Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
30 commits
Select commit Hold shift + click to select a range
e0df11f
Align cross-chain stablecoin proposal with Simon's DEX feedback
0xNeshi Sep 17, 2026
35a166f
remove temp file
0xNeshi Sep 17, 2026
43541e9
Record compliance denials on-ledger via Allocation_Cancel, with off-l…
0xNeshi Sep 21, 2026
6c76eee
Merge branch 'main' into ccb-updates
0xNeshi Sep 29, 2026
c86d1ce
redesign to use transfer flow
0xNeshi Sep 29, 2026
8f62f91
Merge branch 'main' into ccb-updates
0xNeshi Oct 2, 2026
ec7861a
remove redundant mention of CIP112 allocation logic
0xNeshi Oct 2, 2026
5445249
Make cross-chain bridge registry-agnostic: gateway-side D1/D3 checks,…
0xNeshi Oct 2, 2026
7344fad
Trim cross-chain stablecoin proposal: drop Canton primers, out-of-sco…
0xNeshi Oct 2, 2026
7cee406
Move D3 KYC into attester backend, gate redemption on compliance, add…
0xNeshi Oct 2, 2026
5fb0592
Merge remote-tracking branch 'origin/main' into ccb-updates
0xNeshi Oct 5, 2026
484bf8c
Partition the nonce registry by epoch to bound per-mint writes, add t…
0xNeshi Oct 5, 2026
d9b00bf
Replace registry contract keys with disclosed-contract maintainer and…
0xNeshi Oct 5, 2026
801b4e8
rename gateway admin to bridge admin
0xNeshi Oct 5, 2026
e131d27
shorten section 1
0xNeshi Oct 5, 2026
83f1eb2
shorten section 1.1
0xNeshi Oct 5, 2026
ab061c4
shorten section 1: mention compliance checks in first sentence
0xNeshi Oct 5, 2026
c8649e6
clean up scope
0xNeshi Oct 5, 2026
4d8b393
remove d3 entry from 1.3 table
0xNeshi Oct 5, 2026
e4b87ae
update ccsp
0xNeshi Oct 5, 2026
64badd7
Require joint br and ba authority to consume attestations so only a g…
0xNeshi Oct 5, 2026
86051fc
Make listed attesters observers of statements created through the att…
0xNeshi Oct 5, 2026
75a85ff
br also holds featuredappright
0xNeshi Oct 5, 2026
3261c3b
confirm app rewards behavior
0xNeshi Oct 6, 2026
8f801cf
Move the cross-chain bridge prototype into experiments/cross-chain-br…
0xNeshi Oct 6, 2026
b94d49d
Use the redemption request id as the claim nonce
0xNeshi Oct 6, 2026
cb90126
Use the Token Standard reason key for denials, and fix section 1 typos
0xNeshi Oct 6, 2026
e4134c9
Count only listed signers toward the attester quorum, test a removed …
0xNeshi Oct 6, 2026
91a8c84
Give each repeated fact in the cross-chain stablecoin architecture on…
0xNeshi Oct 6, 2026
9d43195
Rewrite unclear prose in the cross-chain stablecoin architecture and …
0xNeshi Oct 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
39 changes: 37 additions & 2 deletions .github/workflows/live-ledger-gates.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# The four gates below all use `--localnet`, so each job starts its own Splice
# The five gates below all run on LocalNet, so each job starts its own Splice
# LocalNet Docker Compose network. Before a job can run its gate, it downloads
# the LocalNet images and waits for the network to become ready. This workflow
# repeats that setup four times, which is why each job needs a 45 minute
# repeats that setup five times, which is why each job needs a 45 minute
# timeout.
#
# The ci workflow already runs the same gates against the in-process
Expand Down Expand Up @@ -120,6 +120,41 @@ jobs:
if-no-files-found: warn
retention-days: 30

bridge-app-rewards:
runs-on: ubuntu-latest
timeout-minutes: 45
steps:
- uses: actions/checkout@v4

- name: Set up Daml
uses: ./.github/actions/setup-daml

- name: Set up Node 24
uses: actions/setup-node@v4
with:
node-version: "24"

# This gate features `ba`, `br`, and the wTOK admin, runs the bridge
# setup and two inbound credits in separate mining rounds, and reports
# the minting allowance of each featured party. The cap sits on the step
# for the same reason as in the traffic-rewards job: a job timeout drops
# the evidence upload below.
- name: Run the bridge app-reward attribution on LocalNet
timeout-minutes: 30
run: scripts/localnet-bridge-app-rewards.sh

- name: Upload bridge app-rewards evidence
if: always()
uses: actions/upload-artifact@v4
with:
name: bridge-app-rewards-evidence
# The minted Ledger API token stays out of the artifact.
path: |
.cache/bridge-app-rewards/
!.cache/bridge-app-rewards/**/*.token
if-no-files-found: warn
retention-days: 30

identity-upgrade:
runs-on: ubuntu-latest
timeout-minutes: 45
Expand Down
5 changes: 3 additions & 2 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -59,6 +59,7 @@ The interoperability gates run real processes and ledger connections:
scripts/cip-interop-validation.sh
scripts/wallet-gateway-cip0103-interop.sh
scripts/localnet-cip0104-traffic-rewards.sh
scripts/localnet-bridge-app-rewards.sh
```

Every gate above takes its ledger through the shared
Expand All @@ -84,8 +85,8 @@ fresh-ledger requirement, and the environment overrides.
The `ci` workflow runs the identity upgrade and CIP interoperability gates
against the sandbox on every pull request, so a pull request pays no container
image pull. The Wallet Gateway gate fetches its npm package at run time, and the
CIP-0104 traffic-rewards gate waits for mining rounds to close, so both stay out
of `ci` and run on the schedule alone. The scheduled `live-ledger-gates` workflow
CIP-0104 traffic-rewards and bridge app-rewards gates wait for mining rounds to
close, so these three stay out of `ci` and run on the schedule alone. The scheduled `live-ledger-gates` workflow
runs every gate on LocalNet, which is where authorization, party rights, package
vetting, and the Amulet reward path on a real synchronizer are validated. Run a
gate on LocalNet locally before you change it, its harness, or a participant
Expand Down
2 changes: 2 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,7 @@ packages follow the `OpenZeppelin/canton-contracts` lifecycle.
| [Compliance](experiments/compliance/) | Alternative shapes for off-ledger checks and on-ledger attestations |
| [Identity](experiments/identity/) | Identity hooks, credential gating, and Smart Contract Upgrade compatibility |
| [Interoperability](experiments/interoperability/) | CIP-0086, CIP-0103, and CIP-0104 behavior on LocalNet and against the Canton Wallet Gateway |
| [Cross-chain bridge](experiments/cross-chain-bridge/) | The Canton side of the attested bridge: gateways, attester quorums, nonce replay protection, redemption, and app-reward attribution on LocalNet |

The [documentation index](docs/README.md) collects the reference architectures
and durable architecture decisions. The [experiment index](experiments/README.md)
Expand Down Expand Up @@ -72,6 +73,7 @@ docs/
reference-architectures/ Application architecture reports
experiments/
compliance/ Compliance-check alternatives
cross-chain-bridge/ Attested bridge prototype on the CIP-0112 registry
identity/ Identity, credential, and SCU research
interoperability/ Live-ledger and third-party compatibility evidence
settlement/ Settlement architecture and executable prototypes
Expand Down
112 changes: 112 additions & 0 deletions dars/manifest.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -27,3 +27,115 @@ artifacts:
source-commit: 7696749737885e25cd88422847105f890f03b00d
source: https://github.com/OpenZeppelin/canton-contracts/tree/7696749737885e25cd88422847105f890f03b00d/experiments/security/pausable-v1
license: MIT
# The cross-chain bridge experiment consumes the entries below. The
# OpenZeppelin DARs are built from `OpenZeppelin/canton-contracts` at
# 8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8 (branch
# `igingu-cip112-simplification-and-rad`, PR #45) targeting Daml-LF 2.1.
# That pausable-v1 build has a different package id from the one above, so
# its file name carries the short commit. The Splice DARs are byte-identical
# copies of the Splice 0.8.3 release artifacts. Never rebuild them from
# source: a local build yields different package ids for the same package
# names and versions.
- package: openzeppelin-tokenCIP112-workflows-v1
version: 0.1.0
file: dars/vendor/openzeppelin-tokenCIP112-workflows-v1-0.1.0.dar
main-package-id: 2f85f0392c01bc6b661f6437ab777186b6a6244fe060bfc18318119c4a5058c9
sha256: 3dd076a5ce62ca2a1a6efc6ad11e7942d2c391fda70de5109da43ccc89e426bb
source-commit: 8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8
source: https://github.com/OpenZeppelin/canton-contracts/tree/8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8/packages/token/tokenCIP112-workflows-v1
license: MIT
- package: openzeppelin-tokenCIP112-v1
version: 0.1.0
file: dars/vendor/openzeppelin-tokenCIP112-v1-0.1.0.dar
main-package-id: e550d594809783ee649774af2cf23c9e1b62ecba2968c749664fe18819cd27df
sha256: 758c1552c706d3a80e7602be51635a050a207941422f3019cfca0623fd099277
source-commit: 8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8
source: https://github.com/OpenZeppelin/canton-contracts/tree/8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8/packages/token/tokenCIP112-v1
license: MIT
- package: openzeppelin-scoped-authorization-grant-v1
version: 0.1.0
file: dars/vendor/openzeppelin-scoped-authorization-grant-v1-0.1.0.dar
main-package-id: af94533f903956b7f53baa95068657c88354d1702660ec016941461143905519
sha256: 750af559c659ba982e6ac2fc97efb3df4945fa7594da1cf5ebca0e49ed44243b
source-commit: 8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8
source: https://github.com/OpenZeppelin/canton-contracts/tree/8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8/packages/access/scoped-authorization-grant-v1
license: MIT
- package: openzeppelin-api-pausable-v1
version: 0.1.0
file: dars/vendor/openzeppelin-api-pausable-v1-0.1.0.dar
main-package-id: 83864acf065cf6771af62ccd480d6adc00f7ee509138ce91e08647d0258b5e81
sha256: a195c96206e4b12552e002733bd12d52865eea233ef20b808c8bf1409a13a88b
source-commit: 8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8
source: https://github.com/OpenZeppelin/canton-contracts/tree/8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8/packages/security/api-pausable-v1
license: MIT
- package: openzeppelin-pausable-v1
version: 0.1.0
file: dars/vendor/openzeppelin-pausable-v1-0.1.0-8a81bc8.dar
main-package-id: 4efa161c910a77aff1f17a4404b6f5822c68347205b902f7b4cfd694ba5eba3d
sha256: eccd08174c9be060b9da5f24c564d361729e8103364c18bed1437be160f9e381
source-commit: 8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8
source: https://github.com/OpenZeppelin/canton-contracts/tree/8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8/packages/security/pausable-v1
license: MIT
- package: splice-api-token-metadata-v1
version: 1.0.0
file: dars/vendor/splice-api-token-metadata-v1-1.0.0.dar
main-package-id: 4ded6b668cb3b64f7a88a30874cd41c75829f5e064b3fbbadf41ec7e8363354f
sha256: 455eb160cb5abd4ae9918a6fbb9dad471f721adda39f0e5c76feef08d05637fc
source-commit: 8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8
source: https://github.com/OpenZeppelin/canton-contracts/blob/8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8/dars/vendor/splice-api-token-metadata-v1-1.0.0.dar
upstream: https://github.com/canton-network/splice/blob/0.8.3/daml/dars/splice-api-token-metadata-v1-1.0.0.dar
license: Apache-2.0
- package: splice-api-token-holding-v2
version: 1.0.0
file: dars/vendor/splice-api-token-holding-v2-1.0.0.dar
main-package-id: 4b7ecfc366d79ccc5ed07c80f26fe489cf2dfd43ce2856c06a78e6a048db7032
sha256: f044b34d7a28c2b6c8a540af720297d55450a889b451dc4eed64a9914f1d6b00
source-commit: 8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8
source: https://github.com/OpenZeppelin/canton-contracts/blob/8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8/dars/vendor/splice-api-token-holding-v2-1.0.0.dar
upstream: https://github.com/canton-network/splice/blob/0.8.3/daml/dars/splice-api-token-holding-v2-1.0.0.dar
license: Apache-2.0
- package: splice-api-token-transfer-events-v2
version: 1.0.0
file: dars/vendor/splice-api-token-transfer-events-v2-1.0.0.dar
main-package-id: 5c1097a9bad0af4bcfe6d3fb0fe55112d3d11f18eae57ddfb14c20836fee226c
sha256: 9a1ebe5aece0a7f1a49069fd7aba0ced92c4ae94e5e3d49cdb097733a87dddbc
source-commit: 8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8
source: https://github.com/OpenZeppelin/canton-contracts/blob/8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8/dars/vendor/splice-api-token-transfer-events-v2-1.0.0.dar
upstream: https://github.com/canton-network/splice/blob/0.8.3/daml/dars/splice-api-token-transfer-events-v2-1.0.0.dar
license: Apache-2.0
- package: splice-api-token-allocation-v2
version: 1.0.0
file: dars/vendor/splice-api-token-allocation-v2-1.0.0.dar
main-package-id: 051a3b0563a6fa4df4cb34448081e48b061e555aa1a265abf6ae8f3f4cafe439
sha256: e349d3a1952cdd52ed55333bef35e9ba40e6e0379521d65556c6aa2f50d9a1fd
source-commit: 8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8
source: https://github.com/OpenZeppelin/canton-contracts/blob/8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8/dars/vendor/splice-api-token-allocation-v2-1.0.0.dar
upstream: https://github.com/canton-network/splice/blob/0.8.3/daml/dars/splice-api-token-allocation-v2-1.0.0.dar
license: Apache-2.0
- package: splice-api-token-transfer-instruction-v2
version: 1.0.0
file: dars/vendor/splice-api-token-transfer-instruction-v2-1.0.0.dar
main-package-id: 29317e3b7b165d2bbf16721bcca0ec4869e53eddb2738bddf790d61af28e0099
sha256: 720e766456b33abdd26bfc21e54d19413559f0a7ee52000e12d3b6c308199faa
source-commit: 8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8
source: https://github.com/OpenZeppelin/canton-contracts/blob/8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8/dars/vendor/splice-api-token-transfer-instruction-v2-1.0.0.dar
upstream: https://github.com/canton-network/splice/blob/0.8.3/daml/dars/splice-api-token-transfer-instruction-v2-1.0.0.dar
license: Apache-2.0
- package: splice-api-token-allocation-instruction-v2
version: 1.0.0
file: dars/vendor/splice-api-token-allocation-instruction-v2-1.0.0.dar
main-package-id: 9818a0b5b827109de03a04c8f6151cde9d1e7fe5123dbb2dfeb0e52d7271287c
sha256: 31de6be30385936105b24c8ea544bb25f6eede0d0c008154a11462bb6d14a17b
source-commit: 8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8
source: https://github.com/OpenZeppelin/canton-contracts/blob/8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8/dars/vendor/splice-api-token-allocation-instruction-v2-1.0.0.dar
upstream: https://github.com/canton-network/splice/blob/0.8.3/daml/dars/splice-api-token-allocation-instruction-v2-1.0.0.dar
license: Apache-2.0
- package: splice-token-standard-utils
version: 2.0.0
file: dars/vendor/splice-token-standard-utils-2.0.0.dar
main-package-id: 9a8f41a2b1456d357dee5677565c21b9a5aa45b80f0ed6be469694445dd4f6e1
sha256: 3346dedf1c4617e92858fe93d6f9c81ebb1a92a6d809378f487e516aa8f877fc
source-commit: 8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8
source: https://github.com/OpenZeppelin/canton-contracts/blob/8a81bc86d7e5b2ec38db4c0c5897ccdb20ac25b8/dars/vendor/splice-token-standard-utils-2.0.0.dar
upstream: https://github.com/canton-network/splice/blob/0.8.3/daml/dars/splice-token-standard-utils-2.0.0.dar
license: Apache-2.0
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
5 changes: 4 additions & 1 deletion docs/reference-architectures/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,10 @@ The reports draw on executable research in this repository:
- [identity experiments](../../experiments/identity/) for claims, credential
gates, and Smart Contract Upgrade compatibility;
- [interoperability experiments](../../experiments/interoperability/) for
LocalNet and Canton Wallet Gateway integration evidence.
LocalNet and Canton Wallet Gateway integration evidence;
- the [cross-chain bridge experiment](../../experiments/cross-chain-bridge/)
for the bridge gateways, attester quorums, redemption, and app-reward
attribution.

The experimental code validates specific mechanisms; the reports specify the
complete target applications that compose them.
Expand Down
Loading
Loading