Invariants / CN-CINPUT-03

CN-CINPUT-03

CN constraint enforced

Consume-side anti-laundering fence: on the node-lifecycle forge path the leadership view MUST be projected from the recovered SeedEpochConsensusInputs surface (PoolDistrView::from_seed_epoch_consensus_inputs over the recovered BootstrapState) and MUST NOT be built from a forge-time operator bundle. No SeedEpochConsensusInputs value may be CONSTRUCTED on the production forge path (no shape-swap of an operator bundle into the recovered-surface type), and the forge-time consensus-input tokens (import_live_consensus_inputs / pool_distr_view_from_consensus_inputs / --consensus-inputs-path) MUST NOT appear in the node-sync/forge driver. Enforced by a data-flow-resistant containment gate (guard (d) of ci_check_consensus_input_provenance.sh: positive recovered- projection grep + negative bundle/cold-token grep + no-literal-construction fence over the comment/test-stripped run_node_sync/forge body), not a bypassable RHS grep.

Source

docs/clusters/PHASE4-N-F-C/cluster.md; L5-produce-from-recovered-state.md

Cluster
PHASE4-N-F-C
Introduced in
PHASE4-N-F-C

Enforcement trace

Tests 2

  • forge_from_recovered_uses_recovered_pool_distr
  • forge_from_recovered_fails_closed_without_recovered_inputs

Cross-references

Attack rationale

If the node-lifecycle forge path could construct (or be fed) a SeedEpochConsensusInputs-shaped object from a forge-time operator bundle, the 'forge from recovered Ade state' guarantee would collapse into a relabeled operator input at the moment of block production — the laundering class CN-CINPUT-02 fences on the populate side, closed here on the consume side.