Invariants / CN-PROD-03

CN-PROD-03

CN derived enforced

produce_mode's forge base state is derived from bootstrap_initial_state (cold-start, fed the operator-seeded ledger from --json-seed + --consensus-inputs) plus the bundle-projected PoolDistrView, epoch nonce (eta0), and absolute slot from the bootstrap tip. SyntheticForgeInputs / build_synthetic_forge_context are deleted; no zero-stake / LedgerState::new / constant-prev-hash forge base remains. The sole path to produce_mode's initial state is the single bootstrap_initial_state authority (no parallel synthetic path). Cold-start branch only; warm-start recovery is Problem 2, deferred to N-U.

Source

docs/planning/phase4-n-t-invariants.md §1 (A1, A2, A6); docs/clusters/PHASE4-N-T/cluster.md §1

Cluster
PHASE4-N-T
Introduced in
PHASE4-N-T

Enforcement trace

Tests 2

  • produce_cli_requires_seed_and_consensus_inputs
  • produce_mode_bootstrap_cold_start_seeds_real_ledger

Cross-references

Attack rationale

Cardano-specific: forging against synthetic zero-stake / empty-ledger state produces blocks that are never leader-eligible and never extend the real chain — a producer that silently forges off fake state would either never win a slot or fork off a non-canonical base. Binding the forge base to the single bootstrap authority makes a synthetic-state producer structurally impossible.

Evidence notes

S5 CI gate ci_check_produce_mode_uses_bootstrap_initial_state.sh: positive grep (bootstrap_initial_state( call present in produce_mode) + negative grep (no SyntheticForgeInputs / build_synthetic_forge_context / inline LedgerState::new( forge-base). Cold-start branch only; warm-start is test-only until N-U.

Open obligation