Invariants / DC-EPOCH-34

DC-EPOCH-34

DC true enforced

Settled-triple integrity. The settled rewind triple (accumulator blob + settled point + settled leadership) is bound by a domain-separated, length-prefixed fingerprint written in the SAME durable commit that promotes it, and that fingerprint is RECOMPUTED and compared before the triple is ever restored from. An absent fingerprint, an unreadable lineage/schema context, or any mismatch refuses the restore and falls back to reset_to_bootstrap, which re-derives from the Mithril-certified baseline. The fallback is always safe, so this can only ever cost refold time; it can never admit an unverified triple.

Source

docs/clusters/LIVE-REFOLD-THRASH/SLICE-RF-1-settled-rewind-must-survive-recovery.md (CE-RF-6)

Introduced in
LIVE-REFOLD-THRASH-RF-1

Enforcement trace

Tests 3

  • a_corrupted_settled_triple_is_refused_and_falls_back
  • a_settled_triple_with_no_fingerprint_is_refused
  • the_settled_fingerprint_binds_every_input

Cross-references

Evidence notes

WHY this is needed before RF-1 and not after: today the recovery path always re-derives the accumulator from the certified baseline, so a silently corrupted settled blob is self-healed by recomputation. RF-1 removes that accidental self-heal on the bounded path by restoring from the triple instead. decode_epoch_accumulator fails closed on malformed bytes, but a flipped bit inside an otherwise valid numeric field decodes cleanly and would be trusted and folded forward from -- and EVIEW-R1/R2 is a live demonstration that a durable store CAN go internally inconsistent and only surface much later at a comparison boundary. The corruption proof flips ONE bit in each triple member in turn and asserts every one is refused AND that refusing leaves the store untouched so the bootstrap fallback stays correct; it was verified to DISCRIMINATE (removing the comparison makes it fail). The binding proof asserts each of the five inputs changes the digest and that length-prefixing prevents ('ab','c') colliding with ('a','bc'). The gate additionally pins STRUCTURE no compiler check covers: domain separation, a versioned domain tag, length-prefixing, write-on-promote, recompute-on-restore, clear-with-the-triple, and let-else on the absent case (a permissive if let would verify when present and silently restore when absent). All four of those regressions were mutated and caught.