HEAD Deltas

Baseline 470f9b89 → HEAD 1e4896eb

commits
files changed
+
lines added
-
lines removed

Rule delta

→ rules (+0, append-only)

IDStatusClusterSummary

New modules

ModuleDetail
ade_codec::address::pointer

BLUE — Era-parameterized pointer decode (Ptr{slot,txIx,certIx}, PointerDecodeError). — EVIEW S3a (band 2)

ade_ledger::stake_ref

BLUE — Typed, era-gated stake-reference classification; no fixed byte offset is authoritative. — EVIEW S2 (band 2)

ade_ledger::pointer_resolve

BLUE — Pointer→credential resolution (pre-Conway only). — EVIEW S3a (band 2)

ade_ledger::reduced_utxo

BLUE — The EVIEW reduction pipeline: TxIn→(Coin,ReducedStakeRef) → per-block advance → per-pool StakeByPool → k-immutable snapshot → bound immutable EpochConsensusView. — EVIEW S3b–S3e (band 2)

ade_ledger::bootstrap_manifest

BLUE — Manifest-bound bootstrap cert-state import (BootstrapManifest/…Error). — EVIEW S3f (band 2)

ade_ledger::ledgerdb_state

BLUE — Native V2 LedgerDB decoders (state→CertState+pool distr+Praos nonces; tables MemPack TxOut→UTxO) + tables→UTxOState. Raw CBOR is RED input; the projection is authority. — Mithril decode (band 4)

ade_ledger::epoch_accumulator

BLUE — The non-UTxO EpochAccumulator + apply_selected_block — the self-sustaining ledger loop. — LIVE-LEDGER S1 (5d16eaef)

ade_ledger::frozen_leadership

BLUE — FrozenLeadershipPoolDistr — the self-contained leadership authority (SET stake + snapshot-frozen VRF) + seed identity. — S4-pre (501bf89a)

ade_ledger::reduced_boundary

BLUE — RVBP reduced-boundary projection types + FullBoundaryStateRequired (capability-typed non-authority). — RVBP P1 (c15be61e)

ade_ledger::bootstrap_reward_update

BLUE — Apply the bootstrap reward update at window-end — byte-exact seed+2 stake (DC-EPOCH-18). — B3c (c4e0413b)

ade_ledger::bootstrap_bridge

BLUE — Bootstrap bridge plumbing for the seed→seed+1 authority transition. — ECA/native-Mithril bridge

ade_ledger::cred

BLUE — Canonical credential type (surfaced by the flipped-Credential-tag decode fix, DC-LEDGER-10). — band 7 (84fec1b5)

ade_ledger::rollback::admission

BLUE — The k-bounded + lineage-checked rollback-admission guard + recovery-reconcile decision. — S5 (48fc423a)

Modified modules

ModuleChanges
ade_ledger

BLUE — The single largest surface. New EVIEW/accumulator/Mithril/governance/reduced-plane families (§2), plus modified rules.rs (EVIEW-gated mark path; per-credential boundary mark; POOLREAP), delegation.rs (cardano-faithful pool lifecycle), snapshot/{utxo_state,chain_dep}.rs (materialization; array(10) chain-dep codec), value.rs/mary.rs/pparams.rs (Word64 value domain + MinUtxoRule), seed_consensus_inputs.rs (v4→v6 sidecar: consensus-profile hashes then security_param/k), wal/event.rs (EpochConsensusViewActivated).

ade_node

RED — node_lifecycle.rs / node_sync.rs carry the relay-loop reduced-checkpoint advance, the automatic epoch-boundary activation, the accumulator co-advance, the per-boundary authority advance, the sealed-leadership promotion (S4), the rollback-follow forge path (LFH S1), and the sidecar_freeze_rsw shared freeze-window derivation (LFH S2). cli.rs gains ade node run / ade mithril snapshot fetch / --bootstrap-mithril.

ade_runtime

RED — The chaindb checkpoint/accumulator stores (§2), consensus_inputs::importer.rs (bootstrap import of fee pot / RUPD / gov proposals / Conway deposit params; the k-required + f≠0 ingress guards), mithril_bootstrap.rs/genesis_bootstrap.rs/seed_consensus_merge.rs (native bootstrap path), consensus/genesis_parser.rs (security_param).

ade_core

BLUE — consensus authority — The ECA-B1/B2 rolling Praos-nonce reshape. consensus/nonce.rs (reshaped NonceInput, one HeaderContribution, EpochBoundary combine+rotation+no-reset, CandidateFreeze removed, MissingLastEpochBlockNonce fail-closed), consensus/praos_state.rs (last_epoch_block_nonce: Option<Nonce>), consensus/header_validate.rs (Step-9 threading of prev_block_hash + freeze_boundary), consensus/era_schedule.rs (praos_rsw_slots). Versioned + backward-compatible; not byte-identical to baseline.

ade_testkit

test — The EVIEW/accumulator hermetic suites, the LedgerDB-decode corpus/oracle suites, the CPDE/CRE governance census suites, the CE-3d differential + B3c-localization suites, the ImmutableDB witness harness.

ade_codec

BLUE — The address::pointer module (§2) + the address module wiring.

ade_types

BLUE — Value/min-UTxO domain types (OutputAssetQuantity / MinUtxoRule surface).

ade_network

mixed (BLUE sub-paths unchanged) — Trivial; no BLUE sub-path type change.

CI checks

CheckStatusWhat it checks
ci_check_native_firstrun_reduced_checkpoint.shNew

DC-MITHRIL-08 (band 6)

ci_check_eview_forecast_crossing.shNew

DC-EPOCH-15 (ECA-5)

ci_check_praos_nonce_follow_evolution.shNew

DC-EPOCH-16 (ECA-B1/B2)

ci_check_epoch_accumulator_no_utxo.shNew

DC-EPOCH-19 (S1)

ci_check_epoch_accumulator_recovery.shNew

DC-EPOCH-20 (S2)

ci_check_poolreap_single_canonical.shNew

DC-EPOCH-21 (S3)

ci_check_boundary_aligned_mark_capture.shNew

DC-EPOCH-22 (S3)

ci_check_bootstrap_rupd_window_end.shNew

DC-EPOCH-18 (B3c)

ci_check_bootstrap_rupd_fee_reduction.shNew

DC-EPOCH-23 (CE-3d)

ci_check_snapshot_pool_set_inclusion.shNew

DC-EPOCH-24 (CE-3d)

ci_check_conway_deposit_params_bootstrap.shNew

DC-CINPUT-07 (band 9)

ci_check_gov_proposal_capture.shNew

DC-GOV-01 (band 9)

ci_check_reduced_boundary_plane.shNew

RVBP (band 10)

ci_check_trusted_replay_boundary.shNew

RVBP / recovery (band 10)

ci_check_frozen_leadership_authority.shNew

S4-pre

ci_check_frozen_recovery_no_seed_window.shNew

S4-L1

ci_check_frozen_promotion_no_seed_window.shNew

S4-L2

ci_check_credential_discriminant_closed.shModified

DC-LEDGER-10 (band 7)

ci_check_warmstart_eta0_overlay.shModified

ECA-B (band 7)

Commit log

HashTypeSummary
1e4896ebchorechore(node): LIVE-FORGE-HARDENING cluster-close review nits
dc14787afeatfeat(node): S2 the durable store is the sole candidate-freeze authority (DC-EPOCH-16)
240cfab3docsdocs(live-forge): S2 slice doc -- warm-start candidate-nonce identity (DC-EPOCH-16)
b52f2240featfeat(node): LIVE-FORGE-HARDENING S1 -- the forge path follows live rollbacks
2f12bb0bdocsdocs(live-forge): open LIVE-FORGE-HARDENING -- cluster + S1 (forge-path rollback-follow)
0ef65c6cdocsdocs(live): LIVE-2 -- record verified KES/opcert validity window
f08191a7docsdocs(live): LIVE-2 -- verify forge machinery on the current binary + live-forge procedure
fde0dd9efixfix(node): LIVE-1b -- bounded recovery-checkpoint retention (chain.db disk-fill)
5e83aaaafeatfeat(node): CE-4A.3-R4 -- warm-restart crash-window recovery after rollback (R4a+R4b+R4c, byte-identical)
bcbae327docsdocs(ledger): CE-4 milestone declaration + registry evidence (literal three-boundary continuous operation)
c5bdc064featfeat(ledger): CE-4B -- three-boundary continuous operation 1340->1343 self-sufficient (N->N+1->N+2->N+3)
8a085b10docsdocs(ledger): open CE-4B -- literal three-boundary continuous-operation proof (N->N+1->N+2->N+3)
4bc49fa6docsdocs(ledger): CE-4A.3-R4 findings -- R4a/R4b fixed+validated, R4c (VRF/nonce reconstruction) OPEN; impl parked
5858bf00docsdocs(ledger): file CE-4A.3-R4 -- warm-restart-after-rollback-before-refold hardening (not a #13 blocker)
fd3826fdfeatfeat(epoch): CE-4A.3-R3 rollback-aware eview resolution + #13 rollback/refold byte-identical
849bc9f0docsdocs(ledger): open CE-4A.3-R3 -- rollback-aware eview activation resolution (the #13 blocker)
58b87dbbdocsdocs(ledger): CE-4A.3-R2 (#13) ratified mechanism -- controlled durable rollback (option a)
ceb390e7docsdocs(ledger): open CE-4A.3-R2 (#13) -- rollback + refold replay-equivalence through the production loop (scoped)
7266f90cfeatfeat(epoch): CE-4A.3-R1 -- warm-start recovery reconstructs the frozen-promoted epoch authority
ca1ae06bdocsdocs(ledger): open CE-4A.3-R1 — warm-start recovery reconstructs the frozen-promoted epoch authority (scoped)
7f4aa463docsdocs(ledger): open CE-4A.3 — restart + rollback replay-equivalence through the production loop (scoped)
af3dc9c7testtest(node): CE-4A.2 — self-derived boundary outputs byte-match cardano at 1341 and 1342 (6 hard surfaces)
22903e8ddocsdocs(ledger): open CE-4A.2 — boundary outputs byte-match cardano at both self-derived boundaries (scoped)
9c6fc3c4testtest(node): CE-4A.1 — production-loop continuous self-sufficiency across two real boundaries
5c04eefbdocsdocs(ledger): CE-4A.1 fail-loud + machine-readable evidence bundle (spec refinement)
8b5d209edocsdocs(ledger): open CE-4A -- mechanical continuous self-sufficiency (two boundaries via the production run-loop)
db702a54featfeat(ledger): S4-L2 sealed authority flip -- promotion reads epoch-indexed frozen leadership only (LIVE-LEDGER-EPOCH-TRANSITION S4-L2)
e9de61e7featfeat(node): S4-L1 — retire seed-window authority from the initial/warm leadership view
7158ddc2docsdocs(ledger): open S4 — the sealed authority flip (epoch-indexed frozen leadership → sole production leader schedule)
c7e1c18ffeatfeat(ledger): epoch-index the frozen leadership authority behind a sole exact-epoch read (S4-0)
8cdd1471featfeat(ledger): native boundary leadership freeze proven vs reference nesPd (S4-pre-2)
3f93252dfeatfeat(node): certify the frozen leadership bootstrap lineage (S4-pre-1c)
13829660featfeat(ledger): persist the frozen leadership authority — canonical codec + durable store schema (S4-pre-1b)
501bf89afeatfeat(ledger): FrozenLeadershipPoolDistr — the self-contained leadership authority + seed identity (S4-pre-1a)
952a03b6docsdocs(ledger): open S4-pre — Frozen Leadership Distribution Authority (self-contained leadership PoolDistr)
67890681featfeat(ledger): Leadership Distribution Authority Trace — leadership = SET stake + snapshot-frozen params VRF (S4 discovered-proof-failure)
ae30fe18docsdocs(ledger): open the Leadership Distribution Authority Trace slice (S4 discovered-proof-failure follow-up)
d37af69afeatfeat(ledger): PoolDistrView::from_accumulator — the accumulator-derived leadership authority (S4 step 1, no behavior change)
1c45479bdocsdocs(ledger): open S4 — the sealed authority flip (accumulator-derived PoolDistrView replaces the seed-window read)
687fea98testtest(ledger): S5 2c — recovery replay-equivalence positive proof (byte-identical reset+refold vs uninterrupted)
8d6bf874featfeat(node): S5 2b part 2 — wire event-qualified recovery admission into the runtime (crash-safe live-rollback pre-clear)
aa2bba37featfeat(rollback): BLUE recovery-reconcile decision (S5 step 2b, part 1 — recovery authority)
3682068bfeatfeat(chaindb): persist the accumulator lineage anchor (LastAdvancedPoint) (S5 step 2a — store authority)
48fc423afeatfeat(rollback): BLUE k-bounded + lineage-checked rollback-admission guard (S5 step 1)
306ceb40docsdocs(ledger): revise S5 scope — the k-bounded rollback guard + lineage-checked reset land in S5, not S4
e096e014docsdocs(ledger): open S5 — restart/rollback replay-equivalence contract (the S4 recovery-promotion precondition)
e476415adocsdocs(ledger): CE-3d final green declaration — flip DC-EPOCH-23 (fee/pot) + DC-EPOCH-24 (snapshot pool-set) to enforced, byte-exact on the v5 schema-v4 seed
392433a1featfeat(epoch): reject a pre-C accumulator store (schema v3->v4) — one replay meaning for the persisted snapshot-inclusion semantics (DC-EPOCH-24)
e469f878featfeat(epoch): snapshot pool-set = cardano ssActiveStake NonZero membership — close the CE-3d go phantom-pool residual (DC-EPOCH-24)
fd8b07c8featfeat(epoch): reduce the bootstrap fee pot by the RUPD feeSS (deltaF) — close the CE-3d reward/pots residual (DC-EPOCH-23)
88128e72featfeat(bootstrap): import snapshot-bound Conway deposit params into native-Mithril bootstrap authority (DC-CINPUT-07)
1580b123testtest(ledger): reduced-plane recovery/fork-switch/boundary proof (RVBP P3)
dafe0faffeatfeat(ledger): build the epoch-boundary mark POST-RUPD from a point-bound base (CE3D-REWARD-ACCOUNT-EVOLUTION-CORRECTION S1)
aa9107a9featfeat(ledger): reduced-plane typed non-authority on the live path (RVBP P1/P2 + B1)
c15be61efeatfeat(ledger): reduced-boundary projection types + FullBoundaryStateRequired (RVBP P1 foundation)
5c5b8f7fdocsdocs(ledger): open REDUCED-VALIDATION-BOUNDARY-PLANE -- invariants + P1 slice (the reduced-plane typed non-authority)
3de15187docsdocs(ledger): S2 design -- the reduced-validation boundary plane (capability-typed split)
a3faf1e0docsdocs(ledger): CE3D-REWARD-ACCOUNT-EVOLUTION-CORRECTION S1 -- boundary reorder design (staged post-RUPD mark, both paths)
a52afd77testtest(ledger): CE3D-REWARD-ACCOUNT-EVOLUTION-CORRECTION S0 -- the go-stake residual root-caused to a pre-RUPD mark snapshot (GREEN diagnosis)
a882d304testtest(ledger): CE3D-GO-STAKE-DERIVATION-LOCALIZATION S1 -- the -343B go-stake residual localized to the reward-account contribution (GREEN evidence)
52a6e2c7testtest(ledger): B3c.0 -- base UTxO proven byte-exact; the -343B go-stake residual adjudicated REAL (GREEN evidence)
710f23dbtesttest(gov): bind S5 report provenance -- exact fixtures, decoder, code commits, canonical hash (reproducible)
dff581abtesttest(gov): the CRE S5 differential proof + residual report -- one artifact, three separated claims
d02cff14featfeat(gov): atomic exec-units parameter-change enactment -- the single-authority enact path (CRE S4.3c)
16a40260testtest(gov): V11 live-seed lineage evidence -- fresh re-bootstrap + warm-restart proven (CRE S4.3b-bootstrap obligation A)
163e1428testtest(gov): the real-witness manifest -- 69c948cd..#0 decodes via keys 20/21 from real bytes (CRE S4.3b-bootstrap obligation B)
0e13d139featfeat(gov): V11 executable execution-memory + previous-action state, inert (CRE S4.3b)
f4a1f748refactorrefactor(gov): one governance authority for the Conway epoch boundary + correct the replay expired-deposit drop (CRE S4.3a)
262415bdfeatfeat(gov): activate the DRep/committee ratification gate on the live boundary (CRE S4.2)
6d2948c7testtest(gov): S4.1b operational capstone — live V2 governance seed re-bootstrap + warm-restart proof
2bf3b41dtesttest(gov): S4.1b — V2 governance seed binding + restart proof (the sealed re-bootstrap boundary)
d6efe3e6featfeat(gov): version ConwayGovState with authoritative num_dormant — no fabricated default (CRE S4.1)
c2f5960etesttest(gov): the CRE S4 oracle anchor — the real ratify gate reproduces the census enactment
96793f46featfeat(ledger): extract the DRep voting-stake derivation as the CRE S3 distribution authority
bae70fe9testtest(ledger): repair the stale VState stub in the ledgerdb_state hermetic fixture
c0471d09featfeat(testkit): bind the CRE enactment census to selected-chain witnesses (ImmutableDB reader + permanent fixture)
b73701a7featfeat(ledger): decode prevPParams + the enacted-authority PParamUpdate root (CRE enactment census)
04f1c2b8testtest(governance): CRE enactment-census row-emission scaffold (canonical rows + the four evidence additions)
7b2f4755featfeat(ledger): decode maxBlockExUnits.mem + the deposit pot for the CRE enactment census
7a27c475fixfix(ledger): tolerate a retired block producer in the non-UTxO decode (surfaced by the CRE enactment census)
965b308atesttest(governance): CRE enactment-census probe -- validate the decoder at epoch 1088 (ratify/enact ground-truth fixture, WIP)
feb5cf10testtest(governance): lock S2 vote-capture replay determinism + reclassify as canonical vote-record authority (CONWAY-RATIFICATION-AND-ENACTMENT-AUTHORITY S2)
c497db9bfeatfeat(governance): capture live votes into the tracked proposals' vote maps, replacing the vote tripwire (CONWAY-RATIFICATION-AND-ENACTMENT-AUTHORITY S2)
9a2b4818featfeat(governance): import the DRep-expiry + committee-hot-key baseline from the VState (CONWAY-RATIFICATION-AND-ENACTMENT-AUTHORITY S1 part 2b)
e57433ccfeatfeat(governance): import the bootstrap DRep vote-delegation baseline from the DState UMap (CONWAY-RATIFICATION-AND-ENACTMENT-AUTHORITY S1 part 2a)
524829e5featfeat(governance): import + commitment-bind the per-action voting thresholds, without activating the gate (CONWAY-RATIFICATION-AND-ENACTMENT-AUTHORITY S1 part 1)
406888abdocsdocs(governance): open CONWAY-RATIFICATION-AND-ENACTMENT-AUTHORITY + the S0 oracle ground-truth harness
84286d95testtest(governance): S5 — prove the S4 refund closes the -500B CE-3d gap on the real proposals (CONWAY-PROPOSAL-DEPOSIT-EXPIRY)
6934afb4featfeat(epoch): the boundary deposit-expiry-refund evaluator — close the -500B CE-3d gap (CONWAY-PROPOSAL-DEPOSIT-EXPIRY S4)
0fbb85e2featfeat(governance): the S4.0 ratification census — prove the committee-only authority resolves the whole tracked set (CONWAY-PROPOSAL-DEPOSIT-EXPIRY)
27e23fd9featfeat(epoch): capture live gov proposals + a vote tripwire + the imported expiry-lifetime authority (CONWAY-PROPOSAL-DEPOSIT-EXPIRY S3)
665f72e4fixfix(test): repair the stale non-UTxO hermetic fixture for the gov-state decoder
9855ad56featfeat(bootstrap): reject a pre-import accumulator at warm-start — absent != empty (CONWAY-PROPOSAL-DEPOSIT-EXPIRY S2)
d2522faffeatfeat(bootstrap): import all post-seed boundary inputs — fee pot, RUPD, gov proposals (CONWAY-PROPOSAL-DEPOSIT-EXPIRY S1)
aeeaf89dfixfix(ledger): pay script-hash and pool-owner stakers their exact reward share
7e3c09effeatfeat(epoch): seed nesBcur and retire the redundant bootstrap-RUPD application
1702006efixfix(epoch): derive monetary-expansion eta from the network's real epoch length, not a mainnet constant (LIVE-LEDGER-EPOCH-TRANSITION, CE-3d)
e8127575fixfix(bootstrap): seed the EpochAccumulator's mark/set/go from the certified snapshot (LIVE-LEDGER-EPOCH-TRANSITION, CE-3d)
b8e33ff0docsdocs(epoch): CE-3c proven live -- the accumulator crosses two real preview boundaries (LIVE-LEDGER-EPOCH-TRANSITION S3, DC-EPOCH-22)
8232fe73featfeat(epoch): the BOUNDARY-ALIGNED co-advancer -- the accumulator crosses live (DC-EPOCH-22, LIVE-LEDGER-EPOCH-TRANSITION S3 #2b-iii)
ee33cc4cfeatfeat(epoch): the durable BoundaryMark witness -- point + lineage, bound before the cross (DC-EPOCH-22, LIVE-LEDGER-EPOCH-TRANSITION S3 #2b-ii)
8d047deefeatfeat(epoch): the accumulator boundary-cross entry point -- supply the mark, fire NEWEPOCH (DC-EPOCH-22, LIVE-LEDGER-EPOCH-TRANSITION S3 #2b-i)
c1a0ec85featfeat(epoch): per-credential boundary mark -- byte-exact member + leader rewards (DC-EPOCH-21, LIVE-LEDGER-EPOCH-TRANSITION S3)
ce22ca27docsdocs(epoch): S3 item #2 finding -- the boundary mark must be PER-CREDENTIAL, not per-pool (LIVE-LEDGER-EPOCH-TRANSITION)
f41456dafixfix(epoch): one canonical POOLREAP at the boundary -- fix the dead delegation-clear + the reward-account discriminant (DC-EPOCH-21, LIVE-LEDGER-EPOCH-TRANSITION S3)
e05a3ec1docsdocs(epoch): scope S3 -- the byte-exact boundary gate, two reconciliation items RESOLVED (LIVE-LEDGER-EPOCH-TRANSITION)
7c7b3a30testtest(epoch): close S2 CE-2b with an exactly-one-fee-scan-per-admit capstone (LIVE-LEDGER-EPOCH-TRANSITION)
d7653561fixfix(epoch): warm-start recovery dispatch -- recover the seed+1 bridge authority, not only seed+2 (EPOCH-CONSENSUS-VIEW)
f76d738bdocsdocs(epoch): record the S2 RECOVER warm-start survival proof + a separate EVIEW finding
89c1bc79docsdocs(epoch): record + mechanically guard S2 RECOVER (LIVE-LEDGER-EPOCH-TRANSITION DC-EPOCH-20)
59153f36featfeat(epoch): advance-to-tip accumulator reconciliation -- warm-start catch-up + reorg rematerialize (LIVE-LEDGER-EPOCH-TRANSITION S2)
6f18ee0edocsdocs(epoch): record the S2 within-epoch wiring live-proven on preview (LIVE-LEDGER-EPOCH-TRANSITION S2)
68846dccfeatfeat(epoch): advance the durable accumulator on the live follow -- observe-only after each durable admit (LIVE-LEDGER-EPOCH-TRANSITION S2, DC-EPOCH-20)
a842cfe1featfeat(epoch): seal the bootstrap SEED accumulator at native firstrun -- the durable within-epoch substrate (LIVE-LEDGER-EPOCH-TRANSITION S2, DC-EPOCH-20)
53e6829afeatfeat(epoch): the bootstrap SEED accumulator -- manifest-bound, two-buffer split (LIVE-LEDGER-EPOCH-TRANSITION S2, PO-3/CE-2f)
9fe01011featfeat(epoch): the within-epoch accumulator advancer -- observe-only stall on a boundary (LIVE-LEDGER-EPOCH-TRANSITION S2, DC-EPOCH-20)
b2185be6featfeat(epoch): durable EpochAccumulatorStore -- the accumulator's single-blob home (LIVE-LEDGER-EPOCH-TRANSITION S2, DC-EPOCH-20, PO-2)
cbf3e68afeatfeat(epoch): validity-aware within-epoch fees -- invalid-tx collateral, not declared fee (LIVE-LEDGER-EPOCH-TRANSITION S2, PO-1)
59f04758docsdocs(epoch): scope LIVE-LEDGER-EPOCH-TRANSITION S2 + declare DC-EPOCH-20 -- atomic-or-rematerialized selected-block admission
5d16eaeffeatfeat(epoch): the non-UTxO EpochAccumulator + apply_selected_block contract -- the self-sustaining ledger loop (DC-EPOCH-19, LIVE-LEDGER-EPOCH-TRANSITION S1)
2ba2bdb3docsdocs(epoch): scope LIVE-LEDGER-EPOCH-TRANSITION + declare DC-EPOCH-19 -- the continuous self-sustaining ledger loop
d6e52170fixfix(epoch): surface the specific bootstrap-RUPD-absent reason at the seed+2 activation seam (DC-EPOCH-18)
c4e0413bfeatfeat(epoch): apply the bootstrap reward update at the window-end -- byte-exact seed+2 stake (DC-EPOCH-18, EPOCH-CONSENSUS-VIEW B3c)
dabb4210featfeat(consensus): warm-start recovery across a crossed epoch boundary
bbae56befeatfeat(node): observable follow progress + a known log destination (node.log)
84fec1b5fixfix(ledger): correct flipped Credential tag in native-bootstrap decode (DC-LEDGER-10)
c13d4414fixfix(epoch): lag-aware activation predicate + did-advance seam -- cross boundary 2 (DC-EPOCH-17, ECA-B3)
b1d0fc7bfeatfeat(epoch): yield-at-boundary -- run_node_sync returns SyncOutcome so the checkpoint advances per-boundary (DC-EPOCH-17, ECA-B3b)
23829091featfeat(epoch): generalize the activation seam to advance per boundary -- replay-derived seed+2 (DC-EPOCH-17, ECA-B3)
b058ff1cfeatfeat(epoch): ActiveEpochAuthority.advance -- per-boundary authority advance (DC-EPOCH-17, ECA-B3)
fc68a295docsdocs(epoch): scope ECA-B3 + declare DC-EPOCH-17 -- replay-derived seed+2 authority
44e07782docsdocs(epoch): flip DC-EPOCH-16 declared -> enforced -- eta0(seed+2) proven live (ECA-B2c)
e8589e1efixfix(epoch): seed the evolving nonce from the full 6-nonce PraosState (DC-EPOCH-16, ECA-B2c)
14880463featfeat(epoch): B2 part 2 -- live RSW freeze + boundary tick on the follow path (DC-EPOCH-16)
9040615bfeatfeat(epoch): B2 part 1 -- RSW era-geometry field + the verified venue k source (DC-EPOCH-16)
7356679adocsdocs(epoch): scope ECA-B2 -- live candidate-freeze (RSW) + boundary tick + the eta0(seed+2) gate
79467c84featfeat(epoch): rolling Praos nonce on the follow path -- chain-dep combine + back-compat snapshot (DC-EPOCH-16, ECA-B1)
c0bc425bdocsdocs(epoch): declare DC-EPOCH-16 + scope ECA-B1 (rolling Praos nonce on the follow path)
4657cee5chorechore(epoch): reconcile EVIEW gates + registry to the post-activation reality (ECA Tier A)
26565becfeatfeat(epoch): native Mithril first-boundary bridge -- survive seed->seed+1 (ECA-5, DC-EPOCH-15)
08fa37f6featfeat(epoch): cross the epoch boundary -- forecast horizon extends with N+1 authority promotion (DC-EPOCH-15, ECA-5)
5599f297docsdocs(epoch): declare DC-EPOCH-15 (forecast horizon <=> N+1 authority promotion) + ECA-5 slice summary
25a6bde3docsdocs: getting-started guide for running Ade on Cardano preview
87e74843fixfix(mithril): snapshot fetch layout symlinks must be absolute (relative --output-dir dangled) (S8)
886ca138fixfix(epoch): native Mithril decode read the leader-VRF eta0 from the wrong PraosState nonce slot (S7)
b0bbaaf5featfeat(epoch): relay-only live follow -- port the forge-ON follow setup into forge-OFF (S6)
54833173featfeat(epoch): native operational continuity -- warm-start snapshot + in-memory seed inputs (S5)
6d223a36featfeat(mithril): `ade mithril snapshot fetch` -- native acquisition + manifest (S4)
3af74b8afeatfeat(cli): `ade node run` native entrypoint -- bootstrap + warm-start, closed to legacy inputs (S3)
769196affeatfeat(epoch): the judge-facing --bootstrap-mithril native startup command (S2 Gap 1b)
59cfa802featfeat(epoch): native FirstRun resolves genesis from the committed --network profile, manifest-bound (S2 Gap 1a)
aa7503bcfeatfeat(epoch): native Mithril FirstRun builds the EVIEW reduced checkpoint inline (DC-MITHRIL-08, S2 Gap 2)
6e04f1fctesttest(epoch): hermetic ADE1 shadow-derive regression + shadow stake-agreement evidence
25d11636docsdocs(invariant-registry): re-scope DC-EVIEW-08 to the ECA window-replay architecture
7964d4dfchorechore(registry): drop a deleted test ref + bind a self-declaring CI gate
a24d0c39docsdocs(grounding): regenerate the four grounding docs at cdcd9397
5333d0b6chorechore(registry): backfill omitted status on DC-EPOCH-14 + DC-MITHRIL-04
cdcd9397featfeat(epoch): live FirstRun -> native Mithril bootstrap invocation (DC-MITHRIL-07, S1d)
942cd97cfeatfeat(epoch): tables -> authoritative UTxOState materialization (DC-MITHRIL-06, S1c)
c952c767featfeat(epoch): native Mithril authority transition -- assemble + atomic persist (DC-MITHRIL-03, S1b)
e84ebb0cchorechore(registry): repair DC-MITHRIL-01/02 ID collision + add a uniqueness guard
53c27bc4featfeat(epoch): native non-UTxO snapshot decoder + manifest-bound network identity (S1a-1)
cb20ab02featfeat(ledger): era-aware protocol-parameter min-UTxO representation (DC-LEDGER-PARAMS-01, S1a-2)
7c769801docsdocs(testkit): track pre-existing epoch_boundary_logic hang as a CI hygiene blocker
5426dcebfeatfeat(ledger): output asset quantity is the Word64 domain (OutputAssetQuantity, DC-LEDGER-VALUE-01)
6cab0d6cfeatfeat(epoch): native V2 LedgerDB tables MemPack TxOut decoder -> faithful UTxO (DC-MITHRIL-02, Stage 2)
3bbba530featfeat(epoch): native V2 LedgerDB state decoder -> canonical CertState (DC-MITHRIL-01, Stage 1)
7386bf82featfeat(epoch): reclassify cli exporter as auxiliary; V2 LedgerDB native-decode probe + manifest v2
f09cc0ecfeatfeat(epoch): bootstrap-cert-state producer, live-verified on Preview
0a500e59testtest(epoch): prove warm-start fail-closes on a wrong CLI network magic (DC-EPOCH-14)
ad41b274featfeat(epoch): atomic epoch-authority transition + crash recovery (ECA-2/3/4)
124c87dafeatfeat(epoch): persist the consensus-profile hashes in the v4 seed sidecar (ECA-2-pre)
a17c7aabfeatfeat(epoch): remove the EVIEW_ACTIVATION_ARMED semantic gate (ECA-1)
4614e977featfeat(epoch): leadership-complete EpochConsensusView + exclusive projection (ECA-0b)
ad704f86featfeat(epoch): cardano-faithful pool lifecycle in the reduced window (ECA-0a)
a50a3ee8featfeat(epoch): wire the gated epoch-view activation into the relay loop (S3f-4d-wire-3b-2)
4c63c03dfeatfeat(epoch): the gated boundary orchestration (S3f-4d-wire-3b-1)
e6e07ae0featfeat(epoch): the boundary-activation orchestration (S3f-4d-wire-3a)
bcef6404featfeat(epoch): the readiness witness + the sole authoritative derive (S3f-4d-wire-2b)
39b2c314featfeat(epoch): runtime readiness witness + replay seed-state checkpoint (S3f-4d-wire-2a)
e14a0e15featfeat(epoch): live source-window extraction for dual-path activation (S3f-4d-wire-1)
bfa0b54afeatfeat(epoch): live stake-by-pool derive for the shadow proof (DC-EPOCH-11, S3f-4d-mat-shadow mechanism)
3c7d9cc2featfeat(epoch): fail-closed readiness gate for the live reduced checkpoint (DC-EPOCH-11, S3f-4d-mat-4)
b151f399featfeat(epoch): reorg re-materialize for the live reduced checkpoint (DC-EPOCH-11, S3f-4d-mat-3)
a916eecefeatfeat(epoch): wire the live reduced checkpoint into the relay loop (DC-EPOCH-11, S3f-4d-mat-2c)
3d597fcbfeatfeat(epoch): live ChainDB-replay checkpoint advancer (DC-EPOCH-11, S3f-4d-mat-2b)
fdc3d062featfeat(epoch): reduced-checkpoint per-block advance primitive (DC-EPOCH-11, S3f-4d-mat-2a)
0ac92cbafeatfeat(epoch): live reduced-checkpoint build at bootstrap (DC-EPOCH-11, S3f-4d-mat-1)
38aa5518featfeat(epoch): boundary activation orchestration -- the sequenced flip (DC-EPOCH-10)
28c05bfffeatfeat(epoch): activation candidate derivation from a validated window (DC-EPOCH-09)
235e3183featfeat(epoch): activation source window + named-role source->target mapping (DC-EPOCH-08)
49a4d8cefeatfeat(epoch): activation durable-before-visible + crash recovery (DC-EPOCH-06)
91293215featfeat(epoch): activation predicate + atomically-published active view (DC-EPOCH-05/07)
29253e4cfeatfeat(epoch): WAL activation record -- the durable activation substrate (DC-EPOCH-04)
86353625featfeat(epoch): deterministic fail-closed epoch-rebind seam (DC-EVIEW-11, strengthens DC-EPOCH-03)
7f7d266afeatfeat(epoch): the window driver -- advance + aggregate over a block window (DC-EVIEW-10)
bd8b0deffeatfeat(epoch): manifest-bound bootstrap cert-state import (DC-EVIEW-09)
3c2db639featfeat(epoch): activation consumption point -- the boundary consumes the aggregate (DC-EVIEW-08 S3f-1)
62eb6738docsdocs(epoch): record the S3c live differential-oracle result (DC-EVIEW-05)
a9d1f148fixfix(ci): S3b-1 checkpoint gate no longer false-positives on the S3c reader
ce778913featfeat(epoch): the bound, immutable EpochConsensusView (DC-EVIEW-07)
88fdfadffeatfeat(epoch): snapshot formation + the k-immutability stability gate (DC-EVIEW-06)
77a7e3f3featfeat(epoch): per-pool stake aggregation -- the linchpin (DC-EVIEW-05)
8c0ff66ffeatfeat(epoch): windowed advance of the reduced-UTxO checkpoint (DC-EVIEW-04b)
83ead7befeatfeat(epoch): durable reduced-UTxO checkpoint -- the minimal native state (DC-EVIEW-04)
388a3b61docsdocs(epoch): scope EPOCH-CONSENSUS-VIEW S3b-1 -- durable reduced-UTxO checkpoint (pre-code)
d6d015ebdocsdocs(epoch): scope EPOCH-CONSENSUS-VIEW S3b (umbrella) -- replay-window materialization
c71a308ffeatfeat(epoch): era-parameterized pointer decode + resolution (DC-EVIEW-03)
7a2462b1docsdocs(epoch): scope EPOCH-CONSENSUS-VIEW S3a -- pointer decode/resolution (pre-code)
a8b5d1c6docsdocs(epoch): scope EPOCH-CONSENSUS-VIEW slice 3 -- native next-epoch view (pre-code)
8f74cceffeatfeat(epoch): typed era-gated stake-reference classification (DC-EVIEW-02)
502b23b5docsdocs(epoch): scope EPOCH-CONSENSUS-VIEW slice 2 -- typed stake-reference classification
85fbc04ffeatfeat(epoch): prove the bounded crash-safe transient-materialization gate (DC-EVIEW-01)
28be6635docsdocs(epoch): slice 1 resolved entry obligations + tightenings + GREEN classification
39a6b5afdocsdocs(epoch): EPOCH-CONSENSUS-VIEW slice 1 scope -- redb temporary-materialization gate
84e1019cdocsdocs(epoch): EPOCH-CONSENSUS-VIEW design-analysis record (architecture selected, mechanism unapproved)
cf508424docsdocs(node): adoption channel is the localRoot dial, not a duplex responder
300959c6fixfix(node): participant forge derives base from the live AO-selected durable tip, not a self-forge latch (DC-FOLLOW-FORGE-01)
5e3c0855featfeat(node): participant venue forges on the AO-selected durable head (CN-FOLLOW-01)
0c2dae4dfixfix(forge): KES-period gate returns the opcert-anchored relative evolution, not the absolute period (DC-CRYPTO-10)
5b99333c(harden)harden(node): forward-sync cache hit-path test + structural rollback invalidation (DC-MEM-11)
88e64df2perfperf(node): forward-sync admit reuses cached UTxO fingerprint, not O(n) per-block recompute (DC-MEM-11)
c51d7d81fixfix(forge): KES shell-init anchors evolution-0 at opcert_start, evolves to current (OP-OPS-04)
1be6e855fixfix(node): warm-start era-schedule uses durable venue geometry (DC-CINPUT-05)
3c6c30eafixfix(admission): persist admitted block bytes before WAL (DC-WAL-05)
13d506cc(registry)registry: enforce RO-MITHRIL-IMPORT-01 with documented evidence gate
31ae1f63(evidence)evidence: add Mithril documented-interface preprod bundle
f268d3d9fixfix(evidence): capture runs end-to-end on the live venue + out-of-tree seed handling
176c7059fixfix(evidence): harden mithril capture for non-destructive scratch venue (no tautology)
93dc99bbfeatfeat(evidence): mithril documented-interface capture + validation tooling (prep, no flip)
88c862ccdocsdocs(invariant-registry): bind T-CONS-01 to CN-CONS-01 enforcement (declared -> enforced)
1b79add0chorechore(idd): bump head_deltas_baseline 862cd2cb -> 470f9b89 (MEM-OPT-UTXO-DISK close)