Invariants / DC-EPOCH-27

DC-EPOCH-27

DC derived enforced

Lineage-bound rewind. A settled rewind target whose header hash no longer resolves canonically at its slot -- a point the chain has ABANDONED -- is REFUSED, and the rollback falls back to the bootstrap rewind. A rewind target ahead of the rollback target is likewise refused. Every refusal path lands on reset_to_bootstrap, the unchanged pre-slice behaviour, so a refusal (or any I/O fault in the predicate) costs refold time and never safety.

Source

docs/clusters/ACCUMULATOR-REFOLD-BOUND/SLICE-S1-settled-rewind-point.md (INV-AR-2)

Introduced in
ACCUMULATOR-REFOLD-BOUND-S1

Enforcement trace

Tests 1

  • settled_rewind_admission_requires_settled_depth_and_intact_lineage

Cross-references

Evidence notes

The gate additionally asserts the bootstrap fallback REMAINS reachable from the rollback path -- removing it would turn a refusal into an unhandled case (verified by negative test at registration). SUPPORTING live evidence only (never the reason for enforcement): the 2026-08-01 sustained preview run measured the UNBOUNDED pre-slice behaviour -- refold 225s at 25,838 slots from the bootstrap anchor rising to 1595s (26.6 min) at 85,690, per-slot cost climbing 0.009->0.019 s/slot, over 14 reorgs in 18h. CE-AR-6 (a live run showing refold no longer grows with uptime) is still OUTSTANDING. Enforcement rests on the named tests + ci/ci_check_accumulator_refold_bound.sh.