Invariants / DC-STORE-11

DC-STORE-11

DC derived enforced

The semantics marker is PER-ARTIFACT, and every authority artifact must agree with the binary independently. chain.db (with the WAL written in lockstep beside it) comes from the data directory while epoch-accumulator.redb and reduced-checkpoint.redb are opened from snapshot_dir, so the authority artifacts can arrive from DIFFERENT provenance. A single store-level marker would therefore let a semantically stale accumulator or reduced checkpoint ride along with a current ChainDb. Because each artifact must equal the binary's required version, pairwise agreement between siblings follows structurally rather than needing a separate cross-check.

Source

docs/clusters/PREPROD-ENTRY-AUTHORITY/SLICE-P6-store-semantics-version-gate.md

Introduced in
PREPROD-ENTRY-AUTHORITY-P6

Enforcement trace

Tests 4

  • fresh_accumulator_is_stamped_and_reopens
  • stale_accumulator_is_rejected_independently_of_the_chaindb
  • fresh_reduced_checkpoint_is_stamped_and_reopens
  • stale_reduced_checkpoint_is_rejected_independently

Cross-references

Evidence notes

The independent-provenance risk is not hypothetical: the P4 investigation runs pair --snapshot-dir preview-snapshot-1376 with --data-dir ade-r2-live, i.e. accumulator and reduced checkpoint from one lineage and chain.db/WAL from another. The positive test proves a CURRENT chain.db still opens while its stale sibling is rejected, so the check cannot pass by rejecting everything. A fresh artifact is STAMPED rather than rejected (keyed off whether the artifact already holds authority content), so bootstrap remains possible -- without that, the gate would reject every store including new ones.