Certs

{-# OPTIONS --safe #-}

open import Ledger.Prelude
open import Ledger.Conway.Specification.Abstract
open import Ledger.Conway.Specification.Transaction using (TransactionStructure)

open import Data.Product using (_×_; _,_)
open import Relation.Binary.PropositionalEquality

open import Ledger.Conway.Conformance.Equivalence.Convert

module Ledger.Conway.Conformance.Equivalence.Certs
  (txs : _) (open TransactionStructure txs)
  (abs : AbstractFunctions txs) (open AbstractFunctions abs)
  where

private
  module L where
    open import Ledger.Conway.Specification.Certs govStructure public

  module C where
    open import Ledger.Conway.Conformance.Certs govStructure public

instance

  DStateToConf : L.Deposits  L.DState  C.DState
  DStateToConf .convⁱ deposits stᵈ =
    let open L.DState stᵈ in
    $\begin{pmatrix} \,\href{Ledger.Conway.Specification.Certs.html#3948}{\htmlId{822}{\htmlClass{Field}{\text{voteDelegs}}}}\, \\ \,\href{Ledger.Conway.Specification.Certs.html#3987}{\htmlId{835}{\htmlClass{Field}{\text{stakeDelegs}}}}\, \\ \,\href{Ledger.Conway.Specification.Certs.html#4027}{\htmlId{849}{\htmlClass{Field}{\text{rewards}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#772}{\htmlId{859}{\htmlClass{Bound}{\text{deposits}}}}\, \end{pmatrix}$

  DStateFromConf : C.DState  L.DState
  DStateFromConf .convⁱ _ dState =
    let open C.DState dState in
    $\begin{pmatrix} \,\href{Ledger.Conway.Conformance.Certs.html#662}{\htmlId{983}{\htmlClass{Field}{\text{voteDelegs}}}}\, \\ \,\href{Ledger.Conway.Conformance.Certs.html#701}{\htmlId{996}{\htmlClass{Field}{\text{stakeDelegs}}}}\, \\ \,\href{Ledger.Conway.Conformance.Certs.html#741}{\htmlId{1010}{\htmlClass{Field}{\text{rewards}}}}\, \end{pmatrix}$

  GStateToConf : L.Deposits  L.GState  C.GState
  GStateToConf .convⁱ deposits stᵍ =
    let open L.GState stᵍ in
    $\begin{pmatrix} \,\href{Ledger.Conway.Specification.Certs.html#4877}{\htmlId{1143}{\htmlClass{Field}{\text{dreps}}}}\, \\ \,\href{Ledger.Conway.Specification.Certs.html#4900}{\htmlId{1151}{\htmlClass{Field}{\text{ccHotKeys}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#1093}{\htmlId{1163}{\htmlClass{Bound}{\text{deposits}}}}\, \end{pmatrix}$

  GStateFromConf : C.GState  L.GState
  GStateFromConf .convⁱ deposits gState =
    let open C.GState gState in
    $\begin{pmatrix} \,\href{Ledger.Conway.Conformance.Certs.html#865}{\htmlId{1294}{\htmlClass{Field}{\text{dreps}}}}\, \\ \,\href{Ledger.Conway.Conformance.Certs.html#901}{\htmlId{1302}{\htmlClass{Field}{\text{ccHotKeys}}}}\, \end{pmatrix}$

data ValidDepsᵈ (pp : PParams) (deps : L.Deposits) : List L.DCert  Set where
  []         : ValidDepsᵈ pp deps []
  delegate   :  {c del kh v certs}
              ValidDepsᵈ pp (C.updateCertDeposit pp (L.delegate c del kh v) deps) certs
              ValidDepsᵈ pp deps (L.delegate c del kh v  certs)
  dereg      :  {c md d certs}
              (L.CredentialDeposit c , d)  deps
              md  nothing  md  just d
              ValidDepsᵈ pp (C.updateCertDeposit pp (L.dereg c md) deps) certs
              ValidDepsᵈ pp deps (L.dereg c md  certs)
  regdrep    :  {c v a certs}
              ValidDepsᵈ pp deps certs
              ValidDepsᵈ pp deps (L.regdrep c v a  certs)
  deregdrep  :  {c d certs}
              ValidDepsᵈ pp deps certs
              ValidDepsᵈ pp deps (L.deregdrep c d  certs)
  regpool    :  {kh p certs}
              ValidDepsᵈ pp deps certs
              ValidDepsᵈ pp deps (L.regpool kh p  certs)
  retirepool :  {kh e certs}
              ValidDepsᵈ pp deps certs
              ValidDepsᵈ pp deps (L.retirepool kh e   certs)
  ccreghot   :  {c v certs}
              ValidDepsᵈ pp deps certs
              ValidDepsᵈ pp deps (L.ccreghot c v  certs)
  reg        :  {c d certs}
              ValidDepsᵈ pp (C.updateCertDeposit pp (L.reg c d) deps) certs
              ValidDepsᵈ pp deps (L.reg c d  certs)

data ValidDepsᵍ (pp : PParams) (deps : L.Deposits) : List L.DCert  Set where
  []         : ValidDepsᵍ pp deps []
  regdrep    :  {c v a certs}
              ValidDepsᵍ pp (C.updateCertDeposit pp (L.regdrep c v a) deps) certs
              ValidDepsᵍ pp deps (L.regdrep c v a  certs)
  deregdrep  :  {c d certs}
              (L.DRepDeposit c , d)  deps
              ValidDepsᵍ pp (C.updateCertDeposit pp (L.deregdrep c d) deps) certs
              ValidDepsᵍ pp deps (L.deregdrep c d  certs)
  delegate   :  {c del kh v certs}
              ValidDepsᵍ pp deps certs
              ValidDepsᵍ pp deps (L.delegate c del kh v  certs)
  dereg      :  {c d certs}
              ValidDepsᵍ pp deps certs
              ValidDepsᵍ pp deps (L.dereg c d  certs)
  regpool    :  {kh p certs}
              ValidDepsᵍ pp deps certs
              ValidDepsᵍ pp deps (L.regpool kh p  certs)
  retirepool :  {kh e certs}
              ValidDepsᵍ pp deps certs
              ValidDepsᵍ pp deps (L.retirepool kh e   certs)
  ccreghot   :  {c v certs}
              ValidDepsᵍ pp deps certs
              ValidDepsᵍ pp deps (L.ccreghot c v  certs)
  reg        :  {c d certs}
              ValidDepsᵍ pp deps certs
              ValidDepsᵍ pp deps (L.reg c d  certs)

record CertDeps* (pp : PParams) (dcerts : List L.DCert) : Set where
  constructor ⟦_,_,_,_⟧*
  field
    depsᵈ : L.Deposits
    depsᵍ : L.Deposits
    -- Invariants
    validᵈ : ValidDepsᵈ pp depsᵈ dcerts
    validᵍ : ValidDepsᵍ pp depsᵍ dcerts

pattern delegate*    ddeps gdeps = $\begin{pmatrix} \,\htmlId{4262}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4266}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4270}{\htmlClass{InductiveConstructor}{\text{delegate}}}\,   \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4281}{\htmlId{4281}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\htmlId{4289}{\htmlClass{InductiveConstructor}{\text{delegate}}}\,    \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4301}{\htmlId{4301}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
pattern dereg*  v w  ddeps gdeps = $\begin{pmatrix} \,\htmlId{4347}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4351}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4355}{\htmlClass{InductiveConstructor}{\text{dereg}}}\, \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4361}{\htmlId{4361}{\htmlClass{Bound}{\text{v}}}}\, \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4363}{\htmlId{4363}{\htmlClass{Bound}{\text{w}}}}\,  \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4366}{\htmlId{4366}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\htmlId{4374}{\htmlClass{InductiveConstructor}{\text{dereg}}}\,       \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4386}{\htmlId{4386}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
pattern regpool*     ddeps gdeps = $\begin{pmatrix} \,\htmlId{4432}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4436}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4440}{\htmlClass{InductiveConstructor}{\text{regpool}}}\,    \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4451}{\htmlId{4451}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\htmlId{4459}{\htmlClass{InductiveConstructor}{\text{regpool}}}\,     \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4471}{\htmlId{4471}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
pattern retirepool*  ddeps gdeps = $\begin{pmatrix} \,\htmlId{4517}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4521}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4525}{\htmlClass{InductiveConstructor}{\text{retirepool}}}\, \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4536}{\htmlId{4536}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\htmlId{4544}{\htmlClass{InductiveConstructor}{\text{retirepool}}}\,  \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4556}{\htmlId{4556}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
pattern regdrep*     ddeps gdeps = $\begin{pmatrix} \,\htmlId{4602}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4606}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4610}{\htmlClass{InductiveConstructor}{\text{regdrep}}}\,    \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4621}{\htmlId{4621}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\htmlId{4629}{\htmlClass{InductiveConstructor}{\text{regdrep}}}\,     \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4641}{\htmlId{4641}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
pattern deregdrep* v ddeps gdeps = $\begin{pmatrix} \,\htmlId{4687}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4691}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4695}{\htmlClass{InductiveConstructor}{\text{deregdrep}}}\,  \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4706}{\htmlId{4706}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\htmlId{4714}{\htmlClass{InductiveConstructor}{\text{deregdrep}}}\, \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4724}{\htmlId{4724}{\htmlClass{Bound}{\text{v}}}}\, \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4726}{\htmlId{4726}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
pattern ccreghot*    ddeps gdeps = $\begin{pmatrix} \,\htmlId{4772}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4776}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4780}{\htmlClass{InductiveConstructor}{\text{ccreghot}}}\,   \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4791}{\htmlId{4791}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\htmlId{4799}{\htmlClass{InductiveConstructor}{\text{ccreghot}}}\,    \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4811}{\htmlId{4811}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
pattern reg*         ddeps gdeps = $\begin{pmatrix} \,\htmlId{4857}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4861}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{4865}{\htmlClass{InductiveConstructor}{\text{reg}}}\,        \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4876}{\htmlId{4876}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\htmlId{4884}{\htmlClass{InductiveConstructor}{\text{reg}}}\,         \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#4896}{\htmlId{4896}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$

open CertDeps*

getCertDeps* :  {pp dcert}  CertDeps* pp dcert  L.Deposits × L.Deposits
getCertDeps* deps = deps .depsᵈ , deps .depsᵍ

updateCertDeps :  {pp dcert dcerts}  CertDeps* pp (dcert  dcerts)  CertDeps* pp dcerts
updateCertDeps (delegate*    ddeps gdeps) = $\begin{pmatrix} \,\htmlId{5181}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{5185}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5164}{\htmlId{5189}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5170}{\htmlId{5197}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
updateCertDeps (dereg* _ _   ddeps gdeps) = $\begin{pmatrix} \,\htmlId{5252}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{5256}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5235}{\htmlId{5260}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5241}{\htmlId{5268}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
updateCertDeps (regpool*     ddeps gdeps) = $\begin{pmatrix} \,\htmlId{5323}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{5327}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5306}{\htmlId{5331}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5312}{\htmlId{5339}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
updateCertDeps (retirepool*  ddeps gdeps) = $\begin{pmatrix} \,\htmlId{5394}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{5398}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5377}{\htmlId{5402}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5383}{\htmlId{5410}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
updateCertDeps (regdrep*     ddeps gdeps) = $\begin{pmatrix} \,\htmlId{5465}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{5469}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5448}{\htmlId{5473}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5454}{\htmlId{5481}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
updateCertDeps (deregdrep* _ ddeps gdeps) = $\begin{pmatrix} \,\htmlId{5536}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{5540}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5519}{\htmlId{5544}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5525}{\htmlId{5552}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
updateCertDeps (ccreghot*    ddeps gdeps) = $\begin{pmatrix} \,\htmlId{5607}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{5611}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5590}{\htmlId{5615}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5596}{\htmlId{5623}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$
updateCertDeps (reg*         ddeps gdeps) = $\begin{pmatrix} \,\htmlId{5678}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\htmlId{5682}{\htmlClass{Symbol}{\text{\_}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5661}{\htmlId{5686}{\htmlClass{Bound}{\text{ddeps}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#5667}{\htmlId{5694}{\htmlClass{Bound}{\text{gdeps}}}}\, \end{pmatrix}$

updateCertDeps* :  {pp} dcerts  CertDeps* pp dcerts  CertDeps* pp []
updateCertDeps* []               deps = deps
updateCertDeps* (dcert  dcerts) deps = updateCertDeps* dcerts (updateCertDeps deps)

instance

  CertStToConf : L.Deposits × L.Deposits  L.CertState  C.CertState
  CertStToConf .convⁱ (ddeps , gdeps) certState =
    let open L.CertState certState in
    $\begin{pmatrix} \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#6009}{\htmlId{6080}{\htmlClass{Bound}{\text{ddeps}}}}\, \,\href{Ledger.Conway.Conformance.Equivalence.Convert.html#278}{\htmlId{6086}{\htmlClass{Function Operator}{\text{⊢conv}}}}\, \,\href{Ledger.Conway.Specification.Certs.html#5283}{\htmlId{6092}{\htmlClass{Field}{\text{dState}}}}\, \\ \,\href{Ledger.Conway.Specification.Certs.html#5303}{\htmlId{6101}{\htmlClass{Field}{\text{pState}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Certs.html#6017}{\htmlId{6110}{\htmlClass{Bound}{\text{gdeps}}}}\, \,\href{Ledger.Conway.Conformance.Equivalence.Convert.html#278}{\htmlId{6116}{\htmlClass{Function Operator}{\text{⊢conv}}}}\, \,\href{Ledger.Conway.Specification.Certs.html#5323}{\htmlId{6122}{\htmlClass{Field}{\text{gState}}}}\, \end{pmatrix}$

  CertStFromConf : C.CertState  L.CertState
  CertStFromConf .convⁱ _ certState =
    let open C.CertState certState in
    $\begin{pmatrix} \,\href{Ledger.Conway.Conformance.Equivalence.Convert.html#460}{\htmlId{6259}{\htmlClass{Function}{\text{conv}}}}\, \,\href{Ledger.Conway.Conformance.Certs.html#1037}{\htmlId{6264}{\htmlClass{Field}{\text{dState}}}}\, \\ \,\href{Ledger.Conway.Conformance.Certs.html#1057}{\htmlId{6273}{\htmlClass{Field}{\text{pState}}}}\, \\ \,\href{Ledger.Conway.Conformance.Equivalence.Convert.html#460}{\htmlId{6282}{\htmlClass{Function}{\text{conv}}}}\, \,\href{Ledger.Conway.Conformance.Certs.html#1077}{\htmlId{6287}{\htmlClass{Field}{\text{gState}}}}\, \end{pmatrix}$

  CERTBASEToConf :  {Γ s s'}
                  L.Deposits × L.Deposits
                    Γ L.⊢ s ⇀⦇ _ ,CERTBASE⦈ s' ⭆ⁱ λ deposits _ 
                     Γ C.⊢ (deposits ⊢conv s) ⇀⦇ _ ,CERTBASE⦈ (deposits ⊢conv s')
  CERTBASEToConf .convⁱ deposits (L.CERT-base h) = C.CERT-base h

  DELEGToConf :  {Γ s dcert dcerts s'}
                  (open L.DelegEnv Γ renaming (pparams to pp))
               CertDeps* pp (dcert  dcerts) 
                 Γ L.⊢ s ⇀⦇ dcert ,DELEG⦈ s' ⭆ⁱ λ deposits _ 
                 Γ C.⊢ (deposits .depsᵈ ⊢conv s) ⇀⦇ dcert ,DELEG⦈ (updateCertDeps deposits .depsᵈ ⊢conv s')
  DELEGToConf .convⁱ (delegate* _ _) (L.DELEG-delegate h) = C.DELEG-delegate h
  DELEGToConf .convⁱ (dereg* v w _ _)  (L.DELEG-dereg h)    = C.DELEG-dereg (h , v , w)
  DELEGToConf .convⁱ (reg* _ _) (L.DELEG-reg h) = C.DELEG-reg h

  POOLToConf :  {pp s dcert s'}  pp L.⊢ s ⇀⦇ dcert ,POOL⦈ s'  pp C.⊢ s ⇀⦇ dcert ,POOL⦈ s'
  POOLToConf .convⁱ _ (L.POOL-regpool h) = C.POOL-regpool h
  POOLToConf .convⁱ _ L.POOL-retirepool  = C.POOL-retirepool

  GOVCERTToConf :  {Γ s dcert dcerts s'}
                  (open L.CertEnv Γ using (pp))
                 CertDeps* pp (dcert  dcerts) 
                   Γ L.⊢ s ⇀⦇ dcert ,GOVCERT⦈ s' ⭆ⁱ λ deposits _ 
                   Γ C.⊢ (deposits .depsᵍ ⊢conv s) ⇀⦇ dcert ,GOVCERT⦈ (updateCertDeps deposits .depsᵍ ⊢conv s')
  GOVCERTToConf .convⁱ (regdrep* _ _)     (L.GOVCERT-regdrep h) = C.GOVCERT-regdrep h
  GOVCERTToConf .convⁱ (deregdrep* v _ _) (L.GOVCERT-deregdrep h) = C.GOVCERT-deregdrep (h , v)
  GOVCERTToConf .convⁱ (ccreghot* _ _)    (L.GOVCERT-ccreghot h)  = C.GOVCERT-ccreghot h

  CERTToConf :  {Γ s dcert dcerts s'} (open L.CertEnv Γ using (pp))
              CertDeps* pp (dcert  dcerts) 
                Γ L.⊢ s ⇀⦇ dcert ,CERT⦈ s' ⭆ⁱ λ deposits _ 
                Γ C.⊢ (getCertDeps* deposits ⊢conv s) ⇀⦇ dcert ,CERT⦈ (getCertDeps* (updateCertDeps deposits) ⊢conv s')
  CERTToConf .convⁱ deposits@(delegate* _ _)    (L.CERT-deleg deleg)  = C.CERT-deleg (deposits ⊢conv deleg)
  CERTToConf .convⁱ deposits@(dereg* _ _ _ _)   (L.CERT-deleg deleg)  = C.CERT-deleg (deposits ⊢conv deleg)
  CERTToConf .convⁱ deposits@(regpool* _ _)     (L.CERT-pool pool)    = C.CERT-pool (conv pool)
  CERTToConf .convⁱ deposits@(retirepool* _ _)  (L.CERT-pool pool)    = C.CERT-pool (conv pool)
  CERTToConf .convⁱ deposits@(regdrep* _ _)     (L.CERT-vdel govcert) = C.CERT-vdel (deposits ⊢conv govcert)
  CERTToConf .convⁱ deposits@(deregdrep* _ _ _) (L.CERT-vdel govcert) = C.CERT-vdel (deposits ⊢conv govcert)
  CERTToConf .convⁱ deposits@(ccreghot* _ _)    (L.CERT-vdel govcert) = C.CERT-vdel (deposits ⊢conv govcert)
  CERTToConf .convⁱ deposits@(reg* _ _)         (L.CERT-deleg deleg)  = C.CERT-deleg (deposits ⊢conv deleg)

  CERTS'ToConf :  {Γ s dcerts s'} (let open L.CertEnv Γ)
                CertDeps* pp dcerts
                  ReflexiveTransitiveClosure {sts = L._⊢_⇀⦇_,CERT⦈_} Γ s dcerts s' ⭆ⁱ λ deposits _ 
                   ReflexiveTransitiveClosure {sts = C._⊢_⇀⦇_,CERT⦈_}
                             Γ (getCertDeps* deposits ⊢conv s) dcerts
                               (getCertDeps* (updateCertDeps* dcerts deposits) ⊢conv s')
  CERTS'ToConf .convⁱ deposits (BS-base Id-nop) = BS-base Id-nop
  CERTS'ToConf .convⁱ deposits (BS-ind r rs)    = BS-ind (deposits ⊢conv r) (updateCertDeps deposits ⊢conv rs)

  CERTSToConf :  {Γ s dcerts s'} (let open L.CertEnv Γ)
               CertDeps* pp dcerts
                 Γ L.⊢ s ⇀⦇ dcerts ,CERTS⦈ s' ⭆ⁱ λ deposits _ 
                  Γ C.⊢ (getCertDeps* deposits ⊢conv s) ⇀⦇ dcerts ,CERTS⦈
                        (getCertDeps* (updateCertDeps* dcerts deposits) ⊢conv s')
  CERTSToConf .convⁱ deposits (RTC (base , step)) =
    RTC (getCertDeps* deposits ⊢conv base , deposits ⊢conv step)

-- Converting form Conformance is easier since the deposit tracking disappears.
instance
  DELEGFromConf :  {Γ s dcert s'}
                 Γ C.⊢ s ⇀⦇ dcert ,DELEG⦈ s' 
                  Γ L.⊢ conv s ⇀⦇ dcert ,DELEG⦈ conv s'
  DELEGFromConf .convⁱ _ (C.DELEG-delegate h)    = L.DELEG-delegate h
  DELEGFromConf .convⁱ _ (C.DELEG-dereg (h , _)) = L.DELEG-dereg h
  DELEGFromConf .convⁱ _ (C.DELEG-reg h)         = L.DELEG-reg h

  POOLFromConf :  {pp s dcert s'}  pp C.⊢ s ⇀⦇ dcert ,POOL⦈ s'  pp L.⊢ s ⇀⦇ dcert ,POOL⦈ s'
  POOLFromConf .convⁱ _ (C.POOL-regpool h) = L.POOL-regpool h
  POOLFromConf .convⁱ _ C.POOL-retirepool  = L.POOL-retirepool

  GOVCERTFromConf :  {Γ s dcert s'}
                   Γ C.⊢ s ⇀⦇ dcert ,GOVCERT⦈ s' 
                    Γ L.⊢ conv s ⇀⦇ dcert ,GOVCERT⦈ conv s'
  GOVCERTFromConf .convⁱ _ (C.GOVCERT-regdrep h)   = C.GOVCERT-regdrep h
  GOVCERTFromConf .convⁱ _ (C.GOVCERT-deregdrep (h , _)) = C.GOVCERT-deregdrep h
  GOVCERTFromConf .convⁱ _ (C.GOVCERT-ccreghot h)  = C.GOVCERT-ccreghot h

  CERTFromConf :  {Γ s dcert s'}  Γ C.⊢ s ⇀⦇ dcert ,CERT⦈ s'  Γ L.⊢ conv s ⇀⦇ dcert ,CERT⦈ conv s'
  CERTFromConf .convⁱ _ (C.CERT-deleg deleg)  = L.CERT-deleg (conv deleg)
  CERTFromConf .convⁱ _ (C.CERT-pool pool)    = L.CERT-pool (conv pool)
  CERTFromConf .convⁱ _ (C.CERT-vdel govcert) = L.CERT-vdel (conv govcert)

  CERTBASEFromConf :  {Γ s s'}
                    Γ C.⊢ s ⇀⦇ _ ,CERTBASE⦈ s' 
                     Γ L.⊢ (conv s) ⇀⦇ _ ,CERTBASE⦈ (conv s')
  CERTBASEFromConf .convⁱ _ (C.CERT-base h) = L.CERT-base h

  CERTS'FromConf :  {Γ s dcerts s'}
                  ReflexiveTransitiveClosure {sts = C._⊢_⇀⦇_,CERT⦈_} Γ s dcerts s' 
                   ReflexiveTransitiveClosure {sts = L._⊢_⇀⦇_,CERT⦈_} Γ (conv s) dcerts (conv s')
  CERTS'FromConf .convⁱ _ (BS-base Id-nop) = BS-base Id-nop
  CERTS'FromConf .convⁱ _ (BS-ind r rs) = BS-ind (conv r) (conv rs)

  CERTSFromConf :  {Γ s dcerts s'}
                 Γ C.⊢ s ⇀⦇ dcerts ,CERTS⦈ s' 
                  Γ L.⊢ conv s ⇀⦇ dcerts ,CERTS⦈ conv s'
  CERTSFromConf .convⁱ _ (RTC (base , step)) = RTC (conv base , conv step)