# Protocol upgrade candidate — 9 October 2026 **Status: isolated research harness; not an activated mainnet upgrade.** The 0.2.1 release preserves the published genesis, balances, legacy signatures and consensus rules. The modules in `upgrade/` do not import or migrate mainnet wallets, run a public node, accept deposits or claim audit approval. ## What is implemented `upgrade/protocol.py` uses the maintained `cryptography` ML-DSA-65 implementation, backed by OpenSSL. ML-DSA is specified in NIST FIPS 204. This does not mean this integration or its cryptographic module is FIPS certified or independently audited. Dependencies are exact-version pinned in `upgrade/requirements.txt`. Commands bind protocol version, devnet chain identifier, account, key epoch, nonce, action and payload. FIPS context strings separate ordinary authorization from new-key possession. Raw public keys are 1,952 bytes and signatures 3,309 bytes. Amounts use canonical decimal strings. Unknown fields, alternative encodings and unsafe numeric ranges are rejected. The SQLite account harness requires the current public key and exact next nonce. Rotation requires signatures from both the existing and replacement keys over the complete command. Rotation preserves the account identifier and balance, increments epoch/nonce, and retires the old authorization key atomically with the event. Failure rolls back the balance, key and sequence together. Restored ML-DSA seed material does not create the one-time-key reuse problem of the legacy scheme, though stolen keys and database rollback still need recovery. `upgrade/storage.py` validates actual proof bytes through Chia's `chiapos` verifier. A regression fixture was produced from a real disposable disk plot, then checked for valid quality and rejection of changed challenge, plot ID and proof bytes. The k=18 fixture is deliberately small and **not** a proposed production security parameter. Plot identities bind chain, owner, nonce and k. This adapter is not a full consensus construction and proves neither continuous storage retention nor network security on its own. ## Required consensus design and review 1. Replace recomputable independent leaves with an analyzed proof-of-space construction. Pin the exact verifier, plot format, implementation and production parameter set after time/space/compression tradeoff analysis. 2. Derive challenges from an independently analyzed randomness/time mechanism. Hashing the producer's chosen previous proof alone is insufficient. Specify entropy, lookback, withholding/grinding bounds, delayed plot eligibility and how challenge availability survives partitions. VDF/timelord or other beacon assumptions must be written and tested before selection. 3. Specify checkpoint timing, difficulty adjustment, quality-to-weight conversion, deterministic tie-breaking and bounded reorganization rules together. Test cheap-history, long-range, eclipse, withholding and bootstrap attacks. Do not reuse the legacy inverse-distance weight merely because a new proof verifies. 4. Bind plot registration, rewards, key rotation and checkpoint signatures to the same versioned protocol and chain domain. Supply plots/verification vectors, canonical serialization fixtures and rejection cases for every node runtime. 5. Benchmark native verifier costs and enforce resource limits before gossip. Current Python Workers cannot be assumed to run these native dependencies. Choose a supported node runtime or an independently verified verifier boundary; never silently substitute a different algorithm or trust a client verdict. ## Migration requirements before mainnet activation - Publish a complete specification and activation rule, with an independently reviewed method for migrating existing balances and retiring legacy keys. - Audit legacy-key claims; compromised/reused legacy keys cannot be made safe by wrapping their claims in a new signature. Define the dispute/recovery process. - Preserve the existing genesis and history. Any new chain/snapshot proposal needs explicit operator/user coordination and verifiable allocation accounting. - Implement browser, desktop and seed interoperability; import/export encryption; durable reorg-aware account/key state; and hardware/backup recovery policy. - Run a sustained multi-operator testnet, upgrade/rollback rehearsal and external audit. Publish exact source commits and residual findings before activation. No activation height, replacement genesis or balance migration is set by this release. A local account harness is not a network testnet. ## Reproduce ```sh python3 -m venv .venv-upgrade .venv-upgrade/bin/pip install -r upgrade/requirements.txt .venv-upgrade/bin/python -m unittest discover -s tests -p 'test_upgrade.py' .venv-upgrade/bin/python -m unittest discover -s tests -p 'test_operations.py' ``` Primary references: - NIST FIPS 204: https://csrc.nist.gov/pubs/fips/204/final - Cryptography ML-DSA API: https://cryptography.io/en/latest/hazmat/primitives/asymmetric/mldsa/ - Chia proof-of-space library and upstream tests: https://github.com/Chia-Network/chiapos These sources describe primitives/APIs; they do not review or endorse Aurion.