Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,5 +19,11 @@ their shared settlement, compliance, identity, and authority assumptions.
- [Token Standard V2 dependency source](decisions/cip-0112-dependency-source.md)
- [Token Standard V2 import evidence](decisions/cip-0112-import-evidence.md)

## Milestone delivery

- [M1 delivery map](m1-delivery.md) maps every Milestone 1 delivery element and
acceptance criterion of the approved ecosystem-stack proposal to its delivered
artifact and validation command.

Executable research, threat models, and experiment-specific documentation live
with their code under [`experiments/`](../experiments/README.md).
48 changes: 48 additions & 0 deletions docs/m1-delivery.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,48 @@
# M1 Delivery Map: Token Foundation and dApp Framework

This document maps every Milestone 1 delivery element and acceptance criterion of the [approved proposal](https://github.com/canton-foundation/canton-dev-fund/blob/main/proposals/2026-04-OpenZeppelin-canton-ecosystem-stack.md) (pinned at `42c0b972`; delivery Q1, May to July 2026) to its delivered artifact, its location, and the command that validates it.

## Delivery elements

### Reference Implementations

| Proposal item | Delivered as | Location |
| --- | --- | --- |
| Research and design: Privacy-Preserving DEX | Reference architecture report (living document) | [reference-architectures/dex.md](reference-architectures/dex.md) |
| Research and design: Lending Protocol | Reference architecture report | [reference-architectures/lending.md](reference-architectures/lending.md) |
| Research and design: Cross-Chain Stablecoin Payment Orchestration | Reference architecture report | [reference-architectures/cross-chain-stablecoin.md](reference-architectures/cross-chain-stablecoin.md) |
| Research and design: Confidential Auction Launchpad | Reference architecture report | [reference-architectures/confidential-auction.md](reference-architectures/confidential-auction.md) |

### Contracts Library

Each proposal item lists every Daml module, test package, and script that delivers it, with what each one does.

| Proposal item | Delivered as | Location |
| --- | --- | --- |
| CIP-56 Canton Network Token Standard implementation | CIP-056 token standard template plus a stablecoin implementation built on it (both public). The ecosystem has since approved the Token Standard V2 upgrade (CIP-0112), which supersedes CIP-56; the rows below consolidate the token foundation on CIP-0112 | [OpenZeppelin/canton-token-template](https://github.com/OpenZeppelin/canton-token-template), [OpenZeppelin/canton-stablecoin](https://github.com/OpenZeppelin/canton-stablecoin) |
| CIP-0112 Token Standard V2 (supersedes CIP-56) | `openzeppelin-tokenCIP112-v1`: a CIP-0112-compliant token package. Modules: `Holding` (holdings with locks), `Transfer` (transfer instructions), `Allocation` and `AllocationRequest`, `Registry` (registry rules and event logging), `D1` (node-attestation compliance hook), `Allowance` (see the CIP-86 rows), plus D2 lawful-process seizure | [canton-contracts `experiments/token/tokenCIP112-v1`](https://github.com/OpenZeppelin/canton-contracts/tree/7696749737885e25cd88422847105f890f03b00d/experiments/token/tokenCIP112-v1) |
| | Test packages: `TokenCIP112V1Test` (core lifecycle scenarios), `TokenCIP112V1AllowanceTest` (11 allowance scenarios), and `TokenCIP112V1SandboxTest` (4 scripts run against a live sandbox over the Ledger API by the `scripts/check-sandbox.sh` gate) | [canton-contracts `experiments/test/tokenCIP112-v1`](https://github.com/OpenZeppelin/canton-contracts/tree/7696749737885e25cd88422847105f890f03b00d/experiments/test/tokenCIP112-v1), [`scripts/check-sandbox.sh`](https://github.com/OpenZeppelin/canton-contracts/blob/7696749737885e25cd88422847105f890f03b00d/scripts/check-sandbox.sh) |
| | Token Standard V2-aligned settlement primitive with D1 compliance and D2 seizure extension points, over a narrow local V2 fixture; a deep settlement exemplar builds on it | [experiments/settlement/cip-0112/](../experiments/settlement/cip-0112/), [experiments/settlement/fixtures/token-standard-v2/](../experiments/settlement/fixtures/token-standard-v2/), [experiments/settlement/exemplar/](../experiments/settlement/exemplar/); decisions in [docs/decisions/](decisions/README.md) |
| CIP-86 ERC20 Compatible Interface implementation | `TokenAllowance` component on the CIP-0112 token core: ERC-20 `approve`/`transferFrom` semantics per CIP-0086 Phase 1 through the registry entry points `TokenRules_ApproveAllowance` (owner-controlled; zero revokes) and `TokenRules_TransferFrom` (spender-controlled; the registry is the only spend path); each spend stamps the spender into the transfer metadata | [canton-contracts `Allowance.daml`](https://github.com/OpenZeppelin/canton-contracts/blob/7696749737885e25cd88422847105f890f03b00d/experiments/token/tokenCIP112-v1/daml/OpenZeppelin/TokenCIP112V1/Allowance.daml) |
| | ERC-20 facade interop exemplar, 6 scripts: `transfer` moves value and conserves supply; `balanceOf` is projection-scoped; `approve`/`transferFrom` moves value via settlement; `transferFrom` beyond the allowance fails; allowance archive is owner-only; D2 seizure is not a burn or refund | [Cip0086Erc20.daml](../experiments/interoperability/cip-exemplar/daml/OpenZeppelin/Experimental/Interop/Cip0086Erc20.daml) |
| | Live-ledger gate: runs the CIP-0086 and CIP-0103 scenarios and the settlement-attribution walkthrough over gRPC, against `dpm sandbox` by default or against Canton LocalNet with `--localnet` | [scripts/cip-interop-validation.sh](../scripts/cip-interop-validation.sh), [CIP-INTEROP.md](../experiments/interoperability/CIP-INTEROP.md) |
| CIP-103 dApp Standard library components | Wallet/dApp interop exemplar, 4 scripts: the wallet drives the full settlement lifecycle and sees the events; V1-wallet direct factory path; privacy scoped to the participants; fail-closed errors surface to the wallet | [Cip0103Wallet.daml](../experiments/interoperability/cip-exemplar/daml/OpenZeppelin/Experimental/Interop/Cip0103Wallet.daml) |
| | Wallet Gateway offer templates, 2 in-memory scripts: the gateway offer flow; offer archives are admin-only | [WalletGateway.daml](../experiments/interoperability/cip-exemplar/daml/OpenZeppelin/Experimental/Interop/WalletGateway.daml) |
| | Live third-party harness against the Canton Wallet Gateway, driven by `scripts/wallet-gateway-cip0103-interop.sh`: externally-signed wallet party, session, command submission via `prepareExecute` + `sign`/`execute`, `txChanged` lifecycle, authenticated ledger reads, and the `isConnected`, `getActiveNetwork`, `getPrimaryAccount`, `signMessage`, and `disconnect` methods | [interoperability/wallet-gateway/](../experiments/interoperability/wallet-gateway/), [scripts/wallet-gateway-cip0103-interop.sh](../scripts/wallet-gateway-cip0103-interop.sh) |
| CIP-104 Traffic-Based App Rewards library support | Settlement-attribution walkthrough: an app-provider may claim only the settlements that it confirmed as executor, and the `SettlementReceipt` and `SettlementEventLogEntry` views alone carry that distinction, without reward-marker templates | [SettlementAttribution.daml](../experiments/interoperability/cip-exemplar/daml/OpenZeppelin/Experimental/Interop/SettlementAttribution.daml) |
| | LocalNet reward gate: the Node harness features the app-provider, switches the network to traffic-based app rewards by SV vote, settles CIP-0112 batches as the featured executor, and follows the reward that the network computes from that traffic, from the Scan attribution to the `RewardCouponV2` and its beneficiary split; runs against the Amulet, Scan, and SV services of LocalNet | [interoperability/traffic-rewards/](../experiments/interoperability/traffic-rewards/), [scripts/localnet-cip0104-traffic-rewards.sh](../scripts/localnet-cip0104-traffic-rewards.sh) |
| | Linter support: the opt-in `observer-only-app-party` detector in `daml-lint` flags an app party demoted to plain observer, which silently stops CIP-0104 reward attribution | [daml-lint `observer_only_app_party`](https://github.com/OpenZeppelin/daml-lint/blob/cba698832991f640f0e0d8a9e2bfb683717c6024/src/detectors/observer_only_app_party.rs) |
| All library code published to GitHub with >90% test coverage | The coverage gates in both repositories currently confirm 100% coverage of the measured templates and choices: each gate fails when any measured repository-owned template or choice is uncovered, and both pass on `main` | canton-specs: [scripts/check-tests.sh](../scripts/check-tests.sh), [ci.yml](../.github/workflows/ci.yml), [coverage.yml](../.github/workflows/coverage.yml) (README badges); canton-contracts: [`scripts/check-coverage.sh`](https://github.com/OpenZeppelin/canton-contracts/blob/7696749737885e25cd88422847105f890f03b00d/scripts/check-coverage.sh) and its coverage workflow |
| Initial Canton section on OpenZeppelin Documentation | Published Canton section in the OpenZeppelin docs | [docs.openzeppelin.com/canton](https://docs.openzeppelin.com/canton) |

## Acceptance criteria: evidence

| Proposal acceptance criterion | Status | Evidence / how to validate |
| --- | --- | --- |
| All library code compiles against the current Daml SDK and passes CI with 100% test pass rate | ✅ | `dpm build --all` on SDK 3.4.11 ([multi-package.yaml](../multi-package.yaml)); [ci.yml](../.github/workflows/ci.yml) (structure, build, lint, SCU smoke, docs links) and [coverage.yml](../.github/workflows/coverage.yml) run on every push; latest local run (2026-08-12): 110/110 Daml Script tests pass across 8 packages |
| 90% code coverage confirmed via automated test reporting | ✅ exceeded: 100% confirmed | Both coverage gates require and currently confirm 100% of the measured repository-owned templates and choices, above the 90% criterion. canton-specs: the merged `dpm test` gate ([scripts/check-tests.sh](../scripts/check-tests.sh)) passes on the current tree (2026-08-12: zero uncovered templates or choices; the README coverage badge tracks `main`). canton-contracts: [`scripts/check-coverage.sh`](https://github.com/OpenZeppelin/canton-contracts/blob/7696749737885e25cd88422847105f890f03b00d/scripts/check-coverage.sh) and the coverage workflow pass on `main` |
| CIP-56 and CIP-86 implementations demonstrate token creation, transfer, and querying on LocalNet, including backwards compatibility | ✅ | CIP-56/CIP-0112: token creation/transfer/query on a live ledger via the canton-contracts sandbox gate (`scripts/check-sandbox.sh` runs `TokenCIP112V1SandboxTest` over the Ledger API), plus the `canton-token-template` and `canton-stablecoin` test suites. CIP-86 on LocalNet: `scripts/cip-interop-validation.sh --localnet` runs the ERC-20 facade scenarios (transfer, delegated transfer, allowance bounds, supply conservation, projection-scoped balance queries) over gRPC against Canton LocalNet (see [CIP-INTEROP.md](../experiments/interoperability/CIP-INTEROP.md)); `approve`/`transferFrom` semantics covered by the 11 `TokenCIP112V1AllowanceTest` scenarios in canton-contracts. Backwards compatibility: the V1-wallet path (`test_cip0103_v1WalletDirectFactoryPath`) and the CIP-56 to V2 migration evidence in `canton-token-template` |
| CIP-103 library components compatible with at least one existing CIP-103 implementation (e.g., Splice Wallet Kernel) | ✅ | Third-party gate: `scripts/wallet-gateway-cip0103-interop.sh` runs the settlement surface against the Canton Wallet Gateway (the CIP-103 implementation formerly named Splice Wallet Kernel, `@canton-network/wallet-gateway-remote@1.6.0`): externally-signed wallet party, session, command submission via `prepareExecute` + `sign`/`execute`, `txChanged` lifecycle, authenticated ledger reads. Passing transcripts (2026-07-22) for both a local sandbox and an external managed DevNet validator (Canton 3.5.9) in [wallet-gateway/evidence/](../experiments/interoperability/wallet-gateway/evidence/); the scheduled [live-ledger-gates workflow](../.github/workflows/live-ledger-gates.yml) re-runs this gate on LocalNet daily |
| CIP-104 library components demonstrate integration with the traffic-based rewards model on LocalNet | ✅ | LocalNet gate: `scripts/localnet-cip0104-traffic-rewards.sh` drives the real reward path on LocalNet with Amulet, Scan, and an SV. The featured app-provider settles CIP-0112 batches as executor, the network computes the reward from that traffic, and the harness follows it to the `RewardCouponV2` and its beneficiaries; a submission by a non-executor is rejected. Attribution: `SettlementAttribution.daml` derives the executor-confirmed settlements from the settlement views alone, with no marker contracts ([CIP-INTEROP.md](../experiments/interoperability/CIP-INTEROP.md)) |
| Architecture documents for Year 1 RIs published and reviewed by Digital Asset | 🟡 published, review in progress | The four reports are published in this public repo under [reference-architectures/](reference-architectures/); the external review round collects inline comments in [PR #40](https://github.com/OpenZeppelin/canton-specs/pull/40) |
| Library and RI code published in public GitHub repositories under MIT license (OZ tooling under AGPL 3.0) | ✅ | [canton-specs](https://github.com/OpenZeppelin/canton-specs) and [canton-contracts](https://github.com/OpenZeppelin/canton-contracts) are public under MIT; [canton-token-template](https://github.com/OpenZeppelin/canton-token-template), [canton-stablecoin](https://github.com/OpenZeppelin/canton-stablecoin), [daml-lint](https://github.com/OpenZeppelin/daml-lint), [daml-props](https://github.com/OpenZeppelin/daml-props), and [daml-verify](https://github.com/OpenZeppelin/daml-verify) are public under AGPL 3.0 |
Loading