Invariants / DC-CONS-23

DC-CONS-23

DC derived enforced

Own-forged stale-tip race safety by extend-only durable admit. An own-forged candidate is admitted to the durable tip ONLY if it EXTENDS the current durable tip at admit time, through the existing EXTEND-ONLY durable admit validation path (receive_apply -> admit_via_block_validity -> block_validity, incl. header_position). If a feed block advanced the tip after forge time (the forge<->feed race), the forged candidate FAILS CLOSED -- via header-position / prev_hash validation, TipBeforeDurable, or WAL prior_fp mismatch -- and the next forge tick re-forges on the current durable tip. N-U adds NO admit-time fork-choice and NO own-block override path. DC-CONS-03 (select_best_chain) remains the fork-choice authority in the follow / chain_selector paths -- NOT the durable admit.

Source

docs/planning/phase4-n-u-forged-block-durability-invariants.md

Introduced in
PHASE4-N-U

Enforcement trace

Cross-references

Strengthened in

Evidence notes

PHASE4-N-U S1 (2026-06-05). ENFORCED. A stale-tip forge (a re-mint block 0 admitted against a chain already at block 0) FAILS CLOSED at the extend-only durable admit -- block_validity rejects the non-extending block; the durable tip is unchanged (stale_tip_forge_fails_closed). No admit-time fork-choice was added (ci_check_forged_durable_admit_via_pump.sh fences select_best_chain/fork_choice absent from the driver); DC-CONS-03 stays the fork-choice authority in the follow/chain_selector paths. Reframed at /cluster-plan from the sketch's (incorrect) fork-choice framing after code investigation confirmed the durable admit is extend-only.