420 Verify¶
420 Verify reproduces deployed contract bytecode from published source and exact build settings. It answers whether source/build inputs correspond to deployed code; it does not certify that the code is secure, audited, endorsed, immutable or authorized.
Verification is bound to network, address and deployed runtime code hash.
Genesis status¶
GEN-10.5 is complete. PR #303 merged the qualified VERIFY-0 through VERIFY-10 implementation into main at 1f937b7ef641980cc118336763ba50ffc8f3cc5a after exact-head 420Docs Qualification #1418 and 420 Integrated Qualification #3678 passed.
The implementation is qualified; public backend/frontend deployment remains pending until real testnet endpoints are provisioned and recorded in testnet/public-services/verify/readiness.json.
Core documentation¶
- Getting started — how verification is submitted, looked up, and interpreted.
- User guide — result classes, history, evidence, and proxy behavior.
- Architecture — trust boundary, canonical inputs, compiler worker, evidence store, API, and integrations.
- Security — adversarial limits, secret rejection, fail-closed behavior, and non-authority guarantees.
- Permissions — what Verify can and cannot authorize.
- Troubleshooting — common mismatch, unavailable-evidence, and deployment issues.
- FAQ — verification meaning and common questions.
- Fees — protocol-fee boundary.
Implementation references¶
- VERIFY-5 bytecode comparison and classification —
FULL_MATCH,PARTIAL_MATCH,MISMATCH, andUNVERIFIABLEplus exact runtime/creation diagnostics. - VERIFY-6 reproducible evidence store and history — append-only evidence history, restart reconstruction, content-hash validation, and non-canonical storage.
- VERIFY-7 proxies and upgrades — proxy relationship resolution, separate proxy/implementation verification, upgrade history, and stale-status invalidation.
- VERIFY-8 public API and Genesis integrations — lookup/submission/evidence endpoints plus Explorer, Registry, and AppStore boundaries.
- VERIFY-9 adversarial hardening and failure recovery — hostile-input limits, secret rejection, compiler-abuse controls, degraded dependencies, restart/tamper recovery, and authority-preserving failure modes.
- VERIFY-10 qualification, reconciliation and closeout — final exact-head qualification, latest-main reconciliation, deployment-readiness boundaries, and GEN-10.6 handoff.
For the complete Genesis implementation summary, see docs/420VERIFY.md and docs/420VERIFY-ROADMAP.md.