Invariants / CN-STORE-08

CN-STORE-08

CN release enforced

Single encoder authority: encode_ledger_state + decode_ledger_state

  • encode_chain_dep + decode_chain_dep + encode_snapshot + decode_snapshot are the SOLE pub fn pairs in the project encoding or decoding LedgerState / PraosChainDepState / (LedgerState, PraosChainDepState) to/from bytes. No parallel canonical encoders. Type-level + CI grep enforcement, mirroring CN-STORE-07.

Source

docs/planning/persistent-snapshot-encoder-invariants.md §1 (I-5)

Enforcement trace

Cross-references

Strengthened in

Attack rationale

A parallel encoder may produce bytes that don't satisfy round-trip equivalence — a corruption attack vector if the wrong encoder is invoked.

Evidence notes

Enforcement is type-level (single module hosts the encoder/decoder pair) + CI grep (no other pub fn returning Vec from &LedgerState or &PraosChainDepState across the workspace). PHASE4-N-K (2026-05-26) strengthening: encode/decode now driven end-to-end by the production orchestrator (bootstrap warm-start, PersistentSnapshotWriter, ade_node shutdown drain). All callers route through the single framing module — no node-binary-side reimplementation.