Invariant Explorer
All 467 registry rules. Search by ID or statement, filter by family / tier / status, isolate drift or enforcement gaps, and export the filtered set. Each row links to its full source → code → tests → CI trace.
Families T True — constitution-level always-true properties DC Derived — invariants derived from the true set CN Classification / constraint — classification-table & attack-surface rules RO Release obligation — release-time discipline OP Operational — deployment / operational practice
Family is the rule's origin/kind — distinct from its tier
(true / derived / release / operational). Most align, but CN rules span all tiers.
family
tier
status
467 of 467 rules
| ID | Tier | Status | Statement | Tests | CI | Flags |
|---|---|---|---|---|---|---|
| CN-ADMIT-01 | release | enforced | Single admission-mode entry authority: exactly one pub fn in ade_node::admission::runner::run_admission enters the admission tokio runner. No second entry point… | 3 | 1 | |
| CN-ADMIT-02 | release | enforced | Single seed-to-snapshot bridge authority: exactly one pub fn in ade_node::admission::seed_to_snapshot converts the imported (UTxOState, ledger_fingerprint, seed… | 4 | 1 | |
| CN-ANCHOR-01 | release | enforced | Single BootstrapAnchor mint authority: exactly one pub fn in ade_runtime::bootstrap_anchor::mint produces a BootstrapAnchor with all 6 fields populated (network… | 5 | 1 | |
| CN-BUILD-01 | true | declared | No build profile, feature flag, cfg, or optimization mode may alter authoritative semantics or persisted bytes | 0 | 0 | |
| CN-BUILD-02 | true | declared | All semantic variability must be explicit runtime protocol data, not hidden compile-time choice | 0 | 0 | |
| CN-BUILD-03 | true | declared | Exactly one semantic interpretation may exist for a given protocol version and bootstrap anchor | 0 | 0 | |
| CN-BUILD-04 | derived | declared | Operator configuration may tune transport, logging, and telemetry, but may not silently weaken ledger, consensus, or persistence semantics | 0 | 0 | |
| CN-CINPUT-01 | constraint | enforced | The seed-epoch consensus inputs (epoch, active-slots coefficient, total active stake, and the per-pool active-stake + registered VRF keyhash distribution) persi… | 3 | 0 | |
| CN-CINPUT-02 | constraint | enforced | The SeedEpochConsensusInputs sidecar MUST be populated ONLY through the single shared ade_runtime::seed_epoch_lineage::persist_seed_epoch_consensus_inputs autho… | 4 | 1 | |
| CN-CINPUT-03 | constraint | enforced | Consume-side anti-laundering fence: on the node-lifecycle forge path the leadership view MUST be projected from the recovered SeedEpochConsensusInputs surface (… | 2 | 1 | |
| CN-CONS-01 | true | enforced | Chain selection must be deterministic for the same candidate chains and protocol observables | 6 | 2 | |
| CN-CONS-02 | derived | declared | Supported rollout skew must not allow a single adversarial input to induce persistent honest-node consensus divergence | 2 | 2 | |
| CN-CONS-03 | derived | enforced | After temporary partition, honest nodes must converge using only protocol-defined observables and declared emergency procedures | 3 | 1 | |
| CN-CONS-04 | derived | enforced | Header validation must bind exactly to the accepted body and consensus context | 13 | 1 | |
| CN-CONS-05 | true | declared | Authoritative consensus decisions must not depend on wall-clock time, arrival-order races, scheduler interleavings, or OS behavior | 5 | 2 | |
| CN-CONS-06 | release | enforced | Cross-impl acceptance: blocks forged by Ade are accepted by cardano-node when delivered via N2N block-fetch / chain-sync. Evidence is operator-action: a sustain… | 3 | 1 | |
| CN-CONS-07 | release | enforced | Self-acceptance bridge + serve provenance. A forged block is NOT eligible for RED broadcast unless Ade's own header validator (PHASE4-N-B path) and body validat… | 15 | 4 | |
| CN-CONS-08 | release | enforced | Receive-side single admission authority: every block that lands in ChainDb via the receive path passed block_validity with BlockValidityVerdict::Valid. No bypas… | 6 | 2 | |
| CN-CONS-IN-01 | release | enforced | Single LiveConsensusInputs importer authority: exactly one pub fn ade_runtime::consensus_inputs::importer::import_live_consensus_inputs converts a cardano-cli J… | 5 | 2 | |
| CN-CRYPTO-01 | true | declared | Verification belongs to the authoritative core; signing belongs outside it | 0 | 0 | |
| CN-CRYPTO-02 | true | partial | All consensus-relevant hashes must be domain-separated and unambiguous | 3 | 0 | |
| CN-CRYPTO-03 | true | declared | All collections with consensus meaning must be ordered deterministically before hashing or comparison | 0 | 0 | |
| CN-CRYPTO-04 | true | declared | Verification failure must fail once and deterministically; no implicit parser or serialization fallback is allowed | 0 | 0 | |
| CN-EPOCH-01 | derived | partial | Stake, rewards, parameter changes, and governance effects may activate only at protocol-defined epoch boundaries | 7 | 0 | |
| CN-EPOCH-02 | true | declared | At each slot or epoch point there is exactly one authoritative committee and governance interpretation | 0 | 0 | |
| CN-EPOCH-03 | derived | declared | Stake snapshots and reward computations must be derivable solely from canonical chain state | 0 | 0 | |
| CN-EPOCH-04 | true | declared | Future decisions may not leak into present validation, and later states may not retroactively reinterpret prior checkpoints | 0 | 0 | |
| CN-FOLLOW-01 | true | enforced | Producer / follow authority separation. (a) DETERMINISTIC SELECTION: the same candidate set yields the same selected canonical durable tip (the AO / select_best… | 8 | 1 | |
| CN-FORGE-01 | derived | enforced | The producer-mode forge handler is a closed transition from CoordinatorEvent::RequestForge { slot, kes_period, ledger_snapshot_ref, chain_tip } to exactly one o… | 8 | 2 | |
| CN-FORGE-02 | derived | enforced | Leader-check splits across the RED/BLUE color boundary: RED produces a VRF proof/output for the slot using the operator's VRF signing key; BLUE verifies the pro… | 10 | 1 | |
| CN-FORGE-03 | derived | enforced | Producer/validator codec symmetry: forge_block emits the era-tagged [era, block] envelope (era = Conway discriminant 7) via the single canonical ade_codec::enco… | 4 | 1 | |
| CN-FORGE-04 | derived | enforced | Producer-side Praos VRF construction must match the Conway/Praos validator authority: the leader VRF proof alpha, the leader-schedule evidence, the LeaderSchedu… | 5 | 1 | |
| CN-GENESIS-01 | derived | enforced | The Shelley genesis closed-contract parser accepts a real cardano-cli `shelley-genesis.json` and produces a canonical `GenesisAnchor`. Required fields (networkM… | 6 | 2 | |
| CN-KES-HEADER-01 | derived | enforced | The KES signature in a forged block's header is over the canonical unsigned-header CBOR pre-image — the CBOR encoding of ShelleyHeaderBody (the first element of… | 3 | 1 | |
| CN-LEDGER-01 | true | declared | apply_block must be a pure deterministic function of prior state and canonical block input | 0 | 0 | |
| CN-LEDGER-02 | true | declared | Same genesis/bootstrap + same block sequence must yield byte-identical authoritative state | 0 | 0 | |
| CN-LEDGER-03 | derived | declared | Validity decisions for transactions and blocks must match the Cardano reference oracle for the same era/protocol version | 0 | 0 | |
| CN-LEDGER-04 | derived | declared | Any two supported production versions that may coexist must return the same validity verdict for every consensus-relevant input | 0 | 0 | |
| CN-LEDGER-05 | true | declared | Each feature must have one semantic processing result; no alternate path may disagree on whether work was already applied, failed, or remains valid | 0 | 0 | |
| CN-LEDGER-06 | true | declared | Failure-state residue must be deterministic and consensus-neutral | 0 | 0 | |
| CN-LEDGER-07 | true | declared | UTxO and asset conservation must hold for every accepted transition, except where protocol rules explicitly authorize mint, burn, rewards, or treasury effects | 1 | 0 | |
| CN-LEDGER-08 | true | declared | No input or equivalent spend authority may be consumed more than once in an accepted canonical chain | 0 | 0 | |
| CN-LEDGER-09 | derived | partial | Witnesses must bind exactly to the intended body, certificates, withdrawals, governance actions, and scripts for the era | 6 | 1 | |
| CN-LEDGER-10 | derived | declared | Conway governance and certificate transitions must occur only through explicit legal state transitions | 0 | 0 | |
| CN-MEM-01 | derived | partial | Untrusted inbound work must be admitted through deterministic bounded policies before consuming scarce authoritative resources | 8 | 1 | |
| CN-MEM-02 | operational | declared | Mempool pressure and peer churn must not starve block validation, chain selection, or persistence | 0 | 0 | |
| CN-MEM-03 | derived | declared | Under overload, work shedding must follow deterministic policy, not timing-dependent collapse | 0 | 0 | |
| CN-MEM-04 | derived | declared | Mempool acceptance rules must never contradict block and ledger acceptance rules for the same authoritative semantics | 0 | 0 | |
| CN-META-01 | true | declared | Every claimed invariant must have at least one mechanical enforcement point | 0 | 0 | |
| CN-META-02 | true | declared | Every consensus-relevant failure mode must have a deterministic structured error shape | 0 | 0 | |
| CN-META-03 | true | declared | Every equivalence claim must be reproducible from named fixtures, oracle versions, and replay inputs | 0 | 0 | |
| CN-MITHRIL-01 | constraint | enforced | A Mithril-sourced seed may bootstrap only after a verified binding: the Mithril manifest's attested {network_magic, genesis_hash, certified_point, certificate_h… | 5 | 2 | |
| CN-NET-01 | operational | declared | A block producer must not accept arbitrary public peer connectivity; it may connect only through trusted relay topology | 0 | 0 | |
| CN-NET-02 | operational | declared | Relay paths must be geographically and topologically diverse enough that isolating one path does not prevent timely propagation | 0 | 0 | |
| CN-NET-03 | operational | declared | No single peer, ASN, region, or operator cluster may dominate the node's authoritative view | 0 | 0 | |
| CN-NET-04 | derived | declared | Peer selection and promotion policies must not allow one adversary-controlled set to deterministically starve honest views | 0 | 0 | |
| CN-NODE-01 | release | enforced | Single bootstrap authority: exactly one pub fn in ade_runtime::bootstrap returns the initial (LedgerState, PraosChainDepState, ChainDb tip) at node startup. Col… | 5 | 3 | |
| CN-NODE-02 | constraint_network | enforced | `--mode node` is the single live-run lifecycle owner. The relay run loop may advance authoritative state ONLY by invoking existing closed seams (bootstrap_initi… | 5 | 2 | |
| CN-NODE-03 | constraint_network | enforced | Operator-key ingress + forge-on flip for --mode node. Ingress constructs an operator-material-backed ForgeActivation STRICTLY through RED-parse -> BLUE-structur… | 11 | 3 | |
| CN-NODE-04 | operational | enforced | --mode node emits a CLOSED, allow-listed diagnostic event vocabulary for feed/forge scheduling: feed_unavailable{reason} with a closed reason enum, forge_tick_c… | 2 | 1 | |
| CN-OPCERT-01 | derived | enforced | The opcert envelope parser accepts a real cardano-cli `node.opcert` text envelope (closed type check `NodeOperationalCertificate` + CBOR array(2) shape locked b… | 5 | 1 | |
| CN-OPERATOR-EVIDENCE-01 | release | enforced | Every PHASE4-N-S-C operator-pass evidence manifest (docs/clusters/PHASE4-N-S-C/CE-N-S-LIVE_YYYYMMDD-<short_commit>.toml) carries the closed schema: schema_versi… | 0 | 2 | |
| CN-OPS-01 | operational | declared | After any partition, authoritative post-incident reconciliation must be derived solely from the recovered canonical chain | 0 | 0 | |
| CN-OPS-02 | operational | declared | Emergency recovery procedures must have explicit admissibility criteria, deterministic inputs and outputs, and defined authority thresholds | 0 | 0 | |
| CN-OPS-03 | operational | declared | Incident evidence must be sufficient to reconstruct the canonical decision path without relying on nondeterministic logs or local operator memory | 0 | 0 | |
| CN-OUTBOUND-RELAY-01 | derived | enforced | OutboundCommand is the sole channel between produce_mode and MuxPump's outbound encoder. The closed enum carries typed ChainSyncServerMsg / BlockFetchServerMsg … | 2 | 1 | |
| CN-PEER-OUTBOUND-MAP-01 | derived | enforced | Per-peer outbound senders are owned by an Arc<RwLock<BTreeMap<PeerId, mpsc::Sender<OutboundCommand>>>>. Listener (run_per_peer_session) inserts on PeerConnected… | 1 | 0 | |
| CN-PLUTUS-01 | derived | enforced | Same script + same redeemers/datum/context + same cost model must produce identical result and budget accounting | 2 | 2 | |
| CN-PLUTUS-02 | derived | declared | Budget exhaustion and script failure must have a single deterministic failure shape | 7 | 1 | |
| CN-PLUTUS-03 | derived | declared | Script context must be canonically and completely derived from transaction plus ledger state | 0 | 0 | |
| CN-PLUTUS-04 | true | enforced | No host-environment property may influence script results | 1 | 1 | |
| CN-PREIMAGE-FIXTURE-01 | derived | enforced | For every block in ade_testkit::validity::corpus::ConwayValidityCorpus, Ade's unsigned_header_pre_image(...) (with inputs derived from decode_block(block_bytes)… | 1 | 0 | |
| CN-PROD-01 | derived | enforced | Producer-mode listener completes the N2N handshake (CN-SESS-02) on every accepted inbound connection before any mini-protocol traffic is exchanged. Pre-handshak… | 1 | 1 | |
| CN-PROD-02 | derived | enforced | Producer slot loop never signs a block whose KES period has rotated past current_period. Slot → KES period is a pure function of (slot, genesis_kes_anchor, slot… | 16 | 2 | |
| CN-PROD-03 | derived | enforced | produce_mode's forge base state is derived from bootstrap_initial_state (cold-start, fed the operator-seeded ledger from --json-seed + --consensus-inputs) plus … | 2 | 1 | |
| CN-PROD-04 | derived | enforced | Every CoordinatorEffect::BroadcastBlock reconstructs the AcceptedBlock from artifact.bytes through the BLUE self_accept authority against the pre-forge base, th… | 3 | 0 | |
| CN-PROTO-01 | derived | declared | Each miniprotocol must be an explicit deterministic state machine with legal typed transitions only | 0 | 0 | |
| CN-PROTO-02 | derived | declared | For the same peer transcript, authoritative state and outbound transcript must be identical | 0 | 0 | |
| CN-PROTO-03 | derived | declared | Agency must be enforced strictly; impossible messages must fail deterministically | 0 | 0 | |
| CN-PROTO-04 | true | declared | Socket fragmentation, multiplexing, arrival order, and timeout behavior must not leak nondeterminism into authoritative logic | 0 | 0 | |
| CN-PROTO-05 | true | declared | Untrusted network inputs must not allocate unbounded authoritative resources before deterministic validation | 0 | 0 | |
| CN-PROTO-06 | derived | enforced | The producer-side session orchestrator can only construct outgoing mini-protocol messages tagged with Server agency. Client-originated messages from the server-… | 7 | 1 | |
| CN-PROTO-07 | derived | enforced | Receive-side agency closure: the receive bridge consumes only peer-originated ForkChoiceSignal and BatchDeliveryEvent values valid for the client-role N2N recei… | 3 | 1 | |
| CN-PUMP-01 | release | enforced | Single admission wire-pump entry per peer: exactly one pub async fn ade_runtime::admission::wire_pump::run_admission_wire_pump drives the per-peer pump that pro… | 5 | 1 | |
| CN-REHEARSAL-FIDELITY-01 | release | enforced | Private-testnet accepted-block bounty dry-run fidelity (two coupled clauses; if either fails the rehearsal becomes misleading). (1) PATH FIDELITY: the C1 privat… | 10 | 3 | |
| CN-REL-01 | release | declared | A release is not mainnet-eligible unless mixed-version topologies against supported predecessors show consensus equivalence on malformed and boundary-case input… | 0 | 0 | |
| CN-REL-02 | release | declared | No single implementation bug should exceed the protocol's intended safety or liveness fault threshold at ecosystem level | 0 | 0 | |
| CN-REL-03 | release | declared | Cross-implementation accept/reject agreement on authoritative corpora is release-blocking | 0 | 0 | |
| CN-SEED-01 | release | enforced | Single JSON seed-importer authority: exactly one pub fn in ade_runtime::seed_import::import_cardano_cli_json_utxo converts a cardano-cli `query utxo --whole-utx… | 19 | 2 | |
| CN-SESS-01 | release | enforced | Single mux frame authority: ade_network::mux::frame::{encode_frame, decode_frame} is the SOLE pub fn pair encoding/decoding `MuxFrame` to/from bytes in the work… | 1 | 1 | |
| CN-SESS-02 | release | enforced | Single handshake authority: ade_network::handshake::n2n_transition is the SOLE pub fn driving the N2N handshake state machine. ade_network::handshake::n2c_trans… | 2 | 1 | |
| CN-SESS-03 | release | enforced | Single session step authority: ade_network::session::core::step is the SOLE pub fn reducing (SessionState, ByteChunkIn) -> (SessionState, Vec<SessionEffect>). N… | 3 | 1 | |
| CN-SESS-04 | release | enforced | Session reducer per-mini-protocol payload reassembly: the GREEN session reducer maintains one accumulating Vec<u8> buffer per AcceptedMiniProtocol variant insid… | 6 | 1 | |
| CN-SESS-05 | derived | enforced | Outbound mini-protocol payloads larger than MAX_PAYLOAD are segmented into ordered mux frames, each no larger than MAX_PAYLOAD, preserving mini-protocol id, mod… | 7 | 1 | |
| CN-SNAPSHOT-01 | derived | declared | A forged block becomes visible to peers only AFTER ServedChainHandle::push_atomic succeeds. The push_atomic call covers the full served_chain_admit call inside … | 3 | 0 | |
| CN-SNAPSHOT-02 | derived | enforced | A RequestRange covering a slot range that is not entirely present in ServedChainSnapshot MUST return NoBlocks per the Cardano block-fetch protocol's failure sem… | 6 | 0 | |
| CN-STORE-01 | true | declared | No authoritative storage initialization may occur before bootstrap or anchor verification succeeds | 0 | 0 | |
| CN-STORE-02 | true | partial | WAL entries, checkpoints, and recovered artifacts must be bound to exactly one anchor or bootstrap lineage | 3 | 0 | |
| CN-STORE-03 | true | enforced | Crash recovery must produce the same authoritative state as clean replay over the accepted canonical inputs | 4 | 1 | |
| CN-STORE-04 | true | enforced | Checkpoints must be atomic: fully committed and valid, or absent | 4 | 1 | |
| CN-STORE-05 | true | enforced | Finalized provenance must be append-only, auditable, and replay-derivable | 3 | 1 | |
| CN-STORE-06 | derived | declared | On-disk bytes must re-enter through the same canonical validation and decode chokepoints as network inputs | 0 | 0 | |
| CN-STORE-07 | release | enforced | Single materialize authority for rolled-back state: the function that materializes (LedgerState, PraosChainDepState) at a target point uses ONLY one SnapshotSto… | 5 | 1 | |
| CN-STORE-08 | release | enforced | Single encoder authority: encode_ledger_state + decode_ledger_state + encode_chain_dep + decode_chain_dep + encode_snapshot + decode_snapshot are the SOLE pub f… | 0 | 1 | |
| CN-TEST-01 | release | declared | Consensus-relevant inputs must be fuzzed differentially across all supported versions and decode or validation paths; any verdict mismatch is release-blocking | 0 | 0 | |
| CN-TEST-02 | release | declared | Every malformed or discrepant input that ever triggered a fork, preview mismatch, or parser disagreement becomes a permanent regression corpus entry | 0 | 0 | |
| CN-TEST-03 | release | declared | Previously failed, duplicate, or boundary-case inputs must remain verdict-stable under resubmission and replay | 0 | 0 | |
| CN-WAL-01 | release | enforced | Single WAL append authority: WalStore::append is the SOLE mutation method on any WalStore impl. No truncate/rewrite/replace method exists on the trait or any im… | 3 | 1 | |
| CN-WIRE-01 | true | declared | Hash-critical original bytes must be preserved and used on all hash/signature-critical paths | 0 | 0 | |
| CN-WIRE-02 | true | declared | Internal replay/state surfaces must use exactly one canonical project encoding | 0 | 0 | |
| CN-WIRE-03 | derived | declared | Consensus-critical deserialization must be equivalent across all supported versions and active code paths | 0 | 0 | |
| CN-WIRE-04 | true | declared | Malformed consensus-relevant inputs must be rejected deterministically before any authoritative state transition | 0 | 0 | |
| CN-WIRE-05 | derived | declared | No legacy or compatibility parser may accept bytes that the canonical parser rejects | 0 | 0 | |
| CN-WIRE-06 | derived | declared | Every network/storage ingress path must pass through named era-aware decode chokepoints | 0 | 0 | |
| CN-WIRE-07 | derived | enforced | Each protocol-visible message must decode into one closed, versioned message type | 45 | 1 | |
| CN-WIRE-08 | derived | enforced | N2N tag-24 CBOR-in-CBOR payload envelopes are constructed and stripped through ONE shared BLUE byte authority in ade_codec (wrap_tag24/unwrap_tag24). Protocol-s… | 24 | 1 | |
| CN-WIRE-09 | derived | enforced | The Shelley-and-later header_body `prev_hash` field is the closed wire grammar `$hash32 / null` (cardano-ledger PrevHash = GenesisHash | BlockHash). Ade represe… | 20 | 1 | |
| CN-WIRE-10 | derived | enforced | Ade's serve-side N2N handshake RESPONDER must encode versionData / MsgAcceptVersion / query-reply in the closed Cardano NodeToNode wire grammar a real cardano-n… | 4 | 1 | |
| CN-WIRE-11 | derived | enforced | Ade's serve-side ChainSync server must be wire-compatible with a real cardano-node follower's MsgFindIntersect, in two halves, served from the SINGLE ServedChai… | 7 | 1 | |
| CN-WIRE-12 | derived | enforced | Ade's FEED/receive-side BlockFetch path MUST remove the protocol tag-24 wrapper using the SINGLE ade_codec unwrap authority (decompose_blockfetch_block = ade_co… | 4 | 1 | |
| DC-ADMIT-01 | derived | enforced | Closed AgreementVerdict sum (GREEN evidence, not authority): exactly four variants — Agreed{our_hash,peer_hash}, Lagging{our_slot,peer_slot}, Diverged{our_hash,… | 8 | 1 | |
| DC-ADMIT-02 | derived | enforced | Verdict emitted exactly once per admit-attempt: every successful admit path produces exactly one agreement_verdict JSONL event. Never twice for the same block_h… | 2 | 1 | |
| DC-ADMIT-03 | derived | enforced | Diverged + InputNotFound are authority-fatal at the binary boundary. Distinct exit codes: EXIT_LIVE_AGREEMENT_DIVERGED=30, EXIT_LIVE_INPUT_NOT_FOUND=31. Mirrors… | 3 | 1 | |
| DC-ADMIT-04 | derived | enforced | Closed AdmissionLogEvent vocabulary (8 variants: admission_started, snapshot_imported, bootstrap_complete, block_received, block_admitted, agreement_verdict, ad… | 9 | 2 | |
| DC-ADMIT-05 | derived | enforced | Per-admit WAL append: every successful admit appends exactly one WalEntry::AdmitBlock to the configured WalStore. The entry's prior_fp chains to the previous en… | 2 | 2 | |
| DC-ADMIT-06 | derived | enforced | Verdict reducer is pure: verdict::derive(admit_outcome, peer_tip) is a pure function over closed input enums → closed output enum. No I/O, no clock, no state. T… | 1 | 1 | |
| DC-ADMIT-07 | true | enforced | Admit-replay-equivalence (true-tier): for every successful WalEntry::AdmitBlock transition, replay from the prior checkpoint plus WAL produces (a) the same post… | 4 | 1 | |
| DC-ADMIT-08 | derived | enforced | Lagging is evidence-state only: AgreementVerdict::Lagging means the local admitted chain is a prefix of the comparison target (peer's announced chain) up to the… | 2 | 1 | |
| DC-ADMIT-09 | derived | enforced | Admission code paths do not add partial reference-script support, permissive ref-script skipping, or any seed-import fallback. N-M-A's fail-fast on JsonSeedErro… | 0 | 1 | |
| DC-ADMIT-10 | derived | enforced | Every admission JSONL block-event carries consensus_inputs_fingerprint. BlockAdmitted, AgreementVerdict, BootstrapComplete, and AdmissionStarted events emit the… | 3 | 2 | |
| DC-ADMIT-11 | derived | enforced | Cross-epoch silent use forbidden. If a peer sends a block whose slot is outside [epoch_start_slot, epoch_end_slot], the runner MUST emit AdmissionHalted { reaso… | 1 | 1 | |
| DC-ADMIT-12 | derived | enforced | Undecodable peer bytes are Diverged (or PeerSentUndecodableBytes); never InputNotFound; never silent clean exit. C strengthens N-M-B's ProcessedBlock::Undecodab… | 1 | 1 | |
| DC-ANCHOR-01 | derived | enforced | BootstrapAnchor canonical CBOR round-trip: encode + decode preserves all 6 fields byte-identically. SCHEMA_VERSION = 1 in the encoded bytes; unknown version on … | 7 | 1 | |
| DC-CBOR-01 | derived | declared | Cardano CBOR decode/encode round-trips to identical bytes for all era types | 0 | 0 | |
| DC-CBOR-02 | derived | declared | Original wire bytes preserved for hash computation on hash-critical paths (see Byte Authority Model) | 0 | 0 | |
| DC-CINPUT-01 | derived | enforced | WARM-START VERIFICATION CAPABILITY (authority surface — NOT production restart). The seed-epoch consensus-input import is a canonical, replay-reconstructable WA… | 18 | 1 | |
| DC-CINPUT-02a | derived | enforced | PROJECTION EQUIVALENCE. The recovered SeedEpochConsensusInputs projects deterministically to the leadership-consumed PoolDistrView (the full LedgerView surface:… | 4 | 0 | |
| DC-CINPUT-02b | derived | enforced | PRODUCER CONSUMPTION (closes CE-A-4b). The node-lifecycle forge base is built from the recovered selected tip + the recovered SeedEpochConsensusInputs: forge_on… | 3 | 2 | |
| DC-CINPUT-03 | derived | enforced | The producer Praos VRF leader/header input is `praos_vrf_input(slot, eta0)` = `blake2b256(slot_be8 ‖ eta0_32)` (= cardano `mkInputVRF`), where eta0 is the Carda… | 3 | 1 | |
| DC-CINPUT-04 | derived | enforced | The receive/feed-path header-validation consensus view -- the LedgerView passed to block_validity -> validate_and_apply_header for Step 5 (VRF-keyhash binding) … | 1 | 1 | |
| DC-CINPUT-05 | true | enforced | Venue epoch geometry is DURABLE REPLAY AUTHORITY. A recovered store MUST replay using the epoch geometry (epoch_start_slot + epoch_length_slots) persisted with … | 5 | 0 | |
| DC-CINPUT-06 | true | enforced | The durable consensus PROFILE includes genesis_hash + protocol_params_hash, persisted canonically in the v4 SeedEpochConsensusInputs sidecar and recovered IDENT… | 5 | 1 | |
| DC-CINPUT-07 | true | declared | Conway deposit-parameter bootstrap authority. The Conway-only deposit params (drep_deposit / gov_action_deposit / drep_activity) are DECODED from the certified … | 13 | 1 | |
| DC-COMPAT-01 | derived | enforced | Cardano compatibility is proven ONLY on observable surfaces — per-block accept/reject verdict, selected tip hash, block hashes, cardano-cli query-utxo result, p… | 1 | 1 | |
| DC-CONS-03 | derived | enforced | Praos chain selection ordering: block number first, then Praos TiebreakerView (slot, issuer, op-cert issue number, VRF output). Density-based ordering is reserv… | 15 | 4 | |
| DC-CONS-04 | derived | enforced | Praos chain-dep state (evolving/candidate/epoch/previous_epoch/lab/last_epoch_block nonces, op-cert counters, last_slot) is owned by N-B consensus, not by the l… | 49 | 1 | |
| DC-CONS-05 | derived | enforced | Authoritative rollback must never exceed the security parameter k measured in blocks (mainnet k = 2160). Rollback requests deeper than k return ExceededRollback… | 11 | 2 | |
| DC-CONS-06 | derived | enforced | rollback(state, depth) produces state byte-identical to truncated replay from the nearest checkpoint. Rollback that would cross the immutable tip (≥ k deep) ret… | 7 | 1 | |
| DC-CONS-07 | derived | enforced | BLUE consensus must consume the HFC schedule only as a typed EraSchedule value anchored to BootstrapAnchorHash. Genesis text parsing happens in RED; BLUE never … | 12 | 1 | |
| DC-CONS-08 | derived | enforced | slot_to_time(EraSchedule, SystemStart, SlotNo) is a pure function; no BLUE consensus path may consult the wall clock to derive a slot or UTC instant for an auth… | 8 | 1 | |
| DC-CONS-09 | derived | enforced | Consensus-derived queries for slots beyond the ledger-view safe zone return OutsideForecastRange, never guessed values. The bound is derived from era history + … | 5 | 1 | |
| DC-CONS-10 | derived | enforced | A header's op-cert issue counter must be >= the highest observed counter for the same (pool, kes_period). Regression yields HeaderInvalid with a typed OpCertCou… | 16 | 1 | |
| DC-CONS-11 | derived | enforced | OpCert kes_period field equals the KES period at the forged slot under an operator-supplied anchor. period_at_slot(slot, anchor) = (slot - anchor) / slots_per_k… | 6 | 1 | |
| DC-CONS-12 | derived | enforced | OpCert serial counter is strictly monotonically increasing per (cold-key, node). BLUE rejects regression or repetition at the RED->BLUE boundary: opcert_validat… | 3 | 1 | |
| DC-CONS-13 | derived | enforced | Forge is pure given a canonical ProducerTick. forge_block has no wall-clock, no rand, no HashMap iteration, no I/O, no locale, and no ambient state. All inputs … | 3 | 2 | |
| DC-CONS-14 | derived | enforced | Forge byte-equality across replays. For two replays of an identical canonical ProducerTick stream over the same initial LedgerState, forge_block produces a byte… | 1 | 2 | |
| DC-CONS-15 | derived | enforced | Forge is invoked only when leader-check passes. forge_block is a forbidden transition for ticks where is_leader(state, vrf_output, sigma, asc) == false at tick.… | 2 | 1 | |
| DC-CONS-16 | derived | enforced | Forged header.body_hash MUST equal blake2b_256(forged_body_wire_bytes), where forged_body_wire_bytes are produced by the single Cardano-compatible canonical blo… | 10 | 3 | |
| DC-CONS-17 | derived | enforced | Block bytes delivered via producer-side block-fetch Block{bytes} are byte-identical to AcceptedBlock.as_bytes() for the AcceptedBlock that cleared self_accept. … | 5 | 2 | |
| DC-CONS-18 | derived | enforced | Header bytes announced via chain-sync RollForward{header,tip} are the header sub-segment of the AcceptedBlock whose body bytes are subsequently servable via blo… | 5 | 3 | |
| DC-CONS-19 | derived | enforced | Receive-side header-body sourcing coherence: when BlockDelivered {block_bytes} arrives at the receive bridge, the decoded header bytes of block_bytes equal the … | 3 | 1 | |
| DC-CONS-20 | derived | enforced | ChainDb-ledger-chain_dep lockstep: a successful receive-side admission updates ChainDb, LedgerState, and PraosChainDepState as one structural transition. A succ… | 8 | 3 | |
| DC-CONS-21 | derived | enforced | Snapshot encode/decode round-trip equivalence: for any reachable (LedgerState, PraosChainDepState), decode(encode(state)) yields a state whose ade_ledger::finge… | 5 | 1 | |
| DC-CONS-22 | derived | enforced | Replay-forward correctness: given state_at_slot_S and the ordered block sequence blocks(S+1..=T) from ChainDb, the replay-forward driver yields a state whose fi… | 4 | 1 | |
| DC-CONS-23 | derived | enforced | Own-forged stale-tip race safety by extend-only durable admit. An own-forged candidate is admitted to the durable tip ONLY if it EXTENDS the current durable tip… | 1 | 1 | |
| DC-CONS-24 | derived | enforced | Forged parent hash byte-equals the peer-visible selected tip. The forged successor's prev_hash byte-equals the followed peer tip hash AND its block_no == follow… | 1 | 1 | |
| DC-CONS-IN-01 | derived | enforced | Closed importer error sum: Io | Json | BadField | MissingField | BadHashHex | BadEpochWindow | BadPoolDistribution | EraNotSupported. No Option field receives a… | 12 | 1 | |
| DC-CONS-IN-02 | derived | enforced | Canonical fingerprint: LiveConsensusInputsCanonical.fingerprint is Blake2b-256 over a canonical CBOR encoding of every field in declared order. Same JSON bytes … | 5 | 1 | |
| DC-CONSENSUS-01 | derived | enforced | Chain selection is deterministic and matches Haskell node behavior | 26 | 3 | |
| DC-CONSENSUS-02 | derived | partial | Leadership verification is pure | 16 | 0 | |
| DC-CORE-01 | derived | enforced | BLUE authoritative crates are sync-only: no async fn, .await, tokio::, async_std::, Future, futures::, task spawning, async channels, or timers. Async runtime c… | 5 | 1 | |
| DC-CRYPTO-01 | derived | enforced | Crypto verification is pure and matches Haskell node on all test vectors | 19 | 1 | |
| DC-CRYPTO-02 | derived | enforced | All signing operations confined to shell | 0 | 1 | |
| DC-CRYPTO-03 | derived | enforced | VRF signing transcript equivalence and verification symmetry. For canonical inputs (slot, epoch_nonce, vrf_signing_key, vrf_role) the RED signer produces a VrfP… | 2 | 1 | |
| DC-CRYPTO-04 | derived | enforced | KES signing transcript equivalence and verification symmetry. For canonical inputs (kes_secret, period, msg) the RED signer produces a KesSignature byte-identic… | 5 | 2 | |
| DC-CRYPTO-05 | derived | enforced | KES evolution discipline: evolve(k_i) -> k_{i+1} is one-way. The evolved key signs period i+1 and MUST NOT sign for period i. RED kes_sign is forbidden when the… | 4 | 2 | |
| DC-CRYPTO-06 | derived | enforced | Ade-native KES envelope is the sole accepted hot-signing-key envelope format. Closed grammar `ade.kes.seed.v1`: load-bearing fields {`format`, `role`, `crypto`,… | 16 | 1 | |
| DC-CRYPTO-07 | derived | enforced | cardano-cli's `KesSigningKey_ed25519_kes_2^6` envelope (the upstream `Sum6KES` expanded-tree serialization, 608 bytes for a fresh key) is loadable via the Ade-o… | 6 | 2 | |
| DC-CRYPTO-08 | derived | enforced | Ade-owned Sum6KES algorithm is Haskell-equivalent. `ade_crypto::kes_sum::Sum6Kes` is byte-identical to Haskell `cardano-base`'s `Sum6KES Ed25519DSIGN`: `derive_… | 18 | 2 | |
| DC-CRYPTO-09 | derived | enforced | Sum6KES expanded signing-key serde and period inference. `raw_serialize_signing_key_kes` / `raw_deserialize_signing_key_kes` are byte-identical to Haskell's `ra… | 15 | 1 | |
| DC-CRYPTO-10 | derived | enforced | The RED signing shell must evolve the operator KES signing key to the requested KES period before signing, using the existing deterministic Sum6KES update primi… | 5 | 1 | |
| DC-DIFF-01 | derived | partial | Differential harness must localize first divergence point between Ade and reference oracle | 2 | 0 | |
| DC-EPOCH-01 | derived | partial | Conway governance timing: proposals accumulate during epoch, ratification and enactment are atomic at epoch boundary, pulsing distributes DRep stake computation… | 7 | 1 | |
| DC-EPOCH-02 | derived | enforced | Hard fork transitions triggered at deterministic slot/epoch boundaries; era translation functions mandatory; forecast horizon extends to era boundary | 9 | 1 | |
| DC-EPOCH-03 | derived | enforced | Single-epoch forge containment on the --mode node spine: in this forge path, a forge is valid only within the single recovered seed epoch. A candidate forge slo… | 6 | 1 | |
| DC-EPOCH-04 | derived | enforced | For a target epoch, AT MOST ONE canonically bound EpochConsensusView may activate (S3f-4a substrate). A distinct WalEntry::EpochConsensusViewActivated (append-o… | 3 | 1 | |
| DC-EPOCH-05 | derived | enforced | Epoch N+1 validation and leadership may NOT observe epoch-N seed inputs (S3f-4b). The active epoch view is a ONE-WAY ActiveEpochView transition: `Seed` (the rec… | 3 | 1 | |
| DC-EPOCH-06 | derived | enforced | Activation is durable-before-visible and replay-identical (S3f-4c). The activation WAL record (EpochConsensusViewActivated) is written and made durable BEFORE t… | 5 | 1 | |
| DC-EPOCH-07 | derived | enforced | A missing / stale / conflicting / mismatched candidate view causes TERMINAL fail-closed behaviour, NEVER fallback consensus (S3f-4b). The activation predicate (… | 3 | 1 | |
| DC-EPOCH-08 | derived | enforced | The activation SOURCE WINDOW is named-role-typed, durable-lineage-pinned, and complete/ordered/bounded (S3f-4d-1). The window that produces an activation candid… | 8 | 1 | |
| DC-EPOCH-09 | derived | enforced | The activation candidate is derived ONLY from a validated source window, bound to the TARGET-epoch context (S3f-4d-2). derive_candidate drives the reduced check… | 1 | 1 | |
| DC-EPOCH-10 | derived | enforced | The boundary activation orchestration is ONE atomic, ordered, durable-before-visible path (S3f-4d-3a). activate_at_boundary sequences, in order: validate the du… | 5 | 1 | |
| DC-EPOCH-11 | derived | declared | The live reduced-UTxO checkpoint (S3f-4d-mat) -- the authoritative reduced-stake state Ade maintains on the selected-chain admission path so it derives its OWN … | 1 | 1 | |
| DC-EPOCH-12 | derived | enforced | The promoted-epoch PoolDistrView is derived EXCLUSIVELY from the sealed EpochConsensusView + the bound-commitment- checked consensus profile (ECA-0b). EpochCons… | 2 | 1 | |
| DC-EPOCH-13 | derived | enforced | No semantic activation gate: no build- or runtime-level switch decides WHETHER the epoch-view activation occurs. There is no EVIEW_ACTIVATION_ARMED const, no `a… | 1 | 1 | |
| DC-EPOCH-14 | true | enforced | Atomic epoch-authority transition + recovery. The node holds exactly ONE owned ActiveEpochAuthority -- the SOLE leadership + header-validation view source -- an… | 11 | 1 | |
| DC-EPOCH-15 | true | enforced | Forecast horizon <=> durable N+1 authority promotion. The relay loop's EraSchedule forecast horizon extends past an epoch boundary N->N+1 IF AND ONLY IF the Act… | 3 | 1 | |
| DC-EPOCH-16 | true | enforced | Rolling Praos chain-dep nonce evolution on the live follow path. Each validated followed header drives ONE indivisible BLUE nonce transition over {slot, prev_bl… | 12 | 1 | |
| DC-EPOCH-17 | derived | declared | Replay-derived per-boundary leadership authority on the live follow path. The activation seam (prepare_authority_for_candidate_slot) ADVANCES the promoted epoch… | 0 | 0 | |
| DC-EPOCH-18 | derived | enforced | Window-end bootstrap reward update for the seed+2 leadership authority. The first post-bootstrap replay-derived authority (seed+2, DC-EPOCH-17) is the per-pool … | 4 | 1 | |
| DC-EPOCH-19 | derived | declared | Self-sustaining live ledger epoch evolution. After every durable selected-chain block, the node holds enough durable, replayable state to derive EVERY future ep… | 2 | 1 | |
| DC-EPOCH-20 | derived | declared | Atomic-or-rematerialized selected-block admission -- no RESUMED split authority. For every selected block admitted to the durable chain, four derived authoritie… | 2 | 1 | |
| DC-EPOCH-21 | derived | declared | The accumulator's epoch-boundary transition reproduces the canonical cardano NEWEPOCH result. POOLREAP is a SINGLE transition in the cardano order (Shelley Pool… | 2 | 1 | |
| DC-EPOCH-22 | derived | declared | BOUNDARY-ALIGNED-MARK-CAPTURE. The live epoch-boundary stake mark is captured ONLY from the durable reduced checkpoint materialized at the EXACT selected-chain … | 11 | 1 | |
| DC-EPOCH-23 | derived | enforced | Bootstrap reward-update fee-buffer authority (CE-3d). The one-shot bootstrap reward update applied at the seed->seed+1 boundary carries the certified snapshot R… | 10 | 1 | |
| DC-EPOCH-24 | derived | enforced | Snapshot pool-set inclusion = cardano's ssActiveStake NonZero membership (CE-3d). The per-epoch stake snapshot (mark/set/go) INCLUDES a registered+delegated sta… | 5 | 1 | |
| DC-EPOCH-25 | derived | declared | Self-contained frozen leadership authority (S4-pre). Cardano's leadership PoolDistr (nesPd) -- the per-pool (active_stake, vrf_keyhash) that decides the leader … | 16 | 3 | |
| DC-EPOCH-26 | derived | enforced | Settled rewind target. The epoch accumulator is NEVER rewound to a point within k of the durable tip: every rewind target is beyond the reach of an admissible r… | 2 | 1 | |
| DC-EPOCH-27 | derived | enforced | Lineage-bound rewind. A settled rewind target whose header hash no longer resolves canonically at its slot -- a point the chain has ABANDONED -- is REFUSED, and… | 1 | 1 | |
| DC-EPOCH-28 | derived | enforced | Leadership coherence across a rewind. A rewind restores CURRENT_LEADERSHIP_BY_EPOCH to exactly the epochs valid at the rewind point, so no sealed leadership obj… | 2 | 1 | |
| DC-EPOCH-29 | derived | enforced | Uncertified after rewind. A rewind clears LAST_ADVANCED_POINT and drops the pending boundary-mark binding, so the store is UNCERTIFIED until a canonical re-fold… | 2 | 1 | |
| DC-EPOCH-30 | derived | enforced | Bounded post-rollback refold. Post-rollback re-derivation is bounded by ~2k and is INDEPENDENT OF NODE UPTIME. The settled rewind point is never more than 2k be… | 2 | 1 | |
| DC-EPOCH-31 | derived | enforced | Rewind replay equivalence. Refolding from the settled rewind point yields state byte-identical to folding straight through from the bootstrap baseline over the … | 1 | 1 | |
| DC-EPOCH-32 | derived | enforced | Boundary seal reads a POSITIONED checkpoint. The boundary mark and the reduced-checkpoint commitment sealed into a frozen-leadership object are captured with th… | 3 | 1 | |
| DC-EPOCH-33 | derived | enforced | Refold re-seal identity. Re-deriving an epoch boundary the node has already crossed re-seals a frozen-leadership object byte-identical to the one the original c… | 1 | 1 | |
| DC-EPOCH-34 | true | enforced | Settled-triple integrity. The settled rewind triple (accumulator blob + settled point + settled leadership) is bound by a domain-separated, length-prefixed fing… | 3 | 1 | |
| DC-EPOCH-35 | derived | enforced | A bounded settled rewind survives the recovery pass that follows a durable rollback. After the ChainDb rollback COMMITS -- never before -- the settled point is … | 7 | 1 | |
| DC-EPOCH-36 | derived | enforced | After the epoch-boundary decision for a block at `slot`, the ledger's epoch MUST equal the venue era schedule's epoch for that slot. A disagreement in EITHER di… | 4 | 1 | |
| DC-EPOCH-37 | release | enforced | Authoritative epoch semantics must be proven PER VENUE, not inferred from a mainnet-shaped corpus. Every venue in the closed node-side registry (`native_firstru… | 4 | 1 | |
| DC-EPOCH-38 | derived | enforced | The Praos candidate-freeze / nonce surface must be proven across SEED-POSITION x VENUE, not once per venue. `eta0(N+1)` is committed from the candidate nonce, w… | 10 | 1 | |
| DC-EPOCH-39 | derived | enforced | A stall's CAUSE is typed, and only a real epoch transition may enter boundary machinery. Advancing the durable accumulator over one block yields exactly one of:… | 4 | 1 | |
| DC-EPOCH-40 | derived | partial | Leadership sigma denominator authority (SLICE LV-1). The leader-check sigma denominator is the SNAPSHOT's total active stake -- cardano's `pdTotalActiveStake` -… | 4 | 2 | |
| DC-EVIDENCE-01 | derived | enforced | Operator-pass live evidence: the C5 live operator pass against the local docker cardano-node-preprod peer produces a JSONL transcript containing AT LEAST: - 1… | 2 | 1 | |
| DC-EVIDENCE-02 | derived | enforced | Adversarial false-accept rejection across 4 mandatory mutation classes: 1. Body byte flip preserving envelope shape 2. Header body-hash mismatch 3. KES / … | 1 | 1 | |
| DC-EVIDENCE-03 | derived | enforced_scaffolding | Convergence-through-reorg transcript shape (CE-AI-6; PHASE4-N-AJ). The participant convergence pass produces ONE JSONL transcript with AT LEAST: - a strict sl… | 0 | 1 | |
| DC-EVIDENCE-04 | derived | enforced | Closed fork-choice convergence evidence (PHASE4-N-AO S9; promotes the live SELECT proof from stderr diagnostics to registry-grade evidence). The live multi-cand… | 4 | 1 | |
| DC-EVIDENCE-05 | derived | enforced | Replayable post-switch branch-continuity verdict (PHASE4-N-AO S10). After a ForkChoiceWin adoption at tip X, a GREEN pure reducer derive_post_switch_continuity(… | 11 | 1 | |
| DC-EVIEW-01 | derived | enforced | Transient epoch-view replay storage is GREEN / non-authoritative substrate. A bounded, disk-backed, TRANSIENT redb store (TransientEpochViewStore) may be materi… | 15 | 3 | |
| DC-EVIEW-02 | derived | enforced | Typed, era-gated stake-reference classification. Given canonical address bytes and a TYPED era / protocol-version context BOUND to the block being processed (Ca… | 18 | 1 | |
| DC-EVIEW-03 | derived | enforced | Era-parameterized pointer decoding + pre-Conway resolution, matching cardano-ledger EXACTLY (the wire authority -- CIP-19 is silent on canonicality, so the card… | 20 | 1 | |
| DC-EVIEW-04 | derived | enforced | The durable reduced-UTxO checkpoint -- the "minimal native state" (S3b Option B). A disk-backed redb store of TxIn -> (Coin, ReducedStakeRef), built from Ade's … | 12 | 1 | |
| DC-EVIEW-04b | derived | enforced | The windowed advance (S3b-2): advance the durable reduced-UTxO checkpoint (DC-EVIEW-04) per epoch boundary by replaying the epoch's admitted blocks, as the redu… | 7 | 1 | |
| DC-EVIEW-05 | derived | enforced | Per-pool stake aggregation (S3c, the linchpin). aggregate_pool_stake computes the next-epoch per-pool active stake from the single ledger authority's own projec… | 8 | 2 | |
| DC-EVIEW-06 | derived | enforced | Snapshot formation + the k-immutability stability gate (S3d). form_mark_snapshot converts the S3c per-pool aggregate (StakeByPool) into the MARK StakeSnapshot's… | 5 | 1 | |
| DC-EVIEW-07 | derived | enforced | The bound, immutable EpochConsensusView (S3e). EpochConsensusView::bind emits the compact next-epoch consensus view from the finalized snapshot (S3d), BOUND to … | 6 | 2 | |
| DC-EVIEW-08 | derived | declared | Activation -- the live-path consumption of Ade's self-derived next-epoch view. MECHANISM (IMPLEMENTED + AUTOMATIC): the boundary activation is wired into the re… | 1 | 1 | |
| DC-EVIEW-09 | derived | enforced | The manifest-bound bootstrap cert-state import (S3f-2 prerequisite). The seed (SeedEpochConsensusInputs, the compact per-POOL active epoch consensus view) and t… | 7 | 1 | |
| DC-EVIEW-10 | derived | enforced | The window driver (S3f-2): advance the reduced UTxO checkpoint + the cert/delegation state forward over a window of ordered blocks, then aggregate per-pool stak… | 2 | 1 | |
| DC-EVIEW-11 | derived | enforced | The deterministic, fail-closed epoch-rebind seam (S3f-3), strengthening DC-EPOCH-03. DC-EPOCH-03 fails the forge closed past the seed-epoch boundary (the recove… | 9 | 1 | |
| DC-EVIEW-12 | derived | enforced | The leadership-complete, self-contained EpochConsensusView (ECA-0b). The candidate view is the production authority for cross-epoch leadership: every INCLUDED p… | 4 | 1 | |
| DC-EVIEW-13 | derived | enforced | Cardano-faithful pool lifecycle in the reduced window (ECA-0a). The cert-state pool lifecycle matches cardano-ledger (Pool.hs/PoolReap.hs/Epoch.hs/SnapShots.hs … | 7 | 1 | |
| DC-FOLLOW-FORGE-01 | derived | enforced | Participant forge-decision mechanics. The keyed Participant venue uses an initial-catch-up -> extend forge mode mirroring the single-producer two-state mode: pa… | 10 | 1 | |
| DC-FORGE-01 | derived | enforced | Given the same canonical input set (slot, eta0, vrf_vk, vrf_proof_or_output, LeaderScheduleAnswer), verify_and_evaluate_leader produces a byte-identical LeaderC… | 3 | 0 | |
| DC-GENESIS-01 | derived | enforced | Given the same canonical Shelley genesis JSON bytes + the same operator-supplied kes_anchor_slot, parse_shelley_genesis produces a byte-identical GenesisAnchor … | 1 | 0 | |
| DC-GENESIS-SRC-01 | derived | enforced | A controlled genesis enters initial state ONLY through the single closed bootstrap_initial_state authority (genesis_initial); the genesis->initial-state transfo… | 4 | 1 | |
| DC-GOV-01 | derived | declared | GOVERNANCE-DEPOSIT-EXPIRY-REFUND (negative proof). Ade refunds a removed governance proposal's deposit to its recorded return address ONLY when it can PROVE, fr… | 5 | 1 | |
| DC-INGRESS-01 | derived | declared | Block/tx/protocol message decoding enters core through named chokepoints; no raw-byte bypass without CI-whitelisted justification | 0 | 1 | |
| DC-INGRESS-02 | derived | declared | Storage rehydration enters core through the same canonical decode chokepoints as network ingress | 0 | 0 | |
| DC-KES-HEADER-01 | derived | enforced | unsigned_header_pre_image(slot, block_no, prev_hash, vrf_data, opcert, kes_period, hot_vkey, body_hash, body_size, protocol_version) is a pure BLUE function. Sa… | 1 | 0 | |
| DC-LEDGER-01 | derived | enforced | apply_block(state, block) is pure and deterministic | 3 | 1 | |
| DC-LEDGER-02 | derived | partial | Same genesis + same blocks = byte-identical ledger state | 5 | 2 | |
| DC-LEDGER-03 | derived | partial | Tx/block validity agrees with Haskell node on all tested inputs | 9 | 3 | |
| DC-LEDGER-04 | derived | partial | Epoch boundary computations (stake snapshots, rewards) match Haskell | 4 | 0 | |
| DC-LEDGER-05 | derived | partial | Witness binding is era-specific: Byron TxWitness, Shelley+ WitsVKey/Scripts/BootstrapWitnesses, Alonzo+ Redeemers/Datums, Conway governance witnesses | 9 | 1 | |
| DC-LEDGER-06 | derived | declared | Script context (ScriptContext/TxInfo) derived from tx + ledger state + network-wide constants (EpochInfo, SystemStart); no host-environment data | 0 | 0 | |
| DC-LEDGER-07 | derived | declared | Coexisting supported versions must return same validity verdict for consensus-relevant inputs | 0 | 0 | |
| DC-LEDGER-08 | derived | enforced | Conway cert-state accumulation is a closed, total, era-versioned transition: for each block at track_utxo, certificates decode through the era-correct closed gr… | 16 | 1 | |
| DC-LEDGER-09 | derived | enforced | Conway governance-certificate accumulation is a closed, total, era-versioned transition into ConwayGovState: every governance-affecting Conway cert that B4 owne… | 17 | 1 | |
| DC-LEDGER-10 | derived | enforced | Credential identity is faithful end-to-end: a stake/committee/DRep credential is a closed sum over {KeyHash, ScriptHash} of a 28-byte hash, never a tag-erased H… | 20 | 1 | |
| DC-LEDGER-11 | derived | enforced | proposal_procedures MUST NOT remain an opaque byte field in the authoritative Conway tx-body shape. ConwayTxBody.proposal_procedures is Option<Vec<ProposalProce… | 21 | 1 | |
| DC-LEDGER-12 | derived | enforced | Every tx in a forged block is admissible via ade_ledger::mempool::admit against the base ledger state, in the snapshot's canonical accumulating order. No tx in … | 4 | 1 | |
| DC-LEDGER-13 | derived | enforced | MAINNET Shelley constants (SHELLEY_START_SLOT / SHELLEY_START_EPOCH / SHELLEY_EPOCH_LENGTH) may enter a computation ONLY through the explicitly-named `mainnet_s… | 4 | 1 | |
| DC-LEDGER-PARAMS-01 | true | enforced | Imported protocol parameters are preserved era-faithfully and are NEVER semantically remapped across eras. The shared `ProtocolParameters` carries the minimum-U… | 7 | 1 | |
| DC-LEDGER-PHASE2-01 | derived | enforced | One authoritative UTxO effect per transaction, gated by phase-2 validity. The UTxO effect of a transaction is derived in exactly ONE place from the canonical bl… | 4 | 1 | |
| DC-LEDGER-PHASE2-02 | derived | enforced | The accumulator consumes a RESOLVED SCALAR; it does not own a UTxO. The ADA a phase-2-invalid transaction consumes is collAdaBalance = sum(value(collateral inpu… | 6 | 1 | |
| DC-LEDGER-PHASE2-03 | derived | enforced | A phase-2-invalid transaction contributes its consumed collateral and NOTHING else. For a tx in the block's invalid_transactions set the accumulator applies exa… | 5 | 1 | |
| DC-LEDGER-PHASE2-04 | derived | enforced | The UTxO authority RETAINS what it destroys on another reader's behalf. A collateral value is authoritative only within [create(x), B), where B is the block who… | 10 | 1 | |
| DC-LEDGER-VALUE-01 | true | enforced | Ade's authoritative UTxO OUTPUT asset quantity preserves the full non-negative Cardano Word64 domain (0 ..= 2^64-1) via the `OutputAssetQuantity(u64)` newtype. … | 8 | 1 | |
| DC-LIVEMEM-01 | derived | enforced | Live-feed bounded memory (operational-hardening; NOT BLUE consensus law). Peer-driven memory on the live --mode node feed is bounded BEFORE authoritative decode… | 4 | 1 | |
| DC-MEM-01 | derived | enforced | Mempool acceptance rules must not contradict block/ledger acceptance rules | 7 | 1 | |
| DC-MEM-02 | derived | enforced | Overload shedding follows deterministic policy, not timing-dependent collapse | 2 | 1 | |
| DC-MEM-03 | derived | enforced | Tx ingress reduces to a closed IngressEvent before BLUE mempool admission; the source variant is evidence/policy/replay metadata only and MUST NOT change the va… | 8 | 1 | |
| DC-MEM-04 | derived | enforced | Replaying the same ordered ingress trace against the same base ledger state produces a byte-identical sequence of (MempoolState, AdmitOutcome) pairs. | 8 | 1 | |
| DC-MEM-05 | derived | declared | The UTxO/ledger state fingerprint and post-state are independent of the UTxO storage backend: an in-memory UTxO and an on-disk UTxO produce byte-identical repla… | 0 | 0 | |
| DC-MEM-06 | derived | partial | The UTxO/ledger state fingerprint is computed by the canonical CBOR encoder over canonically-encoded (fixed-width big-endian) keys, NEVER from a storage backend… | 5 | 2 | |
| DC-MEM-07 | derived | partial | The in-memory portion of the UTxO (read cache + last-k changelog) is bounded by fixed, closed, non-configurable constants; memory pressure cannot grow it unboun… | 4 | 1 | |
| DC-MEM-08 | derived | declared | A compact UTxO/TxOut representation (canonical CBOR slice as the single source of truth + lazily-decoded views) preserves canonical bytes and ledger semantics: … | 0 | 0 | |
| DC-MEM-09 | derived | enforced | The authoritative UTxO lookup interface returns OWNED values (Option<TxOut>), never a borrow into storage. This is the precondition for a swappable UTxO backend… | 1 | 1 | |
| DC-MEM-10 | derived | enforced | The v2 UTxO fingerprint component is a NAMED commutative set commitment (Ristretto255 ECMH) binding (TxIn, TxOut) over the canonical encodings, domain-separated… | 12 | 1 | |
| DC-MEM-11 | derived | enforced | The network forward-sync / forge per-block admit MUST derive the WAL post_fp from the CACHED UTxO-component fingerprint (ForwardSyncState.utxo_fp_cache -> finge… | 4 | 1 | |
| DC-MITHRIL-01 | derived | enforced | verify_mithril_binding is a pure deterministic BLUE predicate over its inputs (the manifest report + the anchor) — no I/O, no clock, no HashMap, no float, no St… | 3 | 1 | |
| DC-MITHRIL-02 | derived | enforced | For Mithril bootstrap, the BootstrapAnchor seed_point MUST be derived from the operator-provided independent seed-point extraction inputs, not from the Mithril … | 3 | 1 | |
| DC-MITHRIL-03 | true | enforced | The native Mithril AUTHORITY TRANSITION assembles the COMPLETE authoritative seed (LedgerState + PraosChainDepState + a NATIVE LiveConsensusInputsCanonical) fro… | 9 | 1 | |
| DC-MITHRIL-04 | derived | enforced | Native V2 LedgerDB `state` decode is faithful, fail-closed, and non-emitting. The cardano-node V2 (utxohd-mem, tablesCodecVersion 1) LedgerDB `state` CBOR is de… | 9 | 1 | |
| DC-MITHRIL-05 | true | enforced | Faithful Word64 multi-asset quantity on the snapshot-import path. The native V2 LedgerDB `tables` MemPack TxOut decode keeps every multi-asset quantity as a ful… | 9 | 1 | |
| DC-MITHRIL-06 | true | enforced | The Stage-2 `tables` (MemPack-decoded TxOuts) materialize into Ade's authoritative `UTxOState` with hash-critical bytes PRESERVED and full Word64 quantities car… | 11 | 1 | |
| DC-MITHRIL-07 | true | enforced | The live `--mode node` FirstRun arm INVOKES the native Mithril bootstrap path (DC-MITHRIL-03 / S1b) from live snapshot files -- it routes the verified Mithril m… | 12 | 1 | |
| DC-MITHRIL-08 | derived | enforced | The native Mithril FirstRun is BOUNDARY-COMPLETE: when the decoded cert-state carries delegations (the EVIEW package), native_first_run_bootstrap builds the liv… | 1 | 1 | |
| DC-NET-01 | derived | declared | Peer selection uses three-tier management (cold/warm/hot) with bounded admission, per-peer resource limits, and eviction policies | 0 | 0 | |
| DC-NODE-01 | derived | enforced | Per-peer session isolation: one peer session's failure (decode error, validity reject, rollback-too-deep, protocol violation) halts only that peer's session. Th… | 5 | 1 | |
| DC-NODE-02 | derived | enforced | Persistent-writer cadence fidelity: the orchestrator's persistent-snapshot writer calls PersistentSnapshotCache::capture only on the schedule emitted by the N-I… | 5 | 1 | |
| DC-NODE-03 | derived | enforced | Clock-injection seam + replay equivalence: the orchestrator depends on a Clock trait yielding now() and tick_stream(). No SystemTime::now() or tokio::time::Inst… | 5 | 2 | |
| DC-NODE-04 | derived | enforced | Authority-fatal halt + shutdown-resume identity: authoritative errors (chain_write failure on a committed rollback, SnapshotDecodeError::UnknownVersion or Finge… | 4 | 1 | |
| DC-NODE-05 | derived | enforced | Forge-slot discipline on the --mode node relay run-loop. A forge is attempted at most once per SlotNo and never for a slot <= the last forged slot (no past or d… | 10 | 3 | |
| DC-NODE-06 | derived | enforced | Self-accept -> serve handoff on the --mode node relay spine (sibling serve task, shape B). Only a BLUE self-accepted forged artifact may enter the sibling serve… | 13 | 3 | |
| DC-NODE-07 | derived | enforced | Node-spine live serve-to-peer. --mode node serves real peers ONLY from the G-B self-accepted ServedChainView (the read side of the single ServedChainHandle fed … | 4 | 2 | |
| DC-NODE-08 | derived | enforced | --mode node MAY forge the genesis-successor (FIRST) block from the recovered authoritative base when ChainDb::tip() AND the recovered tip (recovered.tip) are BO… | 9 | 1 | |
| DC-NODE-09 | derived | enforced | Once --mode node has spawned a --listen serve task (run_node_serve_task) over a ServedChainView, the end of the upstream feed (the relay loop returning -- e.g. … | 4 | 1 | |
| DC-NODE-10 | derived | enforced | After the feed validation/admission advances the node spine (a block ingested -> state.receive evolved), the next forge MUST derive the successor header positio… | 2 | 1 | |
| DC-NODE-11 | derived | enforced | Once --mode node has self-accepted and SERVED a genesis-successor block at block_no 0, it MUST NOT add/replace the served view (ServedChainView) with another bl… | 2 | 1 | |
| DC-NODE-12 | derived | enforced | Own-forged durable admit chokepoint. A self-accepted forged block may become part of the durable chain ONLY by being submitted to the same durable admit chokepo… | 3 | 2 | |
| DC-NODE-13 | derived | enforced | Served view is a durable-chain projection. The ChainView served to followers (ChainSync header advertisement + BlockFetch body) is a deterministic PROJECTION of… | 3 | 1 | |
| DC-NODE-14 | derived | enforced | Every claimed forge parent must be servable or peer-intersectable in the durable served lineage. A --mode node forge may only build on a parent a Haskell peer c… | 4 | 2 | |
| DC-NODE-15 | derived | enforced | Forge admissibility requires the durable servable tip to equal the followed peer tip. A --mode node forge is admissible ONLY when durable_servable_tip == follow… | 3 | 1 | |
| DC-NODE-16 | derived | enforced | Receive idempotency: a peer-delivered block already durably present byte-identically in the ChainDb (same slot, same hash) is an idempotent no-op at the durable… | 3 | 1 | |
| DC-NODE-17 | derived | declared | followed_peer_tip advances ONLY from a real observed peer ChainSync advertisement of the peer's selected tip, INCLUDING the self-adoption echo case where the ad… | 0 | 0 | |
| DC-NODE-18 | derived | enforced | Successor extension after an explicit adoption certificate (single-producer, single successor). After initial peer catch-up against a real peer tip (DC-NODE-15)… | 5 | 1 | |
| DC-NODE-19 | derived | declared | Single-producer forge-loop continuation after follow-link EOF. In an explicitly declared single-producer venue (VenueRole::SingleProducer) that has ALREADY ente… | 0 | 0 | |
| DC-NODE-20 | derived | enforced | Local selected durable chain forge-base authority (rung-1 single-producer). In a declared rung-1 single-producer venue, after Ade self-admits a valid forged blo… | 4 | 2 | |
| DC-NODE-21 | derived | enforced | Adoption certificate is rung-1 evidence-only, never forge authority. The file-based operator adoption certificate is a rung-1 RED EVIDENCE-ONLY shim. It MAY pro… | 3 | 2 | |
| DC-NODE-22 | derived | enforced | Single-producer warm-start re-entry derives forge mode from the recovered local durable spine. In a declared rung-1 single-producer venue, if warm-start recover… | 2 | 1 | |
| DC-NODE-23 | derived | enforced | Shared receive-side fork-choice detector (rung-2). A peer-origin candidate that is NOT already known as part of Ade's admitted durable spine / own-served lineag… | 6 | 1 | |
| DC-NODE-24 | derived | enforced | Venue-split fork-choice resolver (rung-2). The DC-NODE-23 detector's non-spine consequent is gated by venue and TOTAL over the closed venue set: VenueRole::Sing… | 4 | 1 | |
| DC-NODE-25 | derived | enforced | Live fork-choice durable application authority (rung-2). A ChainSelected / RolledBack outcome from the chain_selector orchestrator is applied to the durable sto… | 5 | 2 | |
| DC-NODE-26 | derived | enforced | Decision / durable reconciliation (rung-2). After any applied receive decision, the chain_selector orchestrator's selector.current_tip EQUALS the durable ChainD… | 2 | 1 | |
| DC-NODE-27 | derived | enforced | Rollback+reselection replay-equivalence (rung-2). The ordered live receive-event sequence (RollForward headers, RollBackward points, body deliveries) replayed a… | 4 | 2 | |
| DC-NODE-28 | derived | enforced | No forge across unresolved re-selection (rung-2). Once a peer-origin candidate is classified NeedsForkChoice (DC-NODE-23) in a Participant venue, forging is DIS… | 5 | 2 | |
| DC-NODE-29 | derived | enforced | Live rollback target canonical binding (rung-2; AI-S6 H-1 remediation). For a peer RollBackward(point) on the live Participant path, the rollback target MUST be… | 5 | 1 | |
| DC-NODE-30 | derived | enforced | Participant-path convergence evidence emission (PHASE4-N-AJ). The live `--mode node --participant-venue` rollback-follow path emits the existing closed Agreemen… | 7 | 3 | |
| DC-NODE-31 | derived | enforced | Recovered-anchor live-follow start authority (PHASE4-N-AK). After recovery from a non-Origin bootstrap anchor, the recovered store PERSISTS the bootstrap anchor… | 11 | 0 | |
| DC-NODE-32 | derived | enforced | Recovered-anchor rollback boundary on the single-producer live-follow path (PHASE4-N-AK AK-S2). After recovery to a bare bootstrap anchor, the single-producer f… | 7 | 0 | |
| DC-NODE-33 | derived | enforced | Participant-path recovered-anchor rollback boundary (PHASE4-N-AL) -- the participant MIRROR of DC-NODE-32. On the participant live-follow path (run_participant_… | 5 | 0 | |
| DC-NODE-34 | derived | enforced | Peer-identity restoration (PHASE4-N-AO, SELECT foundation). The live receive path preserves the origin peer identity end-to-end: AdmissionPeerEvent (peer: Strin… | 2 | 1 | |
| DC-NODE-35 | derived | enforced | BLUE-safe candidate construction (PHASE4-N-AO). A CandidateFragment fed to the BLUE fork-choice authority select_best_chain (DC-CONS-03) MUST be derived ONLY fr… | 5 | 1 | |
| DC-NODE-36 | derived | enforced | Live single-selector dispatch (PHASE4-N-AO). The live participant NeedsForkChoice arm (today fail-closed in run_participant_sync, node_lifecycle.rs) routes the … | 4 | 1 | |
| DC-NODE-37 | derived | enforced | Fork-switch never-abandon (PHASE4-N-AO, SELECT primary invariant; the H-1 class at fork-choice scale). When select_best_chain picks a winner that forks BELOW Ad… | 7 | 1 | |
| DC-NODE-38 | derived | enforced | Live multi-block fork-anchor discovery (PHASE4-N-AO S7; the live-geometry gap CE-AO-6 surfaced). A live competing branch is eligible for SELECT only when Ade wa… | 8 | 1 | |
| DC-NODE-39 | derived | enforced | Post-ForkChoiceWin forward-follow continuity (PHASE4-N-AO S11). After a ForkChoiceWin adoption at tip X, Ade must continue receiving and admitting the winning p… | 7 | 1 | |
| DC-NODE-40 | derived | enforced | Rolled-back branch evidence retention for the LCA walk (PHASE4-N-AO S13). Rolled-back blocks MAY be retained only as walk-visible EVIDENCE for future competing-… | 6 | 1 | |
| DC-NODE-41 | derived | enforced | Missing-bridge range re-fetch for winner-descendant recovery (PHASE4-N-AO S14). When a post-ForkChoiceWin WINNING peer (the peer Ade just adopted from) presents… | 6 | 1 | |
| DC-NODE-42 | derived | enforced | LIVE-FORGE-HARDENING S1 within-epoch forge-path rollback guard (INV-FH-4). On the --mode node forge / live-follow path (run_node_sync), a peer RollBackward whos… | 1 | 0 | |
| DC-NODE-43 | derived | declared | Gap-free resume of a reconnected live feed. A reconnected per-peer session resumes chain-sync from the last block actually DELIVERED downstream, never from the … | 0 | 0 | |
| DC-NODE-44 | release | enforced | A warm-start replay divergence (T-REC-05) must be SELF-DESCRIBING: the typed fault carries a `ReplayDivergenceReport` alongside the two fingerprints, naming the… | 6 | 1 | |
| DC-NODE-45 | derived | enforced | ONE bootstrap-bound wall-clock -> absolute-slot authority on the authoritative --mode node producer path. (a) SOLE AUTHORITY: the forge derives its slot ONLY th… | 20 | 1 | |
| DC-NODE-46 | derived | enforced | Every ADMITTED ForgeTick yields either a structured refusal or a leader-schedule decision. No admitted tick may disappear, and none may report a reason that is … | 6 | 1 | |
| DC-NODE-47 | derived | partial | Followed-peer-tip possession evidence (SLICE B12). The forge-admissibility signal (FollowedPeerTipSignal) reports the STRONGEST available evidence that the foll… | 7 | 2 | |
| DC-OPCERT-01 | derived | enforced | Given the same canonical envelope bytes, parse_opcert_envelope produces a byte-identical DecodedOpCertEnvelope across runs. Replay-equivalence anchor for the op… | 1 | 0 | |
| DC-OUTBOUND-FIFO-01 | derived | enforced | The per-peer outbound channel preserves FIFO order: OutboundCommands enqueued for PeerId(p) in order O₁..Oₙ arrive at the peer's TCP socket in the same order (m… | 0 | 0 | |
| DC-PLUTUS-01 | derived | declared | UPLC evaluation is deterministic: same script + args + cost model = identical result | 0 | 0 | |
| DC-PLUTUS-02 | derived | declared | Budget exhaustion produces deterministic structured error | 0 | 0 | |
| DC-PROD-01 | derived | enforced | Producer-mode evidence log emits a closed `ProducerLogEvent` vocabulary: handshake_ok, slot_tick, leader_elected, block_forged, block_served, peer_chain_tip_obs… | 5 | 0 | |
| DC-PROD-02 | derived | enforced | Coordinator slot-tick + forge-result stream replay-equivalence. For a fixed initial CoordinatorState, fixed canonical slot-tick sequence, fixed ledger state, fi… | 1 | 0 | |
| DC-PROD-03 | derived | enforced | Producer chain-forward continuity + replay. The GREEN ChainEvolution linear typestate threads each forge's post-state (post-ledger, post-chain_dep, new tip) int… | 8 | 0 | |
| DC-PROTO-01 | derived | enforced | Protocol state machines have deterministic transitions | 90 | 1 | |
| DC-PROTO-02 | derived | enforced | Transcript-equivalent miniprotocol behavior with Haskell node | 48 | 1 | |
| DC-PROTO-03 | derived | enforced | Full N2N mini-protocol surface: Handshake, ChainSync, BlockFetch, TxSubmission2, KeepAlive, PeerSharing | 6 | 1 | |
| DC-PROTO-04 | derived | enforced | Full N2C mini-protocol surface: Handshake, LocalChainSync, LocalTxSubmission, LocalStateQuery, LocalTxMonitor | 42 | 1 | |
| DC-PROTO-05 | derived | declared | Version negotiation is closed: enumerated N2N/N2C versions, explicit handshake, deterministic refusal on mismatch | 21 | 1 | |
| DC-PROTO-06 | derived | enforced | BLUE mini-protocol transitions are pure functions of (canonical prior state, canonical input message, selected protocol version, deterministic configuration); n… | 90 | 1 | |
| DC-PROTO-07 | derived | enforced | Given canonical inputs (negotiated_version, peer_message_sequence, broadcast_arrival_sequence, session_event_sequence), the producer-side chain-sync / block-fet… | 4 | 3 | |
| DC-PROTO-08 | derived | enforced | Once chain-sync enters a state where the server holds agency, the pure per-session reducer must return exactly one of: a legal RollForward, a legal RollBackward… | 12 | 1 | |
| DC-PROTO-09 | derived | enforced | Receive-side transcript determinism: given canonical inputs (initial_ledger, initial_chain_dep, initial_chaindb, event_sequence), the bridge reducer's output st… | 2 | 2 | |
| DC-PROTO-10 | derived | enforced | Chain-sync server FindIntersect cursor: after the producer chain-sync server answers IntersectFound(point), its read cursor (last_announced) IS that point -- th… | 1 | 0 | |
| DC-PROTO-11 | derived | enforced | TxSubmission2 codec accepts + byte-identically preserves cardano-node's REAL wire form for the txid/tx messages: each txId is era-tagged [eraIndex, hash32] (the… | 9 | 1 | |
| DC-PUMP-01 | derived | enforced | Wire pump emits AdmissionPeerEvent::{Block, TipUpdate, Disconnected} only. It MUST NOT synthesize AgreementVerdict values or any validity claim. The verdict rem… | 3 | 2 | |
| DC-PUMP-02 | derived | enforced | A CLOSED authority event is emitted on every chain-sync reply carrying a Tip: TipUpdate for IntersectFound / IntersectNotFound / RollForward; the DISTINCT Admis… | 3 | 1 | |
| DC-PUMP-03 | derived | enforced | Wire-pump keep-alive client (PHASE4-N-AM). The admission wire pump (run_admission_wire_pump -- the SOLE per-peer pump, CN-PUMP-01) runs the N2N keep-alive CLIEN… | 3 | 1 | |
| DC-PUMP-04 | derived | enforced | Multi-peer wire-pump fairness (PHASE4-N-AO S8; the gap the S7 live retry surfaced). When multiple peers are connected to the participant receive path, no connec… | 3 | 1 | |
| DC-PUMP-05 | derived | enforced | Cooperative keep-alive liveness under downstream backpressure. No stall of the downstream consumer -- of ANY duration or cause (block application, epoch-boundar… | 1 | 1 | |
| DC-PUMP-06 | derived | enforced | Ordered pump progression under backpressure. The sequence of AdmissionPeerEvents delivered to events_out is identical to the unstalled pump for the same peer in… | 1 | 1 | |
| DC-PUMP-07 | derived | enforced | Bounded deferral, fail closed. Peer frames held while the pump waits for downstream capacity are bounded by the fixed, closed, non-configurable MAX_DEFERRED_PEE… | 1 | 1 | |
| DC-PUMP-08 | derived | enforced | Reconnect policy is transport-only and TOTAL. should_reconnect_after is the single named authority classifying the wire pump's closed outcome sum: TRANSPORT los… | 1 | 1 | |
| DC-PUMP-09 | derived | enforced | No bootstrap spin. Reconnect applies ONLY to a session that was established and then lost. An unparseable --peer, or a FIRST dial that fails, keeps the pre-slic… | 2 | 1 | |
| DC-PUMP-10 | derived | enforced | Deterministic, bounded reconnect backoff. Re-dial pacing follows a fixed const escalating schedule (RECONNECT_BACKOFF_SECS) that is monotone non-decreasing and … | 1 | 1 | |
| DC-QUERY-01 | derived | declared | N2C queries are era-aware, typed, and version-gated: each NodeToClientVersion gates which queries are available | 0 | 0 | |
| DC-REF-01 | derived | partial | Every claimed equivalence check must identify its reference source, extraction method, and reproducibility path | 10 | 1 | |
| DC-SEED-01 | derived | enforced | Canonical UtxoFingerprint determinism: the imported UTxOState uses BTreeMap<TxIn, TxOut> iteration order; UtxoFingerprint is Blake2b-256 over canonical CBOR map… | 6 | 2 | |
| DC-SERVEMEM-01 | derived | enforced | Peer-driven serve range work is bounded. The --mode node serve path must not materialize an unbounded chain range, perform per-block full-index scans, or read m… | 12 | 1 | |
| DC-SESS-01 | derived | enforced | Handshake-before-traffic: no mini-protocol frame reaches the orchestrator inbox until the handshake state machine has emitted Accepted. Type-state: a `MuxSessio… | 2 | 1 | |
| DC-SESS-02 | derived | enforced | Closed mini-protocol id registry: the dispatch table over `MiniProtocolId` is a closed `match` on a closed `AcceptedMiniProtocol` enum. Unknown ids return `Sess… | 4 | 1 | |
| DC-SESS-03 | derived | enforced | Per-mini-protocol ordering + session replay equivalence: replaying the same byte chunks through `session::core::step` yields byte-identical outbound frames and … | 3 | 1 | |
| DC-SESS-04 | derived | enforced | Backpressure discipline: every per-peer + per-mini-protocol channel is bounded; queue overflow is fail-fast `TransportError::BackpressureExceeded` rather than s… | 2 | 1 | |
| DC-SESS-05 | derived | enforced | Wire-layer clock injection: the session reducer + dispatch table contain no SystemTime / Instant::now / tokio::time reads. Keep-alive is driven by the PHASE4-N-… | 3 | 1 | |
| DC-SESS-06 | derived | enforced | Replay equivalence under fragmented inbound streams: two reducer runs over the same byte-chunk sequence (including inputs where single CBOR items span multiple … | 3 | 1 | |
| DC-SNAPSHOT-01 | derived | enforced | ServedChainHandle::push_atomic is deterministic in its argument order: the same sequence of push_atomic(a₀), push_atomic(a₁), ..., push_atomic(aₙ) produces a by… | 3 | 0 | |
| DC-STORE-01 | derived | enforced | Recovery from power-loss produces replay-equivalent state | 4 | 1 | |
| DC-STORE-02 | derived | enforced | Append-only provenance for finalized data | 3 | 1 | |
| DC-STORE-03 | derived | enforced | Atomic snapshots (fully written or absent) | 4 | 1 | |
| DC-STORE-04 | derived | declared | ChainDB structure: ImmutableDB (append-only, blocks immutable when k-deep), VolatileDB (recent blocks within k), LedgerDB (snapshots + forward replay) | 0 | 0 | |
| DC-STORE-05 | derived | enforced | Recovery is snapshot + forward replay (not full genesis replay): load most recent valid snapshot, replay forward from ImmutableDB tip | 4 | 1 | |
| DC-STORE-06 | derived | declared | VolatileDB uses ValidateAll after unclean shutdown; NoValidation acceptable during clean operation as optimization | 0 | 0 | |
| DC-STORE-07 | derived | enforced | Snapshot cadence determinism: the decision to take a snapshot at slot S is a pure function of (slot, block_no, cadence_params, last_snapshot). Same canonical in… | 7 | 1 | |
| DC-STORE-08 | derived | enforced | Snapshot encoder canonicality: encode_snapshot(s) is byte-identical across runs. Encoder uses BTreeMap iteration only; no HashMap, no wall-clock, no floats, no … | 9 | 1 | |
| DC-STORE-09 | derived | enforced | Snapshot bytes carry a closed u32 version tag (initial == 1) and the source state's blake2b-256 fingerprint. Decoder reads the version tag first and rejects unk… | 3 | 1 | |
| DC-STORE-10 | true | enforced | Replay equivalence requires the persisted authority store and the binary to agree on the MEANING of the bytes, not merely on their layout. Every durable authori… | 10 | 1 | |
| DC-STORE-11 | derived | enforced | The semantics marker is PER-ARTIFACT, and every authority artifact must agree with the binary independently. `chain.db` (with the WAL written in lockstep beside… | 4 | 1 | |
| DC-STORE-12 | release | enforced | The semantics version may not be left to memory. The declared semantics-bearing surface (`ci/store-semantics-surface.lock`) is content-hashed, and any drift fai… | 0 | 1 | |
| DC-SYNC-01 | derived | enforced | During network forward-sync, a block's preserved wire bytes and its WAL entry MUST be durable before the chain tip advances to it, and admission is chokepoint-o… | 7 | 2 | |
| DC-SYNC-02 | derived | enforced | Continuous relay sync: every loop iteration preserves durable-before-advance (DC-SYNC-01) and advances the tip ONLY through run_node_sync -> pump_block. Verdict… | 4 | 2 | |
| DC-TXV-01 | derived | enforced | tx_validity is a pure function of (LedgerState, tx_cbor). No wall-clock, arrival order, HashMap/HashSet iteration, float, or ambient state may influence a trans… | 1 | 1 | |
| DC-TXV-02 | derived | enforced | A transaction is Valid iff both phase-1 (structural + UTxO rules + witnesses) and phase-2 (Plutus, when scripts are present) accept it. No path may produce a Va… | 2 | 1 | |
| DC-TXV-03 | derived | enforced | Ade's Valid/Invalid verdict for a transaction equals the reference cardano-node verdict, including the reason class where the reference exposes it. Established … | 17 | 1 | |
| DC-TXV-04 | derived | enforced | A Valid transaction yields an applied LedgerState' (the mempool's accumulating view); an Invalid transaction leaves the input state unchanged plus a structured … | 3 | 1 | |
| DC-TXV-05 | derived | enforced | For each era, required_signers(state, tx_body) is a closed, explicit, era-versioned function over every signer source (resolved input payment credentials, expli… | 13 | 1 | |
| DC-TXV-06 | derived | enforced | For each era, the certificate-deposit classification map(state, cert) is a closed, total, era-versioned function: every certificate variant resolves to exactly … | 10 | 1 | |
| DC-TXV-07 | derived | enforced | All deposit/refund amounts used by Conway transaction value-conservation accounting must be sourced from canonical ledger protocol parameters or explicit certif… | 4 | 1 | |
| DC-VAL-01 | derived | enforced | A block's validity verdict is a pure function of (LedgerState, PraosChainDepState, EraSchedule, LedgerView, block_cbor). No wall-clock, arrival order, HashMap/H… | 8 | 1 | |
| DC-VAL-02 | derived | enforced | A block is Valid iff both the consensus header authority (validate_and_apply_header) and the ledger body authority (apply_block_with_verdicts) accept it. No pat… | 2 | 1 | |
| DC-VAL-03 | derived | enforced | The header is validated before the body; body validation never runs on a header-invalid block. The first failing authority determines the reason (fail-fast orde… | 1 | 1 | |
| DC-VAL-04 | derived | enforced | Ade's Valid/Invalid verdict for a block equals the reference cardano-node verdict, including the reason class where the reference exposes it. Established over b… | 6 | 1 | |
| DC-VAL-05 | derived | enforced | A Valid block yields evolved (LedgerState', PraosChainDepState'); an Invalid block yields the unchanged input states plus a structured reason. No partial or in-… | 2 | 1 | |
| DC-VAL-06 | derived | enforced | Every crypto-input, field-size, and structural check on the authority path rejects (produces Invalid) on wrong size or shape and never silently skips. The patte… | 20 | 1 | |
| DC-VIEW-01 | derived | enforced | LiveLedgerView determinism + epoch-window guard. The view is constructed deterministically from LiveConsensusInputsCanonical. Two guards on every LedgerView qu… | 5 | 1 | |
| DC-WAL-01 | derived | enforced | WAL is append-only by type: the WalStore trait carries no method named truncate / rewrite / replace / delete / clear. CI grep enforces across the workspace (no … | 0 | 1 | |
| DC-WAL-02 | derived | enforced | WAL fingerprint-chain integrity: every WalEntry::AdmitBlock has prior_fp == previous entry's post_fp (or anchor's initial_ledger_fingerprint for the first entry… | 6 | 1 | |
| DC-WAL-03 | derived | enforced | Anchor + WAL replay-equivalence: replaying (BootstrapAnchor + WAL entries 1..N) against (initial_ledger from import + per-entry block bytes) produces a final le… | 5 | 0 | |
| DC-WAL-04 | derived | enforced | Forged-block WAL chain integrity. A forged AdmitBlock WAL entry's prior_fp MUST equal the current durable post_fp (the BootstrapAnchor's initial_ledger_fingerpr… | 3 | 1 | |
| DC-WAL-05 | derived | enforced | Received/followed-block durable-admit is BYTES-FIRST. The live admission runner (run_admission) MUST persist an admitted block's preserved ORIGINAL bytes to the… | 2 | 1 | |
| OP-MEM-01 | operational | partial | Mempool pressure and peer churn must not starve block validation, chain selection, or persistence (scheduling priority) | 0 | 1 | |
| OP-MEM-02 | operational | enforced | Ade's owned resident memory (Private_Dirty/RssAnon) under a representative venue stays clearly below the reference Haskell cardano-node's on the same chain, WIT… | 2 | 2 | |
| OP-NET-01 | operational | declared | Block producer connects only through trusted relay topology; no direct public peer connectivity | 0 | 0 | |
| OP-NET-02 | operational | declared | Relay paths geographically and topologically diverse; isolating one path does not prevent timely propagation | 0 | 0 | |
| OP-NET-03 | operational | declared | No single peer, ASN, region, or operator cluster dominates the node's authoritative view | 0 | 0 | |
| OP-OPS-01 | operational | declared | Post-incident reconciliation derived solely from recovered canonical chain | 0 | 0 | |
| OP-OPS-02 | operational | declared | Emergency recovery procedures have explicit admissibility criteria, deterministic inputs/outputs, and authority thresholds | 0 | 0 | |
| OP-OPS-03 | operational | declared | Incident evidence sufficient to reconstruct canonical decision path without relying on nondeterministic logs | 0 | 0 | |
| OP-OPS-04 | operational | enforced | Operator-supplied keys. Ade supports both KES key flows: (a) Ade-native `ade_node --mode key_gen_kes --out-file PATH` emitting an `ade.kes.seed.v1` envelope loa… | 28 | 3 | |
| OP-OPS-05 | operational | enforced | Slot-deadline forging SLA. Forge + self-accept + N2N hand-off must complete within the slot's deadline (1s on mainnet, smaller on testnets). Operational, not co… | 1 | 1 | |
| RO-CLOSE-01 | release | enforced | Unmasked close-gate discipline. Any slice that changes canonical bytes, encoded forms, decoder inputs, or golden fixtures MUST run an UNMASKED full close gate (… | 0 | 0 | |
| RO-GENESIS-REPLAY-01 | release | declared | Ade independently replays the chain from byron genesis through the bootstrap point P, producing the same UTxOState the oracle seed provides. Closes the "Ade has… | 0 | 1 | |
| RO-LIVE-01 | release | partial | A Haskell cardano-node peer issuing RequestRange covering an Ade-forged block receives, via the producer-side block-fetch server, bytes that pass that peer's fu… | 7 | 1 | |
| RO-LIVE-02 | release | partial | A cardano-node peer's RollForward + BlockDelivered stream, consumed by the receive bridge, produces a ChainDb tip equal to the peer's announced tip at every ste… | 5 | 1 | |
| RO-LIVE-03 | release | declared | Live tip-following pass: operator runs `ade_node --peer ADDR` against a private cardano-node peer, captures a 30-minute JSONL log of (peer_tip, ade_tip, agreeme… | 0 | 0 | |
| RO-LIVE-04 | release | enforced | Live wire-smoke pass: operator runs `ade_node --mode wire_only --peer ADDR --network NAME` against a private cardano-node peer. The binary opens TCP, completes … | 11 | 2 | |
| RO-LIVE-05 | release | enforced | Live admission-agreement pass: operator runs `ade_node` against a private cardano-node peer with admission enabled (bootstrap loads a real initial ledger state … | 4 | 1 | |
| RO-LIVE-06 | release | enforced | BA-02 peer-acceptance evidence closure (SCHEMA + CORRELATION MECHANICS ONLY). The BA-02 evidence surface is a closed, versioned manifest (Ba02Manifest) plus a p… | 20 | 2 | |
| RO-MITHRIL-IMPORT-01 | release | enforced | Ade imports a Mithril-authenticated snapshot as an alternative to the cardano-cli JSON seed. Provides cryptographic provenance for the seed artifact (over and a… | 4 | 3 | |
| RO-REL-01 | release | declared | Release not mainnet-eligible without mixed-version topology consensus equivalence on adversarial inputs | 0 | 0 | |
| RO-REL-02 | release | declared | Cross-implementation accept/reject agreement on authoritative corpora is release-blocking | 0 | 0 | |
| RO-REL-03 | release | declared | No single implementation bug should exceed the protocol's intended safety or liveness fault threshold at ecosystem level | 0 | 0 | |
| RO-SYNC-EVIDENCE-01 | release | partial | A committed snapshot->tip sync-evidence manifest carries the closed schema (oracle versions, chain point, fixture refs, sha256, diff/acceptance result) and its … | 1 | 1 | |
| RO-TEST-01 | release | declared | Consensus-relevant inputs fuzzed differentially across all supported versions; any verdict mismatch is release-blocking | 0 | 0 | |
| RO-TEST-02 | release | declared | Every fork/mismatch/parser disagreement that ever occurred becomes a permanent regression corpus entry | 0 | 0 | |
| RO-TEST-03 | release | declared | Failed, duplicate, and boundary-case inputs remain verdict-stable under resubmission and replay | 0 | 0 | |
| T-BOUND-01 | true | declared | Shell may observe nondeterminism but must convert to deterministic inputs before entering core | 0 | 0 | |
| T-BOUND-02 | true | enforced | Authoritative crates never depend on shell crates | 0 | 1 | |
| T-BUILD-01 | true | enforced | No semantic build variability in authoritative code | 0 | 1 | |
| T-BUILD-02 | true | declared | One semantic interpretation per protocol version and input set | 0 | 0 | |
| T-CAUSAL-01 | true | declared | Future decisions may not leak into present validation; no retroactive reinterpretation of prior checkpoints | 0 | 0 | |
| T-CI-01 | true | partial | Every true invariant has mechanical CI enforcement. No waivers. | 0 | 1 | |
| T-COLL-01 | true | declared | Deterministic iteration order for all semantically meaningful collections | 0 | 0 | |
| T-CONS-01 | true | enforced | Chain selection depends only on canonical observables; same candidates -> same tip | 6 | 2 | |
| T-CONS-02 | true | declared | Authoritative consensus decisions must not depend on wall-clock, arrival-order, scheduler, or OS behavior | 0 | 0 | |
| T-CONSERV-01 | true | enforced | UTxO and asset conservation must hold for every accepted transition, except where protocol rules explicitly authorize mint, burn, rewards, or treasury effects | 4 | 1 | |
| T-CORE-01 | true | enforced | Authoritative logic is pure, side-effect-free, and replayable | 2 | 2 | |
| T-CORE-02 | true | enforced | No wall-clock, unseeded randomness, floats, or nondeterministic collections in authoritative paths | 5 | 2 | |
| T-CORE-03 | true | declared | Explicit state transitions: consume old state, produce new state | 0 | 0 | |
| T-CORE-04 | true | declared | Illegal states unrepresentable via types where practical | 0 | 0 | |
| T-DET-01 | true | enforced | Same canonical inputs -> same authoritative bytes (per Byte Authority Model) | 21 | 3 | |
| T-ENC-01 | true | partial | All persisted/hashed/transmitted data uses canonical encoding | 3 | 1 | |
| T-ENC-02 | true | declared | Non-canonical bytes rejected deterministically | 0 | 0 | |
| T-ENC-03 | true | enforced | Round-trip identity: encode(decode(bytes)) == bytes for valid encodings | 19 | 1 | |
| T-EPOCH-01 | true | partial | Exactly one authoritative committee and governance interpretation per epoch | 10 | 0 | |
| T-ERR-01 | true | partial | Errors in authoritative paths are structured, comparable, canonical | 3 | 0 | |
| T-ERR-02 | true | declared | Safety violations fail-fast deterministically | 0 | 0 | |
| T-INGRESS-01 | true | declared | All authoritative external bytes enter the core through named canonical decode/validation chokepoints; unchecked bypasses forbidden except for explicitly whitel… | 0 | 1 | |
| T-KEY-01 | true | declared | Signing and private key operations confined to shell; verification in core | 0 | 0 | |
| T-NOSPEND-01 | true | enforced | No input or equivalent spend authority may be consumed more than once in an accepted canonical chain | 3 | 1 | |
| T-PLATFORM-01 | true | declared | No host-environment property (locale, timezone, architecture, platform) may influence authoritative computation results | 0 | 0 | |
| T-REC-01 | true | enforced | Recovery is replay-equivalent: restart produces byte-identical state to clean run | 9 | 2 | |
| T-REC-02 | true | enforced | All authoritative state derivable by replay from inputs | 2 | 1 | |
| T-REC-03 | true | enforced | Loop-as-replay: the same recovered/bootstrapped state + the same ordered canonical block feed (NodeBlockSource) + the same deterministic loop inputs + the same … | 1 | 1 | |
| T-REC-04 | true | enforced | The WarmStart-recovered forge `chain_dep.epoch_nonce` (eta0) MUST come from the imported/recovered consensus input, never from a snapshot placeholder and never … | 5 | 1 | |
| T-REC-05 | true | enforced | Replay/recovery equivalence including forged admits. Same BootstrapAnchor + same WAL (including forged AdmitBlock entries) -> byte-identical recovered durable t… | 6 | 0 | |
| T-REC-06 | true | enforced | Rollback-materialization replay-equivalence (PHASE4-N-AN). A block that validates during live admit (against the eta0-overlaid chain_dep, T-REC-04) MUST NOT fai… | 2 | 1 | |
| T-RESOURCE-01 | true | declared | Untrusted inputs must not allocate unbounded authoritative resources before deterministic validation | 0 | 0 | |
| T-TRANSPORT-01 | true | declared | Transport nondeterminism (socket fragmentation, mux ordering, timeouts) must not leak into authoritative logic | 0 | 0 |