DC-EPOCH-28
DC derived enforcedLeadership coherence across a rewind. A rewind restores CURRENT_LEADERSHIP_BY_EPOCH to exactly the epochs valid at the rewind point, so no sealed leadership object can outrun the refolded accumulator (which would violate replay equivalence). The leadership table is snapshotted WITH the accumulator blob so the pair is restored atomically. This is the existing reset_to_bootstrap guarantee (CURRENT := BOOTSTRAP) generalised to an arbitrary settled baseline; it is well-defined at any point because leadership is written ONLY at boundary crossings (advance_with_current_leadership is called from exactly one site, inside cross_accumulator_over_boundary_block, riding the same commit).
- Source
docs/clusters/ACCUMULATOR-REFOLD-BOUND/SLICE-S1-settled-rewind-point.md (INV-AR-3)
- Introduced in
- ACCUMULATOR-REFOLD-BOUND-S1
Enforcement trace
Code
Tests 2
- reset_to_settled_restores_pair_and_leaves_store_uncertified
- settled_leadership_encoding_roundtrips_and_fails_closed_when_torn
Cross-references
Evidence notes
The S4-L2 frozen leadership is the forge authority, so a torn accumulator/leadership pair is a consensus fault rather than a performance one. SUPPORTING live evidence only (never the reason for enforcement): the 2026-08-01 sustained preview run measured the UNBOUNDED pre-slice behaviour -- refold 225s at 25,838 slots from the bootstrap anchor rising to 1595s (26.6 min) at 85,690, per-slot cost climbing 0.009->0.019 s/slot, over 14 reorgs in 18h. CE-AR-6 (a live run showing refold no longer grows with uptime) is still OUTSTANDING. Enforcement rests on the named tests + ci/ci_check_accumulator_refold_bound.sh.