Invariants / DC-STORE-10

DC-STORE-10

DC true enforced

Replay equivalence requires the persisted authority store and the binary to agree on the MEANING of the bytes, not merely on their layout. Every durable authority artifact carries a STORE_SEMANTICS_VERSION marker recording which PRODUCTION rules derived its contents, verified on open -- before any recovery work. The gate is strict in every direction: marker ABSENT (a pre-P6 legacy store), OLDER, or NEWER all fail closed with a typed terminal carrying action = RebootstrapRequired. There is deliberately NO stamp tool, NO operator override, NO CLI/env bypass and NO warn-and-continue; RemediationAction has exactly ONE variant so the type system cannot express "trust me". A future migration is permitted ONLY as a sealed migration proof (read an old MARKED store, prove a deterministic old->new transform, write a new store, emit evidence), never as a stamp.

Source

docs/clusters/PREPROD-ENTRY-AUTHORITY/SLICE-P6-store-semantics-version-gate.md

Introduced in
PREPROD-ENTRY-AUTHORITY-P6

Enforcement trace

Tests 10

  • current_marker_is_accepted
  • absent_marker_is_rejected_as_legacy
  • older_marker_is_rejected
  • future_marker_is_rejected
  • the_only_remediation_is_rebootstrap
  • fresh_chaindb_is_stamped_and_reopens
  • unmarked_chaindb_is_rejected_as_legacy
  • older_marked_chaindb_is_rejected
  • future_marked_chaindb_is_rejected
  • the_terminal_names_rebootstrap_and_offers_no_override

Cross-references

Evidence notes

Built from the P4 root cause (e1de7a2e). The six pre-existing version constants (FROZEN_LEADERSHIP=6, SEED_CINPUT=6, BOOTSTRAP_RUPD=3, RECOVERED_ANCHOR_POINT=1, ChainDb SCHEMA_VERSION=3, FINGERPRINT_VERSION=2) all version the ENCODING of bytes; none versions the RULES that produced the values inside them. That distinction is the whole slice: P3 changed the authoritative epoch rule and NO byte layout at all, so every durable object still decoded cleanly while its meaning was three epochs stale, surfacing only as an opaque recovery FingerprintMismatch. PROVEN LIVE against the preserved P4 store: where it previously required a multi-hour investigation to reach FingerprintMismatch { expected: c395bad1.., recovered: 2cda6765.. } AFTER a full replay, it now fails immediately at ChainDb open with StoreSemantics(StoreSemanticsVersionMismatch { artifact: ChainDb, found: Absent, required: 1, action: RebootstrapRequired }). The mechanism generalizes the already-proven FINGERPRINT_VERSION gate, which encodes the required asymmetry in the same function: the ENCODING version upgrades forward on next write, the SEMANTICS version hard-fails in either direction.