DC-EVIEW-01
DC derived enforcedTransient epoch-view replay storage is GREEN / non-authoritative substrate. A bounded, disk-backed, TRANSIENT redb store (TransientEpochViewStore) may be materialized to form a next-epoch consensus view and is then pruned -- it may NEVER survive as authority, influence BLUE outputs directly, or become a fallback source for follow, forge, recovery, or snapshot activation. Five sub-invariants are mechanically enforced. GATE-MEM: the store is disk-backed with a bounded owned-RssAnon delta -- materializing a committed corpus (CORPUS_N) keeps the bulk off the anonymous heap (delta < a FIXED committed ceiling RSS_ANON_DELTA_CEILING_KIB), while UtxoAnchor::len()==CORPUS_N proves the entries live on disk. GATE-CRASH: create -> materialize -> iterate -> dispose is crash-safe -- a SIGKILL at any point (mid-materialize or mid-dispose) leaves no transient store treated as authority, the durable tip + WAL digest + checkpoint digest UNCHANGED, the next normal replay producing IDENTICAL verdicts, and the transient root empty before normal operation resumes. GATE-PURGE: startup purge is fail-closed -- enumerate ONLY the owned transient-epoch-view subtree, validate every candidate name against the deterministic window-key form, delete all, fsync the parent, continue ONLY when empty; any failure (delete / dir-fsync / name-validation) is a STRUCTURED TERMINAL failure (TransientViewError), never best-effort. GATE-NO-FALLBACK: no live follow/forge/recovery/snapshot source file references the transient store. GATE-NOT-LIVE: the slice does not enable track_utxo=true on the live producer path and adds no runtime --transient-view-dir flag (D1: a fixed owned subtree derived from the data root, no consensus-adjacent config surface). The window key is deterministic (blake2b over network|era|epoch|source-chain-point|checkpoint-commitment; no rand/uuid), binding the store identity to the bound-activation bindings.
- Source
docs/clusters/EPOCH-CONSENSUS-VIEW/SLICE-1-redb-materialization-gate.md; docs/clusters/EPOCH-CONSENSUS-VIEW/EPOCH-CONSENSUS-VIEW-design-analysis.md (Deliverable 6, the gate)
- Introduced in
- EPOCH-CONSENSUS-VIEW-S1
Enforcement trace
Code
- crates/ade_runtime/src/chaindb/transient_epoch_view.rs
- crates/ade_runtime/src/bin/transient_view_kill_target.rs
- crates/ade_runtime/tests/transient_view_kill_harness.rs
- crates/ade_runtime/tests/transient_view_memory.rs
- ci/ci_check_transient_view_memory_ceiling.sh
- ci/ci_check_transient_view_no_fallback.sh
- ci/ci_check_transient_view_not_live.sh
Tests 15
- transient_root_is_owned_subtree_of_data_root
- window_key_is_deterministic_and_binding_sensitive
- window_key_validator_accepts_only_the_deterministic_form
- purge_removes_valid_named_leftovers_and_leaves_subtree_empty
- purge_fails_closed_on_a_foreign_artifact_and_deletes_nothing
- purge_is_clean_on_an_empty_or_absent_subtree
- lifecycle_open_materialize_iterate_dispose
- dispose_is_clean_when_window_already_removed
- transient_crash_mid_materialize_smoke
- transient_crash_mid_dispose_smoke
- transient_crash_1000
- durable_state_intact_after_transient_kill_loop
- transient_materialization_rss_anon_delta_bounded
- transient_materialization_is_repeatable_without_ratchet
- local_rss_anon_reader_present_on_linux
Cross-references
Attack rationale
The transient store must not (a) leak onto the anonymous heap (a regression that resident-loaded the materialized UTxO instead of disk-backing it would blow through the fixed RssAnon-delta ceiling -- GATE-MEM catches it), (b) survive a crash as authority or corrupt durable state (a SIGKILL mid-materialize/mid-dispose must leave the durable tip/WAL/checkpoint byte-unchanged and the next replay verdict-identical, with the half-written transient store purged -- GATE-CRASH), (c) be resumed as if authoritative (a transient store is by definition not authority and not resumable, so recovery is unconditional purge, never reconcile -- GATE-PURGE; an UNRECOGNISED name in the owned subtree fails closed rather than being blindly deleted or silently kept), (d) become a fallback consumed by follow/forge/recovery/snapshot (GATE-NO-FALLBACK greps the authority surfaces for zero references; no non-test/non-bin caller constructs it), or (e) silently flip the live producer onto track_utxo=true or add config surface (GATE-NOT-LIVE). The deterministic window key (no rand/uuid) keeps the store identity replay-stable and bound to its view's network/era/epoch/chain-point/checkpoint.
Evidence notes
Introduced at EPOCH-CONSENSUS-VIEW Slice 1 (2026-06-20). The cluster (design record EPOCH-CONSENSUS-VIEW-design-analysis.md) selects Option 3 -- form the next-epoch stake/consensus view by a bounded disk-backed TRANSIENT replay window over Ade's own validated chain, a pure projection of the single ledger authority (no second/parallel stake engine, no per-epoch external oracle). This first slice proves ONLY the substrate: create -> crash through -> recover -> dispose of the bounded transient store WITHOUT changing any durable/authoritative state -- it contains NO stake attribution, NO address decoding, NO EpochConsensusView, NO leader view, NO live wiring (those are later, gated slices). It earns the live-proven status the dormant redb UtxoAnchor backend lacked. Reuses the existing SIGKILL crash idiom (stress_kill_harness.rs precedent) repointed at a transient UtxoAnchor + a kill-during-dispose case, and a locally-replicated /proc/self/status RssAnon reader (ade_runtime does not depend on ade_node, where mem_measure lives -- the reverse dep would invert the arrow). Hermetic proof (2026-06-20): 8 module unit tests (D1 owned-subtree, D2 deterministic+binding-sensitive key + validator, D3 purge removes-valid/fails-closed-on-foreign/clean-on-empty, lifecycle, dispose-idempotent) + 3 crash tests (mid-materialize + mid-dispose smoke green; the 1000-kill closure gate transient_crash_1000 is #[ignore], manual) + durable_state_intact_after_transient_kill_loop + 3 memory tests; the bounded-materialization gate measured CORPUS_N=200000 entries => 34,222,080 on-disk bytes with an owned-RssAnon delta of 38 MiB (39,124 kiB) against the FIXED 128 MiB (131,072 kiB) committed ceiling (3.3x margin), and the no-ratchet two-pass deltas (13.5/11.4 MiB) confirm no per-window heap growth. The dormancy gate ci_check_utxo_disk_anchor.sh stays green (the anchor remains a RED storage backend, not a UtxoStore). track_utxo=false on the live path is UNCHANGED (GATE-NOT-LIVE), preserving the OP-MEM-02 / BA-08 owned-RSS posture (BA-08 1.94<2.57 GiB remains release evidence, not this gate's threshold).