DC-NODE-17
DC derived declaredfollowed_peer_tip advances ONLY from a real observed peer ChainSync advertisement of the peer's selected tip, INCLUDING the self-adoption echo case where the advertised block is already durably held by Ade (the relay re-announcing Ade's own just-adopted block). The advance is a RED scheduling observation of the peer's real selection: it updates forge ADMISSIBILITY only (DC-NODE-15) and must NEVER mutate the durable tip / WAL / ledger (DC-NODE-16 idempotency preserved; replay-neutral) and NEVER reach chain selection / fork-choice (DC-CONS-03 stays the follow authority). A sole producer therefore recognizes catch-up to its own adopted block and forges the successor, sustaining a chain (N, N+1, ...) rather than stalling at one block. NOT a chain-selection rule; a RED observation rule for forge admissibility only.
- Source
docs/planning/sustained-single-producer-forge-invariants.md
- Introduced in
- TBD
Enforcement trace
Cross-references
Evidence notes
Rung-1 Finding B (2026-06-07). DECLARED, NOT enforced -- blocked on OQ-1: a live-instrumented run must first prove WHETHER the relay re-announces/advertises Ade's own adopted block over the follow link. Honest read: followed_peer_tip did not advance to Ade's adopted block N, so the DC-NODE-15 gate stayed NotCaughtUp and Ade forged exactly ONE block per recover (1 succeeded, 65 no_tip_available; relay AddedToCurrentChain block 11 issuer 48a5ff1f == blake2b-224(pool1 cold VK), 0 CandidateTooSparse, then follow link EOF). The precise wire mechanism (RollForward carrying tip=N vs. an idle serve-to-Ade) is UNPROVEN. Enforcement preconditions (ALL required before -> enforced): (1) no WAL append on the advance; (2) no durable ChainDb tip mutation; (3) no ledger/chain_dep mutation; (4) no fork-choice / chain-selection influence; (5) no bypass of the DC-NODE-15 gate durable_servable_tip == followed_peer_tip; (6) committed live evidence that the peer actually re-announces/advertises Ade's adopted block. RED-only, NO BLUE change (mirrors DC-NODE-16's RED-chokepoint shape). Sibling follow-link liveness (SF-6/OQ-2) held in docs/planning/sustained-single-producer-forge-invariants.md, NOT declared, pending proof EOF/reconnect is independent (-> a later DC-NODE-18 or operational rule only if OQ-2 confirms). OQ-1 RESULT (2026-06-07, c2t4 live; diagnostics reverted): the relay does NOT re-announce Ade's own adopted block over the follow link -- Ade forged+got-adopted block 12 (relay AddedToCurrentChain blockNo=12), but followed_peer_tip stayed at block 11 (no TipUpdate(12)), then the link EOF'd. The pump DOES emit TipUpdate on every RollForward (verified live for block 11); there is simply no RollForward(12). DC-NODE-17 is therefore NOT the sustained-forge stall fix: the peer advertisement for Ade's own block never arrives, so observing it cannot un-stick the loop. DC-NODE-17 is RETAINED as a SAFETY/OBSERVATION invariant ONLY -- if the peer advertises a tip, the RED signal must reflect it; never local inference. The sustained-forge stall fix is DC-NODE-18 (single-producer successor forge extends the adopted durable spine); see docs/planning/single-producer-extend-own-spine-invariants.md. Open secondary diagnostic OQ-KA (non-blocking): whether follow-link keep-alive causes a delayed self-echo (which would also make DC-NODE-17 enforceable) -- does NOT drive the DC-NODE-18 slice.