Invariants / DC-CONS-11
DC-CONS-11
DC derived enforcedOpCert kes_period field equals the KES period at the forged slot under an operator-supplied anchor. period_at_slot(slot, anchor) = (slot - anchor) / slots_per_kes_period (integer floor). BLUE rejects header/opcert combinations with mismatched periods at forge time. BLUE MUST NOT infer the anchor from wall-clock or filesystem state; the anchor is a pure input on the canonical ProducerTick.
- Source
docs/planning/phase4-n-c-invariants.md §1 (NC-KES-3/4); Praos / Shelley operational-certificate specification
- Introduced in
- PHASE4-N-C
Enforcement trace
Tests 6
- opcert_validate_accepts_canonical_fixture
- opcert_validate_rejects_period_mismatch
- opcert_validate_rejects_short_hot_vkey
- opcert_validate_first_opcert_no_prev_counter
- opcert_encoder_matches_cardano_cli_byte_identical
- opcert_round_trip_byte_identical