Invariants / CN-KES-HEADER-01

CN-KES-HEADER-01

CN derived enforced

The KES signature in a forged block's header is over the canonical unsigned-header CBOR pre-image — the CBOR encoding of ShelleyHeaderBody (the first element of the outer [header_body, kes_signature] header array). The producer-side recipe (unsigned_header_pre_image) and the validator-side extractor (header_input::decode_block.header_input.kes.header_body_bytes) produce byte-identical output for every corpus block. The branded UnsignedHeaderPreImage(Vec) type's only constructor is the canonical recipe; kes_sign_header accepts only this type — arbitrary-byte signing is mechanically unrepresentable.

Source

docs/planning/phase4-n-s-invariants.md §1 (I1, I2); §2 (N1, N2)

Cluster
PHASE4-N-S-A
Introduced in
PHASE4-N-S-A

Enforcement trace

Tests 3

  • unsigned_header_preimage_matches_decode_block_extraction_for_corpus
  • recipe_output_is_byte_identical_across_two_runs
  • shell_kes_sign_header_produces_verifiable_signature

Cross-references

Strengthened in