DC-EVIEW-08
DC derived declared driftActivation -- the live-path consumption of Ade's self-derived next-epoch view. MECHANISM (IMPLEMENTED + AUTOMATIC): the boundary activation is wired into the relay loop and runs AUTOMATICALLY -- no arming flag (ECA-1/DC-EPOCH-13 removed the semantic gate); the only gate is the deterministic activation predicate over canonical durable state. The self-derived leadership view is produced by ECA WINDOW REPLAY (epoch_wire::maybe_activate_first_boundary -> derive_authoritative_candidate -> EpochConsensusView::bind -> ActiveEpochAuthority::promote); forging + header validation read the promoted N+1 view via authority.pool_distr_view() (node_sync::forge_one_from_recovered). This window-replay derivation SUPERSEDES the original S3f-1 ledger-mark seam: apply_epoch_boundary_full still passes None and the precomputed_mark path is exercised only by tests, so the self-derived view does NOT flow through the ledger boundary mark. The S3f-1 consume/stub seam stays a fail-safe (None -> stub UNCHANGED), pinned by epoch_boundary_consumes_precomputed_aggregate_mark. REMAINING PROOF (the gate to enforced -- LIVE, not code): (1) live shadow agreement -- Ade's checkpoint-derived {pool_distribution, total_active_stake, ADE1 sigma} == cardano-cli stake-snapshot / the fresh oracle bundle (reduction already 100% exact + ADE1 exact on real preview epoch 1334; the perfectly boundary-aligned pool match owed at a real boundary); (2) real Preview Conway boundary activation + continuity -- the UNCHANGED production binary auto-activates across the wall, keeps admitting valid N+1, stays forge-ready, no manual intervention / restart / external stake import; (3) leadership-schedule agreement (ADE1's derived schedule == cardano-cli leadership-schedule) + an accepted ADE1 forge on epoch N+1. Fail-closed: an unbound / mismatched / not-yet-k-deep view is INERT; the producer never elects on it.
- Source
docs/clusters/EPOCH-CONSENSUS-VIEW/SLICE-3f-activation.md; docs/clusters/EPOCH-CONSENSUS-VIEW/SLICE-3-scope.md (the activation slice)
- Introduced in
- EPOCH-CONSENSUS-VIEW-S3f-1
Enforcement trace
Tests 1
- epoch_boundary_consumes_precomputed_aggregate_mark not on disk
Cross-references
Attack rationale
S3f-1 must not change live behaviour: apply_epoch_boundary_full passes None so the stub is used UNCHANGED -- a live regression would require Some on the live path, which the CI gate forbids; the consume/stub fail-safe is pinned by the test (Some -> the aggregate becomes the mark; None -> the empty-cert-state stub mark, not the aggregate). The full activation must never (a) elect on an unbound/mismatched view (S3e matches() requires all bindings + verify), (b) finalize a not-yet-k-deep boundary (S3d is_boundary_stable, strict > k), (c) flip the live producer before the two live proofs pass, or (d) break replay-equivalence (the WAL activation variant is DC-WAL-03 two-run byte-identical, BLUE has no network/clock/rand). CE-71 reward accounting makes its first live appearance at S3f-4, gated on replay + crash + differential + no-change-to-live-decisions.
Evidence notes
Introduced at EPOCH-CONSENSUS-VIEW S3f-1 (2026-06-20). The activation slice is the ONLY live-path change; decomposed so the live flip (S3f-4) is last + gated on two live cardano-node proofs (NOT pure coding). S3f-1 is the fail-safe consumption point: the boundary CAN consume the S3c aggregate (the live-validated linchpin -- DC-EVIEW-05 oracle: reduction byte-exact, aggregation 98.2%-vs-frozen-mark + ADE1 exact) but the live path passes None so nothing changes yet. 1 hermetic test (consume Some(agg) -> aggregate mark; None -> stub mark) + ci_check_eview_activation.sh; updated 5 existing callers (apply_epoch_boundary_full + 4 epoch_oracle_comparison reward-oracle tests) to pass None; cargo test -p ade_ledger (735) + ade_testkit green, no regression. status=declared: the rule is NOT fully enforced until S3f-2..4 + the live proofs. Next: S3f-2 (the window driver) -- which also enables the boundary-aligned stake oracle (the fully-clean pool match owed from DC-EVIEW-05) and is the prerequisite for the leadership-schedule live proof. RE-SCOPED 2026-06-24 (post-ECA): the activation was built by the ECA cluster via WINDOW REPLAY (epoch_wire/epoch_activate/epoch_candidate), NOT the S3f-2 ledger-mark path; the mechanism is automatic + enforced (DC-EPOCH-05..14). Live shadow agreement validated on real preview epoch 1334: reduction 254261/254261 EXACT (100%), ADE1 EXACT, derive_stake_by_pool aggregation 613/624 (98.2%) with a documented mid-epoch-current vs frozen-mark artifact (off-repo evidence ~/.cardano-c2-preview/eview-oracle-evidence/checkpoint-shadow-RESULT.txt). Remaining = the boundary-aligned pool match + the leadership-schedule + accepted-forge live proofs (ECA-5).