Invariants / DC-EVIDENCE-01

DC-EVIDENCE-01

DC derived enforced

Operator-pass live evidence: the C5 live operator pass against the local docker cardano-node-preprod peer produces a JSONL transcript containing AT LEAST:

  • 1 AdmissionStarted with consensus_inputs_fingerprint,
  • 1 BootstrapComplete with the fingerprint,
  • = 1 BlockAdmitted with the fingerprint,

  • = 1 AgreementVerdict { kind: "agreed" }.

And AT MOST:

  • 0 AgreementVerdict { kind: "diverged" } (would mean divergence vs. live preprod — release-blocking),
  • 0 BlockAdmitted for any block whose hash differs from a block the live peer announces at the same slot.

The Lagging count is unconstrained (Lagging is evidence-only; DC-ADMIT-08).

Source

docs/planning/phase4-n-m-c-operator-pass-invariants.md §1 (I-C12)

Enforcement trace

Cross-references

Strengthened in

Evidence notes

PHASE4-N-M-C S5 (2026-05-26) shipped the C5 deliverable in two tiers: (a) live wire-integration is PROVEN end-to-end against the docker preprod peer (committed phase4-n-m-c-wire-only-transcript.jsonl carries peer_dial_started + handshake_ok + peer_tip_read + wire_smoke_complete at slot 76910188); (b) the live consensus-inputs bundle imports cleanly through import_live_consensus_inputs and produces a deterministic fingerprint (committed phase4-n-m-c-consensus-inputs.json, epoch 179, 384 pools).

PHASE4-N-M-A1.1 (2026-05-26) CLOSED the original A1.1 reference-script gate by adding canonical Babbage script_ref (tag(24, bytes(.cbor script))) emission for all four cardano-node-supported script variants (SimpleScript, PlutusScriptV1/V2/V3). Concurrently surfaced and closed the A1.2 Byron-address gate (Base58-encoded Byron-era addresses, ~0.7% of preprod entries) and the Plutus-integer JSON-field tolerance (parsed-form datum/inlineDatum fields stripped from RawUtxoEntry because cardano-cli emits Plutus integers exceeding f64 precision). The full ~2.2 GB preprod UTxO dump now imports cleanly: 1,909,985 entries with deterministic fingerprint across runs. Committed bootstrap transcript docs/evidence/phase4-n-m-a1.1-admission-bootstrap-transcript.jsonl records admission_started + bootstrap_complete events with the canonical consensus_inputs_fingerprint_hex (4cc62d3bdbf18f1c0d98188da5e1a85090e03379068e87267384f9873cf4e920) + initial_ledger_fp_hex (50a4542bdc8c51016025e29d70d9f683d5d3be1f0be960649647bda68abed8eb) at chain_tip_slot 89727988 (epoch 211).

PHASE4-N-M-FRAG (2026-05-27) CLOSED at HEAD 4d3dc98 shipped the session-reducer reassembly + tag-24 unwrap + chain_dep epoch_nonce wiring. The live pass then surfaced Header(VrfCert(VerificationFailed)) at the pool_active_stake_missing stage with epoch=0 — pointing at the era-schedule's epoch-number plumbing, NOT VRF / nonce / pool data.

PHASE4-N-M-SCHED (2026-05-27) CLOSED DC-EVIDENCE-01 outright. Root cause: ade_node::admission::bootstrap::make_schedule_for_imported_window hardcoded start_epoch: EpochNo(0) instead of canonical.epoch_no. With the schedule treating all imported-window slots as epoch 0, LiveLedgerView (which gates lookups by epoch == self.inputs.epoch_no) refused every per-pool lookup → header_validate short-circuited at the pool_active_stake.ok_or(VerificationFailed) line. Fix: thread canonical.epoch_no into make_schedule_for_imported_window.

Committed live transcript at docs/evidence/phase4-n-m-c-operator-pass-transcript.jsonl records the full DC-EVIDENCE-01 statement against a fully-synced docker preprod peer:

  • 1 admission_started with consensus_inputs_fingerprint_hex=8166ba41…
  • 1 bootstrap_complete with initial_ledger_fp_hex=65461b64… and chain_tip_slot=124136968 (epoch 291)
  • 1 block_received at slot 124140368, peer hash d111e613…
  • 1 block_admitted at slot 124140368, our hash d111e613… matches peer hash, post_fp_hex=9528023e…
  • 1 agreement_verdict { kind: "agreed" } at slot 124140368, our_hash == peer_hash == d111e613…
  • 0 agreement_verdict { kind: "diverged" }
  • 0 mismatched-hash block_admitted
  • clean admission_shutdown { reason: "signal_received" }

PHASE4-N-M-FOLLOW (2026-05-27) strengthens by adding a sustained-admission complement: committed transcript at docs/evidence/phase4-n-m-follow-sustained-transcript.jsonl records 34 consecutive block_admitted events across slots 124137045..124137868 (~14 minutes of mainnet chain time) with 0 diverged, 0 mismatched-hash, 0 input_not_found. All 34 verdicts are lagging (by design — the GREEN reducer emits agreed only when our admit slot equals the peer's tip slot exactly, which requires catching up to live for ~150 minutes given preprod block rate). The literal "≥1 Agreed" requirement stays satisfied by the SCHED transcript above; FOLLOW widens the no-divergence surface from a single tip-admit to a 34-block sequential walk.