DC-NODE-45
DC derived enforcedONE bootstrap-bound wall-clock -> absolute-slot authority on the authoritative --mode node producer path. (a) SOLE AUTHORITY: the forge derives its slot ONLY through BootstrapBoundTimingAuthority::slot_at, which projects a DerivedTimingAnchor over the venue's COMPLETE timing calendar from system start. The prior single-anchor conversion (anchor_millis, start_slot, slot_length_ms -> checked_millis_to_slot) is REMOVED from the codebase, not deprecated: two reachable slot authorities are the defect class, so an unpreferred second path does not close it. (b) STORE-SELECTED, NEVER OPERATOR-SELECTED: the venue calendar is resolved by the DURABLE seed-epoch sidecar's genesis_hash; --network and the operator shelley-genesis are fail-closed CROSS-CHECKS only (a --network naming a different venue is terminal; an absent one is simply no cross-check). (c) DURABLE BINDING: establishment refuses unless the reconstructed calendar is self-consistent (each segment transition epoch-aligned with the previous segment's own epoch length), reproduces the store's recorded epoch_start_slot AND epoch_length_slots, contains seed_point_slot inside that epoch, and yields an anchor whose lineage verifies against the calendar (schedule_timing_commitment). (d) RECONSTRUCTED, NOT PERSISTED: the anchor domain is the bootstrap anchor SLOT (never the clock, a peer tip, or an operator timestamp), so same bootstrap lineage + same calendar => byte-identical authority; nothing is persisted, so no store artifact is versioned and recovery behaviour is unchanged (STORE_SEMANTICS_VERSION stays v3). (e) TIMING-ONLY SCOPE: the calendar carries no era identity; slot_at reads system_start, per-segment start_slot and slot_length_ms and nothing else (CE-L2c-12), so historical eras enter as calendar geometry and never as ledger semantics. (f) CONSTITUTIONAL REFUSAL PRESERVED: a snapshot-local schedule still yields ScheduleDoesNotCoverSystemStart on BOTH conversion directions (slot_at and slot_start_time_ms); the compact anchor satisfies that guard by derivation rather than relaxing it. (g) A forge-ON start without a seed-epoch sidecar FAILS CLOSED -- with no bootstrap fact to bind the calendar to, a forge whose slot cannot be justified must not start.
- Source
docs/clusters/PREPROD-LIVE-2-FORGE-READINESS/SLICE-LIVE-2c-authoritative-forge-slot-wiring.md (ACTIVATION section, the truncated-Mithril-schedule RULING and its six-proof fallback bar); docs/clusters/PREPROD-LIVE-2-FORGE-READINESS/SLICE-LIVE-2c-ACTIVATION-handoff.md. Measured live on preprod 2026-08-06: the node derived a logical slot 19 days ahead of the chain, exactly 86_400 * (20s - 1s) = 1_641_600 slots, because the conversion applied the Shelley slot length from the system start and never accounted for preprod's 20s Byron segment.
- Cluster
- PREPROD-LIVE-2-FORGE-READINESS
- Introduced in
- PREPROD-LIVE-2c-ACTIVATION
- Authority surface
- BLUE wall-clock -> logical-slot conversion (selects the KES period, drives VRF leadership, is signed into the header)
Enforcement trace
Code
Tests 20
- ce_l2c_a2_committed_calendar_reproduces_the_durable_epoch_and_the_measured_slot
- dropping_the_historical_timing_segment_is_refused_by_the_durable_binding
- a_self_inconsistent_calendar_is_refused_at_the_transition
- ce_l2c_a4_an_altered_timing_schedule_is_rejected
- ce_l2c_a3_reconstruction_is_byte_identical_and_replayable
- an_anchor_slot_outside_the_bootstrap_epoch_is_refused
- preview_single_segment_calendar_uses_the_same_path
- a_truncated_calendar_cannot_establish_a_timing_authority
- the_durable_epoch_binding_pins_boundaries_not_slot_durations
- ce_l2c_a1_the_live_store_facts_establish_and_convert_the_measured_instant
- the_operator_cannot_choose_the_calendar
- an_uncommitted_venue_fails_closed
- the_operator_genesis_file_cross_checks_origin_and_active_slot_length
- a_store_epoch_the_calendar_cannot_reproduce_fails_closed
- reconstruction_is_byte_identical_across_restarts
- the_timing_table_and_the_identity_registry_cannot_drift
- ce_l2c_5_and_6_live_instant_derives_the_measured_slot_and_refuses_typed
- relay_loop_forge_slot_derived_via_clock_seam
- node_forge_slot_drift_fails_closed
- millis_to_slot_cannot_express_a_multi_length_venue
Cross-references
Evidence notes
Nine mutations caught: byron segment dropped; --network selects the calendar; naive conversion restored on the node path; B11 restored to None; per-tick refusal reset removed; KES reasons collapsed; outcome collapsed to no_tip_available; durable epoch cross-check removed; the constitutional truncated-schedule guard relaxed. The gate is itself negative-tested 11 ways, and that pass found two real weaknesses in it: the call-site rule counted matching LINES (so two conversions on one line read as one) and the cargo invocations needed a NONZERO passed-count assertion (cargo exits 0 on an empty filter). RECORDED LIMIT, as a test rather than an assumption (the_durable_epoch_binding_pins_boundaries_not_slot_durations): the durable binding pins segment BOUNDARIES, not slot DURATIONS -- a calendar with correct boundaries but a wrong historical slot length reproduces the store's epoch geometry exactly and still mis-converts by the full 1_641_600 slots. Durations are held by the committed genesis-hash-selected table plus the ACTIVE-segment cross-check against the operator's real shelley-genesis, the same standing security_param / active_slots_coeff / epoch_length already have in the profile registry.
Evidence
The preserved live fixture (docs/evidence/run-stores/preprod-nonce-1/live2b-slot-authority-discriminators.txt): captured_ms 1_786_021_761_000 -> slot 130_338_561, corroborated by a peer two slots back. Driven through the REAL --mode node loop by ce_l2c_5_and_6_live_instant_derives_the_measured_slot_and_refuses_typed, which reads the slot back out of the typed refusal so the value is proven to reach the KES gate rather than merely be computed.
The durable cross-check is non-vacuous on the live store: preprod epoch 304 must reconstruct to absolute slot 129_686_400 (= 86_400 + (304-4)*432_000), which is what ade-preprod-s7's sidecar recorded at import; dropping the Byron segment yields 131_328_000 and the authority refuses.