Certs

{-# OPTIONS --safe #-}

open import Ledger.Prelude
open import Ledger.Conway.Abstract
open import Ledger.Conway.Transaction using (TransactionStructure)

open import Data.Product using (_×_; _,_)
open import Relation.Binary.PropositionalEquality

open import Ledger.Conway.Conformance.Equivalence.Convert

module Ledger.Conway.Conformance.Equivalence.Certs
  (txs : _) (open TransactionStructure txs)
  (abs : AbstractFunctions txs) (open AbstractFunctions abs)
  where

private
  module L where
    open import Ledger.Conway.Certs govStructure public

  module C where
    open import Ledger.Conway.Conformance.Certs govStructure public

instance

  DStateToConf : L.Deposits  L.DState  C.DState
  DStateToConf .convⁱ deposits stᵈ =
    let open L.DState stᵈ in
    $\begin{pmatrix} \,\href{Ledger.Conway.Certs.html#3883}{\htmlId{780}{\htmlClass{Field}{\text{voteDelegs}}}}\, \\ \,\href{Ledger.Conway.Certs.html#3922}{\htmlId{793}{\htmlClass{Field}{\text{stakeDelegs}}}}\, \\ \,\href{Ledger.Conway.Certs.html#3962}{\htmlId{807}{\htmlClass{Field}{\text{rewards}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#730}{\htmlId{817}{\htmlClass{Bound}{\text{deposits}}}}\, \end{pmatrix}$

  DStateFromConf : C.DState  L.DState
  DStateFromConf .convⁱ _ dState =
    let open C.DState dState in
    $\begin{pmatrix} \,\href{Ledger.Conway.Conformance.Certs.html#606}{\htmlId{941}{\htmlClass{Field}{\text{voteDelegs}}}}\, \\ \,\href{Ledger.Conway.Conformance.Certs.html#645}{\htmlId{954}{\htmlClass{Field}{\text{stakeDelegs}}}}\, \\ \,\href{Ledger.Conway.Conformance.Certs.html#685}{\htmlId{968}{\htmlClass{Field}{\text{rewards}}}}\, \end{pmatrix}$

  GStateToConf : L.Deposits  L.GState  C.GState
  GStateToConf .convⁱ deposits stᵍ =
    let open L.GState stᵍ in
    $\begin{pmatrix} \,\href{Ledger.Conway.Certs.html#4812}{\htmlId{1101}{\htmlClass{Field}{\text{dreps}}}}\, \\ \,\href{Ledger.Conway.Certs.html#4835}{\htmlId{1109}{\htmlClass{Field}{\text{ccHotKeys}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#1051}{\htmlId{1121}{\htmlClass{Bound}{\text{deposits}}}}\, \end{pmatrix}$

  GStateFromConf : C.GState  L.GState
  GStateFromConf .convⁱ deposits gState =
    let open C.GState gState in
    $\begin{pmatrix} \,\href{Ledger.Conway.Conformance.Certs.html#809}{\htmlId{1252}{\htmlClass{Field}{\text{dreps}}}}\, \\ \,\href{Ledger.Conway.Conformance.Certs.html#845}{\htmlId{1260}{\htmlClass{Field}{\text{ccHotKeys}}}}\, \end{pmatrix}$

data ValidDepsᵈ (pp : PParams) (deps : L.Deposits) : List L.DCert  Set where
  []         : ValidDepsᵈ pp deps []
  delegate   :  {c del kh v certs}
              ValidDepsᵈ pp (C.updateCertDeposit pp (L.delegate c del kh v) deps) certs
              ValidDepsᵈ pp deps (L.delegate c del kh v  certs)
  dereg      :  {c md d certs}
              (L.CredentialDeposit c , d)  deps
              md  nothing  md  just d
              ValidDepsᵈ pp (C.updateCertDeposit pp (L.dereg c md) deps) certs
              ValidDepsᵈ pp deps (L.dereg c md  certs)
  regdrep    :  {c v a certs}
              ValidDepsᵈ pp deps certs
              ValidDepsᵈ pp deps (L.regdrep c v a  certs)
  deregdrep  :  {c d certs}
              ValidDepsᵈ pp deps certs
              ValidDepsᵈ pp deps (L.deregdrep c d  certs)
  regpool    :  {kh p certs}
              ValidDepsᵈ pp deps certs
              ValidDepsᵈ pp deps (L.regpool kh p  certs)
  retirepool :  {kh e certs}
              ValidDepsᵈ pp deps certs
              ValidDepsᵈ pp deps (L.retirepool kh e   certs)
  ccreghot   :  {c v certs}
              ValidDepsᵈ pp deps certs
              ValidDepsᵈ pp deps (L.ccreghot c v  certs)
  reg        :  {c d certs}
              ValidDepsᵈ pp (C.updateCertDeposit pp (L.reg c d) deps) certs
              ValidDepsᵈ pp deps (L.reg c d  certs)

data ValidDepsᵍ (pp : PParams) (deps : L.Deposits) : List L.DCert  Set where
  []         : ValidDepsᵍ pp deps []
  regdrep    :  {c v a certs}
              ValidDepsᵍ pp (C.updateCertDeposit pp (L.regdrep c v a) deps) certs
              ValidDepsᵍ pp deps (L.regdrep c v a  certs)
  deregdrep  :  {c d certs}
              (L.DRepDeposit c , d)  deps
              ValidDepsᵍ pp (C.updateCertDeposit pp (L.deregdrep c d) deps) certs
              ValidDepsᵍ pp deps (L.deregdrep c d  certs)
  delegate   :  {c del kh v certs}
              ValidDepsᵍ pp deps certs
              ValidDepsᵍ pp deps (L.delegate c del kh v  certs)
  dereg      :  {c d certs}
              ValidDepsᵍ pp deps certs
              ValidDepsᵍ pp deps (L.dereg c d  certs)
  regpool    :  {kh p certs}
              ValidDepsᵍ pp deps certs
              ValidDepsᵍ pp deps (L.regpool kh p  certs)
  retirepool :  {kh e certs}
              ValidDepsᵍ pp deps certs
              ValidDepsᵍ pp deps (L.retirepool kh e   certs)
  ccreghot   :  {c v certs}
              ValidDepsᵍ pp deps certs
              ValidDepsᵍ pp deps (L.ccreghot c v  certs)
  reg        :  {c d certs}
              ValidDepsᵍ pp deps certs
              ValidDepsᵍ pp deps (L.reg c d  certs)

record CertDeps* (pp : PParams) (dcerts : List L.DCert) : Set where
  constructor ⟦_,_,_,_⟧*
  field
    depsᵈ : L.Deposits
    depsᵍ : L.Deposits
    -- Invariants
    validᵈ : ValidDepsᵈ pp depsᵈ dcerts
    validᵍ : ValidDepsᵍ pp depsᵍ dcerts

pattern delegate*    ddeps gdeps = $\begin{pmatrix} \,\htmlId{4220}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4224}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4228}{\htmlClass{InductiveConstructor}{\text{delegate}}}\,   \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4239}{\htmlId{4239}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\htmlId{4247}{\htmlClass{InductiveConstructor}{\text{delegate}}}\,    \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4259}{\htmlId{4259}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
pattern dereg*  v w  ddeps gdeps = $\begin{pmatrix} \,\htmlId{4305}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4309}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4313}{\htmlClass{InductiveConstructor}{\text{dereg}}}\, \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4319}{\htmlId{4319}{\htmlClass{Bound}{\text{v}}}}\, \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4321}{\htmlId{4321}{\htmlClass{Bound}{\text{w}}}}\,  \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4324}{\htmlId{4324}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\htmlId{4332}{\htmlClass{InductiveConstructor}{\text{dereg}}}\,       \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4344}{\htmlId{4344}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
pattern regpool*     ddeps gdeps = $\begin{pmatrix} \,\htmlId{4390}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4394}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4398}{\htmlClass{InductiveConstructor}{\text{regpool}}}\,    \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4409}{\htmlId{4409}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\htmlId{4417}{\htmlClass{InductiveConstructor}{\text{regpool}}}\,     \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4429}{\htmlId{4429}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
pattern retirepool*  ddeps gdeps = $\begin{pmatrix} \,\htmlId{4475}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4479}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4483}{\htmlClass{InductiveConstructor}{\text{retirepool}}}\, \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4494}{\htmlId{4494}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\htmlId{4502}{\htmlClass{InductiveConstructor}{\text{retirepool}}}\,  \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4514}{\htmlId{4514}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
pattern regdrep*     ddeps gdeps = $\begin{pmatrix} \,\htmlId{4560}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4564}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4568}{\htmlClass{InductiveConstructor}{\text{regdrep}}}\,    \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4579}{\htmlId{4579}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\htmlId{4587}{\htmlClass{InductiveConstructor}{\text{regdrep}}}\,     \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4599}{\htmlId{4599}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
pattern deregdrep* v ddeps gdeps = $\begin{pmatrix} \,\htmlId{4645}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4649}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4653}{\htmlClass{InductiveConstructor}{\text{deregdrep}}}\,  \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4664}{\htmlId{4664}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\htmlId{4672}{\htmlClass{InductiveConstructor}{\text{deregdrep}}}\, \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4682}{\htmlId{4682}{\htmlClass{Bound}{\text{v}}}}\, \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4684}{\htmlId{4684}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
pattern ccreghot*    ddeps gdeps = $\begin{pmatrix} \,\htmlId{4730}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4734}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4738}{\htmlClass{InductiveConstructor}{\text{ccreghot}}}\,   \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4749}{\htmlId{4749}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\htmlId{4757}{\htmlClass{InductiveConstructor}{\text{ccreghot}}}\,    \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4769}{\htmlId{4769}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
pattern reg*         ddeps gdeps = $\begin{pmatrix} \,\htmlId{4815}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4819}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4823}{\htmlClass{InductiveConstructor}{\text{reg}}}\,        \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4834}{\htmlId{4834}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\htmlId{4842}{\htmlClass{InductiveConstructor}{\text{reg}}}\,         \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4854}{\htmlId{4854}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$

open CertDeps*

getCertDeps* :  {pp dcert}  CertDeps* pp dcert  L.Deposits × L.Deposits
getCertDeps* deps = deps .depsᵈ , deps .depsᵍ

updateCertDeps :  {pp dcert dcerts}  CertDeps* pp (dcert  dcerts)  CertDeps* pp dcerts
updateCertDeps (delegate*    ddeps gdeps) = $\begin{pmatrix} \,\htmlId{5139}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{5143}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5122}{\htmlId{5147}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5128}{\htmlId{5155}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
updateCertDeps (dereg* _ _   ddeps gdeps) = $\begin{pmatrix} \,\htmlId{5210}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{5214}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5193}{\htmlId{5218}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5199}{\htmlId{5226}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
updateCertDeps (regpool*     ddeps gdeps) = $\begin{pmatrix} \,\htmlId{5281}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{5285}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5264}{\htmlId{5289}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5270}{\htmlId{5297}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
updateCertDeps (retirepool*  ddeps gdeps) = $\begin{pmatrix} \,\htmlId{5352}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{5356}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5335}{\htmlId{5360}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5341}{\htmlId{5368}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
updateCertDeps (regdrep*     ddeps gdeps) = $\begin{pmatrix} \,\htmlId{5423}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{5427}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5406}{\htmlId{5431}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5412}{\htmlId{5439}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
updateCertDeps (deregdrep* _ ddeps gdeps) = $\begin{pmatrix} \,\htmlId{5494}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{5498}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5477}{\htmlId{5502}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5483}{\htmlId{5510}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
updateCertDeps (ccreghot*    ddeps gdeps) = $\begin{pmatrix} \,\htmlId{5565}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{5569}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5548}{\htmlId{5573}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5554}{\htmlId{5581}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
updateCertDeps (reg*         ddeps gdeps) = $\begin{pmatrix} \,\htmlId{5636}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{5640}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5619}{\htmlId{5644}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5625}{\htmlId{5652}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$

updateCertDeps* :  {pp} dcerts  CertDeps* pp dcerts  CertDeps* pp []
updateCertDeps* []               deps = deps
updateCertDeps* (dcert  dcerts) deps = updateCertDeps* dcerts (updateCertDeps deps)

instance

  CertStToConf : L.Deposits × L.Deposits  L.CertState  C.CertState
  CertStToConf .convⁱ (ddeps , gdeps) certState =
    let open L.CertState certState in
    $\begin{pmatrix} \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5967}{\htmlId{6038}{\htmlClass{Bound}{\text{ddeps}}}}\, \,\href{Ledger.Conway.Conformance.Equivalence.Convert.html#278}{\htmlId{6044}{\htmlClass{Function Operator}{\text{⊢conv}}}}\, \,\href{Ledger.Conway.Certs.html#5218}{\htmlId{6050}{\htmlClass{Field}{\text{dState}}}}\, \\ \,\href{Ledger.Conway.Certs.html#5238}{\htmlId{6059}{\htmlClass{Field}{\text{pState}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5975}{\htmlId{6068}{\htmlClass{Bound}{\text{gdeps}}}}\, \,\href{Ledger.Conway.Conformance.Equivalence.Convert.html#278}{\htmlId{6074}{\htmlClass{Function Operator}{\text{⊢conv}}}}\, \,\href{Ledger.Conway.Certs.html#5258}{\htmlId{6080}{\htmlClass{Field}{\text{gState}}}}\, \end{pmatrix}$

  CertStFromConf : C.CertState  L.CertState
  CertStFromConf .convⁱ _ certState =
    let open C.CertState certState in
    $\begin{pmatrix} \,\href{Ledger.Conway.Conformance.Equivalence.Convert.html#460}{\htmlId{6217}{\htmlClass{Function}{\text{conv}}}}\, \,\href{Ledger.Conway.Conformance.Certs.html#981}{\htmlId{6222}{\htmlClass{Field}{\text{dState}}}}\, \\ \,\href{Ledger.Conway.Conformance.Certs.html#1001}{\htmlId{6231}{\htmlClass{Field}{\text{pState}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Convert.html#460}{\htmlId{6240}{\htmlClass{Function}{\text{conv}}}}\, \,\href{Ledger.Conway.Conformance.Certs.html#1021}{\htmlId{6245}{\htmlClass{Field}{\text{gState}}}}\, \end{pmatrix}$

  CERTBASEToConf :  {Γ s s'}
                  L.Deposits × L.Deposits
                    Γ L.⊢ s ⇀⦇ _ ,CERTBASE⦈ s' ⭆ⁱ λ deposits _ 
                     Γ C.⊢ (deposits ⊢conv s) ⇀⦇ _ ,CERTBASE⦈ (deposits ⊢conv s')
  CERTBASEToConf .convⁱ deposits (L.CERT-base h) = C.CERT-base h

  DELEGToConf :  {Γ s dcert dcerts s'}
                  (open L.DelegEnv Γ renaming (pparams to pp))
               CertDeps* pp (dcert  dcerts) 
                 Γ L.⊢ s ⇀⦇ dcert ,DELEG⦈ s' ⭆ⁱ λ deposits _ 
                 Γ C.⊢ (deposits .depsᵈ ⊢conv s) ⇀⦇ dcert ,DELEG⦈ (updateCertDeps deposits .depsᵈ ⊢conv s')
  DELEGToConf .convⁱ (delegate* _ _) (L.DELEG-delegate h) = C.DELEG-delegate h
  DELEGToConf .convⁱ (dereg* v w _ _)  (L.DELEG-dereg h)    = C.DELEG-dereg (h , v , w)
  DELEGToConf .convⁱ (reg* _ _) (L.DELEG-reg h) = C.DELEG-reg h

  POOLToConf :  {pp s dcert s'}  pp L.⊢ s ⇀⦇ dcert ,POOL⦈ s'  pp C.⊢ s ⇀⦇ dcert ,POOL⦈ s'
  POOLToConf .convⁱ _ (L.POOL-regpool h) = C.POOL-regpool h
  POOLToConf .convⁱ _ L.POOL-retirepool  = C.POOL-retirepool

  GOVCERTToConf :  {Γ s dcert dcerts s'}
                  (open L.CertEnv Γ using (pp))
                 CertDeps* pp (dcert  dcerts) 
                   Γ L.⊢ s ⇀⦇ dcert ,GOVCERT⦈ s' ⭆ⁱ λ deposits _ 
                   Γ C.⊢ (deposits .depsᵍ ⊢conv s) ⇀⦇ dcert ,GOVCERT⦈ (updateCertDeps deposits .depsᵍ ⊢conv s')
  GOVCERTToConf .convⁱ (regdrep* _ _)     (L.GOVCERT-regdrep h) = C.GOVCERT-regdrep h
  GOVCERTToConf .convⁱ (deregdrep* v _ _) (L.GOVCERT-deregdrep h) = C.GOVCERT-deregdrep (h , v)
  GOVCERTToConf .convⁱ (ccreghot* _ _)    (L.GOVCERT-ccreghot h)  = C.GOVCERT-ccreghot h

  CERTToConf :  {Γ s dcert dcerts s'} (open L.CertEnv Γ using (pp))
              CertDeps* pp (dcert  dcerts) 
                Γ L.⊢ s ⇀⦇ dcert ,CERT⦈ s' ⭆ⁱ λ deposits _ 
                Γ C.⊢ (getCertDeps* deposits ⊢conv s) ⇀⦇ dcert ,CERT⦈ (getCertDeps* (updateCertDeps deposits) ⊢conv s')
  CERTToConf .convⁱ deposits@(delegate* _ _)    (L.CERT-deleg deleg)  = C.CERT-deleg (deposits ⊢conv deleg)
  CERTToConf .convⁱ deposits@(dereg* _ _ _ _)   (L.CERT-deleg deleg)  = C.CERT-deleg (deposits ⊢conv deleg)
  CERTToConf .convⁱ deposits@(regpool* _ _)     (L.CERT-pool pool)    = C.CERT-pool (conv pool)
  CERTToConf .convⁱ deposits@(retirepool* _ _)  (L.CERT-pool pool)    = C.CERT-pool (conv pool)
  CERTToConf .convⁱ deposits@(regdrep* _ _)     (L.CERT-vdel govcert) = C.CERT-vdel (deposits ⊢conv govcert)
  CERTToConf .convⁱ deposits@(deregdrep* _ _ _) (L.CERT-vdel govcert) = C.CERT-vdel (deposits ⊢conv govcert)
  CERTToConf .convⁱ deposits@(ccreghot* _ _)    (L.CERT-vdel govcert) = C.CERT-vdel (deposits ⊢conv govcert)
  CERTToConf .convⁱ deposits@(reg* _ _)         (L.CERT-deleg deleg)  = C.CERT-deleg (deposits ⊢conv deleg)

  CERTS'ToConf :  {Γ s dcerts s'} (let open L.CertEnv Γ)
                CertDeps* pp dcerts
                  ReflexiveTransitiveClosure {sts = L._⊢_⇀⦇_,CERT⦈_} Γ s dcerts s' ⭆ⁱ λ deposits _ 
                   ReflexiveTransitiveClosure {sts = C._⊢_⇀⦇_,CERT⦈_}
                             Γ (getCertDeps* deposits ⊢conv s) dcerts
                               (getCertDeps* (updateCertDeps* dcerts deposits) ⊢conv s')
  CERTS'ToConf .convⁱ deposits (BS-base Id-nop) = BS-base Id-nop
  CERTS'ToConf .convⁱ deposits (BS-ind r rs)    = BS-ind (deposits ⊢conv r) (updateCertDeps deposits ⊢conv rs)

  CERTSToConf :  {Γ s dcerts s'} (let open L.CertEnv Γ)
               CertDeps* pp dcerts
                 Γ L.⊢ s ⇀⦇ dcerts ,CERTS⦈ s' ⭆ⁱ λ deposits _ 
                  Γ C.⊢ (getCertDeps* deposits ⊢conv s) ⇀⦇ dcerts ,CERTS⦈
                        (getCertDeps* (updateCertDeps* dcerts deposits) ⊢conv s')
  CERTSToConf .convⁱ deposits (RTC (base , step)) =
    RTC (getCertDeps* deposits ⊢conv base , deposits ⊢conv step)

-- Converting form Conformance is easier since the deposit tracking disappears.
instance
  DELEGFromConf :  {Γ s dcert s'}
                 Γ C.⊢ s ⇀⦇ dcert ,DELEG⦈ s' 
                  Γ L.⊢ conv s ⇀⦇ dcert ,DELEG⦈ conv s'
  DELEGFromConf .convⁱ _ (C.DELEG-delegate h)    = L.DELEG-delegate h
  DELEGFromConf .convⁱ _ (C.DELEG-dereg (h , _)) = L.DELEG-dereg h
  DELEGFromConf .convⁱ _ (C.DELEG-reg h)         = L.DELEG-reg h

  POOLFromConf :  {pp s dcert s'}  pp C.⊢ s ⇀⦇ dcert ,POOL⦈ s'  pp L.⊢ s ⇀⦇ dcert ,POOL⦈ s'
  POOLFromConf .convⁱ _ (C.POOL-regpool h) = L.POOL-regpool h
  POOLFromConf .convⁱ _ C.POOL-retirepool  = L.POOL-retirepool

  GOVCERTFromConf :  {Γ s dcert s'}
                   Γ C.⊢ s ⇀⦇ dcert ,GOVCERT⦈ s' 
                    Γ L.⊢ conv s ⇀⦇ dcert ,GOVCERT⦈ conv s'
  GOVCERTFromConf .convⁱ _ (C.GOVCERT-regdrep h)   = C.GOVCERT-regdrep h
  GOVCERTFromConf .convⁱ _ (C.GOVCERT-deregdrep (h , _)) = C.GOVCERT-deregdrep h
  GOVCERTFromConf .convⁱ _ (C.GOVCERT-ccreghot h)  = C.GOVCERT-ccreghot h

  CERTFromConf :  {Γ s dcert s'}  Γ C.⊢ s ⇀⦇ dcert ,CERT⦈ s'  Γ L.⊢ conv s ⇀⦇ dcert ,CERT⦈ conv s'
  CERTFromConf .convⁱ _ (C.CERT-deleg deleg)  = L.CERT-deleg (conv deleg)
  CERTFromConf .convⁱ _ (C.CERT-pool pool)    = L.CERT-pool (conv pool)
  CERTFromConf .convⁱ _ (C.CERT-vdel govcert) = L.CERT-vdel (conv govcert)

  CERTBASEFromConf :  {Γ s s'}
                    Γ C.⊢ s ⇀⦇ _ ,CERTBASE⦈ s' 
                     Γ L.⊢ (conv s) ⇀⦇ _ ,CERTBASE⦈ (conv s')
  CERTBASEFromConf .convⁱ _ (C.CERT-base h) = L.CERT-base h

  CERTS'FromConf :  {Γ s dcerts s'}
                  ReflexiveTransitiveClosure {sts = C._⊢_⇀⦇_,CERT⦈_} Γ s dcerts s' 
                   ReflexiveTransitiveClosure {sts = L._⊢_⇀⦇_,CERT⦈_} Γ (conv s) dcerts (conv s')
  CERTS'FromConf .convⁱ _ (BS-base Id-nop) = BS-base Id-nop
  CERTS'FromConf .convⁱ _ (BS-ind r rs) = BS-ind (conv r) (conv rs)

  CERTSFromConf :  {Γ s dcerts s'}
                 Γ C.⊢ s ⇀⦇ dcerts ,CERTS⦈ s' 
                  Γ L.⊢ conv s ⇀⦇ dcerts ,CERTS⦈ conv s'
  CERTSFromConf .convⁱ _ (RTC (base , step)) = RTC (conv base , conv step)