T-REC-01
T true enforcedRecovery is replay-equivalent: restart produces byte-identical state to clean run
- Source
Project constitution §2
Enforcement trace
Code
Tests 9
- recover_from_snapshot_and_replay_forward
- recover_from_genesis_when_no_snapshot
- apply_failure_surfaces_with_slot
- snapshot_decode_failure_surfaces_as_error
- snapshot_with_no_post_blocks_is_ok
- stress_kill_smoke
- stress_kill_1000
- snapshot_table_intact_after_kill_loop
- persistent_passes_crash_safety_with_no_kill
Cross-references
Strengthened in
Evidence notes
PHASE4-N-F-A (2026-05-30): recovered state now includes the seed-epoch consensus inputs — the warm-start verification CAPABILITY (DC-CINPUT-01, A3b authority surface) restores the SeedEpochConsensusInputs sidecar byte-identically + fail-closed. PHASE4-N-F-C (2026-05-31): the PRODUCTION restart path is now wired — the --mode node lifecycle owner (warm_start_recovery) drives replay_from_anchor → bootstrap_initial_state(RequiredFromRecoveredProvenance) from the binary, and L4c (node_sync_kill_then_warm_start_recovers_same_tip) proves a synced+advanced tip recovers byte-identically through it. DC-CINPUT-01 is now enforced (production wiring, not just the A3b capability).