CN-PROD-03
CN derived enforcedproduce_mode's forge base state is derived from bootstrap_initial_state (cold-start, fed the operator-seeded ledger from --json-seed + --consensus-inputs) plus the bundle-projected PoolDistrView, epoch nonce (eta0), and absolute slot from the bootstrap tip. SyntheticForgeInputs / build_synthetic_forge_context are deleted; no zero-stake / LedgerState::new / constant-prev-hash forge base remains. The sole path to produce_mode's initial state is the single bootstrap_initial_state authority (no parallel synthetic path). Cold-start branch only; warm-start recovery is Problem 2, deferred to N-U.
- Source
docs/planning/phase4-n-t-invariants.md §1 (A1, A2, A6); docs/clusters/PHASE4-N-T/cluster.md §1
- Cluster
- PHASE4-N-T
- Introduced in
- PHASE4-N-T
Enforcement trace
Code
Tests 2
- produce_cli_requires_seed_and_consensus_inputs
- produce_mode_bootstrap_cold_start_seeds_real_ledger
Cross-references
Attack rationale
Cardano-specific: forging against synthetic zero-stake / empty-ledger state produces blocks that are never leader-eligible and never extend the real chain — a producer that silently forges off fake state would either never win a slot or fork off a non-canonical base. Binding the forge base to the single bootstrap authority makes a synthetic-state producer structurally impossible.
Evidence notes
S5 CI gate ci_check_produce_mode_uses_bootstrap_initial_state.sh: positive grep (bootstrap_initial_state( call present in produce_mode) + negative grep (no SyntheticForgeInputs / build_synthetic_forge_context / inline LedgerState::new( forge-base). Cold-start branch only; warm-start is test-only until N-U.