Invariants / DC-CINPUT-06

DC-CINPUT-06

DC true enforced

The durable consensus PROFILE includes genesis_hash + protocol_params_hash, persisted canonically in the v4 SeedEpochConsensusInputs sidecar and recovered IDENTICALLY at warm-start -- the inputs to the ECA-0b consensus-profile commitment blake2b(domain ‖ genesis_hash ‖ protocol_params_hash ‖ asc) that derive_candidate binds and to_pool_distr_view re-verifies. They are NOT optional EVIEW metadata: a continuous producer must recover the FULL profile from the STORE, never from a restart CLI/config/genesis (the same durable-authority rule as DC-CINPUT-05 venue geometry) and never by recomputing protocol_params_hash from reserialized params (byte-sensitive -- the hash is over the IMPORTED protocol-params JSON). Schema bumped v3->v4 (SEED_CINPUT_SCHEMA_VERSION=4, FIELDS_OUTER=11; the two bytes(32) encode/decode after epoch_nonce); merge_seed_epoch_consensus_inputs populates both from the canonical import bundle; the persist writes v4 bytes BEFORE state is usable. Old v1/v2/v3 sidecars fail closed at decode (UnknownVersion); the bootstrap authority maps a pre-v4 version mismatch to the TYPED, recoverable, auditable BootstrapError::ConsensusInputsSchemaUnsupported{found_version, required_version} (a reimport requirement), DISTINCT from corruption (SeedConsensusSidecarDecode). The fingerprint/WAL provenance (sidecar_hash over the full bytes) AND the BootstrapManifest seed_hash = blake2b_256(sidecar bytes) binding both cover the two new hashes TRANSITIVELY (no manifest format change). No CLI/config/genesis fallback, no recompute. The single recovered consensus-profile authority surface (rejected: splitting the profile across the seed sidecar + a separate EVIEW manifest, which creates a seed-says-A / manifest-says-B mismatch class).

Source

docs/clusters/EPOCH-CONSENSUS-VIEW/SLICE-ECA-2-pre-seed-sidecar-v4.md; user directive 2026-06-21 (the consensus profile is a single recovered authority surface; persist genesis_hash + protocol_params_hash in the v4 sidecar; no separate EVIEW manifest authority, no runtime fallback, no recomputation; typed upgrade error not corruption)

Introduced in
EPOCH-CONTINUITY-ACTIVATION-ECA-2-pre

Enforcement trace

Tests 5

  • seed_epoch_consensus_inputs_round_trips_byte_identical
  • seed_cinput_canonical_bytes_cover_the_consensus_profile_hashes
  • seed_cinput_decode_rejects_unknown_version
  • merge_persists_consensus_profile_hashes
  • warm_start_pre_v4_sidecar_is_typed_schema_upgrade_not_corruption

Cross-references

Attack rationale

Without a durable home, genesis_hash + protocol_params_hash would have to be re-supplied from the restart CLI/config or recomputed at runtime -- both are durable-authority splits (the same class DC-CINPUT-05 closed for venue geometry): the same store + WAL replays/projects DIFFERENTLY depending on restart args, and an operator (or an attacker with CLI access) could swap the consensus profile a recovered store leadership-projects under by passing a different genesis/protocol-params. Recomputing protocol_params_hash from parsed params is worse: the hash is over the IMPORTED JSON bytes, so a re-serialization can differ silently -> a commitment mismatch that fails the ECA-0b projection (or, if the recompute is treated as authority, a WRONG leadership distribution). v4 closes both: the hashes are persisted in the fingerprint/manifest-bound sidecar and recovered byte-identically; a pre-v4 store cannot silently default them -- it fails closed with the TYPED ConsensusInputsSchemaUnsupported (a reimport requirement, distinct from corruption, so the failure is recoverable + auditable rather than a confusing 'corrupt store'). The single-authority-surface choice (vs a separate EVIEW manifest) removes a whole mismatch class (seed-says-profile-A / manifest-says-profile-B).

Evidence notes

Introduced at EPOCH-CONTINUITY-ACTIVATION ECA-2-pre (2026-06-21). The prerequisite for ECA-2 (the deterministic EviewActivationInputs construction): 8 of the 10 activation-input fields were already recoverable from canonical durable state; genesis_hash + protocol_params_hash were not (they lived only in the import-phase LiveConsensusInputsCanonical bundle). User directive: persist them in the SAME sidecar as eta0/asc/venue-geometry (the established durable consensus-inputs authority), v3->v4. Proven: seed_epoch_consensus_inputs_round_trips_byte_identical (v4 round-trips with both hashes); seed_cinput_canonical_bytes_cover_the_consensus_profile_hashes (a change to either hash changes the canonical bytes -> covered by sidecar_hash + manifest seed_hash); seed_cinput_decode_rejects_unknown_version (v1/v2/v3 -> UnknownVersion, expected=4); merge_persists_consensus_profile_hashes (the merge carries both from the bundle); warm_start_pre_v4_sidecar_is_typed_schema_upgrade_not_corruption (a well-formed pre-v4 sidecar -> ConsensusInputsSchemaUnsupported{found:3, required:4}, distinct from a corrupt buffer -> SeedConsensusSidecarDecode). All ~18 SeedEpochConsensusInputs construction sites updated (the two bootstrap 'expected' comparisons mirror the bundle's hashes; the merge is the sole real constructor). Workspace compiles; ade_ledger + ade_runtime + ade_node + ade_testkit green. OPERATIONAL: existing v1/v2/v3 stores must be re-imported (the DC-CINPUT-05 v2->v3 precedent); the off-repo EVIEW package's seed artifact must be produced at v4 so its manifest seed_hash binds the v4 bytes. ECA-2 (next) consumes these recovered hashes to build EviewActivationInputs; this slice only makes them durable + recoverable, fail-closed.