DC-EPOCH-23
DC derived enforcedBootstrap reward-update fee-buffer authority (CE-3d). The one-shot bootstrap reward update applied at the
seed->seed+1 boundary carries the certified snapshot RewardUpdate's feeSS magnitude (deltaF), and the
seed-boundary apply reduces the accumulated fee pot by it EXACTLY ONCE -- cardano's "the fee pot will be
reduced by feeSS" (Shelley epoch.tex): applyRUpd reduces the fee pot by feeSS, THEN SNAP freezes the pot.
(a) DECODED, NEVER SKIPPED OR FABRICATED: deltaF is READ from the Complete nesRu RewardUpdate by the
single native decoder (read_reward_update_deltas via read_any_int, the same sign-agnostic magnitude
mechanism as deltaT/deltaR), threaded onto NativeSnapshotNonUtxoState.rupd_delta_fees and into the
persisted BootstrapRewardUpdate.delta_fees; a malformed (non-integer) deltaF fails closed. There is NO
corrective constant -- the reduction is the decoded value, never a literal. (b) COMMITMENT-BOUND: the
bootstrap RUPD v3 codec binds delta_fees into the domain-separated blake2b canonical commitment, verified
at the seed-boundary apply before the reduction; a tampered feeSS fails closed. (c) EXACTLY ONCE, NEVER
LEAKS: the reduction runs ONLY in the is_seed_boundary branch, before the fee pot is captured as
finished_fees and rotated to prev_epoch_fees (the seed+2 reward's fee input), so the seed epoch's feeSS
does not double-count into the seed+2 reward; a non-seed (native) boundary NEVER reduces; underflow
(delta_fees > epoch_fees) fails closed BootstrapRupdFeesUnderflow. (d) SCHEMA v3 REJECTS PRE-FIX STORES:
BOOTSTRAP_RUPD_SCHEMA_VERSION and EPOCH_ACCUMULATOR_SCHEMA_VERSION are both v3; a pre-fix v1/v2 store
fails closed UnknownVersion on decode, and a v3 store whose embedded bootstrap RUPD lacks delta_fees is
impossible (the v3 codec requires it) -- a fresh judge-snapshot re-bootstrap is the ONLY migration. GROUND
TRUTH (frozen timeline, 1338 judge snapshot): imported utxosFees 2,296,344,810 + followed 1338 tail
308,031,321 = 2,604,376,131; snapshot RewardUpdate feeSS 1,157,103,223; corrected rotated fee pot
2,604,376,131 - 1,157,103,223 = 1,447,272,908; closing the residual rewards +30,800,403 / treasury
+231,420,644 / reserves +894,890,405 (one defect, fanned out by tau=1/5 and pool_pot=(1-tau)).
- Source
CE-3d bootstrap fee-buffer authority slice. Root cause CONFIRMED byte-exact: the native bootstrap decoder SKIPPED RewardUpdate.deltaF and the seed+1 apply never reduced the fee pot by it, so the imported epoch_fees retained the feeSS cardano consumes at seed+1, double-counting into the seed+2 reward update's fees input and inflating total_reward (tau share -> treasury, pool_pot -> rewards + reserves-via-deltaR2). Shelley formal-spec epoch.tex:1396 (fee pot reduced by feeSS on applyRUpd) + :459-461 (utxosFees is a running pot, feeSS the frozen snapshot). Strengthens the DC-EPOCH-18 seed+2 window-end reward authority with the fee-pot reduction cardano performs at applyRUpd. Human review + a live venue byte-exact differential gate precede commit.
- Introduced in
- CE3D-BOOTSTRAP-FEE-BUFFER-S1
Enforcement trace
Code
Tests 10
- ade_ledger::ledgerdb_state::tip_tests::read_reward_update_deltas_returns_delta_fees
- ade_ledger::ledgerdb_state::tip_tests::read_reward_update_deltas_rejects_malformed_delta_fees
- ade_ledger::bootstrap_reward_update::tests::v3_round_trips_delta_fees
- ade_ledger::bootstrap_reward_update::tests::v3_rejects_genuine_v2_blob
- ade_ledger::bootstrap_reward_update::tests::tampered_delta_fees_breaks_the_commitment
- ade_ledger::bootstrap_reward_update::tests::decode_rejects_unknown_version
- ade_ledger::epoch_accumulator::tests::seed_boundary_reduces_fee_pot_by_delta_fees
- ade_ledger::epoch_accumulator::tests::seed_boundary_fee_reduction_underflow_fails_closed
- ade_ledger::epoch_accumulator::tests::non_seed_boundary_never_reduces_fee_pot
- ade_ledger::epoch_accumulator::tests::codec_rejects_unknown_version
Cross-references
Attack rationale
The tempting shortcut is a compensating constant -- subtract the observed 1,157,103,223 to make the pots match -- which would silently mis-account any OTHER snapshot's feeSS (the value is snapshot-specific). This rule forbids that: the reduction MUST be the decoded deltaF (checked by the CI gate's no-literal scan + the checked_sub(rupd.delta_fees.0) assertion), and deltaF is commitment-bound so a tampered snapshot feeSS fails closed. A second shortcut is to fudge the reward formula / tau / the nesRu deltaT-deltaR apply to mask the residual; the fix touches none of those -- it performs cardano's own applyRUpd fee-pot reduction. The schema v3 bump + UnknownVersion fail-close prevent a pre-fix store from being warm-started under the corrected semantics (which would apply the reduction to a pot that already lacks feeSS, or skip it): re-bootstrap is the only migration.