DC-STORE-10
DC true enforcedReplay equivalence requires the persisted authority store and the binary to agree on the MEANING of the
bytes, not merely on their layout. Every durable authority artifact carries a STORE_SEMANTICS_VERSION
marker recording which PRODUCTION rules derived its contents, verified on open -- before any recovery
work. The gate is strict in every direction: marker ABSENT (a pre-P6 legacy store), OLDER, or NEWER all
fail closed with a typed terminal carrying action = RebootstrapRequired. There is deliberately NO
stamp tool, NO operator override, NO CLI/env bypass and NO warn-and-continue; RemediationAction has
exactly ONE variant so the type system cannot express "trust me". A future migration is permitted ONLY
as a sealed migration proof (read an old MARKED store, prove a deterministic old->new transform, write a
new store, emit evidence), never as a stamp.
- Source
docs/clusters/PREPROD-ENTRY-AUTHORITY/SLICE-P6-store-semantics-version-gate.md
- Introduced in
- PREPROD-ENTRY-AUTHORITY-P6
Enforcement trace
Code
Tests 10
- current_marker_is_accepted
- absent_marker_is_rejected_as_legacy
- older_marker_is_rejected
- future_marker_is_rejected
- the_only_remediation_is_rebootstrap
- fresh_chaindb_is_stamped_and_reopens
- unmarked_chaindb_is_rejected_as_legacy
- older_marked_chaindb_is_rejected
- future_marked_chaindb_is_rejected
- the_terminal_names_rebootstrap_and_offers_no_override
Cross-references
Evidence notes
Built from the P4 root cause (e1de7a2e). The six pre-existing version constants (FROZEN_LEADERSHIP=6, SEED_CINPUT=6, BOOTSTRAP_RUPD=3, RECOVERED_ANCHOR_POINT=1, ChainDb SCHEMA_VERSION=3, FINGERPRINT_VERSION=2) all version the ENCODING of bytes; none versions the RULES that produced the values inside them. That distinction is the whole slice: P3 changed the authoritative epoch rule and NO byte layout at all, so every durable object still decoded cleanly while its meaning was three epochs stale, surfacing only as an opaque recovery FingerprintMismatch. PROVEN LIVE against the preserved P4 store: where it previously required a multi-hour investigation to reach FingerprintMismatch { expected: c395bad1.., recovered: 2cda6765.. } AFTER a full replay, it now fails immediately at ChainDb open with StoreSemantics(StoreSemanticsVersionMismatch { artifact: ChainDb, found: Absent, required: 1, action: RebootstrapRequired }). The mechanism generalizes the already-proven FINGERPRINT_VERSION gate, which encodes the required asymmetry in the same function: the ENCODING version upgrades forward on next write, the SEMANTICS version hard-fails in either direction.