DC-MITHRIL-02
DC derived enforcedFor Mithril bootstrap, the BootstrapAnchor seed_point MUST be derived from the operator-provided independent seed-point extraction inputs, not from the Mithril manifest. The Mithril manifest may populate provenance and attestation fields (SeedProvenance::Mithril), but the binding check (verify_mithril_binding) MUST compare two structurally independent origins and fail closed on mismatch. In the production composition the manifest import may be referenced only as whole values (import.provenance -> seed_provenance; &import.report -> the verify call); the import's point-bearing fields must never be drilled into or laundered (via a local binding or a mutate-before-mint) into the anchor's seed_point.
- Source
docs/clusters/PHASE4-N-Z/cluster.md; S1-mithril-production-bootstrap.md
- Cluster
- PHASE4-N-Z
- Introduced in
- PHASE4-N-Z
Enforcement trace
Tests 3
- mithril_bootstrap_fails_closed_on_seed_point_mismatch
- mithril_bootstrap_verifies_before_storage_init
- mithril_bootstrap_succeeds_when_seed_point_matches
Cross-references
Attack rationale
Mithril proves a chain point; it must not be allowed to define both sides of the binding comparison. If the anchor's seed_point were sourced from the manifest (directly, via a local, or by mutating the operator inputs), verify_mithril_binding would compare a value to itself and could never fail — a forged/wrong-point snapshot would bind successfully and seed an attacker-chosen ledger. The two origins must stay structurally independent; the containment gate blocks the laundering class mechanically.