CN-NODE-02
CN constraint_network enforced--mode node is the single live-run lifecycle owner. The relay run loop may
advance authoritative state ONLY by invoking existing closed seams
(bootstrap_initial_state for initial state; run_node_sync -> pump_block for tip
advance). It MUST NOT introduce any alternate bootstrap, apply, forge, evidence,
or tip-advance path, and no second binary arm may drive the live node. Relay-only
this cluster: no forge / evidence path is wired (those are a fenced successor
sub-cluster). The GREEN loop planner emits only a closed lifecycle vocabulary
{ SyncOnce, Idle, HaltCleanly } and cannot express an authority decision.
- Source
docs/planning/phase4-n-f-d-live-node-run-loop-invariants.md
- Introduced in
- PHASE4-N-F-D
Enforcement trace
Tests 5
- relay_loop_syncs_then_halts_clean_on_source_end
- relay_loop_halts_clean_on_shutdown_no_partial_write
- relay_loop_idles_then_syncs_on_incremental_feed
- relay_loop_fails_closed_on_unapplyable_block
- plan_loop_step_forge_precedence_table_is_total
Cross-references
Strengthened in
Attack rationale
A long-running RED loop is the natural place for authority to leak: a "quick" inline apply, a fallback recovery path, a manual put_block to "catch up", or a self-certifying evidence shortcut. Any of these would let unverified state reach the tip outside the closed seams that carry the Mithril binding, durable-before-advance ordering, and self-accept gates. Pinning the loop to the existing seams (RED performs effects, GREEN plans iteration, BLUE authority stays behind the seams) makes that unrepresentable.
Evidence notes
PHASE4-N-F-D invariant sketch (2026-05-31). To be enforced by a new N-F-D containment gate (loop body advances the tip only via run_node_sync; no second bootstrap/apply/forge/evidence/manual-tip path) plus the closed GREEN LoopStep vocabulary. tests + ci_script populated at slice time.