docs/source-release-policy.mdpinned to impactium@637886d

Source-release policy

This page states plainly what becomes open, when, and why — so no one has to guess. Delaying a source drop is a real trade-off, and the honest thing is to declare the schedule rather than leave it ambiguous.

Where we are: private pre-launch

While the record is still impermanent — the building phase and the run-up to Genesis — the code repositories are private. This is deliberate, not evasive: the model and its invariants are still being hardened, development networks reset freely, and there is no live, value-bearing network whose behavior an external reader needs to audit yet. Opening a fast-moving target invites confusion and premature forks of a design that is still settling.

What is already public is substantial: the full documentation — the model, the architecture, the protocol interface shape, the verification model, and the security and threat model. The narrative and the interface are open now; the implementation opens on the schedule below.

What opens, and when

Phase What becomes public
Building (now) Full docs: model, architecture, interface shape, verification and threat models, roadmap
Pre-genesis network Chain ID, the protobuf interface + generated client shape, node/verification instructions; devnets still reset
Toward Genesis External audit scope and artifacts — published before any public incentive or value-bearing interaction, with the audited commit and findings, not a badge
At Genesis / first value-bearing interaction Full reproducible source — the node, the protos, the generated clients, lockfiles, the exact build recipe, and artifact checksums, tagged as a release

The firm commitment is the last row: full source is open no later than the moment any record becomes permanent.

Note what that is anchored to — permanence itself, which is also what Genesis is: the founding token, the point the record stops being disposable. The two coincide, and the wording is deliberately tied to the property rather than to the milestone's name, so that if the vocabulary shifts again the promise does not move with it. The strongest public trust mechanism available to us is not withheld past the point where trust actually starts to matter.

Verifiable before it is open

Closed source does not mean unverifiable. Several checks hold today, before the drop:

  • The node binary is itself distributed as a certified Chain Resource, content-addressed by hash — so what a validator runs can be matched to what was published, independent of the repository.
  • The signing vector pins the transaction wire format, and the state machine is deterministic — every honest node produces the same app hash, and Karma rebuilds by replay.
  • Any committed fact can be escalated to an ICS23 proof against the state root.

So the release schedule is about convenience and completeness of review, not about whether the running network can be checked. See Verifiable, not trusted for what you can confirm right now without any source at all.

Why not open everything today

Because the honest answer is that the invariants, the ActionCatalog parameters, and the Constitution are still being set — in the open, through the pre-genesis process — and freezing a repository around a design that is deliberately still converging would misrepresent how settled it is. The record that opening the source is meant to make trustworthy does not exist until Genesis makes it permanent; the source opens to meet it there.