Invariants / DC-NODE-31

DC-NODE-31

DC derived enforced

Recovered-anchor live-follow start authority (PHASE4-N-AK). After recovery from a non-Origin bootstrap anchor, the recovered store PERSISTS the bootstrap anchor point (slot, hash) as replayable recovery provenance, bound to the recovered anchor fingerprint. On warm-start, BootstrapState resolves the live-follow start tip from that persisted anchor point whenever ChainDb has no servable post-anchor block; resolution order = servable ChainDb tip -> persisted recovered anchor point (non-Origin + provenance-bound) -> Origin/None only if the recovered store is truly Origin/cold-start. A non-Origin recovered store whose anchor-point record is missing / malformed / fingerprint-mismatched FAILS CLOSED before live follow starts. Same recovered store + same WAL => same anchor point => same BootstrapState.tip => same FindIntersect start (replay-equivalent; extends T-REC-05 to the recovered tip surface). The persisted anchor point is the durable restart authority -- NOT CLI re-supply (CLI seed-point is first-run input only). Does not change ChainDb::tip() semantics and does not synthesize a servable block. AI-S4a RollBackward(Origin) fail-close unchanged. The wire-pump consumer (spawn_live_wire_pump_source) is UNCHANGED.

Source

docs/planning/phase4-n-ak-recovered-anchor-tip-invariants.md (AK-INV-1) + docs/clusters/PHASE4-N-AK/cluster.md

Introduced in
PHASE4-N-AK

Enforcement trace

Tests 11

  • crates/ade_runtime/src/bootstrap.rs::resolve_live_follow_start_treats_zero_hash_anchor_as_origin
  • crates/ade_runtime/src/bootstrap.rs::bootstrap_bare_anchor_recovery_surfaces_anchor_as_live_follow_tip
  • crates/ade_runtime/src/bootstrap.rs::bootstrap_true_origin_recovery_surfaces_none_tip
  • crates/ade_runtime/src/bootstrap.rs::bootstrap_servable_chaindb_tip_wins_over_anchor
  • crates/ade_runtime/src/bootstrap.rs::warm_start_loads_persisted_anchor_point
  • crates/ade_runtime/src/bootstrap.rs::warm_start_non_origin_anchor_missing_anchor_point_fails_closed
  • crates/ade_runtime/src/bootstrap.rs::warm_start_anchor_point_fingerprint_mismatch_fails_closed
  • crates/ade_runtime/src/bootstrap.rs::same_store_same_anchor_point_same_findintersect_start
  • crates/ade_runtime/src/seed_epoch_lineage.rs::bootstrap_recover_persists_anchor_point_sidecar
  • crates/ade_ledger/src/recovered_anchor_point.rs::recovered_anchor_point_round_trips_byte_identical
  • crates/ade_node/src/node_lifecycle.rs::recovered_bare_anchor_findintersect_starts_at_anchor_not_origin

CI 0

no CI script — gap

Cross-references

Open obligation