EXP-01 / Program upgrades
Program Upgrades
The KORTX program on Solana mainnet is upgraded in place, under the same address. Each upgrade adds to the program and leaves every existing account as it was. Below: what has shipped, with its transaction, and what is planned next.
Shipped
Upgrade 1 /
Call outcomes on chain
A Nucleate call's outcome (correct, incorrect, partial or void) can now be written on chain in its own account beside the call. The call and its time come from its own commit; the outcome is attested by Kortx Labs.
Upgrade 2 /
Fee ceilings and a 7-day wait
Fees now have hard ceilings compiled into the program, and any change that raises what someone pays has to be proposed on chain and wait 7 days. The wait was switched on 11 seconds after the upgrade; fees themselves are still switched off.
Upgrade transaction on SolscanWait switch-on transaction on Solscan
Program Eag1WgBbZay94E6Z9dLfUcgGUiDZRLD8Qc9qNNK6a7NS serves the binary with sha256 88f43a559402319f1f041343873e0151ca4f8d73d7a404cad71c8e4a3897108b.
Next
In priority order. Items marked decision pending wait on a decision by Kortx Labs as well as on the work.
1Upgrade key behind a multisig
planneddecision pendingOne key can upgrade the program and change its settings today. Moving it to a multisig with a delay means a single compromised key can no longer do either.
2Open-data events
plannedNew event types on the paths that log little today, so the full record can be rebuilt from events alone. Existing instructions keep their behaviour.
3Conditional verifier registration
planneddecision pendingThe five verifiers are admitted by Kortx Labs today. Outside operators could register behind a higher bond and stake thresholds, with Sybil resistance still an open research problem.
4Rent recovery
plannedInstructions to close resolved call outcomes and other spent records in batches, returning the rent to the account that paid it.
5Switching fees on
planneddecision pendingThe fee machinery is live and switched off. Turning it on is itself a fee increase, so it would be proposed on chain and wait the full 7 days first.
How an upgrade ships
Each upgrade is rehearsed first on a local chain started from the live binary: every existing account has to read back byte for byte after the upgrade, and the existing flows (commit, challenge, re-run, ruling, close) have to run through again. New behaviour arrives as new instructions and new accounts, so nothing already on chain is reinterpreted.
This page and the KORTX account on X are updated when an upgrade is live, with its transaction.