DC-EVIEW-04b
DC derived enforcedThe windowed advance (S3b-2): advance the durable reduced-UTxO checkpoint (DC-EVIEW-04) per epoch boundary by replaying the epoch's admitted blocks, as the reduced PROJECTION of the ledger transition's OWN apply -- NOT a parallel reimplementation. reduced_block_delta is a FAITHFUL MIRROR of the ledger's track_utxo: it iterates the block's tx_bodies through the SAME extract_inputs_outputs_from_tx, removes the same spent TxIns, computes the same tx_hash = blake2b_256(tx_body_wire_bytes), and produces the same (tx_hash, output_index) keys -- emitting a bounded delta (spent, produced) whose produced outputs are REDUCED to (Coin, ReducedStakeRef) (S3b-1). The equality reduced_block_delta == reduce(track_utxo) is PROVEN on a REAL Conway block (not synthetic CBOR -- the real-interop discipline). The cert/delegation/pool/reward advance reuses the ledger's OWN process_block_certificates (advance_cert_state; single authority). The durable checkpoint advances via apply_block_delta (remove spent + insert produced), which INVALIDATES the completeness marker until finalize() recomputes it after the whole window -- a crash mid-window leaves an INCOMPLETE checkpoint that is rebuilt (the reduced UTxO is reconstructible by replay, DC-EVIEW-04), never a wrong stake snapshot from a partial advance. At Conway the S3a PointerMap is UNUSED (pointer outputs reduce to NonContributing), so the advance does not populate it. No live producer-path change; track_utxo=true stays out of the live path.
- Source
docs/clusters/EPOCH-CONSENSUS-VIEW/SLICE-3b-replay-window-materialization.md; docs/clusters/EPOCH-CONSENSUS-VIEW/SLICE-3b-1-reduced-utxo-checkpoint.md
- Introduced in
- EPOCH-CONSENSUS-VIEW-S3b-2
Enforcement trace
Code
Tests 7
- reduced_delta_equals_reduce_of_track_utxo_on_real_conway_block
- intra_block_chained_spend_cancels_phantom_matches_track_utxo
- reduced_block_delta_is_deterministic
- empty_block_yields_empty_delta
- advance_cert_state_over_real_block_does_not_error
- apply_block_delta_then_finalize
- advance_over_real_conway_block_matches_build_from
Cross-references
Attack rationale
The advance must not (a) diverge from the ledger's own UTxO transition -- reduced_block_delta reuses the SAME extract_inputs_outputs_from_tx + tx_hash as track_utxo, proven byte-equal to reduce(track_utxo) on a REAL Conway block, so the reduced UTxO is the ledger's projection, not a second computation that could disagree; (b) be tested only synthetically -- the equality is proven on real wire data per the real-interop discipline (synthetic round-trips miss wire-format bugs); (c) reimplement the cert/reward rules -- advance_cert_state calls the ledger's OWN process_block_certificates; (d) leave a partial advance mistaken for complete -- apply_block_delta invalidates the marker, finalize re-writes it, a crash mid-window is INCOMPLETE and rebuilt (reconstructible by replay); or (e) touch the live path -- track_utxo=true stays out of the live producer/follow path and no live call site references the advance. The PointerMap is correctly unused at Conway (pointers are NonContributing).
Evidence notes
Introduced at EPOCH-CONSENSUS-VIEW S3b-2 (2026-06-20), the second half of S3b (Option B). THE rigor proof: reduced_block_delta == reduce(track_utxo) on the REAL captured Conway block (crates/ade_node/tests/fixtures/raw_era_block_conway.cbor, public chain data) -- this resolves the real-block-fixture requirement (the cheap path: compare against the ledger's OWN track_utxo, which inherits its correctness for any input). reduced_block_delta mirrors track_utxo's exact loop (cbor array over tx_bodies -> extract_inputs_outputs_from_tx -> remove spent -> tx_hash=blake2b_256(wire) -> produce (tx_hash,idx)), reducing outputs via reduce_txout. SECURITY-REVIEW FIX (the one HIGH found + fixed before commit): track_utxo THREADS the UTxO across a block's txs, so a tx may spend an output produced by an EARLIER tx in the SAME block (intra-block chained spend) and that output ends ABSENT; the first cut accumulated flat (spent, produced) vectors with NO cancellation, so apply_block_delta's remove-then-insert left the produced-then-spent output as a PHANTOM (-> over-counted stake -> wrong leader schedule). FIX: reduced_block_delta threads an intra-block produced BTreeMap and CANCELS any output spent later in the block (produced.remove(&input); an input that hit the intra-block produced set is NOT a prior-checkpoint spend), so the emitted delta is the NET block effect. REGRESSION TEST intra_block_chained_spend_cancels_phantom_matches_track_utxo: a 2-tx block (real tx1 + a synthetic tx2 spending (tx1_hash,0)) proves reduced_block_delta == reduce(track_utxo) WITH chaining (the phantom is absent). The single-tx fixture had not exercised this path. The cert advance reuses process_block_certificates (the ledger's own cert/delegation/pool/reward path). made track_utxo / extract_inputs_outputs_from_tx / process_block_certificates pub(crate). The durable checkpoint advances by apply_block_delta + finalize (incomplete-until-finalize, crash-safe). SIMPLIFICATION (recorded): the S3a PointerMap is UNUSED at Conway (pointer outputs are NonContributing in the reduced store -> never a Pointer ref to resolve), so S3b-2 does not populate it; S3a's pointer machinery stays for the general tx-validity surface. 10 hermetic tests (4 reduced_advance: real-block equality, deterministic, empty-block, cert-advance-real-block; 6+2 checkpoint: + apply_block_delta_then_finalize, advance_over_real_conway_block_matches_build_from). cargo test -p ade_ledger + -p ade_runtime green. NO aggregation (S3c), NO snapshot/emission (S3d/e), NO live wiring, NO track_utxo=true on live, NO leader/header use. The full crash-safe windowed driver over a real epoch (the prior/next checkpoint lifecycle) + the live bootstrap wiring are exercised at cluster activation; S3b-2 proves the advance MECHANISM (delta + cert advance + checkpoint apply) on real wire data. Next: S3c aggregates the advanced checkpoint (Base-cred coins + reward balances per pool via the delegation map) -- the linchpin, ORACLE vs cardano-cli stake-snapshot (a LIVE gate).