DC-NODE-31
DC derived enforcedRecovered-anchor live-follow start authority (PHASE4-N-AK). After recovery from a non-Origin bootstrap anchor, the recovered store PERSISTS the bootstrap anchor point (slot, hash) as replayable recovery provenance, bound to the recovered anchor fingerprint. On warm-start, BootstrapState resolves the live-follow start tip from that persisted anchor point whenever ChainDb has no servable post-anchor block; resolution order = servable ChainDb tip -> persisted recovered anchor point (non-Origin + provenance-bound) -> Origin/None only if the recovered store is truly Origin/cold-start. A non-Origin recovered store whose anchor-point record is missing / malformed / fingerprint-mismatched FAILS CLOSED before live follow starts. Same recovered store + same WAL => same anchor point => same BootstrapState.tip => same FindIntersect start (replay-equivalent; extends T-REC-05 to the recovered tip surface). The persisted anchor point is the durable restart authority -- NOT CLI re-supply (CLI seed-point is first-run input only). Does not change ChainDb::tip() semantics and does not synthesize a servable block. AI-S4a RollBackward(Origin) fail-close unchanged. The wire-pump consumer (spawn_live_wire_pump_source) is UNCHANGED.
- Source
docs/planning/phase4-n-ak-recovered-anchor-tip-invariants.md (AK-INV-1) + docs/clusters/PHASE4-N-AK/cluster.md
- Introduced in
- PHASE4-N-AK
Enforcement trace
Code
- crates/ade_ledger/src/recovered_anchor_point.rs
- crates/ade_runtime/src/bootstrap.rs
- crates/ade_runtime/src/recovered_anchor.rs
- crates/ade_runtime/src/seed_epoch_lineage.rs
- crates/ade_runtime/src/chaindb/
- crates/ade_node/src/node_lifecycle.rs
- crates/ade_runtime/src/mithril_bootstrap.rs
- crates/ade_runtime/src/admission/wire_pump.rs
Tests 11
- crates/ade_runtime/src/bootstrap.rs::resolve_live_follow_start_treats_zero_hash_anchor_as_origin
- crates/ade_runtime/src/bootstrap.rs::bootstrap_bare_anchor_recovery_surfaces_anchor_as_live_follow_tip
- crates/ade_runtime/src/bootstrap.rs::bootstrap_true_origin_recovery_surfaces_none_tip
- crates/ade_runtime/src/bootstrap.rs::bootstrap_servable_chaindb_tip_wins_over_anchor
- crates/ade_runtime/src/bootstrap.rs::warm_start_loads_persisted_anchor_point
- crates/ade_runtime/src/bootstrap.rs::warm_start_non_origin_anchor_missing_anchor_point_fails_closed
- crates/ade_runtime/src/bootstrap.rs::warm_start_anchor_point_fingerprint_mismatch_fails_closed
- crates/ade_runtime/src/bootstrap.rs::same_store_same_anchor_point_same_findintersect_start
- crates/ade_runtime/src/seed_epoch_lineage.rs::bootstrap_recover_persists_anchor_point_sidecar
- crates/ade_ledger/src/recovered_anchor_point.rs::recovered_anchor_point_round_trips_byte_identical
- crates/ade_node/src/node_lifecycle.rs::recovered_bare_anchor_findintersect_starts_at_anchor_not_origin
CI 0
no CI script — gap