Invariants / CN-CONS-08

CN-CONS-08

CN release enforced

Receive-side single admission authority: every block that lands in ChainDb via the receive path passed block_validity with BlockValidityVerdict::Valid. No bypass, no header-only fast path, no trusted-prefix mode. Invalid verdicts leave receive state unchanged and halt the peer pipeline with a structured error; no silent skip, no partial application. Receive-side analog of CN-CONS-07 (broadcast gate).

Source

docs/planning/receive-side-bridge-invariants.md §1 (I-1, folds I-7)

Cluster
PHASE4-N-H
Authority surface
receive-side block admission gate

Enforcement trace

Tests 6

  • admit_via_block_validity_accepts_corpus_block
  • admit_via_block_validity_rejects_corrupted_body
  • receive_apply_block_delivered_with_matching_header_admits
  • receive_apply_block_delivered_validity_invalid_rejects
  • receive_apply_rollback_returns_out_of_scope
  • receive_apply_replay_byte_identical_over_corpus

Cross-references

Strengthened in

Attack rationale

A peer that can sneak unvalidated bytes into our ChainDb pollutes the ledger downstream and forces divergence from the rest of the network.

Evidence notes

Enforcement is type-level: AdmittedBlock token has a private constructor reachable only from a block_validity::Valid branch; the ChainDb-write wrapper takes AdmittedBlock by value. AdmittedBlock is deliberately a distinct type from AcceptedBlock to keep producer/receive gates non-interfering.

Evidence

  • AdmittedBlock has a private constructor reachable only from admit_via_block_validity. The reducer's BlockDelivered branch runs admit_via_block_validity, persists through ChainDbWrite, and only then commits state. Failure on validity invalid leaves state unchanged (test receive_apply_block_delivered_validity_invalid_rejects).

  • RollBackward returns RollbackOutOfScope per Path A scope; receive state stays consistent (test receive_apply_rollback_returns_out_of_scope).

  • ChainDbWrite trait takes AdmittedBlock by value; no path persists raw bytes.

  • PHASE4-N-I strengthening: admit + rollback symmetry — every rollback materializes via the same block_validity authority (replay-forward fold composes block_validity per block). materialize_rolled_back_state is the SOLE pub fn returning (LedgerState, PraosChainDepState) — CN-STORE-07 mirrors this admission gate for the rollback path.

  • PHASE4-N-K strengthening: admit path now driven end-to-end by the production orchestrator (orchestrator::core::step) via the GREEN dispatch_*_inbound wrappers. The orchestrator never reconstructs AdmittedBlock and never bypasses receive_apply; per-peer dispatch errors halt only that peer (DC-NODE-01).