Invariants / DC-CONS-12

DC-CONS-12

DC derived enforced

OpCert serial counter is strictly monotonically increasing per (cold-key, node). BLUE rejects regression or repetition at the RED->BLUE boundary: opcert_validate fails when prev_counter is Some(c) and opcert.counter <= c. RED feeds the value from durable per-node state; BLUE never trusts an in-memory-only counter.

Source

docs/planning/phase4-n-c-invariants.md §1 (NC-OC-2); Cardano operational-certificate counter discipline

Introduced in
PHASE4-N-C

Enforcement trace

Tests 3

  • opcert_validate_rejects_counter_regression
  • opcert_validate_rejects_counter_repeat
  • opcert_validate_rejects_bad_signature_over_cold_key

Cross-references