CN-CONS-07
CN release enforcedSelf-acceptance bridge + serve provenance. A forged block is NOT eligible for RED broadcast unless Ade's own header validator (PHASE4-N-B path) and body validator (PHASE4-B1 path) accept it under the same slot, era, and context. Self-acceptance failure halts the producer deterministically. RED broadcast is gated on the BLUE self-accept verdict. SERVE PROVENANCE (no unvalidated bytes leave the node): every byte the node serves to a peer (ChainSync header advertisement / BlockFetch body) traces to the single validated admit path -- for --mode node, a deterministic PROJECTION of the durable ChainDb (whose sole production writers are pump_block / DC-NODE-12 and the validated warm-start / genesis replay bootstrap_initial_state), covering BOTH forged (self_accept) and received (admit_via_block_validity) durable bytes through the one durable admit; for --mode produce, the self_accept'd AcceptedBlock served-chain index. PHASE4-N-U restates the serve clause from the in-memory-token dependency (N-G S2: served bytes must originate as a live AcceptedBlock token, lost on restart) to durable-provenance -- PRESERVING the TRUE invariant (no unvalidated bytes leave) while letting serve follow the durable chain (a follower fetches coherent history A->B, never B without A; serve survives restart). See DC-NODE-13.
- Source
docs/planning/phase4-n-c-invariants.md §1 (NC-SELF-1); docs/clusters/PHASE4-N-U/S3-serve-as-durable-chain-projection.md (serve-provenance restatement)
- Introduced in
- PHASE4-N-C
Enforcement trace
Code
- crates/ade_ledger/src/producer/self_accept.rs
- crates/ade_ledger/src/block_validity/transition.rs
- crates/ade_ledger/src/producer/served_chain.rs
- crates/ade_runtime/src/network/served_chain_projection.rs
- crates/ade_runtime/src/network/serve_dispatch.rs
- crates/ade_ledger/src/receive/admitted.rs
- crates/ade_ledger/src/receive/chain_write.rs
Tests 15
- self_accept_accepts_freshly_forged_block
- self_accept_rejects_corrupted_body_hash
- self_accept_rejects_invalid_kes_signature
- self_accept_rejects_unbalanced_tx_in_body
- broadcast_callable_only_with_accept_verdict
- served_chain_admit_admits_corpus_block
- served_chain_admit_idempotent_on_byte_identity
- served_chain_admit_independent_of_order
- served_chain_snapshot_iteration_is_btreemap_ordered
- served_chain_block_bytes_accessor_returns_accepted_block_slice
- served_chain_range_bytes_returns_inclusive_window
- served_chain_fingerprint_replay_byte_identical
- admit_via_block_validity_accepts_corpus_block
- admit_via_block_validity_rejects_corrupted_body
- receive_apply_block_delivered_with_matching_header_admits
Cross-references
Strengthened in
Attack rationale
Prevents Ade from broadcasting blocks its own validator would reject — eliminates producer/validator drift as a release failure mode. PHASE4-N-G strengthening: prevents the network seam from being an end-run around the gate; bytes that reach the wire must trace through AcceptedBlock -> ServedChainSnapshot. PHASE4-N-H strengthening: prevents the receive seam from being an end-run; bytes that reach ChainDb via the receive path must trace through AdmittedBlock (the mirror token) — same block_validity authority, two separate gate tokens (AcceptedBlock for broadcast, AdmittedBlock for admission). PHASE4-N-U strengthening (serve clause): closes the durable-serve seam — when --mode node serves its adopted chain (forged AND received) to followers, the bytes are a read-only projection of the durable ChainDb whose sole production writers are pump_block (DC-NODE-12) + the validated warm-start replay; serving cannot leak a byte that did not clear block_validity. The restatement is a strict generalization of the N-G token-proof (the durable ChainDb is precisely where the AcceptedBlock + AdmittedBlock gate outputs land, durable-before-tip), not a relaxation.
Evidence notes
Cardano-specific only in that the validators it wraps are Ade's Cardano-block validators (PHASE4-N-B + PHASE4-B1). The bridge pattern is general: producer authority must agree with validator authority before bytes leave BLUE. N-G S2 extends the bridge into the producer-side server pump's read path. N-H S1/S2 establishes the receive-side mirror: AdmittedBlock private-constructor token consumed by ChainDbWrite. The producer + receive gates are deliberately separate types so cross-use is mechanically impossible (¬P-6).