Invariants / DC-PROTO-11

DC-PROTO-11

DC derived enforced

TxSubmission2 codec accepts + byte-identically preserves cardano-node's REAL wire form for the txid/tx messages: each txId is era-tagged [eraIndex, hash32] (the HardFork GenTxId, e.g. [6, h'..'] for Conway), and the txid/tx sequences are CBOR indefinite-length arrays (9f .. ff). Decode accepts definite AND indefinite sequences; encode reproduces the indefinite form so a captured frame re-encodes byte-identically; the era tag is preserved (never stripped or guessed) so a requester echoes the exact advertised id.

Source

Live server-side tx-submission2 capture (option B) finding; DC-PROTO-02; Byte Authority Model §3

Introduced in
TXSUB2-CODEC-REALWIRE

Enforcement trace

Tests 9

  • codec::tx_submission::tests::roundtrip_every_variant
  • codec::tx_submission::tests::encoder_emits_indefinite_sequences
  • codec::tx_submission::tests::real_cardano_reply_txids_decodes_and_re_encodes_byte_identical
  • codec::tx_submission::tests::decode_accepts_definite_sequence_form
  • codec::tx_submission::tests::decode_rejects_bare_txid
  • codec::tx_submission::tests::decode_rejects_wrong_txid_hash_length
  • codec::tx_submission::tests::decode_rejects_unterminated_indefinite_sequence
  • tx_submission2_real_capture_corpus::real_capture_round_trips_byte_identical
  • tx_submission2_real_capture_corpus::reply_txids_entries_are_real_32_byte_txids

Cross-references

Evidence notes

Live server-side capture (option B): the docker public-preprod cardano-node 11.0.1 dialed Ade as a localRoots peer and, as the tx-submission2 provider, sent MsgReplyTxIds in its real wire form [1, 9f [[6,h'..32'],size] ff] (indefinite entries array + era-tagged Conway=6 txid). Ade's prior codec (definite arrays + bare 32-byte txids) FALSE-REJECTED it ('indefinite-length array not allowed') -- a real Cardano incompatibility the synthetic round-trip tests had missed. The captured frame is preserved at corpus/network/n2n/tx_submission2/preprod_server_txsub_reply_txids_00_recv.cbor and hardcoded in the byte-identity unit test. The live full-exchange (ReplyTxIds -> RequestTxs -> ReplyTxs) confirmation + the DC-PROTO-02 flip are the follow-up, pending a public-preprod mempool tx (the capture harness is left running).