Invariants / CN-PUMP-01

CN-PUMP-01

CN release enforced

Single admission wire-pump entry per peer: exactly one pub async fn ade_runtime::admission::wire_pump::run_admission_wire_pump drives the per-peer pump that produces AdmissionPeerEvents. The pump owns the MuxTransportHandle and runs the chain-sync + block-fetch state machine. The pump is the SOLE producer on the runner's peer_events channel. No second pump path; no per-call fallback.

Source

docs/planning/phase4-n-m-c-operator-pass-invariants.md §1 (I-C5)

Enforcement trace

Tests 5

  • admission::wire_pump::tests::pump_emits_tip_update_and_request_next_on_intersect_found_no_block_fetch
  • admission::wire_pump::tests::pump_emits_tip_update_on_intersect_not_found
  • admission::wire_pump::tests::rollforward_drives_block_fetch_then_request_next
  • admission::wire_pump::tests::extract_chain_sync_header_point_returns_slot_and_hash
  • admission::wire_pump::tests::extract_chain_sync_header_point_rejects_malformed_envelope

Cross-references

Strengthened in

Evidence notes

PHASE4-N-M-FOLLOW (2026-05-27) strengthens by making the pump follow the peer's chain in order: IntersectFound emits TipUpdate + RequestNext (no tip-jump block-fetch); each RollForward extracts a Point from the header envelope and block-fetches it; chain-sync RequestNext gates on block-fetch BatchDone. Live sustained pass against docker preprod admits 34 consecutive blocks (slot range 124137045..124137868) with 0 divergence — committed transcript at docs/evidence/phase4-n-m-follow-sustained-transcript.jsonl.