Cashu Fault Lab
Browse documentation

Evidence architecture

Faults travel. Trust does not.

The lab controls the disturbance, durable implementations recover, and a separate oracle decides what the evidence can support.

System map

One delivery. Separate authorities.

Delivery stays implementation-owned. Evidence crosses the trust boundary before any safety or liveness claim is accepted.

Delivery pathImplementation-owned recovery
  1. 01

    Durable sender

    Reserves proofs, persists one immutable payload, and recovers the same delivery identity.

  2. 02

    HTTP/Nostr faults

    Drops, delays, duplicates, and reorders lab-controlled transport events.

  3. 03

    Durable receiver

    Persists intent and receipts across crashes without granting itself a pass.

Independent observations
  • From durable sender

    Exact payload

    Preserves the immutable payload bytes and delivery identity used for every retry.

  • From durable receiver

    Mint recovery

    Reconciles possible proof consumption against independent mint observations.

Evaluation

Independent oracle

Evaluates safety and liveness from authorities outside the implementation.

Portable output

JSON/JUnit/HTML evidence

Unsupported claims remain explicitly not observable.

Durable sender → HTTP/Nostr faults → durable receiver. Sender payload evidence and receiver mint-recovery evidence branch downward, converge at the independent oracle, then flow to JSON, JUnit, and HTML evidence.

Separation of concerns

Recovery behavior is not release evidence.

A sender may converge and a receiver may avoid duplicate credit while the release gate still remains blocked. Behavior is observed per run; qualification additionally requires independent implementations, mints, authorities, and review.

Run resultObserved

Successful recovery

One tested pair can demonstrate correct behavior for one deterministic run.

  • Same delivery converges
  • Duplicate credit is prevented
  • Receipt and mint state reconcile
Release gateIndependent

Release qualification

A release claim needs broader evidence than a single implementation can produce.

  • Independent implementation pairs
  • Distinct mints and authorities
  • Reviewed qualifying evidence

Use run evidence for feedback. Use the strict gate for release claims.

Inspect the strict release gate