Invariants / DC-EVIDENCE-02

DC-EVIDENCE-02

DC derived enforced

Adversarial false-accept rejection across 4 mandatory mutation classes:

  1. Body byte flip preserving envelope shape
  2. Header body-hash mismatch
  3. KES / signature corruption
  4. VRF proof or output tamper

Each mutation produces either: (a) BlockAdmitted NOT emitted + AgreementVerdict::Diverged + exit code 30, OR (b) AdmissionHalted { reason: PeerSentUndecodableBytes } when corruption breaks decode before admit-attempt.

In NO case may a mutation produce BlockAdmitted (false accept), Agreed, or InputNotFound. False-accept is release-blocking (memory [[feedback-fail-closed-validation]]).

Source

docs/planning/phase4-n-m-c-operator-pass-invariants.md §1 (I-C11)

Enforcement trace

Tests 1

  • adversarial_corpus_rejects_all_four_mutation_classes

Cross-references

Strengthened in

Evidence notes

PHASE4-N-M-FOLLOW (2026-05-27) widens the natural-stream complement of the 4-mutation adversarial corpus: committed transcript at docs/evidence/phase4-n-m-follow-sustained-transcript.jsonl records 34 consecutive block_admitted events from real chain-sync stream + block-fetch with 0 diverged, 0 mismatched-hash, 0 input_not_found. Each admitted block's hash matches the peer's chain-sync-announced hash for that slot by construction (no false-accept across the 34-block sample).