DC-GOV-01
DC derived declaredGOVERNANCE-DEPOSIT-EXPIRY-REFUND (negative proof). Ade refunds a removed governance proposal's deposit to its recorded return address ONLY when it can PROVE, from canonical governance state and the Conway rules, that the proposal could NOT have ratified or enacted; otherwise it fails closed (terminal structured failure). The refund (deposit-pot debit + return-address credit) is a total, deterministic, replay- equivalent boundary transition; the proof is canonical, persisted-or-reproducibly-derivable, and testable. Ade never decides a proposal RATIFIES, only proves when one CANNOT. The tracked proposal set is canonical at every boundary: imported from the certified snapshot (bootstrap), kept current by capturing live proposal_procedures (tx-body field 20) during follow, and PROTECTED by a vote tripwire -- any canonical selected-chain vote (field 19) targeting a tracked proposal makes its tracked vote map non-canonical and is terminal (Ade does not tally/ratify/enact). Every persisted field that decides a future refund is canonical, never defaulted: expires_after = proposed_in + govActionLifetime, and govActionLifetime is IMPORTED from the certified curPParams (never a placeholder) -- a 0/un-imported lifetime at capture is terminal, never a fabricated expiry. No silent skip / empty default: an unknown GovActionState / GovAction variant, an unsupported committee representation, or a malformed field 19/20 is terminal; an ABSENT proposal/committee set is never reinterpreted as an EMPTY one (a pre-import store fails closed -> re-bootstrap required).
- Source
docs/clusters/CONWAY-PROPOSAL-DEPOSIT-EXPIRY/cluster.md (sections 2-4, declared by this cluster); CIP-1694 (proposal lifecycle: deposit -> expiry -> refund to return_addr from the deposit pot, distinct from a treasury withdrawal). Ground-truthed 2026-06-30 against a POST-1340 cardano db-analyser extraction: the CE-3d -500B reward differential is dropped expired-proposal deposit refunds (5 TreasuryWithdrawals proposals, deposit 100k ADA each, proposed_in 1309 / expires_after 1339, refunded at the 1340->1341 boundary).
- Introduced in
- CONWAY-PROPOSAL-DEPOSIT-EXPIRY-S1
Enforcement trace
Code
no enforcing code — gap
Tests 5
- ade_ledger::epoch_accumulator::tests (s3_live_proposal_captured_with_identity_epoch_and_expiry, s3_two_proposals_one_tx_get_sequential_indices_same_txid, s3_vote_on_tracked_proposal_is_terminal, s3_vote_on_untracked_proposal_is_carried_forward, s3_cross_tx_same_block_vote_on_just_submitted_proposal_is_terminal, s3_invalid_tx_carrying_proposal_is_fail_closed, s3_invalid_tx_carrying_vote_is_fail_closed, s3_malformed_field20_is_fail_closed, s3_malformed_field19_is_fail_closed, s3_block_without_governance_fields_is_noop, s3_capture_skips_non_gov_fields_and_is_replay_equivalent, s3_unproven_zero_lifetime_refuses_to_fabricate_expiry, s3_gov_state_none_is_untracked_and_skipped)
- ade_ledger::ledgerdb_state::tip_tests::v6_commitment_is_deterministic_and_binds_gov (v7 binds the imported gov_action_lifetime)
- ade_ledger tests/ledgerdb_nonutxo_hermetic.rs::happy_minimal_state_decodes_all_fields (imported_gov.gov_action_lifetime == 6 read from curPParams idx 26)
- ade_runtime::mithril_native_assembly::tests::native_assembly_maps_each_field_from_its_source (gov_state.gov_action_lifetime seeded from the import, not 0)
- ade_runtime::chaindb::epoch_accumulator_store::tests::governance_import_gate_rejects_absent_but_allows_empty (S2 absent != empty)