DC-EVIEW-12
DC derived enforcedThe leadership-complete, self-contained EpochConsensusView (ECA-0b). The candidate view is the production authority for cross-epoch leadership: every INCLUDED pool carries BOTH its active stake AND its era-correct effective VRF keyhash -- pool_vrf_keyhashes.keys() == stake_by_pool.keys() (is_leadership_complete) -- plus a FULL consensus-profile commitment (protocol_params_commitment). derive_candidate builds the pool set by the cardano-faithful intersection delegated (the window-end stake, DC-EVIEW-05) INTERSECT registered (the window-end pool_params, DC-EVIEW-13/DC-EVIEW-10): a delegated-but-unregistered pool is DROPPED (cardano silently drops stake delegated to a pool absent from the snapshot's params); each kept pool's VRF is the window-end pool_params[p].vrf_hash (the mark VRF, ECA-0a); the total is recomputed over the kept set (checked_add, fail-closed Overflow). The protocol_params_commitment = consensus_profile_commitment(genesis_hash, protocol_params_hash, asc) = blake2b(genesis ++ protocol-params ++ ASC) -- the FULL profile (NOT ASC-only; user correction 2026-06-21), computed ONCE from the canonical CandidateProfile and bound; it is folded into the canonical_hash, and matches() requires both is_leadership_complete() AND commitment equality, so an incomplete or wrong-profile view is INERT. derive_candidate performs NO filesystem/config/network read. Pure, total, deterministic (replay-equivalent: an equivalent replay yields a byte-identical candidate canonical_hash).
- Source
docs/clusters/EPOCH-CONSENSUS-VIEW/SLICE-ECA-0b-leadership-complete-view.md; user directive 2026-06-21 (freeze the effective VRF + a full consensus-profile commitment; PoolDistrView derives exclusively from the sealed view; cardano numDelegators>0 pool inclusion)
- Introduced in
- EPOCH-CONTINUITY-ACTIVATION-ECA-0b
Enforcement trace
Code
Tests 4
- leadership_complete_required_for_matches
- canonical_hash_is_binding_sensitive
- derive_candidate_binds_target_epoch_and_round_trips_through_recovery
- derive_candidate_canonical_hash_is_replay_equivalent
Cross-references
Attack rationale
A view that pairs a correct stake distribution with the WRONG VRF keys, an INCOMPLETE VRF set, or the WRONG genesis/protocol profile would lead with a wrong identity or accept/reject the wrong blocks. The risks are closed: (a) incomplete leadership -- a pool with stake but no VRF (or vice versa) makes is_leadership_complete() false, and matches() requires it, so the view is INERT (leadership_complete_required_for_matches); (b) wrong profile -- a valid stake/VRF view consumed under the wrong genesis or protocol params is rejected because protocol_params_commitment is bound + matches() requires equality (NOT ASC-only -- the full profile, so a wrong genesis is caught); (c) silent tamper -- the VRF map + the commitment are in the canonical_hash (canonical_hash_is_binding_sensitive: a VRF change or a commitment change changes the identity); (d) un-cardano pool set -- derive_candidate intersects delegated INTERSECT registered, dropping a delegated-but-unregistered pool (cardano's snapshot-build), and keeps a 0-stake delegated registered pool (DC-EVIEW-05 numDelegators>0); (e) hidden I/O / non-determinism -- derivation is pure (no filesystem/config/network), and an equivalent replay yields a byte-identical candidate (derive_candidate_canonical_hash_is_replay_equivalent). The projection that CONSUMES this view is DC-EPOCH-12.
Evidence notes
Introduced at EPOCH-CONTINUITY-ACTIVATION ECA-0b (2026-06-21), built on ECA-0a (DC-EVIEW-13, which makes the window driver surface the correct window-end pool_params/VRF). The view is now self-contained leadership authority. Both user corrections are in: (1) aggregate_pool_stake includes a 0-stake delegated pool (numDelegators>0, DC-EVIEW-05 strengthened) so the pool SET matches cardano's PoolDistr; (2) the commitment is the FULL profile (genesis + protocol-params + ASC), not ASC-only, so the projection cannot be consumed under the wrong genesis/config. ade_ledger 639 lib + ade_node 366 lib green; the threading through the (gated-off, byte-identical) activation chain compiles with no live-path change (EVIEW_ACTIVATION_ARMED stays false). NOT YET continuous operation: ECA-0b only makes the candidate leadership-complete + the projection exclusive -- activation (ECA-1..4), the first unattended boundary, and the Model-A cert-state continuity test across >=2 boundaries are still ahead. CLAIM BOUNDARY: ECA-0b completes leadership-ready candidate CONSTRUCTION; it does not activate the candidate or prove continuous operation.