Invariants / DC-STORE-08

DC-STORE-08

DC derived enforced

Snapshot encoder canonicality: encode_snapshot(s) is byte-identical across runs. Encoder uses BTreeMap iteration only; no HashMap, no wall-clock, no floats, no rand. Definite-length CBOR containers.

Source

docs/planning/persistent-snapshot-encoder-invariants.md §1 (I-2)

Enforcement trace

Tests 9

  • snapshot::chain_dep::tests::chain_dep_encode_deterministic_across_runs
  • snapshot::utxo_state::tests::utxo_state_encode_deterministic_across_runs
  • snapshot::cert_state::tests::cert_state_encode_deterministic_across_runs
  • snapshot::epoch_state::tests::epoch_state_encode_deterministic_across_runs
  • snapshot::gov_state::tests::pparams_encode_deterministic_across_runs
  • snapshot::gov_state::tests::gov_state_encode_deterministic_across_runs
  • snapshot::ledger::tests::ledger_state_encode_deterministic_across_runs
  • snapshot::framing::tests::snapshot_encode_deterministic_across_runs
  • snapshot::framing::tests::round_trip_via_fingerprint_combined

Cross-references

Strengthened in

Evidence notes

PHASE4-N-K (2026-05-26) strengthening: encoder canonicality now exercised by the persistent writer (PersistentSnapshotWriter::on_admitted / force_capture) and by the shutdown drain (ade_node::node::run_node_until_shutdown). Round-trip determinism asserted end-to-end in shutdown_then_resume_produces_byte_identical_state.