcash-testnet-guide-contract.sh) and records SDK connectivity as “Not implemented” (docs/zcash-testnet-setup.md:258) |
contract script (failing, unwired) | finding 6 (disputed — second examiner: the guide satisfies U10’s node/wallet scope; the failing contract exceeds the requirement) |
| ID | Requirement | Implementation evidence | Tests | Status |
|---|---|---|---|---|
| R1 | Taker-first on-chain ordering; maker must not lock until taker lock confirmed | crates/swap-core/src/lib.rs:1097-1141 (TakerLockNotConfirmed until policy met; non-zero policy :658-668) |
swap-core transition tests | pass |
| R2 | On-chain-only execution after first lock | e2e deploy/scripts/node-e2e.py:663-699 (offline-after-lock); compile-fail doctest crates/btc-swap-sdk/src/sdk.rs:1250-1258; peerless resume crates/btc-swap-sdk/src/sdk.rs:881 |
BTC e2e | pass (BTC lane; XMR/ZEC lanes carry no such e2e — inherits finding 2, confirmed) |
| R3 | Missing chain dependency: app still starts, other chains still swap, clearly reported | runtime per-route degradation crates/maker-node/src/route_health.rs:60-202; but chains are compile-time features, and a Delivery outage at startup is fatal |
crates/maker-node/tests/route_health.rs:98,324 |
finding 2 (confirmed), finding 5 (unconfirmed) |
| R4 | Local swap-state persistence; resume after crash/restart | crates/swap-store/src/lib.rs:699-1911 (WAL SQLite, immediate transactions); boot-time drain crates/maker-node/src/bin/lez-maker-node.rs:434-445 |
crates/swap-store/tests/restart_recovery.rs:226 |
pass |
| R5 | Concurrent swap isolation | per-swap CAS keys crates/swap-store/src/lib.rs:1831,2029-2030; lease-based actors crates/maker-node/src/bin/lez-maker-node.rs:433; escrow-slot admission crates/maker-node/src/btc_lifecycle.rs:625-638 |
interleaved run per ADR 0041 | pass (BTC; multi-pair/fault-injected coverage absent, noted) |
| R6 | Timelock params account for variance/congestion/drift; choices documented with rationale | ZEC/XMR match docs/milestone-1/parameter-profiles.md exactly (crates/zec-swap-sdk/src/profile.rs:80-99, crates/xmr-swap-sdk/src/agreement_v1.rs:52-68); BTC parameterisation contested |
ordering enforced config.rs:143-181 per second examiner |
finding 7 (disputed — second examiner: deploy/scripts/gen-config.sh:228-229 and deploy/README.md:235-263 document the deployed BTC profiles) |
| R7 | Bitcoin refund construction stated and justified; pre-signed failure modes enumerated/mitigated | ADR 0009 justifies script-path partly on “signs when needed”; the code pre-signs the refund with a setup-time fee and no bump path (crates/btc-swap-sdk/src/sdk.rs:396-434, ADR 0213 “No fee bumping after signing”) |
none | finding 8 (disputed — second examiner: the extra-failure-modes clause is conditional on the pre-signed key-path choice, which was not made) |
| R8 | Graceful handling + documentation when Delivery/Chat temporarily unreachable | runtime degraded mode + reconcile (crates/maker-node/src/lib.rs:1264-1283, crates/node-common/src/run_local_delivery.rs:429-583); startup outage aborts the daemon |
offline-after-lock e2e covers the running-daemon case only |
finding 5 (unconfirmed) |