DC-EPOCH-29
DC derived enforcedUncertified after rewind. A rewind clears LAST_ADVANCED_POINT and drops the pending boundary-mark binding, so the store is UNCERTIFIED until a canonical re-fold rewrites the anchor: a rewound store is never lineage authority. Additionally BOTH rewind paths discard the STAGED (pending) rewind buffer, which was taken on the chain being abandoned -- while the already-SETTLED point (>= k old, unreachable by an admissible reorg) is deliberately kept, so a second rollback still has a bounded target.
- Source
docs/clusters/ACCUMULATOR-REFOLD-BOUND/SLICE-S1-settled-rewind-point.md (INV-AR-4)
- Introduced in
- ACCUMULATOR-REFOLD-BOUND-S1
Enforcement trace
Code
Tests 2
- reset_to_settled_restores_pair_and_leaves_store_uncertified
- bootstrap_reset_discards_the_settled_rewind_point
Cross-references
Evidence notes
Preserves the S5 crash-safety property verbatim: a crash inside the rollback window leaves an anchor-absent store that the next advance refolds from canonical. SUPPORTING live evidence only (never the reason for enforcement): the 2026-08-01 sustained preview run measured the UNBOUNDED pre-slice behaviour -- refold 225s at 25,838 slots from the bootstrap anchor rising to 1595s (26.6 min) at 85,690, per-slot cost climbing 0.009->0.019 s/slot, over 14 reorgs in 18h. CE-AR-6 (a live run showing refold no longer grows with uptime) is still OUTSTANDING. Enforcement rests on the named tests + ci/ci_check_accumulator_refold_bound.sh.