EXP-01---- traces committed---- incidents---- reproducibility---- bondedSolana mainnet
KORTX

EXP-01 / Program upgrades

Program Upgrades

The KORTX program on Solana mainnet is upgraded in place, under the same address. Each upgrade adds to the program and leaves every existing account as it was. Below: what has shipped, with its transaction, and what is planned next.

Shipped

  1. Upgrade 1 /

    Call outcomes on chain

    A Nucleate call's outcome (correct, incorrect, partial or void) can now be written on chain in its own account beside the call. The call and its time come from its own commit; the outcome is attested by Kortx Labs.

    Upgrade transaction on Solscan

  2. Upgrade 2 /

    Fee ceilings and a 7-day wait

    Fees now have hard ceilings compiled into the program, and any change that raises what someone pays has to be proposed on chain and wait 7 days. The wait was switched on 11 seconds after the upgrade; fees themselves are still switched off.

    Upgrade transaction on SolscanWait switch-on transaction on Solscan

Program Eag1WgBbZay94E6Z9dLfUcgGUiDZRLD8Qc9qNNK6a7NS serves the binary with sha256 88f43a559402319f1f041343873e0151ca4f8d73d7a404cad71c8e4a3897108b.

Next

In priority order. Items marked decision pending wait on a decision by Kortx Labs as well as on the work.

  1. 1Upgrade key behind a multisig

    planneddecision pending

    One key can upgrade the program and change its settings today. Moving it to a multisig with a delay means a single compromised key can no longer do either.

  2. 2Open-data events

    planned

    New event types on the paths that log little today, so the full record can be rebuilt from events alone. Existing instructions keep their behaviour.

  3. 3Conditional verifier registration

    planneddecision pending

    The five verifiers are admitted by Kortx Labs today. Outside operators could register behind a higher bond and stake thresholds, with Sybil resistance still an open research problem.

  4. 4Rent recovery

    planned

    Instructions to close resolved call outcomes and other spent records in batches, returning the rent to the account that paid it.

  5. 5Switching fees on

    planneddecision pending

    The fee machinery is live and switched off. Turning it on is itself a fee increase, so it would be proposed on chain and wait the full 7 days first.

How an upgrade ships

Each upgrade is rehearsed first on a local chain started from the live binary: every existing account has to read back byte for byte after the upgrade, and the existing flows (commit, challenge, re-run, ruling, close) have to run through again. New behaviour arrives as new instructions and new accounts, so nothing already on chain is reinterpreted.

This page and the KORTX account on X are updated when an upgrade is live, with its transaction.