Invariants / DC-LIVEMEM-01

DC-LIVEMEM-01

DC derived enforced

Live-feed bounded memory (operational-hardening; NOT BLUE consensus law). Peer-driven memory on the live --mode node feed is bounded BEFORE authoritative decode/apply: a per-mini-protocol reassembly buffer (ade_network::session::core proto_buffers) over 16 MiB fails closed with a structured SessionError (drop the peer); the WirePump lookahead (ade_node::node_sync) stops opportunistic draining at 256 buffered blocks, letting the existing bounded mpsc (cap 64) back-pressure the pump. No silent truncation, no partial decode, no unbounded fallback. The bounds are CLOSED CONSTANTS -- defensive implementation bounds, NOT Cardano semantic parameters; they may be tightened by a future hardening slice, but no runtime option (CLI / env / config) may disable them or set them to unbounded. The cap fires before the BLUE decode path (unchanged); the verdict-decoupled NodeBlockSource contract, the relay-loop containment, and the served-chain handoff fence are all unchanged.

Source

docs/planning/phase4-n-f-g-e-invariants.md

Introduced in
PHASE4-N-F-G-E

Enforcement trace

Tests 4

  • session_reassembly_tail_over_cap_fails_closed
  • session_reassembly_tail_under_cap_still_drains_complete_item
  • wirepump_lookahead_stops_at_cap
  • wirepump_lookahead_cap_preserves_relay_behavior_under_normal_feed

Cross-references

Strengthened in

Evidence notes

PHASE4-N-F-G-E invariant sketch (/invariants gate). ENFORCED at the PHASE4-N-F-G-E close (4 tests + ci_check_live_feed_memory_bounds.sh green; both containment fences byte-unchanged; IDD + per-cluster security review PASS, no BLOCK). Prompted by the PHASE4-N-F-G-C per-cluster security review (MEDIUM) + SEAMS §7 candidate #6: the G-C live-feed wiring EXPOSED two pre-existing unbounded peer-driven memory surfaces (reused N-M-FRAG / N-M-C infra) on the --mode node binary path. The prior CBOR length-overflow remote-DoS (fixed in N-X) is NOT reintroduced -- this is a pre-decode reassembly/scheduling bound. Bounds: MAX_REASSEMBLY_TAIL_BYTES = 16 MiB (session::core, GREEN); MAX_WIRE_PUMP_LOOKAHEAD = 256 (node_sync, RED).

Precision (close-review, do not overclaim): the reassembly check is post-extend, so a single buffer's transient peak is cap + one <=64 KiB mux frame (~16.06 MiB), not an absolute 16 MiB. ProtoBuffers holds up to 10 INDEPENDENT per-protocol buffers each capped separately, so the per-connection aggregate ceiling is ~10x the single-buffer cap -- still O(constant) per connection (the invariant "peer-driven memory is bounded before decode/apply" holds). Per-connection-COUNT limits / peer resource fairness are a SEPARATE, out-of-scope surface (a future hardening slice). The claim is NARROW: bounded memory before authoritative decode/apply -- NOT full network DoS resistance, NOT peer fairness, NOT BA-02/live-evidence readiness.

NO live-evidence / BA-02 / rehearsal claim; NO RO-LIVE flip; NO serve / forge / containment change.