Invariants / DC-NODE-29

DC-NODE-29

DC derived enforced

Live rollback target canonical binding (rung-2; AI-S6 H-1 remediation). For a peer RollBackward(point) on the live Participant path, the rollback target MUST be resolved against the durable ChainDb and use the stored chain point (stored slot + hash) as the SOLE authority. The peer-supplied slot MUST equal the stored slot for that hash; on any mismatch (or unknown hash, or Origin) the path fails closed with a typed error BEFORE commit_rollback, BEFORE WalEntry::RollBack, BEFORE any ChainDb / LedgerState / PraosChainDepState mutation. No rollback target may be built from mixed peer/local authority (peer-supplied slot + locally-verified hash). Reconciliation (DC-NODE-26) remains the post-apply backstop but is NOT the only defense.

Source

docs/clusters/PHASE4-N-AI/S6-rollback-target-slot-hash-binding.md (H-1 remediation)

Introduced in
PHASE4-N-AI

Enforcement trace

Tests 5

  • rollback_slot_hash_mismatch_fails_before_mutation
  • participant_rollback_applies_durably
  • participant_rollback_to_unknown_point_fails_closed
  • forge_path_rollback_slot_hash_mismatch_fails_before_mutation
  • forge_path_rollback_to_unknown_point_fails_closed

Cross-references

Strengthened in

Attack rationale

Closes H-1 (cluster-close security review): a Byzantine peer's RollBackward naming a real in-chain hash with an arbitrary lower slot would truncate the durable chain to a peer-chosen depth (mixed peer/local authority) and brick the node; reconciliation caught the slot/hash mismatch only AFTER commit_rollback + WalEntry::RollBack had mutated disk. Pre-commit canonical target binding rejects it with a typed error and zero durable mutation.