DC-EPOCH-25
DC derived declaredSelf-contained frozen leadership authority (S4-pre). Cardano's leadership PoolDistr (nesPd) -- the per-pool
(active_stake, vrf_keyhash) that decides the leader schedule -- is answered by a self-contained, persisted
FrozenLeadershipPoolDistr, and by NOTHING else. to_pool_distr_view reads stake AND VRF DIRECTLY from that
frozen object; it NEVER re-derives them at leadership-use time from the go snapshot, the active
cert_state.pool.pools params, future_pools, or the retiring map. Deriving leadership from go stake + active
params is a DISPROVEN hypothesis (LDAT): leadership stake is the SET snapshot and includes zero-stake
registered pools AND retired/POOLREAP'd pools whose VRF is ABSENT from active state -- the active params drop
a real leadership-relevant pool's VRF (proven: exactly 1 retired 1M-ADA pool on the v5 seed). The disproven
builder is quarantined test-only as from_accumulator_go_active_params_for_test_only.
(a) CANONICAL + FAIL-CLOSED CODEC: encode_frozen_leadership / decode_frozen_leadership
(array(6)[version, target_leadership_epoch, source_slot, source_hash, source_checkpoint_commitment, map{ pool_keyhash -> array(2)[active_stake, vrf_keyhash] }],
FROZEN_LEADERSHIP_SCHEMA_VERSION=6; S4-L2 added source_checkpoint_commitment -- the reduced-checkpoint commitment
finalized AT source_slot/source_hash, captured at freeze time, so the promoted candidate authority reads its leader
schedule's provenance DIRECTLY, never a live/historical checkpoint lookup) + canonical_hash (blake2b-256). Decode fails closed on unknown version,
wrong shape, duplicate / non-canonical pool-key order, field overflow, trailing bytes, or any non-byte-canonical
encoding (re-encode != input); zero-stake pools are preserved.
(b) DURABLE, EPOCH-INDEXED, SEPARATE FROM THE ACCUMULATOR BLOB: persisted in EpochAccumulatorStore under a
store-level leadership-schema-v6 marker + the canonical object, INDEXED BY target_leadership_epoch, written in
ONE atomic redb commit. The accumulator BLOB codec is UNCHANGED (still v4-decodable), so non-authority
observe-only follow still reads existing stores. The SOLE leadership read is the EXACT epoch-indexed authority
leadership_authority_for_epoch(e), which returns ONLY the object whose target_leadership_epoch == e and fails
closed otherwise: OldAccumulatorSchemaNotLeadershipCertified (legacy v4 / no marker), LeadershipEpochNotSealed
(no object sealed for e -- NEVER a "latest / current / nearest" fallback), LeadershipEpochMismatch (a mis-keyed
store), MissingFrozenLeadershipDistr (torn), or MalformedFrozenLeadershipDistr (corrupt). NO production read of
"the current leadership object" exists. reset_to_bootstrap RESTORES current := bootstrap (the two-key model:
the native post-boundary epochs are dropped and the refold re-produces them -- replay-equivalent -- never a
stale post-boundary object).
(c) SOURCE-BOUND BOOTSTRAP IMPORT: the native first-run bootstrap seeds the epoch-indexed bootstrap-certified
initial condition via seal_bootstrap_leadership_epochs -- nesPd_{seed} from the manifest-bound seed record's
pool_distribution AND nesPd_{seed+1} from the imported MARK snapshot (s1a.mark_pool_distr) -- each written to
BOTH the bootstrap and current epoch tables in one commit, with a no-duplicate-epoch check and an encode->decode
canonical self-check (FrozenLeadershipCanonicalDecodeFailed) before any write. The SOURCE binding to the
certified bootstrap point is enforced at the native_firstrun call site (the seal is skipped on a foreign
lineage). The seed record's pool_distribution IS the leadership nesPd (byte-exact: from_frozen == the seed
leadership PoolDistr, 659/659, incl. zero-stake + the retired 1M-ADA pool's frozen VRF), durable +
replay-equivalent (byte-identical canonical hash across clean advance, within-k rollback+reset+refold, and warm
restart).
RECURRENCE (S4-pre-2): at each self-derived epoch boundary the node FREEZES the next epoch's leadership nesPd
as an authoritative boundary effect (EpochBoundaryEffect::FreezeLeadership), sealed atomically with the
accumulator advance (one redb commit). The pool SET is numDelegators>0 -- the pre-POOLREAP delegation-map image
INTERSECT the registered pools (DC-EPOCH-24's derived-PoolDistr membership, DISTINCT from the full registered
set: 703 registered but 658 in nesPd) -- INCLUDING zero-stake-with-delegator + retiring pools; stake is the
just-built mark's per-pool stake (0 if absent); VRF is the pre-POOLREAP frozen params (capture-time, never a
use-time active-param lookup). PROVEN byte-exact vs the cardano reference nes[5]: boundary 1340->1341 froze
target_leadership_epoch=1342 == POST-1342 nesPd 658/658. A boundary advance NEVER commits without its matching
frozen leadership (RED atomic enforcement); a reset restores current := bootstrap (never a stale post-boundary
object).
BRIDGE (S4-0): leadership is stored in TWO epoch-indexed tables -- bootstrap_leadership_by_epoch (the immutable
bootstrap-certified initial condition) + current_leadership_by_epoch (the bootstrap epochs UNION the native
boundary freezes) -- and read ONLY by exact target epoch (above). The bootstrap seeds the certified initial
condition that native freezes cannot: nesPd_{seed} from the seed record's pool_distribution AND nesPd_{seed+1}
from the imported MARK snapshot -- the ONE epoch (e.g. 1339) no native freeze produces (the cross into seed+1
freezes nesPd_{seed+2}); native freezes cover seed+2 and beyond. There is NO gap: for every epoch E the node
validates, nesPd_E is either bootstrap-seeded (seed / seed+1) or native-frozen (seed+2+, from the cross into
E-1). PROVEN across the full band 1338..=1342: exact-index reads return the object whose target == the queried
epoch (bootstrap 1338 seed-record + 1339 MARK, native 1340/1341/1342), each byte-stable across reopen, with
off-band (1337/1343) + a legacy store failing closed, and a reset restoring current := bootstrap.
These slices PERSIST + certify + RECUR + recover + EPOCH-INDEX the frozen leadership authority behind a SOLE
exact-epoch read; they do NOT yet promote it to the production leader-schedule source (that swap -- retiring the
three PoolDistrView::from_seed_epoch_consensus_inputs read sites in favour of
leadership_authority_for_epoch(slot_epoch) + deleting the seed+2 ceiling in epoch_wire.rs + adding a
seed-authority-resurrection guard -- is S4 proper, a separate authority-promotion slice; DONE in S4-L2, below).
PROMOTION (S4-L2): the FORWARD promotion path is frozen-only too. prepare_authority_for_candidate_slot sources
candidate leadership BEYOND the bootstrap bridge (candidate >= seed+2) SOLELY from
promotion_leadership_authority_for_epoch(candidate) (promotion-certified = current-present AND bootstrap-absent,
else NotPromotionCertified) -> from_frozen_leadership over the frozen object's OWN freeze-time source point +
source_checkpoint_commitment (leadership-free metadata; stake/VRF/pool set read ONLY from the frozen object). The
retired seed+2 window-replay ceiling is DELETED: EVERY boundary past the bridge crosses through the frozen object
(seed+2 AND the former-ceiling seed+3 proven). A missing store / unsealed / non-promotion-certified / malformed
object is a fail-closed terminal (PromotionLeadershipUnavailable / LeadershipEpochNotSealed / NotPromotionCertified /
MalformedFrozenLeadershipDistr), NEVER a window-replay or seed fallback. The accumulator store is threaded
run_node_sync -> prepare_authority_for_candidate_slot; the run-loop freeze captures source_checkpoint_commitment =
the reduced checkpoint finalized AT the mark source point (s_prev), never a fabricated zero. The observe/discard
boundary path constructs NO leadership effect; only the effect-producing path (with a real commitment) freezes.
- Source
docs/clusters/LIVE-LEDGER-EPOCH-TRANSITION/SLICE-S4-PRE-FROZEN-LEADERSHIP-DISTRIBUTION.md + SLICE-S4-PRE-1C-LEADERSHIP-BOOTSTRAP-LINEAGE.md. Root: the S4 same-epoch identity gate FAILED (from_accumulator go+active-params produced 626/627 pools vs the seed's 659; 1 leadership pool had no active params), and the Leadership Distribution Authority Trace (ce3d_boundary_differential::ldat_classify_leadership_pools) proved leadership = SET-snapshot stake + snapshot-frozen pool params/VRF, incl. a retired 1M-ADA pool whose VRF is absent from active state.
- Introduced in
- LIVE-LEDGER-EPOCH-TRANSITION-S4-pre-1a
Enforcement trace
Code
- crates/ade_ledger/src/frozen_leadership.rs
- crates/ade_runtime/src/chaindb/epoch_accumulator_store.rs
- crates/ade_node/src/native_firstrun.rs
- crates/ade_ledger/src/epoch_accumulator.rs
- crates/ade_runtime/src/chaindb/epoch_accumulator_advance.rs
- crates/ade_node/src/node_lifecycle.rs
- crates/ade_ledger/src/consensus_view.rs
- crates/ade_ledger/src/reduced_epoch_view.rs
- crates/ade_node/src/epoch_wire.rs
- crates/ade_node/src/node_sync.rs
- ci/ci_check_frozen_leadership_authority.sh
- ci/ci_check_frozen_promotion_no_seed_window.sh
Tests 16
- ade_ledger::frozen_leadership::tests (codec round-trip, stable + content-bound hash, zero-stake preserved, wrong-version / duplicate / unsorted / trailing rejected; to_pool_distr_view reads stake+VRF directly)
- ade_ledger::frozen_leadership::tests::from_boundary_snapshot_is_the_delegation_image_not_the_full_registered_set (numDelegators>0 membership: a registered-but-undelegated pool is excluded)
- ade_ledger::epoch_accumulator::tests::boundary_leadership_effect_batch_invariants_are_enforced (ordered/no-dup/labeled effect, typed terminal)
- ade_runtime::chaindb::epoch_accumulator_store::tests (S4-0 epoch-indexed: seal_current_and_read_exact_by_epoch, epoch_indexed_leadership_survives_reopen, leadership_authority_fails_closed_on_legacy_store, leadership_authority_rejects_missing_epoch_under_valid_marker, leadership_authority_rejects_wrong_epoch_object, leadership_authority_rejects_wrong_version_marker, leadership_authority_rejects_malformed_object, seal_bootstrap_leadership_epochs_rejects_duplicate_epoch)
- ade_runtime::chaindb::epoch_accumulator_store::tests::reset_to_bootstrap_restores_only_bootstrap_indexed_leadership (two-key epoch-indexed model: reset restores current := bootstrap, the native post-boundary epochs dropped)
- ade_runtime::chaindb::epoch_accumulator_store::tests::reset_clears_current_leadership_when_no_bootstrap_object
- ade_runtime::chaindb::epoch_accumulator_store::tests::seal_advance_reset_round_trip_is_exact (accumulator seal -> advance -> reorg reset exact round-trip; advance_with_current_leadership seals accumulator + leadership in one redb commit)
- ce3d_boundary_differential::s4pre_frozen_leadership_seed_identity
- ce3d_boundary_differential::s4pre_1c_frozen_leadership_bootstrap_lineage
- ce3d_boundary_differential::s4_0_epoch_indexed_leadership_acceptance_1338_to_1342 (full leadership band 1338..=1342 read by EXACT index: bootstrap 1338 seed-record + 1339 MARK, native 1340/1341/1342; distinct objects, byte-stable across reopen, reset restores current := bootstrap, off-band 1337/1343 + legacy store fail closed)
- ade_node::node_lifecycle::tests::s4_l1_frozen_leadership_view_is_byte_identical_to_seed_and_fails_closed (S4-L1: the flipped production leadership read == the retired seed projection byte-identical, and fails closed on an absent/uncertified authority -- no seed fallback)
- ce3d_boundary_differential::ldat_classify_leadership_pools
- ce3d_boundary_differential::s5_recovery_replay_equivalence_within_k_rollback (S4-pre-2 REFERENCE PROOF: boundary 1340->1341 frozen leadership byte-matches POST-1342 reference nesPd 658/658 incl 32 zero-stake; fingerprint #8 frozen leadership hash byte-identical across clean advance vs within-k rollback+reset+refold + warm restart)
- ade_node::epoch_wire::tests::s4_l2_frozen_promotion_crosses_seed_plus_2_and_seed_plus_3 (S4-L2: candidate seed+2 AND the former-ceiling seed+3 both promote via promotion_leadership_authority_for_epoch -> from_frozen_leadership; each view == the frozen projection; the retired path terminated at seed+3)
- ade_node::epoch_wire::tests::s4_l2_frozen_promotion_fails_closed_on_every_non_promotion_source (S4-L2: missing store -> PromotionLeadershipUnavailable; unsealed -> LeadershipEpochNotSealed; bootstrap-only -> NotPromotionCertified -- never a window-replay fallback)
- ade_runtime::chaindb::epoch_accumulator_store::tests::leadership_authority_rejects_malformed_object (S4-L2: the promotion reader propagates a corrupt object as MalformedFrozenLeadershipDistr -- fail-closed typed terminal)