Invariants / DC-EPOCH-26

DC-EPOCH-26

DC derived enforced

Settled rewind target. The epoch accumulator is NEVER rewound to a point within k of the durable tip: every rewind target is beyond the reach of an admissible reorg. Separation is measured in BLOCK units (LastAdvancedPoint.block_no vs the tip's height from resolve_canonical_point), NOT slots -- a slot comparison would embed an active-slot-coefficient assumption and be wrong wherever f differs. The staged (pending) point is promoted to the settled rewind target only once the tip has outrun it by k.

Source

docs/clusters/ACCUMULATOR-REFOLD-BOUND/SLICE-S1-settled-rewind-point.md (INV-AR-1)

Introduced in
ACCUMULATOR-REFOLD-BOUND-S1

Enforcement trace

Tests 2

  • settled_point_is_only_promoted_once_k_blocks_settled
  • settled_rewind_admission_requires_settled_depth_and_intact_lineage

Cross-references

Evidence notes

Generalises the reset_to_bootstrap trust argument: the bootstrap blob was trusted because it is immutable and certified; a point older than k is trusted because no admissible reorg can reach it. SUPPORTING live evidence only (never the reason for enforcement): the 2026-08-01 sustained preview run measured the UNBOUNDED pre-slice behaviour -- refold 225s at 25,838 slots from the bootstrap anchor rising to 1595s (26.6 min) at 85,690, per-slot cost climbing 0.009->0.019 s/slot, over 14 reorgs in 18h. CE-AR-6 (a live run showing refold no longer grows with uptime) is still OUTSTANDING. Enforcement rests on the named tests + ci/ci_check_accumulator_refold_bound.sh.