Tacet · trust model
Carried over verbatim from PLAN-APPENDIX.md A.8 (the original Heirloom design), plus the rows the protocol escalation adds.
executeRedemptionDefault); stated plainly.claimSealed pays the address in the revealed preimage, never the TEE operator or msg.sender./verify/pnpm verify:all shows window coverage.skewMargin + beat at window midpoint + self-check in beat.ts (exactly one memo, exactly 32 bytes).hookPending + permissionless retryHook. Garbage/unexpected hook return values default to TERMINATE, never a privileged write. See the hostile-consequence test family (ObligationRegistryHostileConsequence.t.sol).RUNBOOK.md section 4 — the FCC scaffold's own deployment prerequisites (VPN to Flare's internal indexer DB, a GCP Confidential Space VM) are outside this environment's reach, so the sealed-reveal middleware was never deployed. The on-chain sealed-commitment mechanism itself (claimSealed) is real, tested, and live-demoable independent of the TEE.close()+register() inside a compliance hook) reverts under the registry's 300k-gas stipendCircleConsequence splits round-advance into a separate permissionless advanceRound() call outside any hook — a lesson learned live in this repo (see RUNBOOK.md gotchas), not a theoretical concern.Range proven
Three consequences ship in this repo, each a different shape of money logic on the same proof rails:
A fourth, CharityConsequence, was built entirely from templates/consequence-template — proving the abstraction holds for someone who has never seen the registry’s internals before, not just the reference implementations.
What auditors should re-check themselves
Everything in pnpm verify:all’s output is independently reproducible from a Coston2 RPC alone: every stored proof is re-decoded from its original transaction calldata and re-submitted as a fresh view call against the live FdcVerification/Relay root, not against a cached or trusted intermediate result.