Invariants / DC-CONS-19
DC-CONS-19
DC derived enforcedReceive-side header-body sourcing coherence: when BlockDelivered {block_bytes} arrives at the receive bridge, the decoded header bytes of block_bytes equal the header_bytes cached from the most recent RollForward at the same (slot, hash). A peer cannot switch headers between announcement and body delivery.
- Source
docs/planning/receive-side-bridge-invariants.md §1 (I-2)
- Cluster
- PHASE4-N-H
- Authority surface
- receive-side header-body cross-check
Enforcement trace
Tests 3
- receive_apply_block_delivered_with_no_cached_header_rejects
- receive_apply_block_delivered_with_mismatched_cached_header_rejects
- receive_apply_block_delivered_with_matching_header_admits
Cross-references
Evidence
The reducer's BlockDelivered branch derives (slot, block_hash) from decode_block then looks up the cache at that key. Absent or key-mismatched → HeaderBodyMismatch. block_hash = blake2b_256(header_sub_slice) binds header content to the key; a cached entry at a matching key has bytes that hash to the same block_hash by construction.