Invariants / DC-EPOCH-25

DC-EPOCH-25

DC derived declared

Self-contained frozen leadership authority (S4-pre). Cardano's leadership PoolDistr (nesPd) -- the per-pool (active_stake, vrf_keyhash) that decides the leader schedule -- is answered by a self-contained, persisted FrozenLeadershipPoolDistr, and by NOTHING else. to_pool_distr_view reads stake AND VRF DIRECTLY from that frozen object; it NEVER re-derives them at leadership-use time from the go snapshot, the active cert_state.pool.pools params, future_pools, or the retiring map. Deriving leadership from go stake + active params is a DISPROVEN hypothesis (LDAT): leadership stake is the SET snapshot and includes zero-stake registered pools AND retired/POOLREAP'd pools whose VRF is ABSENT from active state -- the active params drop a real leadership-relevant pool's VRF (proven: exactly 1 retired 1M-ADA pool on the v5 seed). The disproven builder is quarantined test-only as from_accumulator_go_active_params_for_test_only. (a) CANONICAL + FAIL-CLOSED CODEC: encode_frozen_leadership / decode_frozen_leadership (array(6)[version, target_leadership_epoch, source_slot, source_hash, source_checkpoint_commitment, map{ pool_keyhash -> array(2)[active_stake, vrf_keyhash] }], FROZEN_LEADERSHIP_SCHEMA_VERSION=6; S4-L2 added source_checkpoint_commitment -- the reduced-checkpoint commitment finalized AT source_slot/source_hash, captured at freeze time, so the promoted candidate authority reads its leader schedule's provenance DIRECTLY, never a live/historical checkpoint lookup) + canonical_hash (blake2b-256). Decode fails closed on unknown version, wrong shape, duplicate / non-canonical pool-key order, field overflow, trailing bytes, or any non-byte-canonical encoding (re-encode != input); zero-stake pools are preserved. (b) DURABLE, EPOCH-INDEXED, SEPARATE FROM THE ACCUMULATOR BLOB: persisted in EpochAccumulatorStore under a store-level leadership-schema-v6 marker + the canonical object, INDEXED BY target_leadership_epoch, written in ONE atomic redb commit. The accumulator BLOB codec is UNCHANGED (still v4-decodable), so non-authority observe-only follow still reads existing stores. The SOLE leadership read is the EXACT epoch-indexed authority leadership_authority_for_epoch(e), which returns ONLY the object whose target_leadership_epoch == e and fails closed otherwise: OldAccumulatorSchemaNotLeadershipCertified (legacy v4 / no marker), LeadershipEpochNotSealed (no object sealed for e -- NEVER a "latest / current / nearest" fallback), LeadershipEpochMismatch (a mis-keyed store), MissingFrozenLeadershipDistr (torn), or MalformedFrozenLeadershipDistr (corrupt). NO production read of "the current leadership object" exists. reset_to_bootstrap RESTORES current := bootstrap (the two-key model: the native post-boundary epochs are dropped and the refold re-produces them -- replay-equivalent -- never a stale post-boundary object). (c) SOURCE-BOUND BOOTSTRAP IMPORT: the native first-run bootstrap seeds the epoch-indexed bootstrap-certified initial condition via seal_bootstrap_leadership_epochs -- nesPd_{seed} from the manifest-bound seed record's pool_distribution AND nesPd_{seed+1} from the imported MARK snapshot (s1a.mark_pool_distr) -- each written to BOTH the bootstrap and current epoch tables in one commit, with a no-duplicate-epoch check and an encode->decode canonical self-check (FrozenLeadershipCanonicalDecodeFailed) before any write. The SOURCE binding to the certified bootstrap point is enforced at the native_firstrun call site (the seal is skipped on a foreign lineage). The seed record's pool_distribution IS the leadership nesPd (byte-exact: from_frozen == the seed leadership PoolDistr, 659/659, incl. zero-stake + the retired 1M-ADA pool's frozen VRF), durable + replay-equivalent (byte-identical canonical hash across clean advance, within-k rollback+reset+refold, and warm restart). RECURRENCE (S4-pre-2): at each self-derived epoch boundary the node FREEZES the next epoch's leadership nesPd as an authoritative boundary effect (EpochBoundaryEffect::FreezeLeadership), sealed atomically with the accumulator advance (one redb commit). The pool SET is numDelegators>0 -- the pre-POOLREAP delegation-map image INTERSECT the registered pools (DC-EPOCH-24's derived-PoolDistr membership, DISTINCT from the full registered set: 703 registered but 658 in nesPd) -- INCLUDING zero-stake-with-delegator + retiring pools; stake is the just-built mark's per-pool stake (0 if absent); VRF is the pre-POOLREAP frozen params (capture-time, never a use-time active-param lookup). PROVEN byte-exact vs the cardano reference nes[5]: boundary 1340->1341 froze target_leadership_epoch=1342 == POST-1342 nesPd 658/658. A boundary advance NEVER commits without its matching frozen leadership (RED atomic enforcement); a reset restores current := bootstrap (never a stale post-boundary object). BRIDGE (S4-0): leadership is stored in TWO epoch-indexed tables -- bootstrap_leadership_by_epoch (the immutable bootstrap-certified initial condition) + current_leadership_by_epoch (the bootstrap epochs UNION the native boundary freezes) -- and read ONLY by exact target epoch (above). The bootstrap seeds the certified initial condition that native freezes cannot: nesPd_{seed} from the seed record's pool_distribution AND nesPd_{seed+1} from the imported MARK snapshot -- the ONE epoch (e.g. 1339) no native freeze produces (the cross into seed+1 freezes nesPd_{seed+2}); native freezes cover seed+2 and beyond. There is NO gap: for every epoch E the node validates, nesPd_E is either bootstrap-seeded (seed / seed+1) or native-frozen (seed+2+, from the cross into E-1). PROVEN across the full band 1338..=1342: exact-index reads return the object whose target == the queried epoch (bootstrap 1338 seed-record + 1339 MARK, native 1340/1341/1342), each byte-stable across reopen, with off-band (1337/1343) + a legacy store failing closed, and a reset restoring current := bootstrap. These slices PERSIST + certify + RECUR + recover + EPOCH-INDEX the frozen leadership authority behind a SOLE exact-epoch read; they do NOT yet promote it to the production leader-schedule source (that swap -- retiring the three PoolDistrView::from_seed_epoch_consensus_inputs read sites in favour of leadership_authority_for_epoch(slot_epoch) + deleting the seed+2 ceiling in epoch_wire.rs + adding a seed-authority-resurrection guard -- is S4 proper, a separate authority-promotion slice; DONE in S4-L2, below). PROMOTION (S4-L2): the FORWARD promotion path is frozen-only too. prepare_authority_for_candidate_slot sources candidate leadership BEYOND the bootstrap bridge (candidate >= seed+2) SOLELY from promotion_leadership_authority_for_epoch(candidate) (promotion-certified = current-present AND bootstrap-absent, else NotPromotionCertified) -> from_frozen_leadership over the frozen object's OWN freeze-time source point + source_checkpoint_commitment (leadership-free metadata; stake/VRF/pool set read ONLY from the frozen object). The retired seed+2 window-replay ceiling is DELETED: EVERY boundary past the bridge crosses through the frozen object (seed+2 AND the former-ceiling seed+3 proven). A missing store / unsealed / non-promotion-certified / malformed object is a fail-closed terminal (PromotionLeadershipUnavailable / LeadershipEpochNotSealed / NotPromotionCertified / MalformedFrozenLeadershipDistr), NEVER a window-replay or seed fallback. The accumulator store is threaded run_node_sync -> prepare_authority_for_candidate_slot; the run-loop freeze captures source_checkpoint_commitment = the reduced checkpoint finalized AT the mark source point (s_prev), never a fabricated zero. The observe/discard boundary path constructs NO leadership effect; only the effect-producing path (with a real commitment) freezes.

Source

docs/clusters/LIVE-LEDGER-EPOCH-TRANSITION/SLICE-S4-PRE-FROZEN-LEADERSHIP-DISTRIBUTION.md + SLICE-S4-PRE-1C-LEADERSHIP-BOOTSTRAP-LINEAGE.md. Root: the S4 same-epoch identity gate FAILED (from_accumulator go+active-params produced 626/627 pools vs the seed's 659; 1 leadership pool had no active params), and the Leadership Distribution Authority Trace (ce3d_boundary_differential::ldat_classify_leadership_pools) proved leadership = SET-snapshot stake + snapshot-frozen pool params/VRF, incl. a retired 1M-ADA pool whose VRF is absent from active state.

Introduced in
LIVE-LEDGER-EPOCH-TRANSITION-S4-pre-1a

Enforcement trace

Tests 16

  • ade_ledger::frozen_leadership::tests (codec round-trip, stable + content-bound hash, zero-stake preserved, wrong-version / duplicate / unsorted / trailing rejected; to_pool_distr_view reads stake+VRF directly)
  • ade_ledger::frozen_leadership::tests::from_boundary_snapshot_is_the_delegation_image_not_the_full_registered_set (numDelegators>0 membership: a registered-but-undelegated pool is excluded)
  • ade_ledger::epoch_accumulator::tests::boundary_leadership_effect_batch_invariants_are_enforced (ordered/no-dup/labeled effect, typed terminal)
  • ade_runtime::chaindb::epoch_accumulator_store::tests (S4-0 epoch-indexed: seal_current_and_read_exact_by_epoch, epoch_indexed_leadership_survives_reopen, leadership_authority_fails_closed_on_legacy_store, leadership_authority_rejects_missing_epoch_under_valid_marker, leadership_authority_rejects_wrong_epoch_object, leadership_authority_rejects_wrong_version_marker, leadership_authority_rejects_malformed_object, seal_bootstrap_leadership_epochs_rejects_duplicate_epoch)
  • ade_runtime::chaindb::epoch_accumulator_store::tests::reset_to_bootstrap_restores_only_bootstrap_indexed_leadership (two-key epoch-indexed model: reset restores current := bootstrap, the native post-boundary epochs dropped)
  • ade_runtime::chaindb::epoch_accumulator_store::tests::reset_clears_current_leadership_when_no_bootstrap_object
  • ade_runtime::chaindb::epoch_accumulator_store::tests::seal_advance_reset_round_trip_is_exact (accumulator seal -> advance -> reorg reset exact round-trip; advance_with_current_leadership seals accumulator + leadership in one redb commit)
  • ce3d_boundary_differential::s4pre_frozen_leadership_seed_identity
  • ce3d_boundary_differential::s4pre_1c_frozen_leadership_bootstrap_lineage
  • ce3d_boundary_differential::s4_0_epoch_indexed_leadership_acceptance_1338_to_1342 (full leadership band 1338..=1342 read by EXACT index: bootstrap 1338 seed-record + 1339 MARK, native 1340/1341/1342; distinct objects, byte-stable across reopen, reset restores current := bootstrap, off-band 1337/1343 + legacy store fail closed)
  • ade_node::node_lifecycle::tests::s4_l1_frozen_leadership_view_is_byte_identical_to_seed_and_fails_closed (S4-L1: the flipped production leadership read == the retired seed projection byte-identical, and fails closed on an absent/uncertified authority -- no seed fallback)
  • ce3d_boundary_differential::ldat_classify_leadership_pools
  • ce3d_boundary_differential::s5_recovery_replay_equivalence_within_k_rollback (S4-pre-2 REFERENCE PROOF: boundary 1340->1341 frozen leadership byte-matches POST-1342 reference nesPd 658/658 incl 32 zero-stake; fingerprint #8 frozen leadership hash byte-identical across clean advance vs within-k rollback+reset+refold + warm restart)
  • ade_node::epoch_wire::tests::s4_l2_frozen_promotion_crosses_seed_plus_2_and_seed_plus_3 (S4-L2: candidate seed+2 AND the former-ceiling seed+3 both promote via promotion_leadership_authority_for_epoch -> from_frozen_leadership; each view == the frozen projection; the retired path terminated at seed+3)
  • ade_node::epoch_wire::tests::s4_l2_frozen_promotion_fails_closed_on_every_non_promotion_source (S4-L2: missing store -> PromotionLeadershipUnavailable; unsealed -> LeadershipEpochNotSealed; bootstrap-only -> NotPromotionCertified -- never a window-replay fallback)
  • ade_runtime::chaindb::epoch_accumulator_store::tests::leadership_authority_rejects_malformed_object (S4-L2: the promotion reader propagates a corrupt object as MalformedFrozenLeadershipDistr -- fail-closed typed terminal)

Cross-references

Strengthened in

Open obligation