Invariants / DC-EPOCH-13

DC-EPOCH-13

DC derived enforced

No semantic activation gate: no build- or runtime-level switch decides WHETHER the epoch-view activation occurs. There is no EVIEW_ACTIVATION_ARMED const, no armed parameter, no if !armed short-circuit, and no equivalent env var / build feature / CLI option anywhere in crates/. Activation is AUTOMATIC and DETERMINISTIC: the ONLY gate is the activation predicate over canonical durable state (candidate exists + bindings match the selected chain + source window complete + readiness valid + activation WAL durable => promote; else => structured terminal halt). maybe_activate_first_boundary proceeds to the sole authoritative activation whenever the seed epoch's window is COMPLETE (the durable tip located in a LATER epoch via era_schedule.locate -- never the wall clock) AND no view is promoted yet (idempotent); it fails closed (terminal ActivationError) on any error. The non-EVIEW byte-identical guarantee keys on CANONICAL STATE (the EVIEW cert-state package / reduced checkpoint absent => no EVIEW), never a flag: maybe_activate_epoch_boundary short-circuits only when (eview_activation, reduced_checkpoint) is not (Some, Some). Every replay of the same durable inputs makes the same activation decision.

Source

docs/clusters/EPOCH-CONSENSUS-VIEW/SLICE-ECA-1-remove-activation-gate.md; user directive 2026-06-21 (a build/runtime flag deciding whether a consensus transition occurs is a forbidden semantic gate; activation must be automatic + deterministic from canonical state; the predicate is the only gate)

Introduced in
EPOCH-CONTINUITY-ACTIVATION-ECA-1

Enforcement trace

Cross-references

Attack rationale

A flag/env/build switch that decides whether a consensus transition happens is a mixed/variable semantic surface: two builds (or two operators) of the same node would make DIFFERENT activation decisions on the same durable chain, and a replay could not reproduce the decision -- exactly the closed-semantic-surface + replay-equivalence violation the doctrine forbids. ECA-1 removes the scaffold entirely: ci_check_eview_automatic_activation.sh negative-greps that EVIEW_ACTIVATION_ARMED / an armed: bool param / an if !armed guard appear NOWHERE in crates/, and positive-asserts the orchestration gates ONLY on deterministic boundary detection (era_schedule.locate) + the idempotent promoted check + the canonical-state presence (Some inputs + Some checkpoint) + the predicate (activate_at_boundary). The proof maybe_activate_first_boundary_is_automatic_and_fails_closed_not_flag_gated shows a crossed boundary AUTOMATICALLY drives the activation and fails closed on an empty window (where the removed flag would have no-opped), never promoting against an unproven state. The remaining inert binding (eview_activation = None) is canonical-state-keyed un-finished wiring (ECA-2 constructs it from the EVIEW package), NOT a flag -- a non-EVIEW node has no cert-state package, so its byte-identical behavior is correct, not gated.

Evidence notes

Introduced at EPOCH-CONTINUITY-ACTIVATION ECA-1 (2026-06-21). Removes the EVIEW_ACTIVATION_ARMED dev scaffold (the const + the armed param threaded through EviewActivationInputs::maybe_activate -> maybe_activate_first_boundary + the if !armed short-circuit + the node_lifecycle call passing the const). NO equivalent flag replaces it (the negative grep over crates/ is the mechanical enforcement). The live follow/forge path stays BYTE-IDENTICAL: after ECA-1 the relay loop still binds eview_activation = None (inert), but ONLY because the deterministic construction of the inputs from canonical state is ECA-2 -- inert by un-finished wiring, never by a semantic gate. Strengthens DC-EPOCH-11 (its -wire arming gate is removed; the relay-loop activation call is now flag-free + keyed on canonical state). ade_node lib 366 green (incl. the new automatic-activation proof); ci_check_eview_automatic_activation.sh + ci_check_eview_live_checkpoint.sh (18)/(19) updated green. The user's forbidden-gate correction: success is NOT 'did someone flip the flag at one boundary' but Ade running continuously across the boundary with no manual arming/restart/import (ECA-2..5 deliver the live capability + proof).