Verdict count: 11 confirmed / 4 disputed / 1 unconfirmed (16 findings total).

How the evidence is classed

Skipped, mocked, parked or unrun tests were never treated as conformance: the parked ZEC/XMR CI tests, the unwired guide-contract scripts and the un-run standalone-sequencer harness count only as what the pass rows attest — presence of an artifact, not evidence of a passing run.

Requirement trace — refs/tags/v0.2.5

The first pass’s trace, copied as written, joined to the merged finding statuses. Toolchain: pinned Rust workspace built with cargo --locked; the CI gate lives in .github/workflows/ci.yml driving scripts/run-ci-quality-gates.sh.

Legend: pass = concrete implementation plus test evidence at the described boundary; finding N = diverges, see finding N below; unresolved = no verifiable evidence either way in a static checkout (not a pass). Rows marked pass* pass at the cited layer but inherit a filed cross-cutting finding.

Functionality

ID Requirement Implementation evidence Tests Status
F1 No central server; advertisement over Logos Delivery, coordination over Logos Chat crates/node-common/src/run_local_delivery.rs:40 (LIP-23 content topic), crates/node-common/src/logos_chat_gateway.rs:1-6, apps/basecamp/README.md:12,72 (pinned Logos Chat 0.2.2 / Delivery 0.2.x) node e2e (deploy/scripts/node-e2e.py) pass* — no central service anywhere; but the network transport lives only in the Basecamp apps, see finding 13 (confirmed)
F2 LEZ–BTC via BIP-340 adaptor sigs + Taproot; cooperative claim is a key-path spend; refund pre-signed key-path or script-path CSV tapleaf claim key-path: crates/btc-swap-sdk/src/transaction.rs:152-155,224; shape enforced crates/btc-core-adapter/src/evidence.rs:507-520; CSV tapleaf crates/btc-swap-sdk/src/p2tr.rs:234-247; MuSig2/adaptor crates/adaptor-signature/src/lib.rs:820-869 e2e assertion deploy/scripts/node-e2e.py:377-401 pass (construction). Justification staleness is finding 8 (disputed)
F3 LEZ–XMR via adaptor sigs + cross-curve DLEQ (h4sh3d/COMIT); atomicity by spend-key-share transfer, no on-chain scripting crates/xmr-swap-sdk/src/shared_spend.rs:209-268 (spend key from extracted adaptor scalar), crates/xmr-swap-sdk/src/cross_curve.rs:148-220 (sigma_fun cross-curve DLEQ); event-gated maker recovery crates/swap-core/src/lib.rs:249-259 SDK crate tests; no node-level e2e pass* at SDK layer (crate itself disclaims production acceptance, crates/xmr-swap-sdk/src/lib.rs:10); unreachable from the shipped product, see finding 2 (confirmed)
F4 LEZ–ZEC via BIP-199 HTLC; Zcash refund deadline strictly succeeds LEZ deadline by a documented margin script crates/zec-swap-sdk/src/lib.rs:187-247 (exact BIP-199 layout); ordering crates/swap-core/src/lib.rs:208-241,301-306; margin values crates/zec-swap-sdk/src/profile.rs:80-99 matching docs/milestone-1/parameter-profiles.md:70-71 SDK crate tests; ZEC lane parked in CI pass (contract layer); unreachable from the shipped product, see finding 2 (confirmed)
F5 Risc0 LEZ escrow locks per-chain proof-contingent funds; refund after timelock guest compat/lez-v0.2-provisional/escrow/methods/guest/src/bin/zec_escrow_v02.rs; three claim authorities compat/lez-v0.2-provisional/escrow/src/lib.rs:30-52; claim window ..refund_at, refund window refund_at.. compat/lez-v0.2-provisional/escrow/src/lib.rs:817,1021 escrow guest tests, cycle drift-guard pass for BTC/ZEC authorities; the XMR variant’s punish path violates the refund clause, see finding 16 (confirmed, raised by second pass)
F6 Both legs atomic; no state where one party receives funds and the other does not crates/swap-core/src/lib.rs:1143-1207 guards; bypass via reorg detour crates/swap-core/src/lib.rs:993-999,1358-1367; stale maker flag crates/swap-core/src/lib.rs:1098-1141 failing proof tests on the proof branch finding 4 (confirmed), finding 15 (confirmed, raised by second pass), finding 16 (confirmed, raised by second pass)
F7 Native LEZ token and custom tokens via ATAs escrow+SDK implement it (compat/lez-v0.2-provisional/escrow/src/lib.rs:279-289,1242,1288; crates/btc-swap-sdk/src/asset_sdk.rs:46-55) but no product surface reaches it and XMR/ZEC have no token path escrow-layer tests only finding 9 (confirmed)
F8 Two pricing modes (local static; Logos-module C API), pluggable sources trait crates/maker-node/src/price_source.rs:75-119; C-ABI adapter crates/logos-price-c-api/src/lib.rs + include/lez_logos_price_api.h; per-route selection crates/maker-node/src/lib.rs:1553-1585; CLI static prices crates/maker-node/src/bin/lez-maker-cli.rs:62-75 maker-node tests pass (static prices settable via CLI; the spec’s “config file or CLI” is satisfied by the CLI path)
F9 Headless maker daemon covering config, pricing, advertisement, execution, monitoring; fully CLI-operable without GUI daemon crates/maker-node/src/bin/lez-maker-node.rs; but network liquidity advertisement requires the Basecamp GUI runtime operator journey tests (local Delivery only) finding 13 (confirmed)

Usability

ID Requirement Implementation evidence Tests Status
U1 Per-pair SDK exposing full lifecycle (discovery, negotiation, escrow, claim, refund) lifecycle surfaces for all three (crates/btc-swap-sdk/src/sdk.rs:819-1523, crates/xmr-swap-sdk/src/sdk.rs:432-615, crates/zec-swap-sdk/src/sdk.rs:100-1944); discovery/negotiation are injected ports SDK tests and examples finding 11 (disputed — second examiner: dependency-injected transports are a valid SDK surface)
U2 Maker daemon + systemd unit + documented installation steps unit packaging/systemd/lez-maker-node.service; installer scripts/install-maker-node-service.sh; no installation documentation anywhere none for the docs clause finding 3 (confirmed)
U3 Maker CLI: pairs/prices config, start/stop, history, manual claim/refund over IPC/RPC crates/maker-node/src/bin/lez-maker-cli.rs:39-179; systemctl-backed control crates/node-common/src/service_control.rs:27-28,197-240 crates/maker-node/tests/operator_journey.rs:61,423 pass
U4 Taker CLI: discovery, initiation, monitoring, claim, refund crates/taker-node/src/bin/lez-taker-cli.rs:88-111,212-235 taker-node tests pass* — XMR/ZEC lifecycle feature-gated off by default, see finding 2 (confirmed)
U5 Maker Basecamp mini-app: configure pairs and prices, monitor, history app exists (apps/basecamp/maker/) but is hardwired to LEZ–BTC package-contract check (BTC scope only) finding 10 (confirmed)
U6 Taker Basecamp mini-app as primary taker interface app exists (apps/basecamp/taker/) but pair list is ["Bitcoin"] and ZEC shield-after-swap guidance was removed package-contract check (BTC scope only) finding 10 (confirmed)
U7 SPEL-framework IDL for the escrow program(s) compat/lez-v0.2-provisional/escrow/src/lib.rs:1947-1990 (__program_idl() + tests), compat/spel-zec-escrow/tests/generated_client.rs:44, build-time client generation compat/lez-v0.2-provisional/build.rs:5 IDL tests, generated-client test pass
U8 bitcoind testnet setup doc: config, wallet, funds, self-hosted + public docs/bitcoin-testnet4-setup.md:76,179,192,238 CI-enforced (scripts/run-ci-quality-gates.sh:86) pass
U9 monerod stagenet setup doc incl. monero-wallet-rpc and funds, self-hosted + public docs/monero-stagenet-setup.md does not exist; the repo’s own guard scripts/test-monero-stagenet-guide-contract.sh:6,15 fails guard exists but fails and is unwired finding 1 (confirmed)
U10 zcashd/zebrad testnet setup doc incl. transparent wallet and funds, self-hosted + public docs/zcash-testnet-setup.md exists but fails its own contract (scripts/test-zcash-testnet-guide-contract.sh) and records SDK connectivity as “Not implemented” (docs/zcash-testnet-setup.md:258) contract script (failing, unwired) finding 6 (disputed — second examiner: the guide satisfies U10’s node/wallet scope; the failing contract exceeds the requirement)

Reliability

ID Requirement Implementation evidence Tests Status
R1 Taker-first on-chain ordering; maker must not lock until taker lock confirmed crates/swap-core/src/lib.rs:1097-1141 (TakerLockNotConfirmed until policy met; non-zero policy :658-668) swap-core transition tests pass
R2 On-chain-only execution after first lock e2e deploy/scripts/node-e2e.py:663-699 (offline-after-lock); compile-fail doctest crates/btc-swap-sdk/src/sdk.rs:1250-1258; peerless resume crates/btc-swap-sdk/src/sdk.rs:881 BTC e2e pass (BTC lane; XMR/ZEC lanes carry no such e2e — inherits finding 2, confirmed)
R3 Missing chain dependency: app still starts, other chains still swap, clearly reported runtime per-route degradation crates/maker-node/src/route_health.rs:60-202; but chains are compile-time features, and a Delivery outage at startup is fatal crates/maker-node/tests/route_health.rs:98,324 finding 2 (confirmed), finding 5 (unconfirmed)
R4 Local swap-state persistence; resume after crash/restart crates/swap-store/src/lib.rs:699-1911 (WAL SQLite, immediate transactions); boot-time drain crates/maker-node/src/bin/lez-maker-node.rs:434-445 crates/swap-store/tests/restart_recovery.rs:226 pass
R5 Concurrent swap isolation per-swap CAS keys crates/swap-store/src/lib.rs:1831,2029-2030; lease-based actors crates/maker-node/src/bin/lez-maker-node.rs:433; escrow-slot admission crates/maker-node/src/btc_lifecycle.rs:625-638 interleaved run per ADR 0041 pass (BTC; multi-pair/fault-injected coverage absent, noted)
R6 Timelock params account for variance/congestion/drift; choices documented with rationale ZEC/XMR match docs/milestone-1/parameter-profiles.md exactly (crates/zec-swap-sdk/src/profile.rs:80-99, crates/xmr-swap-sdk/src/agreement_v1.rs:52-68); BTC parameterisation contested ordering enforced config.rs:143-181 per second examiner finding 7 (disputed — second examiner: deploy/scripts/gen-config.sh:228-229 and deploy/README.md:235-263 document the deployed BTC profiles)
R7 Bitcoin refund construction stated and justified; pre-signed failure modes enumerated/mitigated ADR 0009 justifies script-path partly on “signs when needed”; the code pre-signs the refund with a setup-time fee and no bump path (crates/btc-swap-sdk/src/sdk.rs:396-434, ADR 0213 “No fee bumping after signing”) none finding 8 (disputed — second examiner: the extra-failure-modes clause is conditional on the pre-signed key-path choice, which was not made)
R8 Graceful handling + documentation when Delivery/Chat temporarily unreachable runtime degraded mode + reconcile (crates/maker-node/src/lib.rs:1264-1283, crates/node-common/src/run_local_delivery.rs:429-583); startup outage aborts the daemon offline-after-lock e2e covers the running-daemon case only finding 5 (unconfirmed)