diff --git a/specs/requirements/CONFORMANCE_GAPS.md b/specs/requirements/CONFORMANCE_GAPS.md index 6277b3197..c8c1cef46 100644 --- a/specs/requirements/CONFORMANCE_GAPS.md +++ b/specs/requirements/CONFORMANCE_GAPS.md @@ -1712,16 +1712,29 @@ After each step, every read (the cell, the index, the object, the spool from pos MR-STOR-0116 and MR-STOR-0118 are Met. MR-STOR-0119 stays Partial: its retention clause is now exercised, but exit by handover, retirement and the survivor rule are not built. +### 6.49 Eight more DSM core rows that cited removed code (`docs/dsm-core-rows-citing-removed-items`, 2026-09-30) + +§6.44 listed nine MR-DSM rows citing items removed inside files that still exist. MR-DSM-0092 is §6.47's. The other eight are re-verified here against the specification and `main`. + +| Row | Was | Now | Why | +|---|---|---|---| +| MR-DSM-0034 | Partial (`put_cell_leader_first`) | Met | `route_seats` writes leader first, then each later seat in route order, each copy carrying the chain so far. | +| MR-DSM-0083 | Partial (`put_cell_leader_first`) | Met | As 0034; a write cut short after the leader is carried to finality by the next party. | +| MR-DSM-0002, 0004, 0005, 0014, 0199 | Partial (`verify_receipt_bytes`) | Partial | The receipt's state rules, the tip the receiver holds, adoption before a credit and the canonical apply are the checks now. The candidate, guard, Π and index structure remain absent (G3, MR-DSM-0009, MR-DSM-0126). | +| MR-DSM-0068 | Partial (`StorageNodeSDK`, `fetch_immutable_payload`) | Partial | Both read paths re-hash; `fetch_verified` has no test serving it bytes that do not re-hash. | + +Mutation control, run on 2026-09-30 and restored byte for byte: the writer carrying a no-response slot in place of the leader's link, so later copies do not begin with it. `dsm_sdk::handlers::sender_admission_tests::a_transfer_registers_the_senders_root_at_the_next_position` and `dsm_sdk::handlers::faucet_flow_tests::a_release_cut_short_after_the_leader_is_carried_by_the_next_claimant_and_bricks_nothing` both go red. + ## 7 Totals | Spec | Rows | Met | Partial | Missing | Violated | Not code | Deferred | |---|---|---|---|---|---|---|---| -| DSM high-level (MR-DSM) | 272 | 76 | 110 | 39 | 0 | 29 | 18 | +| DSM high-level (MR-DSM) | 272 | 78 | 108 | 39 | 0 | 29 | 18 | | SoFi (MR-SOFI) | 342 | 217 | 84 | 18 | 6 | 17 | 0 | | dBTC (MR-DBTC) | 135 | 0 | 0 | 0 | 0 | 0 | 135 | | Storage node (MR-STOR) | 158 | 47 | 31 | 61 | 0 | 18 | 1 | | Storage §14 lines added after the pin (STOR-014) | 11 | 9 | 1 | 1 | 0 | 0 | 0 | -| **All** | **918** | **349** | **226** | **119** | **6** | **64** | **154** | +| **All** | **918** | **351** | **224** | **119** | **6** | **64** | **154** | ## 8 Per-requirement results @@ -1730,10 +1743,10 @@ MR-STOR-0116 and MR-STOR-0118 are Met. MR-STOR-0119 stays Partial: its retention | MR-ID | Status | Code (crate · file · function) | Test | Gap / note | |---|---|---|---|---| | MR-DSM-0001 | Partial | dsm · types/device_state.rs · `advance` (balance subtraction only); economic/register.rs · `economic_root_register_key` (SoFi economic position only) | economic_lineage_register::each_position_of_each_identity_is_its_own_cell | Registration of every value-moving advance is in place (G6 withdrawn); the general κres/Σ consumption model the theorem is stated over is absent (G3). | -| MR-DSM-0002 | Partial | dsm · types/device_state.rs · `advance`; dsm_sdk · sdk/receipts.rs · `verify_receipt_bytes` | `receipts::tests::first_ever_receipt_requires_merkle_pre_root_not_cas_parent_root` | Relationship-chain continuation is decidable (parent and child inclusion). The candidate and guard structure the continuation predicate needs (P, Γ) does not exist (MR-DSM-0120–0131). | +| MR-DSM-0002 | Partial | `dsm::verification::receipt_verification::verify_receipt_state`; `dsm::bilateral::offline::decide_confirm`; `dsm::types::device_state::DeviceState::advance` | `dsm::verification::receipt_verification::tests::the_state_rules_hold_only_for_the_move_the_writes_prove`; `dsm_sdk::sdk::receipts::tests::a_first_step_receipt_starts_from_the_root_the_device_committed` | Re-verified 2026-09-30 (§6.49). `verify_receipt_bytes` was removed in #977. A receipt carries its parent and child tips and the write set that moves its author's root from the parent root to the child root, and the rules that decide it are one function. The receiver decides the step against the tip it holds. The candidate and guard structure the continuation predicate needs (P, Γ) does not exist (G3, out of beta by §5). | | MR-DSM-0003 | Met | `dsm::types::device_state::advance` (pure over &self; the SDK commit is CAS, first commit wins) | `dsm::types::device_state::tests::concurrent_advances_from_same_root_produce_different_children` | — | -| MR-DSM-0004 | Partial | dsm_sdk · sdk/receipts.rs · `verify_receipt_bytes`; dsm · types/device_state.rs · `advance` | no test found | The recipient checks its own relationship tip. There is no committed policy component Π (MR-DSM-0126). | -| MR-DSM-0005 | Partial | dsm_sdk · sdk/receipts.rs · `verify_receipt_bytes` | `receipts::tests::first_ever_receipt_requires_merkle_pre_root_not_cas_parent_root` | Successor check tested for relationship heads. The realization predicate lacks CandidateOK and GuardOK (MR-DSM-0014). | +| MR-DSM-0004 | Partial | `dsm::types::device_state::DeviceState::advance`; `dsm::bilateral::offline::decide_confirm` | `dsm::types::device_state::tests::a_relationship_steps_only_from_a_leaf_the_device_committed`; `dsm::types::device_state::tests::a_credit_of_an_unadopted_token_is_refused_at_advance` | Re-verified 2026-09-30 (§6.49). `verify_receipt_bytes` was removed in #977. The receiver steps only from the relationship tip it committed, and refuses a credit of a token its committed state has not adopted. There is no committed policy component Π (MR-DSM-0126). | +| MR-DSM-0005 | Partial | `dsm::verification::receipt_verification::verify_receipt_state`; `dsm::bilateral::offline::decide_confirm`; `dsm_sdk::storage::client_db::canonical_apply::insert_canonical_apply_identity_with_conn` | `dsm::verification::receipt_verification::tests::the_state_rules_hold_only_for_the_move_the_writes_prove`; `dsm_sdk::storage::client_db::transactions::tests::the_tip_moves_only_from_the_steps_parent_and_a_replay_is_recognised` | Re-verified 2026-09-30 (§6.49). `verify_receipt_bytes` was removed in #977. A step whose child tip is not the successor its fields name fails its state rules; a tip moves only from the step's parent, and the canonical apply realizes one child per parent (MR-DSM-0170). The realization predicate lacks CandidateOK and GuardOK (MR-DSM-0014). | | MR-DSM-0006 | Not code | — | — | Part IV offline, out of scope. | | MR-DSM-0007 | Partial | dsm · vault/limbo_vault.rs::claim (2026); vault/dlv_manager.rs::claim_vault_content (236) | no test found | Nothing in `dsm` or `dsm_sdk` calls `.claim(`, `claim_vault_content`, or exercises `Operation::DlvClaim`. | | MR-DSM-0008 | Partial | dsm · types/state_types.rs::State::compute_hash (485-521) | — | Hashes `forward_commitment`; no guard-family digest concept exists anywhere in the file. | @@ -1742,7 +1755,7 @@ MR-STOR-0116 and MR-STOR-0118 are Met. MR-STOR-0119 stays Partial: its retention | MR-DSM-0011 | Partial | dsm · economic/register.rs::economic_root_register_key (58-68) | economic_lineage_register::each_position_of_each_identity_is_its_own_cell | K derived from (G, DevID, position) only for this one cell type. | | MR-DSM-0012 | Partial | dsm · economic/register.rs (write-once cell) | economic_lineage_register::registering_an_arbitrary_root_yields_nothing_validated | Stands in for Σ only for SoFi economic-position. | | MR-DSM-0013 | Partial | dsm · economic/peer_acceptance.rs::verify_peer_transfer_acceptance (214-221); core/bilateral_transaction_manager.rs::compute_smt_key | economic_peer_evidence::a_valid_acceptance_bundle_verifies_and_every_binding_is_load_bearing; smt_tripwire_theorem::theorem1_relationship_scoped_keys | Covers SoFi peer-debit + SMT-key uniqueness; general cross-chain sharing not traced elsewhere. | -| MR-DSM-0014 | Partial | dsm · types/device_state.rs · `advance`; dsm_sdk · sdk/receipts.rs · `verify_receipt_bytes` | no test found | Structural, linearity (heads only) and policy checks exist as separate steps. CandidateOK and GuardOK have nothing to check: there is no P or Γ. | +| MR-DSM-0014 | Partial | `dsm::types::device_state::DeviceState::advance`; `dsm::verification::receipt_verification::verify_receipt_state`; `dsm::bilateral::offline::decide_confirm` | `dsm::verification::receipt_verification::tests::the_state_rules_hold_only_for_the_move_the_writes_prove`; `dsm::types::device_state::tests::a_relationship_steps_only_from_a_leaf_the_device_committed`; `dsm::types::device_state::tests::a_credit_of_an_unadopted_token_is_refused_at_advance` | Re-verified 2026-09-30 (§6.49). `verify_receipt_bytes` was removed in #977. The structural rules (`verify_receipt_state`), linearity (a step only from the tip the device committed) and policy (adoption before a credit) are checked, as separate steps rather than one Accept of named conjuncts. CandidateOK and GuardOK have nothing to check: there is no P or Γ (G3). | | MR-DSM-0015 | Partial | dsm · types/device_state.rs · `advance` (returns `Result`) | no test found | No Accept predicate of named conjuncts exists (MR-DSM-0014). | | MR-DSM-0016 | Met | `dsm::types::device_state::advance` (takes &self; an Err produces no state) | `dsm::types::device_state::tests::advance_rejects_balance_underflow`; `dsm::types::device_state::tests::advance_rejects_balance_overflow` | — | | MR-DSM-0017 | Partial | `dsm::sofi::resolve::Acquired`; `dsm::economic::peer_lineage::validate_peer_lineage`; `dsm_sdk::sdk::economic_registers::RootClaimSettlement` | `dsm::economic::peer_lineage::tests::a_step_failure_keeps_the_class_it_was_established_in`; `dsm::economic::peer_lineage::tests::a_claim_that_is_not_final_decides_nothing_yet` | Re-verified 2026-09-29 (§6.44). sofi/arith.rs was deleted in #976. Evidence not in hand is an acquisition status, never a predicate value: acquisition ends in `Acquired::Exhausted`, with nothing evaluated and nothing recorded, and the peer walk keeps each failure's class, so evidence it could not obtain is retried and only evidence that verified as wrong is Invalid. Gap: the challenge rule (storage §9.1) that ends retrying where others depend on the outcome is not built (G8, ladder step 3a). | @@ -1762,7 +1775,7 @@ MR-STOR-0116 and MR-STOR-0118 are Met. MR-STOR-0119 stays Partial: its retention | MR-DSM-0031 | Met | `dsm::economic::register::economic_root_register_key` | `dsm::economic_lineage_register::each_position_of_each_identity_is_its_own_cell` | — | | MR-DSM-0032 | Met | `dsm::economic::register::position_seed`; `dsm::route_chain::RoutedCell::new`; `dsm::route_chain::Route::of`; `dsm::route_chain::Route::leader` | `dsm::sofi::fisher_yates::tests::different_seeds_can_choose_different_first_members`; `dsm::route_chain::tests::a_route_is_the_fisher_yates_permutation_of_the_committed_set` | The seed is `position_seed` over G, DevID, position and the validated parent root, which `RootCell::new` hands to the route; no node id or availability view enters it. The earlier citation, `position_leader`, is reached by no shipped build (§6.39). | | MR-DSM-0033 | Met | `dsm::economic::register::RegisteredEconomicRoot::from_verified_single_root` | `dsm::economic::register::registered_root_construction_tests::a_registered_root_is_a_projection_of_a_verified_claim`; `dsm::economic::register::registered_root_construction_tests::a_conditional_claim_has_nothing_to_construct_from` | — | -| MR-DSM-0034 | Partial | dsm_sdk · sdk/storage_node_sdk.rs::put_cell_leader_first (1475-1506) | — | Leader-first order confirmed; no accumulated chain object threaded between writes (A6 not implemented). | +| MR-DSM-0034 | Met | `dsm_sdk::sdk::route_seats::write_recorded`; `dsm_sdk::sdk::route_seats::from_leader`; `dsm_sdk::sdk::route_seats::continue_write` | `dsm_sdk::handlers::sender_admission_tests::a_transfer_registers_the_senders_root_at_the_next_position`; `dsm_sdk::sdk::route_seats::tests::a_value_the_leader_already_holds_is_not_written_there_again` | Re-verified 2026-09-30 (§6.49). `put_cell_leader_first` is gone. `route_seats` writes a claim to the leader first, then to each later seat in route order, each copy carrying the chain so far, the leader's link first. Mutation: the next seat's copy carrying no leader link turns both the root registration and the carried-release test red (§6.49). | | MR-DSM-0035 | Met | `dsm::route_chain::evaluate`; `dsm::route_chain::CellEvidence`; `dsm_storage_node::api::cells` | `dsm::route_chain::tests::the_first_recognized_value_at_the_leader_holds_the_cell`; `dsm::route_chain::tests::junk_first_at_the_leader_blocks_nothing`; `dsm_storage_node::cells_keep_everything::a_second_value_at_a_key_is_kept_after_the_first_never_refused` | sofi/arith.rs and its tests were deleted in #976; Core now evaluates each cell from raw seat reads in route_chain::evaluate, and the node keeps every value without deciding anything. | | MR-DSM-0036 | Met | `dsm::economic::register::read_root_cell`; `dsm::economic::register::root_claim_naming`; `dsm::route_chain::evaluate`; `dsm::route_chain::ChainState` | `dsm::economic::register::registered_root_construction_tests::a_held_root_cell_carries_the_exact_bytes_that_hold_it`; `dsm::economic::register::registered_root_construction_tests::a_final_root_claim_has_a_completion_proof_that_checks`; `dsm::route_chain::tests::three_links_are_final_two_preserved_one_leader_held`; `dsm::route_chain::tests::the_first_recognized_value_at_the_leader_holds_the_cell`; `dsm::route_chain::tests::a_copy_whose_chain_does_not_begin_with_the_leader_link_does_not_count` | Re-verified 2026-09-29 (§6.41). sofi/arith.rs and its count-based test were deleted in #976. A root cell's reading is `route_chain::evaluate` over claims naming that cell's key: the first such claim in the leader's log holds it, final on the leader's link and two further links of one chain. | | MR-DSM-0037 | Met | `dsm::route_chain::evaluate`; `dsm::route_chain::Missing` | `dsm::route_chain::tests::an_unread_leader_is_missing_and_no_other_seat_stands_in`; `dsm::economic::native_reserve::tests::finality_without_the_deterministic_leader_is_impossible` | sofi/arith.rs was deleted in #976; an unread leader is Missing::LeaderUnread in route_chain::evaluate and no other seat stands in. | @@ -1796,7 +1809,7 @@ MR-STOR-0116 and MR-STOR-0118 are Met. MR-STOR-0119 stays Partial: its retention | MR-DSM-0065 | Met | `dsm_storage_node::api::objects::immutable::put_immutable`; `dsm_storage_node::api::cells::put_cell` | `dsm_storage_node::db::store_properties::immutable_put_is_write_once_on_the_tuple`; `dsm_storage_node::db::store_properties::a_conflicting_put_leaves_the_first_write_untouched`; `dsm_storage_node::cells_keep_everything::a_second_value_at_a_key_is_kept_after_the_first_never_refused` | The legacy object store, PaidK, `device_auth` and the registry are deleted (#992, §6.28; re-examined 2026-09-27, §6.36 H). The immutable store is write-once on the tuple and a cell keeps every value; a re-put changes nothing held. | | MR-DSM-0066 | Partial | dsm_storage_node · api/objects/immutable.rs::put_immutable (137-149) | immutable_store_round_trip::re_putting_identical_bytes_acks_and_the_read_is_unchanged | The suite runs on Postgres since the SQLite backend was deleted (2026-09-24). | | MR-DSM-0067 | Partial | dsm_storage_node · api/objects/immutable.rs::get_immutable (177-187) | no test found | Code recomputes on read, but no test stores a corrupted tuple to prove refusal. | -| MR-DSM-0068 | Partial | dsm_sdk · sdk/storage_node_sdk.rs::StorageNodeSDK::fetch_immutable_verified (1715-1755); sdk/storage_io.rs::fetch_immutable_payload (205-256) | no test found | Production-path client re-hash code located precisely; no test exercises a hostile/mismatched node response. | +| MR-DSM-0068 | Partial | `dsm::sofi::storage::stored`; `dsm_sdk::sdk::storage_node_sdk::SetClient::fetch_verified` | `dsm::sofi::storage::tests::wrong_bytes_never_count`; `dsm::sofi::storage::tests::a_wrong_namespace_never_counts` | Re-verified 2026-09-30 (§6.49). `StorageNodeSDK` and `fetch_immutable_payload` are gone. Both read paths re-hash: `stored` counts only answers whose bytes re-hash to the address, and `fetch_verified` takes the first member's bytes that do. Partial: no test serves `fetch_verified` bytes that do not re-hash. | | MR-DSM-0069 | Missing | — | — | The tip mirror (dsm_storage_node api/identity/tips.rs) and its tests were deleted in #977; nothing in the node or SDK holds a per-device head or encrypted per-relationship leaves, and only its two hash-domain constants remain in api/infra/hardening.rs. | | MR-DSM-0070 | Partial | dsm_storage_node · api/transport/b0x.rs (spool insert/retrieve/ack, 190-212+) | `b0x.rs::a_submitted_envelope_is_read_back_from_its_spool` (Postgres) | The spool round-trips a sealed envelope byte for byte; the node still decodes what it is given (storage §1 rule 2 finding stands). | | MR-DSM-0071 | Partial | dsm_storage_node · api/transport/b0x.rs::submit_b0x_envelope (238+, only decodes outer Envelope) | no test found | Code never inspects inner payload, but no dedicated negative test. | @@ -1811,7 +1824,7 @@ MR-STOR-0116 and MR-STOR-0118 are Met. MR-STOR-0119 stays Partial: its retention | MR-DSM-0080 | Missing | — | — | The legacy object store, PaidK, `device_auth` and the registry are deleted (#992, §6.28; re-examined 2026-09-27, §6.36 H). No receipt counting exists; storage payment is out of beta (§5). | | MR-DSM-0081 | Met | `dsm::route_chain::RoutedCell::new`; `dsm::route_chain::Route::of`; `dsm::route_chain::Route::leader`; `dsm::economic::register::position_seed`; `dsm::sofi::derive::storage_seed` | `dsm::sofi::fisher_yates::tests::different_seeds_can_choose_different_first_members`; `dsm::sofi::exercise::tests::an_attempt_cells_leader_is_bound_to_the_vault_and_the_parent_root`; `dsm::route_chain::tests::a_route_is_the_fisher_yates_permutation_of_the_committed_set` | A device's cells are seeded by `position_seed` (genesis, id, position, validated root) and a vault's attempt cells by `storage_seed` (vault id, parent root); `RoutedCell::new` refuses any set but the committed one. The earlier citation, `position_leader`, is reached by no shipped build (§6.39). | | MR-DSM-0082 | Partial | dsm · economic/register.rs::position_seed (74-86, signature has no node-id/availability parameter) | no test found | `position_seed` takes no node id or availability input. No test fails if one is added. | -| MR-DSM-0083 | Partial | dsm_sdk · sdk/storage_node_sdk.rs::put_cell_leader_first | — | Same gap as 0034. | +| MR-DSM-0083 | Met | `dsm_sdk::sdk::route_seats::write_recorded`; `dsm_sdk::sdk::route_seats::continue_recorded_writes`; `dsm_sdk::sdk::route_seats::from_leader` | `dsm_sdk::handlers::faucet_flow_tests::a_release_cut_short_after_the_leader_is_carried_by_the_next_claimant_and_bricks_nothing`; `dsm_sdk::sdk::route_seats::tests::a_value_the_leader_already_holds_is_not_written_there_again` | Re-verified 2026-09-30 (§6.49). `put_cell_leader_first` is gone. The writer goes leader first and carries the chain seat to seat; a write cut short after the leader is carried along the rest of its route by another party, and is then final. | | MR-DSM-0084 | Met | `dsm_storage_node::api::cells::put_cell` | `dsm_storage_node::cells_keep_everything::a_second_value_at_a_key_is_kept_after_the_first_never_refused`; `dsm_storage_node::cells_keep_everything::an_identical_value_put_twice_is_held_twice` | — | | MR-DSM-0085 | Met | `dsm::route_chain::evaluate`; `dsm::route_chain::ChainState` | `dsm::route_chain::tests::the_first_recognized_value_at_the_leader_holds_the_cell`; `dsm::route_chain::tests::junk_first_at_the_leader_blocks_nothing`; `dsm::route_chain::tests::three_links_are_final_two_preserved_one_leader_held`; `dsm::route_chain::tests::only_links_of_one_chain_count_toward_final` | Re-verified 2026-09-29 (§6.41). sofi/arith.rs was deleted in #976; the winner is the first recognized object in the leader's arrival log, and its state is the count of valid links of one chain, the leader's first. | | MR-DSM-0086 | Met | `dsm::route_chain::evaluate`; `dsm::route_chain::ChainState`; `dsm_storage_node::api::cells` | `dsm::route_chain::tests::the_first_recognized_value_at_the_leader_holds_the_cell`; `dsm::route_chain::tests::the_state_is_the_count_of_valid_links`; `dsm_storage_node::cells_keep_everything::a_second_value_at_a_key_is_kept_after_the_first_never_refused` | sofi/arith.rs was deleted in #976; winner (leader link) and finality (count of valid links) are derived by route_chain::evaluate from raw reads, and the node stores bytes without evaluating them. | @@ -1927,7 +1940,7 @@ MR-STOR-0116 and MR-STOR-0118 are Met. MR-STOR-0119 stays Partial: its retention | MR-DSM-0196 | Not code | — | — | Emissions dependency boundary (out of scope this round). | | MR-DSM-0197 | Met | `dsm::economic::native_reserve::NativeReserveState::genesis`; `dsm::economic::native_reserve::release_constructible` | `dsm::economic::native_reserve::tests::no_valid_reserve_transition_can_mint_era`; `dsm::economic::native_reserve::tests::total_era_is_conserved_along_the_lineage`; `dsm::types::device_state::tests::a_builtin_token_cannot_be_created_at_the_accepting_transition`; `dsm::economic_write_set::a_token_is_created_once_on_its_creators_lineage` | Operation::Mint and the mint gate were removed in #976, so the cited builtin-mint test is gone; ERA exists only as the genesis reserve and every release subtracts from it. | | MR-DSM-0198 | Deferred | — | — | DBTC, excluded this round. | -| MR-DSM-0199 | Partial | dsm · types/device_state.rs · `advance` (`embedded_parent`); dsm_sdk · sdk/receipts.rs · `verify_receipt_bytes` | `receipts::tests::first_ever_receipt_requires_merkle_pre_root_not_cas_parent_root` | Parent binding holds. There is no committed index (MR-DSM-0009). | +| MR-DSM-0199 | Partial | `dsm::types::device_state::DeviceState::advance`; `dsm::verification::receipt_verification::verify_receipt_state` | `dsm::types::device_state::tests::a_relationship_steps_only_from_a_leaf_the_device_committed`; `dsm_sdk::sdk::receipts::tests::a_first_step_receipt_starts_from_the_root_the_device_committed` | Re-verified 2026-09-30 (§6.49). `verify_receipt_bytes` was removed in #977. A step embeds the parent tip the device holds, and its receipt's parent root is the root the device committed. There is no committed index (MR-DSM-0009). | | MR-DSM-0200 | Met | `dsm::types::device_state::DeviceState::advance`; `dsm::types::device_state::DeviceState::establish_relationship`; `dsm_sdk::sdk::core_sdk::CoreSDK::establish_relationship` | `dsm::types::device_state::tests::a_relationship_steps_only_from_a_leaf_the_device_committed` | relationship.rs is gone; advance refuses a relationship whose leaf the device has not committed, and contact add establishes that leaf; the cited contact-manager test only adds a contact and was dropped. | | MR-DSM-0201 | Missing | — | — | Nothing refuses an operation whose application changes nothing: a Generic operation with no balance delta advances (the cited state_machine::transition module was deleted in #977). | | MR-DSM-0202 | Partial | `dsm_storage_node::api::vault::paidk::{require_paidk L44, submit_receipt L66}`; the no-op rate limiter that stood here is deleted (2026-09-24) | none | Byte-metered storage-credit charging per §17 is not built. | diff --git a/specs/requirements/INTENT_MANIFEST.tsv b/specs/requirements/INTENT_MANIFEST.tsv index f1baf42fb..39575ce18 100644 --- a/specs/requirements/INTENT_MANIFEST.tsv +++ b/specs/requirements/INTENT_MANIFEST.tsv @@ -27,6 +27,9 @@ MR-DSM-0032 dsm::route_chain::Route::leader android MUST_REACH active dsm_sdk::j MR-DSM-0032 dsm::route_chain::Route::of android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::sofi::fisher_yates::tests::different_seeds_can_choose_different_first_members;dsm::route_chain::tests::a_route_is_the_fisher_yates_permutation_of_the_committed_set - CONFORMANCE §8 MR-DSM-0032 (Met) MR-DSM-0032 dsm::route_chain::RoutedCell::new android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::sofi::fisher_yates::tests::different_seeds_can_choose_different_first_members;dsm::route_chain::tests::a_route_is_the_fisher_yates_permutation_of_the_committed_set - CONFORMANCE §8 MR-DSM-0032 (Met) MR-DSM-0033 dsm::economic::register::RegisteredEconomicRoot::from_verified_single_root android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::economic::register::registered_root_construction_tests::a_registered_root_is_a_projection_of_a_verified_claim;dsm::economic::register::registered_root_construction_tests::a_conditional_claim_has_nothing_to_construct_from - CONFORMANCE §8 MR-DSM-0033 (Met) +MR-DSM-0034 dsm_sdk::sdk::route_seats::continue_write android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm_sdk::handlers::sender_admission_tests::a_transfer_registers_the_senders_root_at_the_next_position;dsm_sdk::sdk::route_seats::tests::a_value_the_leader_already_holds_is_not_written_there_again - CONFORMANCE §8 MR-DSM-0034 (Met) +MR-DSM-0034 dsm_sdk::sdk::route_seats::from_leader android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm_sdk::handlers::sender_admission_tests::a_transfer_registers_the_senders_root_at_the_next_position;dsm_sdk::sdk::route_seats::tests::a_value_the_leader_already_holds_is_not_written_there_again - CONFORMANCE §8 MR-DSM-0034 (Met) +MR-DSM-0034 dsm_sdk::sdk::route_seats::write_recorded android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm_sdk::handlers::sender_admission_tests::a_transfer_registers_the_senders_root_at_the_next_position;dsm_sdk::sdk::route_seats::tests::a_value_the_leader_already_holds_is_not_written_there_again - CONFORMANCE §8 MR-DSM-0034 (Met) MR-DSM-0035 dsm::route_chain::CellEvidence android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::route_chain::tests::the_first_recognized_value_at_the_leader_holds_the_cell;dsm::route_chain::tests::junk_first_at_the_leader_blocks_nothing;dsm_storage_node::cells_keep_everything::a_second_value_at_a_key_is_kept_after_the_first_never_refused - CONFORMANCE §8 MR-DSM-0035 (Met) MR-DSM-0035 dsm::route_chain::evaluate android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::route_chain::tests::the_first_recognized_value_at_the_leader_holds_the_cell;dsm::route_chain::tests::junk_first_at_the_leader_blocks_nothing;dsm_storage_node::cells_keep_everything::a_second_value_at_a_key_is_kept_after_the_first_never_refused - CONFORMANCE §8 MR-DSM-0035 (Met) MR-DSM-0036 dsm::economic::register::read_root_cell android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::economic::register::registered_root_construction_tests::a_held_root_cell_carries_the_exact_bytes_that_hold_it;dsm::economic::register::registered_root_construction_tests::a_final_root_claim_has_a_completion_proof_that_checks;dsm::route_chain::tests::three_links_are_final_two_preserved_one_leader_held;dsm::route_chain::tests::the_first_recognized_value_at_the_leader_holds_the_cell;dsm::route_chain::tests::a_copy_whose_chain_does_not_begin_with_the_leader_link_does_not_count - CONFORMANCE §8 MR-DSM-0036 (Met) @@ -63,6 +66,9 @@ MR-DSM-0081 dsm::route_chain::Route::leader android MUST_REACH active dsm_sdk::j MR-DSM-0081 dsm::route_chain::Route::of android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::sofi::fisher_yates::tests::different_seeds_can_choose_different_first_members;dsm::sofi::exercise::tests::an_attempt_cells_leader_is_bound_to_the_vault_and_the_parent_root;dsm::route_chain::tests::a_route_is_the_fisher_yates_permutation_of_the_committed_set - CONFORMANCE §8 MR-DSM-0081 (Met) MR-DSM-0081 dsm::route_chain::RoutedCell::new android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::sofi::fisher_yates::tests::different_seeds_can_choose_different_first_members;dsm::sofi::exercise::tests::an_attempt_cells_leader_is_bound_to_the_vault_and_the_parent_root;dsm::route_chain::tests::a_route_is_the_fisher_yates_permutation_of_the_committed_set - CONFORMANCE §8 MR-DSM-0081 (Met) MR-DSM-0081 dsm::sofi::derive::storage_seed android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::sofi::fisher_yates::tests::different_seeds_can_choose_different_first_members;dsm::sofi::exercise::tests::an_attempt_cells_leader_is_bound_to_the_vault_and_the_parent_root;dsm::route_chain::tests::a_route_is_the_fisher_yates_permutation_of_the_committed_set - CONFORMANCE §8 MR-DSM-0081 (Met) +MR-DSM-0083 dsm_sdk::sdk::route_seats::continue_recorded_writes android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm_sdk::handlers::faucet_flow_tests::a_release_cut_short_after_the_leader_is_carried_by_the_next_claimant_and_bricks_nothing;dsm_sdk::sdk::route_seats::tests::a_value_the_leader_already_holds_is_not_written_there_again - CONFORMANCE §8 MR-DSM-0083 (Met) +MR-DSM-0083 dsm_sdk::sdk::route_seats::from_leader android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm_sdk::handlers::faucet_flow_tests::a_release_cut_short_after_the_leader_is_carried_by_the_next_claimant_and_bricks_nothing;dsm_sdk::sdk::route_seats::tests::a_value_the_leader_already_holds_is_not_written_there_again - CONFORMANCE §8 MR-DSM-0083 (Met) +MR-DSM-0083 dsm_sdk::sdk::route_seats::write_recorded android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm_sdk::handlers::faucet_flow_tests::a_release_cut_short_after_the_leader_is_carried_by_the_next_claimant_and_bricks_nothing;dsm_sdk::sdk::route_seats::tests::a_value_the_leader_already_holds_is_not_written_there_again - CONFORMANCE §8 MR-DSM-0083 (Met) MR-DSM-0084 dsm_storage_node::api::cells::put_cell node MUST_REACH active dsm_storage_node::main dsm_storage_node::cells_keep_everything::a_second_value_at_a_key_is_kept_after_the_first_never_refused;dsm_storage_node::cells_keep_everything::an_identical_value_put_twice_is_held_twice - CONFORMANCE §8 MR-DSM-0084 (Met) MR-DSM-0085 dsm::route_chain::ChainState android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::route_chain::tests::the_first_recognized_value_at_the_leader_holds_the_cell;dsm::route_chain::tests::junk_first_at_the_leader_blocks_nothing;dsm::route_chain::tests::three_links_are_final_two_preserved_one_leader_held;dsm::route_chain::tests::only_links_of_one_chain_count_toward_final - CONFORMANCE §8 MR-DSM-0085 (Met) MR-DSM-0085 dsm::route_chain::evaluate android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::route_chain::tests::the_first_recognized_value_at_the_leader_holds_the_cell;dsm::route_chain::tests::junk_first_at_the_leader_blocks_nothing;dsm::route_chain::tests::three_links_are_final_two_preserved_one_leader_held;dsm::route_chain::tests::only_links_of_one_chain_count_toward_final - CONFORMANCE §8 MR-DSM-0085 (Met) diff --git a/specs/requirements/INTENT_PINS.tsv b/specs/requirements/INTENT_PINS.tsv index 6ac218e2e..4bea76bef 100644 --- a/specs/requirements/INTENT_PINS.tsv +++ b/specs/requirements/INTENT_PINS.tsv @@ -21,6 +21,9 @@ MR-DSM-0032 dsm::route_chain::Route::leader android MUST_REACH active dsm_sdk::j MR-DSM-0032 dsm::route_chain::Route::of android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::sofi::fisher_yates::tests::different_seeds_can_choose_different_first_members;dsm::route_chain::tests::a_route_is_the_fisher_yates_permutation_of_the_committed_set - CONFORMANCE §8 MR-DSM-0032 (Met) 2013F3M9AGR3DCKTBC99GGRT07CA4EQ27QNQ42X46MG5NF1WZ3G0 Met SATISFIED reached:REACHED rust-analyzer cargo dsm 0.1.0-beta.3 route_chain/impl#[Route]of(). 2H7D33H2YAHV1P8H49KSWBYX8C1X27V35D0EM1TNFQPRPA2YJB80 BVXRH3S26GHXZQZTGRZ5G96BAWMRZ77KT31BHP0087QKZ7FMN1V0;W788VB29XB0H3C03HTMGZEKSK1W8VCW1CA5JFXQET0VVDAAA7XGG 8b2814918a9f0cf54a83d29080a9c6bf177682d9 8SHR4EESR8T3XETWBM3JDKF7ZJ6ZW4NH2E2K1VD9P2YE1Z0XVE40 MR-DSM-0032 dsm::route_chain::RoutedCell::new android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::sofi::fisher_yates::tests::different_seeds_can_choose_different_first_members;dsm::route_chain::tests::a_route_is_the_fisher_yates_permutation_of_the_committed_set - CONFORMANCE §8 MR-DSM-0032 (Met) 8333YBAQFA06Z5TYA69FBXSQTPGAT6RKTQ57GGB8S5920Y4DEMR0 Met SATISFIED reached:REACHED rust-analyzer cargo dsm 0.1.0-beta.3 route_chain/impl#[RoutedCell]new(). 4SZQMENH08549QSKCVCF1SW6YKDK7A5G989H2M47JZEQ5BBXX8KG BVXRH3S26GHXZQZTGRZ5G96BAWMRZ77KT31BHP0087QKZ7FMN1V0;W788VB29XB0H3C03HTMGZEKSK1W8VCW1CA5JFXQET0VVDAAA7XGG 8b2814918a9f0cf54a83d29080a9c6bf177682d9 ST6MSQ75JFYVX99XHVFG83Z63RSAQDK9X3MEJ6MCGDS239AQ0W70 MR-DSM-0033 dsm::economic::register::RegisteredEconomicRoot::from_verified_single_root android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::economic::register::registered_root_construction_tests::a_registered_root_is_a_projection_of_a_verified_claim;dsm::economic::register::registered_root_construction_tests::a_conditional_claim_has_nothing_to_construct_from - CONFORMANCE §8 MR-DSM-0033 (Met) VVBYPPQETBZNJF29J58W86Z2RK2AZ1K7EY90W60WA0GE1J7SNXZG Met SATISFIED reached:REACHED_VIA_DISPATCH rust-analyzer cargo dsm 0.1.0-beta.3 economic/register/impl#[RegisteredEconomicRoot]from_verified_single_root(). 4VDYNQTXA8HN8P2MJ9QQZ3GCP1W84BDK9PB4BA50GWMMT8CCRW60 07M6VXSBTEWZ6M28KY53WZJ91ZZBXME3W9DP5GG4F2CNN7D25Y80;HEKA3HZSRS4YZYZXM00VCTH7B3MP17S4M6Y9M3XYNFRB0CWRY8ZG 8b2814918a9f0cf54a83d29080a9c6bf177682d9 Z9MJC0Y7HX12W92VRY6VTVDXE03CAEE19VHE4Z9CD7PAFBFH66HG +MR-DSM-0034 dsm_sdk::sdk::route_seats::continue_write android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm_sdk::handlers::sender_admission_tests::a_transfer_registers_the_senders_root_at_the_next_position;dsm_sdk::sdk::route_seats::tests::a_value_the_leader_already_holds_is_not_written_there_again - CONFORMANCE §8 MR-DSM-0034 (Met) XGYWEXASDM0MS2KD0KWRZZ3MK9ZTSA7ANYRCSFCQH7QV6ZGJEHSG Met SATISFIED reached:REACHED rust-analyzer cargo dsm_sdk 0.1.0-beta.3 sdk/route_seats/continue_write(). 6FMSY7E5JPM9NTAGFDDS1FAK03RDQYP038Y94XC5QYM13BMKR1EG 726GH86QGPH65T1WX7SYKFXWDFW5262PGK59BX434Q4ZQBXGFJJ0;VNPKYRQBSDT6NSK3TCAK6BC7KM4E3F6DPVH5FQD23B9RW9X28GD0 51741a78b75d3985354ed589a830cd8b74f75e00 F2KEKDR0Y3J2CXGCJKF0MYF29BSZT33YQ4QEHSY9YP1DFC0EF5N0 +MR-DSM-0034 dsm_sdk::sdk::route_seats::from_leader android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm_sdk::handlers::sender_admission_tests::a_transfer_registers_the_senders_root_at_the_next_position;dsm_sdk::sdk::route_seats::tests::a_value_the_leader_already_holds_is_not_written_there_again - CONFORMANCE §8 MR-DSM-0034 (Met) H1CWTG6Q0T1HX9XKMD5DDP3JCR5M83QKBWPDSGZN94HVQCPXAZGG Met SATISFIED reached:REACHED_VIA_DISPATCH rust-analyzer cargo dsm_sdk 0.1.0-beta.3 sdk/route_seats/from_leader(). 9ZABMZ2N2RQEHFV3C93MP670EWE93FWBYPGBEAHNKVHVT392BY9G 726GH86QGPH65T1WX7SYKFXWDFW5262PGK59BX434Q4ZQBXGFJJ0;VNPKYRQBSDT6NSK3TCAK6BC7KM4E3F6DPVH5FQD23B9RW9X28GD0 51741a78b75d3985354ed589a830cd8b74f75e00 T96EEYGTGH4HF8CQ4FNJ3BVW5ZH0Q13896A9D3B2G8CGQ63AWCEG +MR-DSM-0034 dsm_sdk::sdk::route_seats::write_recorded android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm_sdk::handlers::sender_admission_tests::a_transfer_registers_the_senders_root_at_the_next_position;dsm_sdk::sdk::route_seats::tests::a_value_the_leader_already_holds_is_not_written_there_again - CONFORMANCE §8 MR-DSM-0034 (Met) 2JSVRB7DW1KN8Y807FW3CV8PZ1Y1XJ8DX7GYKZFJCH9PDD37EBHG Met SATISFIED reached:REACHED_VIA_DISPATCH rust-analyzer cargo dsm_sdk 0.1.0-beta.3 sdk/route_seats/write_recorded(). XFZ4MJN90YQHHVDA84C8HF7TB70PSSP6PY6ABCAP7CA7VPDZB58G 726GH86QGPH65T1WX7SYKFXWDFW5262PGK59BX434Q4ZQBXGFJJ0;VNPKYRQBSDT6NSK3TCAK6BC7KM4E3F6DPVH5FQD23B9RW9X28GD0 51741a78b75d3985354ed589a830cd8b74f75e00 85TV0DQP2P98GT0MAZ231QG29PX72PDFGN6EW4WBXJZCGM439CX0 MR-DSM-0035 dsm::route_chain::CellEvidence android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::route_chain::tests::the_first_recognized_value_at_the_leader_holds_the_cell;dsm::route_chain::tests::junk_first_at_the_leader_blocks_nothing;dsm_storage_node::cells_keep_everything::a_second_value_at_a_key_is_kept_after_the_first_never_refused - CONFORMANCE §8 MR-DSM-0035 (Met) TCJEEWRQXVHNZC1132YNF90XXAQZQTZ3S5KGK6ZYWCTDV7AC04Q0 Met SATISFIED reached:REACHED_VIA_DISPATCH rust-analyzer cargo dsm 0.1.0-beta.3 route_chain/CellEvidence# QV40SKJZ42A6MBZWKDQA4CJWH85MXYAY7PSKE4NAGGH7GD2MSRVG 59HMF52A70ZHART8C2PE1QV3XJYG77TTFS6J7RC5JDYYXQHVYBWG;P9HAC0KWS1VJ4VSA5TH2988NV4XZS3FRHEXF3DY2RS3XF2GJG9WG;YWFYJ5X3F04XQ0RQDFCC3V2567212ENFPGS75T86RBTB8RX5HNX0 375506f9333de6e529968767d19d565d189cc385 57VVZ0JM90M1Q8H8RD4VF00NYVHFFXJEWD6681FB3C4NRWC0NPVG MR-DSM-0035 dsm::route_chain::evaluate android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::route_chain::tests::the_first_recognized_value_at_the_leader_holds_the_cell;dsm::route_chain::tests::junk_first_at_the_leader_blocks_nothing;dsm_storage_node::cells_keep_everything::a_second_value_at_a_key_is_kept_after_the_first_never_refused - CONFORMANCE §8 MR-DSM-0035 (Met) F9WS3MZKFTQYN31C5VR0D346EM2X9FSF30X16C5ZDHM9JZ4ZSAPG Met SATISFIED reached:REACHED_VIA_DISPATCH rust-analyzer cargo dsm 0.1.0-beta.3 route_chain/evaluate(). YDWWSD384KR0Y5SX880F4JJW5FD3398XM4D8923KYM2Y99H7RMYG 59HMF52A70ZHART8C2PE1QV3XJYG77TTFS6J7RC5JDYYXQHVYBWG;P9HAC0KWS1VJ4VSA5TH2988NV4XZS3FRHEXF3DY2RS3XF2GJG9WG;YWFYJ5X3F04XQ0RQDFCC3V2567212ENFPGS75T86RBTB8RX5HNX0 375506f9333de6e529968767d19d565d189cc385 80H4QNCSN1GD63GMZREVS0ADXSW0B7SYAFXX8HJVEFR630E3TRJG MR-DSM-0036 dsm::economic::register::read_root_cell android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::economic::register::registered_root_construction_tests::a_held_root_cell_carries_the_exact_bytes_that_hold_it;dsm::economic::register::registered_root_construction_tests::a_final_root_claim_has_a_completion_proof_that_checks;dsm::route_chain::tests::three_links_are_final_two_preserved_one_leader_held;dsm::route_chain::tests::the_first_recognized_value_at_the_leader_holds_the_cell;dsm::route_chain::tests::a_copy_whose_chain_does_not_begin_with_the_leader_link_does_not_count - CONFORMANCE §8 MR-DSM-0036 (Met) VM6MF12WPRK1X3YF3867K6YTNBMS3KTS84JJBMC59TCH2TREH3X0 Met SATISFIED reached:REACHED_VIA_DISPATCH rust-analyzer cargo dsm 0.1.0-beta.3 economic/register/read_root_cell(). RZFX32A412E7RSJPV3Z1JP4JTV48EYKAJZP3DWK6MJGRSR1PWX40 D1QRPZ5RJWJT8SBK5VRYRM4Z3N0B46SM5R9A1Y6NGEEGGCXNA7NG;42P91M5ZGX188HDJDZ8K6MB7SNHDBNGM6ET0PY1ND0CHP84T2TQG;RER4TYRAT6GB0E6N4X8MAT264FZ3CNJGR8D9AVYTYCRSJWWS727G;59HMF52A70ZHART8C2PE1QV3XJYG77TTFS6J7RC5JDYYXQHVYBWG;H4T19ZPDRZ06ZVP6FD61382XDW2QGTC37XTVWGTYN2NXMXWKS1RG 375506f9333de6e529968767d19d565d189cc385 9VGY4D148B6Y9E011EYCEH5M1W183DD83XY5C9R5QRWFHC22TSEG @@ -57,6 +60,9 @@ MR-DSM-0081 dsm::route_chain::Route::leader android MUST_REACH active dsm_sdk::j MR-DSM-0081 dsm::route_chain::Route::of android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::sofi::fisher_yates::tests::different_seeds_can_choose_different_first_members;dsm::sofi::exercise::tests::an_attempt_cells_leader_is_bound_to_the_vault_and_the_parent_root;dsm::route_chain::tests::a_route_is_the_fisher_yates_permutation_of_the_committed_set - CONFORMANCE §8 MR-DSM-0081 (Met) S8M8MYWMV296D8PJEGRG0PTTZBQRS4CZRY8E2ZG60X6KPV6Z2MKG Met SATISFIED reached:REACHED rust-analyzer cargo dsm 0.1.0-beta.3 route_chain/impl#[Route]of(). 2H7D33H2YAHV1P8H49KSWBYX8C1X27V35D0EM1TNFQPRPA2YJB80 BVXRH3S26GHXZQZTGRZ5G96BAWMRZ77KT31BHP0087QKZ7FMN1V0;7NB7WHEC4FWCEBDEE5HE46BNM5CE1VHPVEEEB0FFV84CKYFFKSHG;W788VB29XB0H3C03HTMGZEKSK1W8VCW1CA5JFXQET0VVDAAA7XGG 8b2814918a9f0cf54a83d29080a9c6bf177682d9 0307HHK55MT6R0A2QF5HW43Q90FWN9KB0ZD2XVT2HNP9KDKE3RJ0 MR-DSM-0081 dsm::route_chain::RoutedCell::new android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::sofi::fisher_yates::tests::different_seeds_can_choose_different_first_members;dsm::sofi::exercise::tests::an_attempt_cells_leader_is_bound_to_the_vault_and_the_parent_root;dsm::route_chain::tests::a_route_is_the_fisher_yates_permutation_of_the_committed_set - CONFORMANCE §8 MR-DSM-0081 (Met) R1XJ51B00JYQ0CFW48TNVKP6AG1N7N6TM9XHFW45PZJXBZ531BG0 Met SATISFIED reached:REACHED rust-analyzer cargo dsm 0.1.0-beta.3 route_chain/impl#[RoutedCell]new(). 4SZQMENH08549QSKCVCF1SW6YKDK7A5G989H2M47JZEQ5BBXX8KG BVXRH3S26GHXZQZTGRZ5G96BAWMRZ77KT31BHP0087QKZ7FMN1V0;7NB7WHEC4FWCEBDEE5HE46BNM5CE1VHPVEEEB0FFV84CKYFFKSHG;W788VB29XB0H3C03HTMGZEKSK1W8VCW1CA5JFXQET0VVDAAA7XGG 8b2814918a9f0cf54a83d29080a9c6bf177682d9 04RN0B957PD31NB6YRVG8Z02H9MZB5A9GV7CRGMGWY5TAEB1ZQE0 MR-DSM-0081 dsm::sofi::derive::storage_seed android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::sofi::fisher_yates::tests::different_seeds_can_choose_different_first_members;dsm::sofi::exercise::tests::an_attempt_cells_leader_is_bound_to_the_vault_and_the_parent_root;dsm::route_chain::tests::a_route_is_the_fisher_yates_permutation_of_the_committed_set - CONFORMANCE §8 MR-DSM-0081 (Met) GX68RWZ2RZ2JNWRRNXJ1CXZNRWBRD8THRWAH0F6Q8S2A7VP5PWMG Met SATISFIED reached:REACHED_VIA_DISPATCH rust-analyzer cargo dsm 0.1.0-beta.3 sofi/derive/storage_seed(). 5PY9J9KYQ3QX5BAFVGQF6TYSN1KVAXVGAVXNFZSD9HYSY7MKE5D0 BVXRH3S26GHXZQZTGRZ5G96BAWMRZ77KT31BHP0087QKZ7FMN1V0;7NB7WHEC4FWCEBDEE5HE46BNM5CE1VHPVEEEB0FFV84CKYFFKSHG;W788VB29XB0H3C03HTMGZEKSK1W8VCW1CA5JFXQET0VVDAAA7XGG 8b2814918a9f0cf54a83d29080a9c6bf177682d9 1X6ZDGBTP4P5MYA25DPG2TSV1B0W87HH8HGD1KCB5P3P3635A3G0 +MR-DSM-0083 dsm_sdk::sdk::route_seats::continue_recorded_writes android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm_sdk::handlers::faucet_flow_tests::a_release_cut_short_after_the_leader_is_carried_by_the_next_claimant_and_bricks_nothing;dsm_sdk::sdk::route_seats::tests::a_value_the_leader_already_holds_is_not_written_there_again - CONFORMANCE §8 MR-DSM-0083 (Met) WGPCPBM1SA4PGKPN9E59BT5AJJ72HY3CSJWRGYHTEPADGRD5B1JG Met SATISFIED reached:REACHED rust-analyzer cargo dsm_sdk 0.1.0-beta.3 sdk/route_seats/continue_recorded_writes(). 0MEY5P7E3Q3A0PPKYG3BZSEWY62NGEP5C53BJ4NK5GPBVGPRMET0 BZ9XT8DRJK88M5GT3F2QF911XCNR8NEEN01C2XXQNEKFN21Z8E40;VNPKYRQBSDT6NSK3TCAK6BC7KM4E3F6DPVH5FQD23B9RW9X28GD0 51741a78b75d3985354ed589a830cd8b74f75e00 0CH425GH5XX259J7EZB4YPBXAFY69A352Q7383WJ4ZDAZ90FJZ10 +MR-DSM-0083 dsm_sdk::sdk::route_seats::from_leader android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm_sdk::handlers::faucet_flow_tests::a_release_cut_short_after_the_leader_is_carried_by_the_next_claimant_and_bricks_nothing;dsm_sdk::sdk::route_seats::tests::a_value_the_leader_already_holds_is_not_written_there_again - CONFORMANCE §8 MR-DSM-0083 (Met) 02CADGVPDSJ5GP2ASASE3NZBTGRGY7NRFSG689ES0SPPV0R07D70 Met SATISFIED reached:REACHED_VIA_DISPATCH rust-analyzer cargo dsm_sdk 0.1.0-beta.3 sdk/route_seats/from_leader(). 9ZABMZ2N2RQEHFV3C93MP670EWE93FWBYPGBEAHNKVHVT392BY9G BZ9XT8DRJK88M5GT3F2QF911XCNR8NEEN01C2XXQNEKFN21Z8E40;VNPKYRQBSDT6NSK3TCAK6BC7KM4E3F6DPVH5FQD23B9RW9X28GD0 51741a78b75d3985354ed589a830cd8b74f75e00 KZWXE9CNS0QQY6HMWVAGK6R4J7ZY80QMF3C1N3TTSQNATEABP45G +MR-DSM-0083 dsm_sdk::sdk::route_seats::write_recorded android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm_sdk::handlers::faucet_flow_tests::a_release_cut_short_after_the_leader_is_carried_by_the_next_claimant_and_bricks_nothing;dsm_sdk::sdk::route_seats::tests::a_value_the_leader_already_holds_is_not_written_there_again - CONFORMANCE §8 MR-DSM-0083 (Met) 61NGJNYCZR135GWM7YF08DXDZRQXHEJF8MM0F098KTRPA3ZJ28M0 Met SATISFIED reached:REACHED_VIA_DISPATCH rust-analyzer cargo dsm_sdk 0.1.0-beta.3 sdk/route_seats/write_recorded(). XFZ4MJN90YQHHVDA84C8HF7TB70PSSP6PY6ABCAP7CA7VPDZB58G BZ9XT8DRJK88M5GT3F2QF911XCNR8NEEN01C2XXQNEKFN21Z8E40;VNPKYRQBSDT6NSK3TCAK6BC7KM4E3F6DPVH5FQD23B9RW9X28GD0 51741a78b75d3985354ed589a830cd8b74f75e00 FW5V2NYK39GGVGB7VHAKFQTYEBH5W77HYARSVFP8ZM90WFWZ2QFG MR-DSM-0084 dsm_storage_node::api::cells::put_cell node MUST_REACH active dsm_storage_node::main dsm_storage_node::cells_keep_everything::a_second_value_at_a_key_is_kept_after_the_first_never_refused;dsm_storage_node::cells_keep_everything::an_identical_value_put_twice_is_held_twice - CONFORMANCE §8 MR-DSM-0084 (Met) HHNF5NG9NYHNAH1NSX2483HBEFDM3S53KWZA7YGPSSQT88VG86MG Met SATISFIED reached:REACHED rust-analyzer cargo dsm_storage_node 0.1.0-beta.3 api/cells/put_cell(). GZ7EWHR37RDX3J8J1HVVPMX123TAWYFWP82BXDSQSWZ99K6JX02G YWFYJ5X3F04XQ0RQDFCC3V2567212ENFPGS75T86RBTB8RX5HNX0;RZXD867E5R3SXTNXZVK8BRBRKEJ61R3YAJATSNHKWK6BXYGBMBVG 375506f9333de6e529968767d19d565d189cc385 F80S6WS74CGCEDS8S1K80PKEPC2F8ZKJK5ZAXFM9DA41SG1XD360 MR-DSM-0085 dsm::route_chain::ChainState android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::route_chain::tests::the_first_recognized_value_at_the_leader_holds_the_cell;dsm::route_chain::tests::junk_first_at_the_leader_blocks_nothing;dsm::route_chain::tests::three_links_are_final_two_preserved_one_leader_held;dsm::route_chain::tests::only_links_of_one_chain_count_toward_final - CONFORMANCE §8 MR-DSM-0085 (Met) T8N990ZNCAQHKVJZ6HFN9A1MM87W9BQMP5VMGX9MHHS083SJWYMG Met SATISFIED reached:REACHED_VIA_DISPATCH rust-analyzer cargo dsm 0.1.0-beta.3 route_chain/ChainState# CHXY693QW5TWC7T4105BZNBR0000FFCHQ1WXAKBHWGBQYX4WRD90 59HMF52A70ZHART8C2PE1QV3XJYG77TTFS6J7RC5JDYYXQHVYBWG;P9HAC0KWS1VJ4VSA5TH2988NV4XZS3FRHEXF3DY2RS3XF2GJG9WG;RER4TYRAT6GB0E6N4X8MAT264FZ3CNJGR8D9AVYTYCRSJWWS727G;5W9841Y111S07377NM3VYDXBV71NH5N3Q62YCB6XJ7PRRS4B45B0 375506f9333de6e529968767d19d565d189cc385 YKN2VVJ5G3EFMF76TW2597HHGABACX3JW7XG66KXPE2BPR0PAN00 MR-DSM-0085 dsm::route_chain::evaluate android MUST_REACH active dsm_sdk::jni::unified_protobuf_bridge::Java_com_dsm_wallet_bridge_UnifiedNativeApi_dispatchIngress dsm::route_chain::tests::the_first_recognized_value_at_the_leader_holds_the_cell;dsm::route_chain::tests::junk_first_at_the_leader_blocks_nothing;dsm::route_chain::tests::three_links_are_final_two_preserved_one_leader_held;dsm::route_chain::tests::only_links_of_one_chain_count_toward_final - CONFORMANCE §8 MR-DSM-0085 (Met) HGGVW2N3XNM8JACAV4XG0SWAAM580QR2FCXPDBPARHW6SX9G4KGG Met SATISFIED reached:REACHED_VIA_DISPATCH rust-analyzer cargo dsm 0.1.0-beta.3 route_chain/evaluate(). YDWWSD384KR0Y5SX880F4JJW5FD3398XM4D8923KYM2Y99H7RMYG 59HMF52A70ZHART8C2PE1QV3XJYG77TTFS6J7RC5JDYYXQHVYBWG;P9HAC0KWS1VJ4VSA5TH2988NV4XZS3FRHEXF3DY2RS3XF2GJG9WG;RER4TYRAT6GB0E6N4X8MAT264FZ3CNJGR8D9AVYTYCRSJWWS727G;5W9841Y111S07377NM3VYDXBV71NH5N3Q62YCB6XJ7PRRS4B45B0 375506f9333de6e529968767d19d565d189cc385 454SBDN36ZNXKWXNK9GN2N1FPD7W4TA56KJG271M3R14TZ1FS030 diff --git a/specs/requirements/VERIFICATION_MATRIX.md b/specs/requirements/VERIFICATION_MATRIX.md index 3c480c9cb..bd883b1c2 100644 --- a/specs/requirements/VERIFICATION_MATRIX.md +++ b/specs/requirements/VERIFICATION_MATRIX.md @@ -56,6 +56,7 @@ Tests named `dsm_sdk::…` run on devices created as wallet creation creates the | A malformed storage-node CA list is an error | `dsm_sdk` · sdk/storage_node_sdk.rs · `read_ca_certs` | `dsm_sdk::sdk::storage_node_sdk::tests::custom_ca_certs_is_a_list_of_readable_paths_or_an_error` | Skip restored → red (2026-09-24). | — | | MR-DSM-0116, MR-DSM-0117, MR-DSM-0028: a relationship's leaf holds its head from `h_0`, and a step's pre-state root is the root the device committed | `dsm` · types/device_state.rs · `DeviceState::establish_relationship`, `DeviceState::advance` (refuses an unestablished relationship) | `dsm::types::device_state::tests::a_relationship_steps_only_from_a_leaf_the_device_committed`; `dsm_sdk::sdk::receipts::tests::a_first_step_receipt_starts_from_the_root_the_device_committed` | Seeding fallback restored → red (2026-09-24). | TLA+ `DSM_tiny`, `DSM_small` direct replay | | MR-DSM-0036, MR-DSM-0085: the value holding a cell is the first recognized in the leader's log, final only on the leader's link and two further links of one chain; a root cell recognizes only claims naming its key | `dsm` · route_chain.rs · `evaluate`, `ChainState::with_further_links`; economic/register.rs · `root_claim_naming` | `dsm::route_chain::tests::three_links_are_final_two_preserved_one_leader_held`; `dsm::route_chain::tests::the_first_recognized_value_at_the_leader_holds_the_cell`; `dsm::route_chain::tests::a_copy_whose_chain_does_not_begin_with_the_leader_link_does_not_count`; `dsm::economic::register::registered_root_construction_tests::a_held_root_cell_carries_the_exact_bytes_that_hold_it` | The leader's link alone counted final → eight `route_chain` tests red, among them the first two named. `root_claim_naming` accepting any key → `a_held_root_cell_carries_the_exact_bytes_that_hold_it` red (2026-09-29). | `tla/DSM_RouteChain.tla::StatesNest`; `tla/DSM_RouteChain.tla::AtMostOneFinal` | +| MR-DSM-0034, MR-DSM-0083: a writer writes the leader first, then each later seat in route order, each copy carrying the chain so far; any party may carry a write the leader already holds to finality | `dsm_sdk` · sdk/route_seats.rs · `write_recorded`, `from_leader`, `continue_write`, `continue_recorded_writes` | `dsm_sdk::handlers::sender_admission_tests::a_transfer_registers_the_senders_root_at_the_next_position`; `dsm_sdk::handlers::faucet_flow_tests::a_release_cut_short_after_the_leader_is_carried_by_the_next_claimant_and_bricks_nothing` | The next seat's copy carrying a no-response slot in place of the leader's link → both tests red (2026-09-30). | — | | MR-DSM-0116, MR-DSM-0121: a relationship's leaf holds its current head, and the device tree drops no leaf however many relationships it holds | `dsm` · merkle/sparse_merkle_tree.rs · `SparseMerkleTree::update_leaf` (no capacity); types/device_state.rs · `DeviceState::advance` (writes `(rel_key, h_{n+1})`) | `dsm::types::device_state::tests::a_relationships_leaf_holds_its_current_head`; `dsm::types::device_state::tests::every_relationship_stays_in_the_root_past_the_old_capacity` | A 1,024-leaf cap in `update_leaf` → `every_relationship_stays_in_the_root_past_the_old_capacity` red. A step writing the head it moved past → `a_relationships_leaf_holds_its_current_head` red, while `a_relationship_steps_only_from_a_leaf_the_device_committed` stays green (2026-09-29). | — | | MR-DSM-0046: a payer who withholds its root claim leaves the receiver unable to accept, and nothing is Invalid | `dsm` · economic/peer_lineage.rs · `validate_peer_lineage` (an open root cell is `Incomplete`) | `dsm::economic::peer_lineage::tests::a_claim_naming_other_coordinates_never_holds_the_root_cell` | An open root cell read as Invalid → red (2026-09-29). | — | | MR-DSM-0170: two children of one parent can both be constructed, but only one is realized | `dsm_sdk` · storage/client_db/canonical_apply.rs · `lookup_canonical_apply_status`, `insert_canonical_apply_identity_with_conn` (UNIQUE on relationship and parent) | `dsm_sdk::storage::client_db::canonical_apply::tests::the_same_relationship_and_parent_with_a_different_transition_conflicts`; `dsm_sdk::storage::client_db::canonical_apply::tests::different_identity_reusing_nonce_or_parent_is_conflict` | The lookup no longer matching the (relationship, parent) alone → `the_same_relationship_and_parent_with_a_different_transition_conflicts` red (2026-09-29). The insert's UNIQUE constraint is a second check and was not removed. | — |