Invariants / CN-SESS-05

CN-SESS-05

CN derived enforced

Outbound mini-protocol payloads larger than MAX_PAYLOAD are segmented into ordered mux frames, each no larger than MAX_PAYLOAD, preserving mini-protocol id, mode, and byte order. Concatenating segment payloads reconstructs the original payload exactly. Payloads above MAX_OUTBOUND_PAYLOAD_BYTES fail closed. Segmentation uses the single existing frame encoder authority and is the outbound inverse of CN-SESS-04 inbound reassembly.

Source

docs/clusters/PHASE4-N-AB/cluster.md §1; project_pre_rolive_hardening_queue.md item 2

Cluster
CL-WIRE-PROTOCOL
Introduced in
PHASE4-N-AB
Authority surface
wire-layer outbound segmentation across mux frame boundaries

Enforcement trace

Tests 7

  • crates/ade_network/src/session/core.rs::tests::outbound_payload_at_max_payload_is_one_frame
  • crates/ade_network/src/session/core.rs::tests::outbound_payload_over_max_payload_segments_into_two
  • crates/ade_network/src/session/core.rs::tests::outbound_segment_order_preserved
  • crates/ade_network/src/session/core.rs::tests::outbound_segments_keep_same_mini_protocol_id_and_mode
  • crates/ade_network/src/session/core.rs::tests::outbound_large_payload_reassembles_byte_identical_via_inbound
  • crates/ade_network/src/session/core.rs::tests::outbound_payload_at_upper_bound_is_allowed
  • crates/ade_network/src/session/core.rs::tests::outbound_payload_over_upper_bound_fails_closed

Cross-references

Evidence notes

Declared at cluster scoping (2026-06-06, user-confirmed). Pre-RO-LIVE hardening item 2. The outbound inverse of CN-SESS-04: that rule made Ade REASSEMBLE inbound multi-frame payloads (Conway blocks > 65535-byte mux SDU limit); this rule makes Ade SEGMENT its own outbound payloads the same way, so a large served BlockFetch Block is transmittable. Before N-AB, handle_outbound + encode_inner_frame both errored (OutboundPayloadTooLarge) above MAX_PAYLOAD = 65535 -> Ade could receive but not send large blocks. Design (GREEN session::core, no BLUE change): handle_outbound segments; encode_inner_frame stays strict single-frame; MAX_OUTBOUND_PAYLOAD_BYTES = 16 MiB (fixed, non-configurable; symmetric with the inbound MAX_REASSEMBLY_TAIL_BYTES / DC-LIVEMEM-01). Byte-preserving + lossless; one captured timestamp reused across a message's segments (GREEN calls no clock). Enforced at S1 with ci/ci_check_outbound_segmentation.sh + the 7 required tests; declared rows are skipped by ci_check_registry_code_locus_exists.sh.