Invariants / DC-PUMP-03

DC-PUMP-03

DC derived enforced

Wire-pump keep-alive client (PHASE4-N-AM). The admission wire pump (run_admission_wire_pump -- the SOLE per-peer pump, CN-PUMP-01) runs the N2N keep-alive CLIENT (mini-protocol 8): on a cadence STRICTLY under the peer's keep-alive timeout (~97s observed) it sends KeepAliveMessage::KeepAlive(cookie) (Initiator) via the EXISTING outbound OutboundFrame path, advancing the REUSED BLUE ade_network::keep_alive state machine (keep_alive_transition: ClientIdle -> ServerHasAgency{cookie}); on the inbound MsgResponseKeepAlive(cookie') it advances the SAME state machine (ServerHasAgency{cookie} + Server -> ClientIdle, validating cookie' == cookie). WIRE-ONLY: the keep-alive client produces no canonical input, no WAL entry, and NO AdmissionPeerEvent (Block / TipUpdate / RollBackward / Disconnected) -- it never affects admission, the durable chain, fork-choice, the convergence-evidence vocabulary, replay-equivalence, or any BLUE state (the DC-PUMP-01 emit-set stays unwidened). MUST NOT: redefine the BLUE keep-alive grammar (reuse ade_network::keep_alive + ::codec::keep_alive); use a cadence >= the peer timeout; send a new MsgKeepAlive while one is in flight (respect ServerHasAgency agency); block / starve / reorder the chain-sync or block-fetch flow; dispatch a keep-alive frame as a chain-sync/block-fetch event (closed match over AcceptedMiniProtocol); silently swallow a grammar violation (fail closed via AdmissionWirePumpError::KeepAlive -- drop the peer); use rand / wall-clock for the cookie (monotonic u16 counter); implement a keep-alive SERVER/responder (client only -- the responder is a CE-AM-LIVE-gated follow-on). With the client running, a live participant AND single-producer follow sustains past the ~97s keep-alive deadline -- the prerequisite that makes the CE-AI-6 induced-reorg convergence capture runnable. SCOPE: the keep-alive client ONLY; does NOT add multi-peer ChainSel, does NOT flip CN-CONS-03, does NOT broaden CN-PUMP-01 / DC-PUMP-01 / DC-PUMP-02 (cross-refs, preserved).

Source

docs/planning/phase4-n-am-wire-pump-keepalive-sustain-invariants.md + docs/clusters/PHASE4-N-AM/cluster.md

Introduced in
PHASE4-N-AM

Enforcement trace

Tests 3

  • admission::wire_pump::tests::wire_pump_sends_keep_alive_on_quiescent_cadence
  • admission::wire_pump::tests::wire_pump_keep_alive_response_validates_cookie_no_event
  • admission::wire_pump::tests::wire_pump_keep_alive_cookie_mismatch_fails_closed

Cross-references

Strengthened in

Open obligation