Invariants / DC-EPOCH-03

DC-EPOCH-03

DC derived enforced

Single-epoch forge containment on the --mode node spine: in this forge path, a forge is valid only within the single recovered seed epoch. A candidate forge slot beyond the recovered seed epoch FAILS CLOSED -- it cannot be forged, served, or signed as a valid block. The seed-epoch nonce (eta0) is frozen at the recovered value; the forge apply path does NOT drive the BLUE CandidateFreeze / EpochBoundary nonce transitions (they exist in ade_core::consensus::nonce but nothing drives them on the forge path), so signing past the boundary with a stale eta0 is a peer-reject class and is forbidden, not silently attempted. Cross-epoch production (nonce roll + epoch transition driven from an epoch-aware tick + follow/durability) is a SEPARATE nonce-roll/epoch-transition cluster, NOT this one. The off-epoch slot fails closed with a structured local outcome (a fail-closed boundary for this single-epoch forge path, hardening DC-NODE-05's single-epoch cluster-scope containment for the live-serve path).

Source

docs/planning/phase4-n-f-g-invariants.md

Introduced in
PHASE4-N-F-G-A

Enforcement trace

Tests 6

  • forge_epoch_admission_within_seed_epoch_admits
  • forge_epoch_admission_off_epoch_fails_closed
  • forge_epoch_admission_unlocatable_fails_closed
  • node_forge_off_epoch_slot_fails_closed
  • node_forge_no_epoch_boundary_promotion_on_forge_path
  • forge_tick_off_epoch_slot_fails_closed_local

Cross-references

Strengthened in

Evidence notes

PHASE4-N-F-G invariant sketch (/invariants gate). Declared at sketch. Single-epoch scope (OQ3) resolved with the user: do NOT patch nonce rollover into this cluster. The BLUE nonce authority's epoch-boundary transitions are present but undriven on the forge path (verified C1 scoping pass section 4a); this rule makes the boundary a fail-closed wall rather than a stale-eta0 sign. tier = derived (Cardano-specific in its Praos nonce / KES-period / leader-VRF details).