CN-CONS-08
CN release enforcedReceive-side single admission authority: every block that lands in ChainDb via the receive path passed block_validity with BlockValidityVerdict::Valid. No bypass, no header-only fast path, no trusted-prefix mode. Invalid verdicts leave receive state unchanged and halt the peer pipeline with a structured error; no silent skip, no partial application. Receive-side analog of CN-CONS-07 (broadcast gate).
- Source
docs/planning/receive-side-bridge-invariants.md §1 (I-1, folds I-7)
- Cluster
- PHASE4-N-H
- Authority surface
- receive-side block admission gate
Enforcement trace
Code
Tests 6
- admit_via_block_validity_accepts_corpus_block
- admit_via_block_validity_rejects_corrupted_body
- receive_apply_block_delivered_with_matching_header_admits
- receive_apply_block_delivered_validity_invalid_rejects
- receive_apply_rollback_returns_out_of_scope
- receive_apply_replay_byte_identical_over_corpus
Cross-references
Strengthened in
Attack rationale
A peer that can sneak unvalidated bytes into our ChainDb pollutes the ledger downstream and forces divergence from the rest of the network.
Evidence notes
Enforcement is type-level: AdmittedBlock token has a private constructor reachable only from a block_validity::Valid branch; the ChainDb-write wrapper takes AdmittedBlock by value. AdmittedBlock is deliberately a distinct type from AcceptedBlock to keep producer/receive gates non-interfering.
Evidence
AdmittedBlock has a private constructor reachable only from admit_via_block_validity. The reducer's BlockDelivered branch runs admit_via_block_validity, persists through ChainDbWrite, and only then commits state. Failure on validity invalid leaves state unchanged (test receive_apply_block_delivered_validity_invalid_rejects).
RollBackward returns RollbackOutOfScope per Path A scope; receive state stays consistent (test receive_apply_rollback_returns_out_of_scope).
ChainDbWrite trait takes AdmittedBlock by value; no path persists raw bytes.
PHASE4-N-I strengthening: admit + rollback symmetry — every rollback materializes via the same block_validity authority (replay-forward fold composes block_validity per block). materialize_rolled_back_state is the SOLE pub fn returning (LedgerState, PraosChainDepState) — CN-STORE-07 mirrors this admission gate for the rollback path.
PHASE4-N-K strengthening: admit path now driven end-to-end by the production orchestrator (orchestrator::core::step) via the GREEN dispatch_*_inbound wrappers. The orchestrator never reconstructs AdmittedBlock and never bypasses receive_apply; per-peer dispatch errors halt only that peer (DC-NODE-01).