Invariants / DC-NODE-04

DC-NODE-04

DC derived enforced

Authority-fatal halt + shutdown-resume identity: authoritative errors (chain_write failure on a committed rollback, SnapshotDecodeError::UnknownVersion or FingerprintMismatch during bootstrap) halt the binary deterministically with a non-zero exit code — no silent retry, no fallback decode. Clean shutdown drains the admit/write/snapshot pipeline to a quiescent point (bounded — no waiting indefinitely for peer sessions) and writes a final snapshot via the persistent writer; restarting against the same (chaindb, snapshot store) produces a byte-identical initial (LedgerState, PraosChainDepState, ChainDb tip).

Schema-version migration (snapshot v1 -> v2 upgrade tooling) is the snapshot-format lifecycle concern of DC-STORE-09, NOT a shutdown-semantics concern of this rule. This rule does NOT carry that open_obligation.

Source

docs/planning/phase4-n-k-orchestrator-binary-invariants.md §1 (I-6, I-7)

Enforcement trace

Tests 4

  • crates/ade_node/tests/shutdown_resume_identity.rs::shutdown_then_resume_produces_byte_identical_state
  • crates/ade_node/tests/shutdown_resume_identity.rs::shutdown_clean_exits_with_evidence
  • crates/ade_node/tests/shutdown_resume_identity.rs::cold_start_without_genesis_fails_with_generic_startup_code
  • crates/ade_node/tests/authority_fatal_decode.rs::binary_halts_on_authority_fatal_decode_error

Cross-references

Strengthened in

Evidence notes

PHASE4-N-K S7 (2026-05-26) shipped ade_node::node::run_node_until_shutdown with closed authority-fatal exit-code mapping (EXIT_AUTHORITY_FATAL_IO=10, EXIT_AUTHORITY_FATAL_DECODE=12, EXIT_GENERIC_STARTUP=1) and PersistentSnapshotWriter::force_capture in the shutdown drain. shutdown_then_resume_produces_byte_identical_state proves DC-NODE-04 end-to-end on a Conway 576 corpus block. binary_halts_on_authority_fatal_decode_error proves the no-silent-retry property. Schema-migration tooling is the open_obligation on DC-STORE-09, not on this rule.