Invariants / DC-MITHRIL-08

DC-MITHRIL-08

DC derived enforced

The native Mithril FirstRun is BOUNDARY-COMPLETE: when the decoded cert-state carries delegations (the EVIEW package), native_first_run_bootstrap builds the live EVIEW reduced-UTxO checkpoint INLINE from the materialized UTxO -- reduce_txout each output -> ReducedUtxoCheckpoint::build_from -> seal_bootstrap at the certified slot -- BEFORE the UTxO is consumed by the bootstrap. So a Mithril-started node persists (reduced-checkpoint.redb + the seed sidecar + the durable tip), exactly the triple ECA activation requires: at the next epoch boundary the node DERIVES + PROMOTES its own next-epoch authority (not inert). (a) GATED: a snapshot whose cert-state has no delegations builds NO checkpoint and the bootstrap output is BYTE-IDENTICAL (DC-EPOCH-11 point 8). (b) INLINE: the build uses the underlying BLUE/GREEN primitives (ade_ledger::reduced_utxo::reduce_txout, ade_runtime::chaindb::ReducedUtxoCheckpoint) directly -- it does NOT couple native_firstrun to admission::bootstrap's private helper; the two RED bootstrap paths stay independent (the shared authority is the primitive, not a RED helper). (c) FAIL-CLOSED: an open / build_from / seal_bootstrap failure is a terminal NativeFirstRunError::ReducedCheckpoint BEFORE authority visibility (the WAL commit-point inside the bootstrap stays the sole discovery gate; the inline build runs before it) -- NO bootable partial state. SCOPE: this is the inline checkpoint-build mechanism (Gap 2 of the slice); the judge-facing --bootstrap-mithril command (Gap 1) and the LIVE boundary continuity proof (cold restart + ChainSync + cross-boundary promotion + forge + Haskell adoption) are separate -- the live continuity flips DC-EPOCH-11 / DC-EVIEW-08, not this rule.

Source

docs/clusters/MITHRIL-VERIFIED-ANCHOR-INTEGRATION/SLICE-S2-mithril-first-run-continuity.md; user directive 2026-06-24 (make the native Mithril FirstRun boundary-usable: build the EVIEW reduced checkpoint INLINE on the native route before the UTxO is dropped, gated on delegations, so a Mithril-started node is not inert at the boundary; implement INLINE -- do NOT couple native_firstrun to admission::bootstrap)

Introduced in
MITHRIL-VERIFIED-ANCHOR-INTEGRATION-S2

Enforcement trace

Cross-references