T-REC-06
T true enforcedRollback-materialization replay-equivalence (PHASE4-N-AN). A block that validates during live admit (against the eta0-overlaid chain_dep, T-REC-04) MUST NOT fail rollback-materialize replay because materialization substituted a different nonce source. materialize_rolled_back_state (the SOLE rolled-back-state authority, CN-STORE-07) MUST reconstruct the replay chain_dep with the SAME recovered eta0 (epoch nonce) the live-admit path uses (praos_vrf_input(slot, eta0), DC-CINPUT-03); the persisted snapshot's placeholder / genesis epoch_nonce MUST NOT reach VRF verification on the rollback-replay path. Same recovered store + same ordered WAL/feed => same chain_dep inputs => same block_validity result on the live-admit and rollback paths. eta0 is the recovered canonical input (the seed-epoch SeedEpochConsensusInputs.epoch_nonce sidecar) -- never peer data, wall-clock, CLI re-supply, or a re-query. VRF validation strength is UNCHANGED on the rollback path (no bypass / skip / loosening). SCOPE: the recovered seed epoch (no epoch-boundary crossing within the follow window -- eta0 is the constant epoch nonce); a multi-epoch rollback nonce-evolution is a named out-of-scope follow-on. Surfaced by the CE-AI-6 reorg (the rollback-follow died at ReplayFailedAt VrfCert); unblocks CE-AI-6.
- Source
docs/planning/phase4-n-an-rollback-materialize-eta0-invariants.md + docs/clusters/PHASE4-N-AN/cluster.md
- Introduced in
- PHASE4-N-AN
Enforcement trace
Code
Tests 2
- rollback_materialize_overlays_recovered_eta0_replay_equivalent (crates/ade_ledger/src/rollback/materialize.rs -- None overlay => VrfCert; Some(eta0) => Valid + materialized epoch_nonce == eta0 == the live-admit nonce basis)
- rollback_materialize_does_not_bypass_vrf_on_wrong_eta0 (crates/ade_ledger/src/rollback/materialize.rs -- a WRONG eta0 still fails the header VRF: the overlay is not a bypass)