DC-MEM-06
DC derived partialThe UTxO/ledger state fingerprint is computed by the canonical CBOR encoder over canonically-encoded (fixed-width big-endian) keys, NEVER from a storage backend's native iteration order, AND is independent of the process memory allocator (allocation addresses/sizes are never fingerprinted). Store iteration order and the allocator are implementation details and must not enter any authoritative fingerprint.
- Source
Project constitution §4 (determinism); RFC 8949 §4.2.1; MEM-OPT cluster plan
- Introduced in
- MEM-OPT-OPS
Enforcement trace
Code
Tests 5
- streaming_matches_whole_buffer_across_fixtures
- streaming_fingerprint_independent_of_textual_order
- streaming_surfaces_conversion_error_not_swallowed
- streaming_rejects_duplicate_txin_fail_closed
- streaming_rejects_exact_duplicate_string_key_but_oracle_collapses
Cross-references
Strengthened in
Evidence notes
Declared at MEM-OPT scoping (2026-06-15). De-risks the on-disk UTxO: redb/LMDB/RocksDB iterate in sorted key-byte order, which equals canonical order ONLY for fixed-width big-endian TxIn keys (txid ++ BE index); native-endian keys are a cross-arch footgun. The allocator (mimalloc/jemalloc) is determinism-neutral -- allocation addresses are never fingerprinted. PARTIAL at MEM-OPT-OPS S1 (2026-06-15): the allocator-neutrality clause is now MECHANICALLY ENFORCED -- ade_node swaps the process global allocator to mimalloc (crates/ade_node/src/main.rs) and ci/ci_check_alloc_determinism_neutral.sh asserts exactly one #[global_allocator] at the RED binary entry + ZERO allocator references in any BLUE crate (the allocator type is invisible to every canonical encoder/fingerprint). The store-iteration-order clause stays DECLARED pending the on-disk UTxO (MEM-OPT-UTXO-DISK), which has no backing store yet -- hence partial, not enforced. The gate proves STATIC invisibility (the allocator type is absent from every BLUE crate + the BLUE ade_network submodules); the RUNTIME 'allocator changes no fingerprint' guarantee is carried by the standing T-DET-01 apply-block-twice fingerprint-identity corpus + DC-WAL-03 replay-equivalence. STRENGTHENED at MEM-OPT-OPS S2 (2026-06-15): the canonical-fingerprint invariant is now also exercised on the STREAMING seed-import path -- the streamed import computes the byte-identical canonical UtxoFingerprint as the whole-buffer path regardless of JSON parse/textual order (hermetic streaming_matches_whole_buffer_across_fixtures over 10 fixtures incl. negatives + streaming_fingerprint_independent_of_textual_order; live: S2 bootstrap initial_ledger_fp == S1's fb7cb12a..., ci_check_mem_opt_s2_import_peak.sh). 'never from ... iteration order' now provably covers parse/ingestion order too. A per-slice IDD review (M1) surfaced that distinct JSON key strings can collide on one canonical TxIn (uppercase vs lowercase hex; #0 vs #00) and would otherwise let the two import paths pick different survivors. The streaming PRODUCTION path now rejects ANY duplicate TxIn fail-closed -- both the canonical-collision case (distinct strings #0/#00 -> same TxIn) AND the exact-duplicate JSON string-key case (JsonSeedError::DuplicateTxIn; streaming_rejects_duplicate_txin_fail_closed + streaming_rejects_exact_duplicate_string_key_but_oracle_collapses). Honest scope (an EVIDENCE-SCOPE CORRECTION from the per-cluster security review -- NOT a production bug): the whole-buffer ORACLE is NOT AUTHORITATIVE for exact-duplicate JSON keys -- serde map ingestion collapses them last-wins (Ok) -- so on that one input the two TEST paths diverge (streaming Err, oracle Ok). cardano-cli emits unique outref keys by construction, so the divergent input is not naturally producible; the streaming PRODUCTION path fails closed on every duplicate TxIn form (canonical-collision AND exact-duplicate-string) -- byte-identical-or-rejected, never an order-dependent fingerprint. Equivalence is therefore claimed ONLY for valid unique-key seeds AND for malformed inputs where both paths are expected to agree (streaming_matches_whole_buffer_across_fixtures); the exact-duplicate-string-key case is a pinned, documented oracle asymmetry (streaming_rejects_exact_duplicate_string_key_but_oracle_collapses), never a silent assurance.