DC-NODE-29
DC derived enforcedLive rollback target canonical binding (rung-2; AI-S6 H-1 remediation). For a peer RollBackward(point) on the live Participant path, the rollback target MUST be resolved against the durable ChainDb and use the stored chain point (stored slot + hash) as the SOLE authority. The peer-supplied slot MUST equal the stored slot for that hash; on any mismatch (or unknown hash, or Origin) the path fails closed with a typed error BEFORE commit_rollback, BEFORE WalEntry::RollBack, BEFORE any ChainDb / LedgerState / PraosChainDepState mutation. No rollback target may be built from mixed peer/local authority (peer-supplied slot + locally-verified hash). Reconciliation (DC-NODE-26) remains the post-apply backstop but is NOT the only defense.
- Source
docs/clusters/PHASE4-N-AI/S6-rollback-target-slot-hash-binding.md (H-1 remediation)
- Introduced in
- PHASE4-N-AI
Enforcement trace
Tests 5
- rollback_slot_hash_mismatch_fails_before_mutation
- participant_rollback_applies_durably
- participant_rollback_to_unknown_point_fails_closed
- forge_path_rollback_slot_hash_mismatch_fails_before_mutation
- forge_path_rollback_to_unknown_point_fails_closed
Cross-references
Strengthened in
Attack rationale
Closes H-1 (cluster-close security review): a Byzantine peer's RollBackward naming a real in-chain hash with an arbitrary lower slot would truncate the durable chain to a peer-chosen depth (mixed peer/local authority) and brick the node; reconciliation caught the slot/hash mismatch only AFTER commit_rollback + WalEntry::RollBack had mutated disk. Pre-commit canonical target binding rejects it with a typed error and zero durable mutation.