Invariants / DC-CINPUT-01

DC-CINPUT-01

DC derived enforced

WARM-START VERIFICATION CAPABILITY (authority surface — NOT production restart). The seed-epoch consensus-input import is a canonical, replay-reconstructable WAL fact: an additive closed WalEntry::SeedEpochConsensusInputsImported variant (distinct tag; does NOT participate in the AdmitBlock prior_fp/post_fp chain), appended AFTER the sidecar put (the WAL append is the commit point). Replay reconstructs a typed RecoveredBootstrapProvenance view (exactly one per store/anchor; duplicate or anchor-mismatch fails closed). Given that view, bootstrap_initial_state's warm-start branch (RequiredFromRecoveredProvenance) restores the sidecar and verifies it fail-closed: sidecar present, blake2b_256 == provenance.sidecar_hash, A1 decode, anchor_fp + epoch_no binding, byte- identity re-encode — exposing the recovered SeedEpochConsensusInputs or halting (typed BootstrapError, EXIT_AUTHORITY_FATAL_DECODE, no bundle fallback). This is proven on the AUTHORITY SURFACE (bootstrap_initial_state exercised directly); no production mode is wired to it (node.rs run_node_until_shutdown + recover_node_state are test-only; produce_mode cold-starts). The PRODUCTION restart path is this rule's open obligation, deferred to PHASE4-N-F-C.

Source

docs/clusters/PHASE4-N-F-A/cluster.md; A3a-wal-provenance-entry.md; A3b-warm-start-restore.md

Cluster
PHASE4-N-F-A
Introduced in
PHASE4-N-F-A

Enforcement trace

Tests 18

  • wal_seed_cinput_entry_round_trips_byte_identical
  • replay_yields_bootstrap_provenance_view
  • replay_rejects_duplicate_provenance_entry
  • replay_rejects_anchor_mismatched_provenance_entry
  • admit_block_chain_unaffected_by_provenance_entry
  • warm_start_restores_seed_epoch_consensus_inputs_byte_identical
  • warm_start_fails_closed_on_missing_sidecar
  • warm_start_fails_closed_on_hash_mismatch
  • warm_start_fails_closed_on_anchor_mismatch
  • warm_start_fails_closed_on_epoch_mismatch
  • warm_start_required_provenance_rejects_malformed_sidecar
  • warm_start_never_falls_back_to_consensus_inputs_path
  • warm_start_recovers_seed_epoch_consensus_inputs_byte_identical
  • warm_start_fails_closed_on_missing_wal_provenance
  • warm_start_fails_closed_on_duplicate_provenance
  • warm_start_fails_closed_on_multiple_anchor_lineages
  • warm_start_dispatch_succeeds_end_to_end
  • node_sync_kill_then_warm_start_recovers_same_tip

Cross-references

Strengthened in

Evidence notes

PHASE4-N-F-C (2026-05-31, L3): the PRODUCTION restart path is now wired. The --mode node lifecycle owner (crates/ade_node/src/node_lifecycle.rs::warm_start_recovery) opens PersistentChainDb + FileWalStore, replays via replay_from_anchor to a RecoveredBootstrapProvenance, and calls bootstrap_initial_state(RequiredFromRecoveredProvenance) — the same fail-closed verify chain proven at the A3b authority surface, now driven from the binary's warm-start branch. node.rs run_node_until_shutdown + recover_node_state remain the legacy test-only surface (untouched). L4c (node_sync_kill_then_warm_start_recovers_same_tip) additionally proves a synced+advanced tip recovers byte-identically through this same production path. Gate ci_check_lifecycle_owner_uses_bootstrap_initial_state.sh fences the owner against any genesis/bundle/cold/recover_node_state fallback.