DC-EPOCH-21
DC derived declaredThe accumulator's epoch-boundary transition reproduces the canonical cardano NEWEPOCH result. POOLREAP is a SINGLE transition in the cardano order (Shelley PoolReap.hs, which Conway reuses), consolidated inside the shared apply_epoch_boundary_with_registrations so the full-ledger and accumulator paths share ONE order whose halves cannot silently fail to compose: (a) adopt staged future-pool re-registrations (drop orphans); (b) reap the pools retiring at EXACTLY this epoch (== e, never <= e); (c) refund each reaped pool's deposit to its OWN reward-account credential decoded by the REAL key/script discriminant (registered -> that reward account, unregistered -> treasury); (d) clear the reaped pools' delegators where the reap happens, so the clear can never be dead; (e) remove the reaped pools from the active set + the retiring schedule. No split POOLREAP whose clear half silently no-ops (the pre-S3 bug: the inline retirement emptied the retiring map before a trailing apply_pool_reap could match == e, so the delegation-clear was dead code), and no KeyHash projection that misroutes a script-hash reward account. The boundary's reward update is computed over the held nesBprev and the go snapshot AFTER within-epoch withdrawals, and SNAP rotates mark->set->go with the new mark = the reduced-checkpoint stake aggregate -- these two (the discriminant-correct RUPD reward crediting, still keyed by bare Hash28, and the live mark wiring) are enforced PROGRESSIVELY as S3 lands its live-mark wiring and its byte-exact differential gate vs a live cardano-node.
- Source
docs/clusters/LIVE-LEDGER-EPOCH-TRANSITION/SLICE-S3-boundary-gate.md. Resolves the two S1-recorded byte-exact reconciliation items (POOLREAP completeness/ordering; reward-account credential discriminant) against the cardano-ledger source (Shelley Rules/PoolReap.hs) + the actual Ade boundary surfaces. The pre-S3 split (apply_epoch_boundary_with_registrations inline retirement + a trailing delegation::apply_pool_reap call in cross_epoch_boundary) left the delegation-clear DEAD because the inline retirement emptied the retiring map first, so the trailing reap's == e match found nothing.
- Introduced in
- LIVE-LEDGER-EPOCH-TRANSITION-S3
Enforcement trace
Code
no enforcing code — gap
Tests 2
- ade_ledger::rules::cert_state_dispatch::poolreap_ce3a (poolreap_reaps_exact_epoch_only -- == e reaped, > e and a STALE < e kept [proves == not <=]; poolreap_refund_registered_else_treasury -- registered operator refunded its deposit, unregistered -> treasury; poolreap_clears_reaped_pool_delegations -- THE dead-clear regression: a delegation to a reaped pool is cleared, a surviving one kept, the delegator registration preserved; poolreap_script_hash_reward_account_refunds_to_script_cred -- a 0xF0 reward account refunds to its ScriptHash credential, NOT a KeyHash projection of the same 28 bytes, and is not sent to treasury; poolreap_adopts_future_pool_params -- staged re-registration params adopted into the active set, future_pools drained, orphan future dropped)
- ade_ledger::epoch_accumulator::tests::cross_epoch_boundary_per_credential_mark_pays_member_rewards (item #2a -- the PER-CREDENTIAL boundary mark pays NON-ZERO member + leader rewards where the per-pool mark paid zero; the go.delegations the reward computation reads survive) + epoch_boundary_consumes_precomputed_aggregate_mark (Some(precomputed_mark) = the per-credential StakeSnapshot used DIRECTLY, both pool_stakes and delegations survive)