DC-EVIEW-09
DC derived enforcedThe manifest-bound bootstrap cert-state import (S3f-2 prerequisite). The seed
(SeedEpochConsensusInputs, the compact per-POOL active epoch consensus view) and the cert state (CertState =
DelegationState + PoolState, the per-CREDENTIAL ledger continuation state) are DIFFERENT authority surfaces
and stay SEPARATELY TYPED -- the closed seed record is NOT widened. They bind ONLY through a canonical
BootstrapManifest carrying {network_magic, era, source_point, seed_hash, cert_state_hash, source_commitment}.
The cert-state artifact is the COMPLETE canonical CertState produced/consumed by the EXISTING codec
(encode_cert_state / decode_cert_state, reused VERBATIM -- never hand-reconstructed loose delegation/reward
maps), so it carries the registration/lifecycle facts the codec requires. verify_and_import_cert_state
decodes the manifest, requires it match the bootstrap's network + era, requires the seed and cert-state bytes
to hash to the manifest's committed hashes, then decodes the (now hash-bound) cert state -- FAIL-CLOSED on a
malformed manifest, a seed/cert-state hash mismatch, a network/era mismatch, or a cert state that does not
decode. At bootstrap (import_bootstrap_cert_state, discovered by convention next to the seed:
- Source
docs/clusters/EPOCH-CONSENSUS-VIEW/SLICE-3f-activation.md; user directive 2026-06-21 (separate manifest-bound authority surfaces)
- Introduced in
- EPOCH-CONSENSUS-VIEW-S3f-2-pre
Enforcement trace
Code
Tests 7
- manifest_round_trips_canonically
- verify_and_import_happy_path
- seed_hash_mismatch_fails_closed
- cert_state_hash_mismatch_fails_closed
- network_and_era_mismatch_fail_closed
- malformed_manifest_fails_closed
- malformed_cert_state_fails_closed_after_hash_ok
Cross-references
Attack rationale
The import must not (a) widen the closed seed record into two authority surfaces -- they stay separately typed, bound only by the manifest; (b) hand-reconstruct the delegation/reward maps -- it reuses the canonical decode_cert_state VERBATIM, so the COMPLETE CertState (incl. registration/lifecycle facts) is imported, not a lossy subset; (c) accept an unbound or mismatched package -- a seed/cert-state whose bytes do not hash to the manifest's committed hashes, a wrong network/era, a malformed manifest, or a cert state that does not decode all FAIL CLOSED before any bootstrap state durables; (d) accept a half package -- exactly one of {manifest, cert-state} present fails closed (seed-without-cert-state or cert-state-without-manifest); or (e) change live producer behaviour -- leader election still reads the seed's PoolDistrView; this only populates cert_state for later self-derived views. The hash binding makes the seed + cert-state + chain point one tamper-evident package.
Evidence notes
Introduced at EPOCH-CONSENSUS-VIEW S3f-2-pre (2026-06-21), resolving the VERIFIED gap (code-trace, codebase=truth): the bootstrap LedgerState.cert_state.delegation was EMPTY (build_seed_ledger set only utxo+params; the seed carries only pool_distribution; track_utxo=false skips cert accumulation), so the window driver would miss every pre-bootstrap delegator. User chose (option 1) a SEPARATE manifest-bound cert-state artifact over widening the seed; the existing cert-state codec is reused verbatim. 7 hermetic tests (manifest round-trip; happy import; seed-hash / cert-state-hash / network / era mismatch fail-closed; malformed manifest; malformed-cert-state-after-hash-ok). cargo test -p ade_ledger (742) + -p ade_node --lib (324) green; updated 6 build_seed_ledger/seed_to_snapshot callers (1 prod + 5 test) to thread cert_state. NO live producer change. The cert-state artifact = cardano-node dstate.accounts (delegation+rewards), exactly the DC-EVIEW-05 oracle data -- so Ade can now hold its OWN delegation map at bootstrap, no runtime cardano-node dependency, no genesis replay, no second ledger authority. Next: S3f-2 (the window driver) over the populated cert_state, then the boundary-aligned stake oracle + S3f-3/S3f-4 (the gated live flip).