Invariants / DC-MITHRIL-04

DC-MITHRIL-04

DC derived enforced

Native V2 LedgerDB state decode is faithful, fail-closed, and non-emitting. The cardano-node V2 (utxohd-mem, tablesCodecVersion 1) LedgerDB state CBOR is decoded as a DETERMINISTIC BLUE projection of the Conway NewEpochState into Ade's canonical CertState + pool distribution + Praos nonces -- the raw cardano-node CBOR is RED/diagnostic INPUT, never the authority; the authority is the Ade-canonical encode_cert_state bytes. (a) DETERMINISTIC: same state bytes + same authoritative epoch => byte-identical canonical CertState + the same probe commitment (blake2b of encode_cert_state). (b) EXPLICIT ERA-TAGGED NAVIGATION: the HardFork telescope is navigated by counting past eras (each carrying an end bound) to the ONE current era (carrying the live state); the current era index MUST equal Conway -- never a silent "take the latest element"; any other current era is terminal UnsupportedEra. (c) MANDATORY REAL VRF: every active pool's VRF is decoded from the pstate pool-params (never the zeroed-VRF shortcut); a zero VRF is terminal ZeroVrf; PoolDistr and the decoded pools cross-check on VRF where both expose it -- a mismatch is terminal PoolDistrVrfMismatch even at zero stake. (d) POINT AUTHORITY: the decoded NES epoch (internal to the certified snapshot's content) is cross-checked against the authoritative epoch derived from the verified Mithril-certified point's beacon -- NEVER the filename-derived slot; a mismatch is terminal EpochMismatch. (e) ROUND-TRIP FAITHFUL: the decoded CertState survives a canonical encode/decode round-trip (terminal RoundTripMismatch otherwise). (f) NON-EMITTING (Stage 1): the decode yields a structured probe report only -- NO LedgerState / UTxO seed / admission artifact (the tables/UTxO reader + the admission anchor are Stage 2). Malformed CBOR halts deterministically (MalformedCbor; bounded reads, no best-effort partial decode). Validated against a real cardano-node V2 Preview snapshot (704 pools, all real-VRF; counts -- 704 pools / 60329 delegations / 90099 rewards -- match the independent cardano-cli consensus/certstate producer run) AND a verified Mithril preprod ancillary snapshot (epoch 296, 528 pools all real-VRF, the same structural verdict, the NES epoch == the certificate beacon).

Source

docs/clusters/EPOCH-CONSENSUS-VIEW/SLICE-MITHRIL-VERIFIED-ANCHOR-IMPORT.md; user directive 2026-06-22/23 (the bounty bootstrap is a verified Mithril Cardano DB snapshot decoded natively; Stage 1 is a narrow non-emitting format-and-fidelity slice replacing the test loader's zeroed-VRF shortcut with a production-faithful state decoder before the tables path; the manifest-certified point is authoritative, the filename only a locator; telescope navigation explicit + era-tagged; real VRF mandatory; PoolDistr<->pool VRF cross-check; raw CBOR RED/diagnostic, evidence in Ade canonical bytes; no UTxO/admission mutation; same bytes + manifest => byte-identical CertState canonical + probe commitments; acceptance = local Preview corpus + one verified Mithril snapshot, same verdict)

Enforcement trace

Tests 9

  • happy_minimal_state_decodes_with_required_elements
  • determinism_same_bytes_same_commitment
  • zero_vrf_is_terminal
  • wrong_era_is_terminal_no_fallback_to_latest
  • pool_distr_vrf_mismatch_is_terminal
  • epoch_mismatch_is_terminal
  • malformed_cbor_is_terminal
  • decode_local_preview_corpus
  • decode_verified_mithril_ledger_state

Cross-references

Strengthened in