Invariants / T-EPOCH-01
T-EPOCH-01
T true partialExactly one authoritative committee and governance interpretation per epoch
- Source
Project constitution §2, 01_core §13, audit #18
- Cluster
- CONWAY-RATIFICATION-AND-ENACTMENT-AUTHORITY
- Authority surface
- CRE S4.3a: the Conway epoch boundary has exactly ONE governance authority (plan_conway_governance_epoch); the accumulator-follow and direct-replay paths reach it through the single shared applier apply_epoch_boundary_with_registrations, so identical canonical boundary inputs yield the IDENTICAL governance delta (proposal set, deposit routing, treasury delta, governance fingerprint) OR the IDENTICAL structured terminal, regardless of entry path. The accumulator's separate deposit-refund pre-pass is DELETED; no second production path removes a proposal or decides a refund destination (mechanically total via the single-authority gate, which asserts zero production planner calls in the accumulator). A potentially-ratifiable action is a fail-closed terminal with ZERO mutation, computed before any state is constructed. ENACTMENT is now performed ATOMICALLY for the supported exec-units MEMORY-ONLY parameter-change subset (CRE S4.3c): a single fully-ratified ParameterChange chaining onto the current root enacts ONE atomic delta — the new Tx/block memory limits (steps preserved), the advanced previous-pparam-action root, the winner Enacted plus its losing-sibling subtree PrunedByEnactment, and every deposit return — applied at the SAME single point, byte-identical on the accumulator and replay paths (cre_s4_3c_enactment_is_identical_on_replay_and_accumulator_paths) and reproducing the real on-chain 1095->1096 enactment (cre_s4_3c_enactment_differential_1095). At most ONE action enacts per boundary; a ratifiable chain child (ChainedEnactment) or more-than-one competing ratifiable sibling (CompetingRatifiableActions — cardano-ledger's submission-order pick is not reconstructable from canonical state) is a symmetric fail-closed terminal. So the SUPPORTED exec-units enactment subset is ENFORCED. BROADER enactment stays PARTIAL and fail-closed: other action kinds (treasury/hard-fork/committee/constitution), parameter fields outside exec-units, an Unversioned pre-V11 state on the enact path (UnversionedStateOnEnactPath), and multi-ratifiable competition all halt with ZERO mutation — the cluster is NOT globally complete. The CRE S5 consolidated report (cre_s5_differential_report) proves the CE-3d governance refund discrepancy is closed and isolates the remaining residual as the B3c UTxO-component go-stake undercount, not governance.
Enforcement trace
Tests 10
- cre_s4_3a_cross_path_gov_delta_is_identical
- cre_s4_3a_replay_path_refunds_all_five_expiries
- cre_s4_3a_potentially_ratifiable_terminals_both_paths
- cre_s4_3a_rupd_consumed_once_with_governance_refund_at_seed_boundary
- cre_s4_3a_single_governance_authority_no_second_path
- cre_s4_3c_enactment_is_identical_on_replay_and_accumulator_paths
- cre_s4_3c_supported_witness_enacts_prunes_siblings_refunds_all
- cre_s4_3c_ratifiable_chain_child_of_winner_halts
- cre_s4_3c_competing_ratifiable_siblings_halt
- cre_s4_3c_pending_chain_child_is_carried_not_pruned
CI 0
no CI script — gap