DC-MITHRIL-04
DC derived enforcedNative V2 LedgerDB state decode is faithful, fail-closed, and non-emitting. The cardano-node V2
(utxohd-mem, tablesCodecVersion 1) LedgerDB state CBOR is decoded as a DETERMINISTIC BLUE projection of
the Conway NewEpochState into Ade's canonical CertState + pool distribution + Praos nonces -- the raw
cardano-node CBOR is RED/diagnostic INPUT, never the authority; the authority is the Ade-canonical
encode_cert_state bytes. (a) DETERMINISTIC: same state bytes + same authoritative epoch => byte-identical
canonical CertState + the same probe commitment (blake2b of encode_cert_state). (b) EXPLICIT ERA-TAGGED
NAVIGATION: the HardFork telescope is navigated by counting past eras (each carrying an end bound) to the
ONE current era (carrying the live state); the current era index MUST equal Conway -- never a silent "take
the latest element"; any other current era is terminal UnsupportedEra. (c) MANDATORY REAL VRF: every active
pool's VRF is decoded from the pstate pool-params (never the zeroed-VRF shortcut); a zero VRF is terminal
ZeroVrf; PoolDistr and the decoded pools cross-check on VRF where both expose it -- a mismatch is terminal
PoolDistrVrfMismatch even at zero stake. (d) POINT AUTHORITY: the decoded NES epoch (internal to the
certified snapshot's content) is cross-checked against the authoritative epoch derived from the verified
Mithril-certified point's beacon -- NEVER the filename-derived slot; a mismatch is terminal EpochMismatch.
(e) ROUND-TRIP FAITHFUL: the decoded CertState survives a canonical encode/decode round-trip (terminal
RoundTripMismatch otherwise). (f) NON-EMITTING (Stage 1): the decode yields a structured probe report only
-- NO LedgerState / UTxO seed / admission artifact (the tables/UTxO reader + the admission anchor are
Stage 2). Malformed CBOR halts deterministically (MalformedCbor; bounded reads, no best-effort partial
decode). Validated against a real cardano-node V2 Preview snapshot (704 pools, all real-VRF; counts --
704 pools / 60329 delegations / 90099 rewards -- match the independent cardano-cli consensus/certstate
producer run) AND a verified Mithril preprod ancillary snapshot (epoch 296, 528 pools all real-VRF, the
same structural verdict, the NES epoch == the certificate beacon).
- Source
docs/clusters/EPOCH-CONSENSUS-VIEW/SLICE-MITHRIL-VERIFIED-ANCHOR-IMPORT.md; user directive 2026-06-22/23 (the bounty bootstrap is a verified Mithril Cardano DB snapshot decoded natively; Stage 1 is a narrow non-emitting format-and-fidelity slice replacing the test loader's zeroed-VRF shortcut with a production-faithful state decoder before the tables path; the manifest-certified point is authoritative, the filename only a locator; telescope navigation explicit + era-tagged; real VRF mandatory; PoolDistr<->pool VRF cross-check; raw CBOR RED/diagnostic, evidence in Ade canonical bytes; no UTxO/admission mutation; same bytes + manifest => byte-identical CertState canonical + probe commitments; acceptance = local Preview corpus + one verified Mithril snapshot, same verdict)
Enforcement trace
Code
Tests 9
- happy_minimal_state_decodes_with_required_elements
- determinism_same_bytes_same_commitment
- zero_vrf_is_terminal
- wrong_era_is_terminal_no_fallback_to_latest
- pool_distr_vrf_mismatch_is_terminal
- epoch_mismatch_is_terminal
- malformed_cbor_is_terminal
- decode_local_preview_corpus
- decode_verified_mithril_ledger_state