Stance: keep the honest lab frame and build until the frame is obsolete.
Respect is not requested in copy. It is earned when a skeptical engineer can clone, break, and still find the invariants holding.
This document is the north star. ROADMAP.md is the checklist. Normative behavior is whatever SPEC.md + CI enforce.
| Skeptic move | Our answer |
|---|---|
| “Cute metaphor” | Point at bun run test:all + SPEC invariants |
| “Vapor bridge” | Point at a non-stub foreign verifier + frozen fixture |
| “Not an L1” | Point at multi-host tip extension, stall recovery, headers sync |
| “Sovereignty theater” | Point at ≥7 live diverse providers failing cloud-majority sets on the wire |
| “QR marketing” | Point at OTS leaf enforcement + live PIX-ML-DSA-65 (bun run test:mldsa) + QUANTUM.md |
| “Optical scam” | Point at real camera capture + two-device Kindling that fails remote |
Public voice rule: claim only what the highest passing gate allows. Vocabulary (Kindling, Worldlight, PoLS) stays — claims escalate with gates.
Guide: art guided by science it need not name (One.Creed.guide). Light verbs compress the physics of being; they do not excuse missing invariants.
Never: hide gaps behind thesis strings. Thesis strings describe intent; gates prove delivery.
Runnable, tested, and framed as a lab prototype with real crypto:
IS_STUB=false) + CosmWasm twin + custody inversion (Gate E)docs/BENCH.md (Gate F lab)Allowed claim: “Executable post-quantum-class UTXO lab; multi-host tip extension; ULA verify + phone-capable light path (lab).”
Forbidden claim: “Production L1 / production bridge / AWS-proof network / BFT mainnet.”
| Pillar | Done means |
|---|---|
| L1 | Independent hosts extend one tip; stalled sequencers recoverable; light clients sync headers; published benches |
| Bridge | Lock on A → verify on B with real crypto; no stub lightProofValid; testnet value moved end-to-end |
| Sovereignty | Live ≥7-provider set; diversity enforced on join; no required CDN/API hostname for ledger use |
| Custody / Kindling | Personal Source + two-device optical (or proven proximity) path; SMS still never spends |
| Crypto | Critical. Versioned schemes; ML-DSA-65 shipped; production default ML-DSA; OTS retained for constrained devices |
Invention stays (INVENT.md). Uptake bridges stay optional.
Each gate has evidence (repo artifact) and claim unlock. Do not advertise the next claim early.
Build
init / node / join demo — docs/demos/two-node.md + bun run test:netget_pixels / pixels hole-fill + /sync joinbun run test:four-node + docs/DEVNET.mdEvidence: docs/demos/two-node.md + bun run test:net + test:four-node
Claim unlock: “Multi-host Pixel network (prototype tip extension).” — not fault-tolerant consensus yet.
Build
skipCount in light proof; bun run test:fault)replaceTipIfBetter)Evidence: SPEC §4.1 + bun run test:fault
Claim unlock: “Fault-tolerant PoLS (lab).” Still not “BFT mainnet.”
Build
signPixel / verifyPixel scheme surface@noble/post-quantum) on tx + PoLSsrc/lib/pixel/vectors/quantum-v1.json + test:vectors)scheme + ML-DSA secret / OTS nextLeafPIXEL_SIG_SCHEME / DEFAULT_SCHEME=PIX-ML-DSA-65 for new genesisEvidence: bun run test:mldsa + bun run test:vectors green; QUANTUM.md
Claim unlock: “Crypto-agile PQ signatures — ML-DSA-65 default birth, hash-OTS retained.”
Build
ULAVerifier stub with real verify of frozen ULA fixture (PIX-HASH-OTS-128-KECCAK)contracts/cosmwasm/ula-verifier)PixelUsdcLock Locked → LockFeeder.feed → shineIn (bun run test:ula-relayer)BRIDGE_CUSTODY_AXIOM, test:bridge-custody)test:ula-mldsa)ULAOffchainMldsaGate.sol) — not full on-chain DilithiumEvidence: green Foundry + docs/BRIDGE-STATUS.md + docs/ULA-MLDSA.md (public tx links pending)
Claim unlock (partial): “ULA verify real on EVM/CosmWasm twins (lab); native ML-DSA ULAs; PQ commit gate; local lock→shineIn; foreign verify ≠ vault release.” Full “Testnet ULA bridge” when public links land. Do not claim “on-chain Dilithium.”
Build
/sync/headers, get_headers / headers, verifyHeaderChain)proveBalance / verifyBalanceProof, pix_getBalanceProof)peer-score.ts)docs/BENCH.md via bun run test:benchEvidence: bun run test:light + docs/BENCH.md from test:bench
Claim unlock: “Phone-capable light client path (lab).” — stateRoot at tip today; per-pixel historical state commits still open.
Build
join / sequencer admission calls assertSovereignIfLiveEvidence: live report snapshot + policy rejection demo (cloud-majority join fails)
Claim unlock: “Diversity-enforced sequencer set (pilot network).”
Build
getUserMedia + canvas sample (optical-capture.ts)bun run test:optical)channel: "optical-capture" when physical captures providedEvidence: test:optical + kindling optical-capture path green
Claim unlock: “Optical capture path shipped (pilot); presence-bound Kindling when channel=optical-capture.”
Build
acceptBlock + ULA) — THREAT-MODEL.mdAUDIT.md status PREPARINGbun run test:audit-scope invariantsEvidence: docs/AUDIT.md (PREPARING until report link)
Claim unlock (now): “Scoped audit package prepared; external review pending.”
Claim unlock (after report + fixes): “Audited components (scoped).” Full “trusted L1” only after broader ops maturity.
Build
Evidence: public peers, chaos drill writeup, sovereignty report continuous
Claim unlock: “Pixel public pilot / mainnet-candidate.”
| Stream | Owner shape | Depends on |
|---|---|---|
| Node / consensus | Systems | B → C → F |
| Crypto | Cryptography | D (can start now) |
| Bridge / Solidity | Eth + relayer | E (can start stub→real now) |
| Sovereignty ops | Operators | G (needs B+) |
| Kindling / mobile | Client | H (needs D for safe keys) |
| Field access | BD/KS pilots | Access + Kindling invite; never blocks L1 |
Coders pick a stream via CONTRIBUTING.md. Non-coders: field pilots and provider ops still move Gate G/H.
pix_protocolInfo.status — e.g. gates: ["A","B"].verifyLight).AUDIT.md scope; publish report linkPIXEL_TRANSPORT_KEM=1, test:kem-wire) — default still plaintexttest:chaos-drill) — not Gate J public evidencefieldDigest; acceptBlock recomputes and rejects mismatch (bun run test:field, SPEC § FieldWitness). PATH note: invent gate evidence — not a rename of prevHash. Verification, continuity of the scene, custody of the tip.pix_protocolInfo gates honest as evidence landsGate D is in. Gate I package is preparing. Continuity desk can drill origin-dark → till accrue in lab — still a pilot, not a costume. FieldWitness is invent evidence for tip custody as a sphere lock — not simile alone.