CN-CONS-03
CN derived enforcedAfter temporary partition, honest nodes must converge using only protocol-defined observables and declared emergency procedures
- Source
classification_table.md §D
Enforcement trace
Tests 3
- higher_block_no_wins
- equal_block_no_tiebreaker_decides
- tiebreaker_loss_keeps_current
Strengthened in
Attack rationale
Prevents ad hoc operator heuristics from becoming consensus inputs.
Evidence notes
Cardano-specific constraints on convergence mechanism beyond universal replay-equivalent convergence. FLIPPED to enforced at PHASE4-N-AO (CE-AO-6) on a NATURAL two-producer multi-candidate SELECT pass: ade_node @ commit 2a03ac73; transcript ao-CN-CONS-03-FLIP-natural-conv.jsonl, sha256 6713efe96ffd0e0fa304020c7784d6bbf11be0df0e3340e7feeab4d1429ca13f, preserved OUTSIDE the repo (competition-secrecy); captured 2026-06-13. NATURAL mode -- both Haskell producers (cn1/cn2, testnet-magic 42) live throughout, NO loser-freeze, NO post-fork operator intervention; the SELECT decision is entirely Ade's. Checker PASS (ci_check_post_switch_convergence_window.sh / the post_switch_continuity replayable reducer): ContinuesSelectedBranch, terminal AgreedAtSwitchTip{slot 391} (exact agreement, our_hash==peer_hash), 25 admitted descendants chained, 0 diverged, every fork-choice win terminal. SCOPE (honest): proves convergence for the EXERCISED two-producer partition-and-reconverge venue (PHASE4-N-AO S1-S14); NOT an unbounded multi-peer ChainSel claim; post-switch endless-flip-flop survival is out of scope. A FREEZE-mode run (loser paused AFTER Ade's decision) is retained OUTSIDE the repo as a SELECT-independence diagnostic only, never as flip evidence (a frozen peer also breaks the reducer's peer-observed-ahead terminal).