ADR-0003: Settlement parameters at launch

Window length: multi-prover live → revisit. Bond floor: any TVL milestone → mandatory re-derivation.

Status: accepted. Dated 2026-08-13.

Status: accepted (2026-08-13) · Prompt: §5 D5, §6 C6

Decision

  • Challenge window: 7 days (604 800 s) — SUPERSEDED by ADR-0016 (2026-09-04), which sets 48 hours (172 800 s). The policy below is what survives: the window was never shortened for marketing, and ADR-0016 shortens it against measured arithmetic — the dispute game needs hours, not days — while keeping ADR-0015's 24-hour air gap for the job the window was wrongly doing. Quote the total exit, window plus air gap, never the window alone. Original text: Not shortened for marketing; shortened only when a validity proof, not a timer, guarantees correctness (multi-prover per ADR-0002).
  • Proposing: permissionless-with-bond in the core. No mutable operator allowlist as the security mechanism (defect 6 of the source snippet). The launch program MAY wrap the core with a temporary allowlist — behind a published timelock, stated on the security page, and removed by Stage 1 criteria.
  • Proposer bond: placeholder floor in core config; sized against value-at-risk before any real deposits (§6 C12), re-derived as TVL grows with an automated review trigger.
  • Time: on-chain Clock sysvar only, injected into the core as a parameter. The core has no way to read a clock — the defect-1 fix is structural, not disciplinary.
  • Finality rule: a root finalizes only if its parent is Final and its own window has elapsed unchallenged. Withdrawals verify against Final roots only (§7.2 inv. 2/3).

Reversal triggers

Window length: multi-prover live → revisit. Bond floor: any TVL milestone → mandatory re-derivation.