In brief
This page is source-sensitive. Treat application, covenant, proof, and readiness wording as bounded by the listed public sources and Open Questions.
What this page explains#
A counter covenant starter is a teaching pattern to verify, not an upstream-endorsed production recipe. It introduces successor checks, negative tests, and state encoding while keeping every concrete rule source-gated. This page sits in Covenants. It gives the topic a plain-language handle first, then shows the working idea, the mechanism, the source trail, and any limits that still matter. This category keeps the UTXO model visible while explaining stateful patterns. A covenant does not mutate account storage in place; it validates a spend and the successor output that carries the next state.
The writing follows a simple Kaspa documentation pattern: answer the practical question first, then link outward for details. The closest public sources for this page are DOC-TOCCATA-COVENANT-STATE, RK-COVENANTS, TOOL-SILVERSCRIPT-REPO. Local notes can help choose what to explain, but public-facing references resolve to upstream websites, repositories, papers, release pages, or docs.
How to think about it#
The practical model starts by naming the layer that owns the topic: wallet use, node operation, consensus, transaction validation, Toccata script behavior, tooling, or research. From there, the page shows which public source can support the explanation and where the explanation becomes incomplete.
For Counter Covenant Starter, the model is built around these anchors: current count encoding is a design hypothesis until tied to a concrete script and successor-output source path; the spend must prove or check the allowed increment before the pattern can be promoted; the successor carries the new state only when the script and output binding enforce that relation; recommended tests include wrong state, wrong successor, stale head, and malformed state; local examples must be cross-checked with source. This model is useful, but it does not encode every constant, branch, error type, or edge case. Those details belong in the source path and the source notes.
How it works#
1. current count encoding is a design hypothesis until tied to a concrete script and successor-output source path. Covenant mechanics stay anchored in UTXOs, but the page's main question is state continuity. The current output is spent, the script inspects transaction context, and the successor output must carry the allowed next state. Covenant IDs, authorization groups, script context, and indexer head tracking are helper surfaces; they do not replace the actual successor validation rule.
2. the spend must prove or check the allowed increment before the pattern can be promoted. Covenant mechanics stay anchored in UTXOs, but the page's main question is state continuity. The current output is spent, the script inspects transaction context, and the successor output must carry the allowed next state. Covenant IDs, authorization groups, script context, and indexer head tracking are helper surfaces; they do not replace the actual successor validation rule.
3. the successor carries the new state only when the script and output binding enforce that relation. Covenant mechanics stay anchored in UTXOs, but the page's main question is state continuity. The current output is spent, the script inspects transaction context, and the successor output must carry the allowed next state. Covenant IDs, authorization groups, script context, and indexer head tracking are helper surfaces; they do not replace the actual successor validation rule.
4. recommended tests include wrong state, wrong successor, stale head, and malformed state. Covenant mechanics stay anchored in UTXOs, but the page's main question is state continuity. The current output is spent, the script inspects transaction context, and the successor output must carry the allowed next state. Covenant IDs, authorization groups, script context, and indexer head tracking are helper surfaces; they do not replace the actual successor validation rule.
5. local examples must be cross-checked with source. Covenant mechanics stay anchored in UTXOs, but the page's main question is state continuity. The current output is spent, the script inspects transaction context, and the successor output must carry the allowed next state. Covenant IDs, authorization groups, script context, and indexer head tracking are helper surfaces; they do not replace the actual successor validation rule.
This mechanism section keeps the covenant rule, the spent output, the successor output, covenant ID, authorization context, and indexer responsibility separate. Local case studies stay local experience unless rewritten against public sources.
How to check it#
| Step | Check | Evidence gate |
|---|---|---|
| 1 | Check current count encoding is a design hypothesis until tied to a concrete script and successor-output source path. | Read DOC-TOCCATA-COVENANT-STATE, RK-COVENANTS, TOOL-SILVERSCRIPT-REPO; verify spent-output context, successor-output rule, covenant ID, and negative cases separately. |
| 2 | Check the spend must prove or check the allowed increment before the pattern can be promoted. | Read DOC-TOCCATA-COVENANT-STATE, RK-COVENANTS, TOOL-SILVERSCRIPT-REPO; verify spent-output context, successor-output rule, covenant ID, and negative cases separately. |
| 3 | Check the successor carries the new state only when the script and output binding enforce that relation. | Read DOC-TOCCATA-COVENANT-STATE, RK-COVENANTS, TOOL-SILVERSCRIPT-REPO; verify spent-output context, successor-output rule, covenant ID, and negative cases separately. |
| 4 | Check recommended tests include wrong state, wrong successor, stale head, and malformed state. | Read DOC-TOCCATA-COVENANT-STATE, RK-COVENANTS, TOOL-SILVERSCRIPT-REPO; verify spent-output context, successor-output rule, covenant ID, and negative cases separately. |
| 5 | Check local examples must be cross-checked with source. | Read DOC-TOCCATA-COVENANT-STATE, RK-COVENANTS, TOOL-SILVERSCRIPT-REPO; verify spent-output context, successor-output rule, covenant ID, and negative cases separately. |
When using this page for covenant design, verify the spent output, script context, authorization rule, successor output, state encoding, and negative cases separately. Indexer head tracking and local design notes are supporting evidence, not replacements for the covenant rule.
Related Pages#
- covenant-head-indexer-starter
- covenants
- vault-covenant-starter