RO-MITHRIL-IMPORT-01
RO release enforcedAde imports a Mithril-authenticated snapshot as an alternative to the cardano-cli JSON seed. Provides cryptographic provenance for the seed artifact (over and above the Blake2b-256 seed_artifact_hash that CN-ANCHOR-01 records).
Lower priority than RO-LIVE-05; resolves after PHASE4-N-M-C closes.
- Source
docs/planning/phase4-n-m-ledger-seed-invariants.md §10 carry-forward; PHASE4-N-Y S1/S7
Enforcement trace
Code
Tests 4
- mithril_binding_rejects_certified_point_other_than_seed_point
- mithril_anchor_rejects_field_mismatch
- mithril_import_fail_closed_blocks_storage_init
- mithril_bootstrap_fails_closed_on_seed_point_mismatch
Cross-references
Strengthened in
Evidence notes
CLOSED 2026-06-17. PHASE4-N-Y introduced the Ade-side Mithril provenance binding (CN-MITHRIL-01/DC-MITHRIL-01). Item (b) closed in PHASE4-N-Z (bootstrap_from_mithril_snapshot wired production composition, verify-before-bootstrap fail-closed, DC-MITHRIL-02 + ci_check_mithril_seed_point_independence.sh). Item (a) RECLASSIFIED (Tier-4 non-goal; documented-interface path -- see docs/active/mithril-documented-interface-runbook.md). Item (c) closed: a real, validator-green, operator-witnessed documented-interface bundle is committed at docs/evidence/mithril-documented-evidence_preprod_2026-06-17.toml (release-preprod cert f52a1d7c..., CardanoDatabase epoch 295 immutable 5829). ade_node --mode node first-run imported the real ~4 GB epoch-295 UTxO seed via the NON-DESTRUCTIVE FROZEN scratch venue (canonical .cardano-node-preprod DB untouched); verify_mithril_binding PASSED with the independently-sourced certified_point (Mithril cert/snapshot metadata) == the operator-extracted seed point (frozen node); a flipped-hash negative control failed closed with Binding(CertifiedPointMismatch), exit 41. Gated by ci/ci_check_mithril_documented_evidence.sh (vacuous-PASS when absent, strict when committed; the multi-GB UTxO seed is out-of-tree/hash-pinned like *-utxo-seed.json). SCOPE: a release/evidence invariant -- documented-interface Mithril import is validator-gated against a committed manifest with independent Mithril-metadata binding, positive first-run import, and negative-control fail-closed proof. NOT a claim of full from-genesis sync (RO-GENESIS-REPLAY-01, owed) or live track_utxo=true ledger application.
Evidence
docs/evidence/mithril-documented-evidence_preprod_2026-06-17.toml (validator-green via ci/ci_check_mithril_documented_evidence.sh; cert f52a1d7c..., epoch 295; binding pass + CertifiedPointMismatch negative control)
docs/active/mithril-documented-interface-runbook.md (operator runbook + decision record)