Invariants / DC-SESS-05

DC-SESS-05

DC derived enforced

Wire-layer clock injection: the session reducer + dispatch table contain no SystemTime / Instant::now / tokio::time reads. Keep-alive is driven by the PHASE4-N-K Clock seam (ade_runtime::clock::Clock). Mux frame timestamps enter through caller-supplied parameters at the RED runner boundary, not the GREEN core.

Source

docs/planning/phase4-n-l-wire-protocol-invariants.md §1 (I-5)

Enforcement trace

Tests 3

  • crates/ade_runtime/src/orchestrator/keep_alive_session.rs::tests::keep_alive_session_emits_one_event_per_clock_tick
  • crates/ade_runtime/src/orchestrator/keep_alive_session.rs::tests::keep_alive_session_is_pure_under_deterministic_clock
  • crates/ade_runtime/src/orchestrator/keep_alive_session.rs::tests::keep_alive_cadence_default_is_60s

Cross-references

Strengthened in

Evidence notes

PHASE4-N-L S2+S8 (2026-05-26): session/*.rs contain no SystemTime/Instant/tokio::time reads (ci/ci_check_session_core_closure.sh + ci/ci_check_clock_seam.sh extended). KeepAliveSession drives via Clock trait — DeterministicClock test proves replay equivalence on the keep-alive side.