Invariants / T-REC-06

T-REC-06

T true enforced

Rollback-materialization replay-equivalence (PHASE4-N-AN). A block that validates during live admit (against the eta0-overlaid chain_dep, T-REC-04) MUST NOT fail rollback-materialize replay because materialization substituted a different nonce source. materialize_rolled_back_state (the SOLE rolled-back-state authority, CN-STORE-07) MUST reconstruct the replay chain_dep with the SAME recovered eta0 (epoch nonce) the live-admit path uses (praos_vrf_input(slot, eta0), DC-CINPUT-03); the persisted snapshot's placeholder / genesis epoch_nonce MUST NOT reach VRF verification on the rollback-replay path. Same recovered store + same ordered WAL/feed => same chain_dep inputs => same block_validity result on the live-admit and rollback paths. eta0 is the recovered canonical input (the seed-epoch SeedEpochConsensusInputs.epoch_nonce sidecar) -- never peer data, wall-clock, CLI re-supply, or a re-query. VRF validation strength is UNCHANGED on the rollback path (no bypass / skip / loosening). SCOPE: the recovered seed epoch (no epoch-boundary crossing within the follow window -- eta0 is the constant epoch nonce); a multi-epoch rollback nonce-evolution is a named out-of-scope follow-on. Surfaced by the CE-AI-6 reorg (the rollback-follow died at ReplayFailedAt VrfCert); unblocks CE-AI-6.

Source

docs/planning/phase4-n-an-rollback-materialize-eta0-invariants.md + docs/clusters/PHASE4-N-AN/cluster.md

Introduced in
PHASE4-N-AN

Enforcement trace

Tests 2

  • rollback_materialize_overlays_recovered_eta0_replay_equivalent (crates/ade_ledger/src/rollback/materialize.rs -- None overlay => VrfCert; Some(eta0) => Valid + materialized epoch_nonce == eta0 == the live-admit nonce basis)
  • rollback_materialize_does_not_bypass_vrf_on_wrong_eta0 (crates/ade_ledger/src/rollback/materialize.rs -- a WRONG eta0 still fails the header VRF: the overlay is not a bypass)

Cross-references

Open obligation