ade_codec
BLUE- Purpose
Owns Cardano-canonical CBOR ingress — the only place in the workspace that turns raw bytes into typed semantic values, with wire-byte preservation for every hash-bearing structure. Owns the standalone opcert byte authority, the canonical Conway-tx preserved-byte splitter, the canonical block-envelope encoder
cbor::envelope::encode_block_envelope, and the single workspace tag-24 CBOR-in-CBOR wire-envelope authoritycbor::tag24::{wrap_tag24, unwrap_tag24}. Exposes the shared canonical CBOR read/write primitives (read_map_header,read_array_header,canonical_width,ContainerEncoding,IntWidth) the BLUE codecs inade_ledger(incl. the native Mithril MemPack/state decoders) +ade_networkbuild on. Owns the POSITION-BLIND headerprev_hashcodecshelley::block::decode_prev_hash(CN-WIRE-09) and the era-parameterized pointer-address decoderaddress::pointer::{Ptr, PointerDecodeError}. (Noade_codectype change sincecdcd9397— 13.)- Creates
PreservedCbor<T>,RawCbor,BlockEnvelope,ByronDecodedBlock,CodecContext,CodecError,ContainerEncoding,IntWidth, era-tagged block/tx wrappers,OpCertCodecError,TxComponents<'a>,TagEnvelopeError(closed),address::pointer::Ptr+address::pointer::PointerDecodeError(closed). 13 public types.- Interprets
All canonical Cardano CBOR.
unwrap_tag24is the single workspace authority that strips a tag-24 (0xd8 0x18) envelope (zero-copy borrow, fail-closed).shelley::block::decode_prev_hashdecodes the headerprev_hashPOSITION-BLIND.address::pointer::decode_pointer_address(addr_bytes, era)decodes a pointer address's variable-length(slot, txIx, certIx)tail (era-parameterized; the retirement era gate lives inade_ledger::stake_ref).- MUST NOT
(1) Construct
PreservedCboroutsideade_codec. (2) Re-encode wire bytes when computing hashes. (3) Use any forbidden BLUE pattern. (4) Depend on any workspace crate exceptade_types. (5)–(11) per-construct prohibitions (Conway cert/withdrawals/governance, opcert, tx_components, single block-envelope encoder). (12, CN-WIRE-08)cbor::tag24—wrap_tag24/unwrap_tag24defined exactly once; fail-closed; no second/hand-rolled tag-24 parse anywhere. (13, CN-WIRE-09)shelley::block::decode_prev_hash— POSITION-BLIND; the position-aware coupling lives inade_ledger::block_validity::header_position. (14)address::pointer— BYTE REPRESENTATION ONLY; MUST NOT resolve a credential, apply the Conway pointer-retirement era gate, or attribute stake; a malformed / under-length tail fails closed (PointerDecodeError), never a fabricated coordinate.- Inbound deps
ade_ledger(heavy; incl. the reduced-viewstake_ref/pointer_resolve+ the nativemithril_utxo_materialize/ledgerdb_*decoders),ade_plutus,ade_testkit,ade_network,ade_runtime,ade_core_interop,ade_node.- Outbound deps
ade_types. std-only; dev-depsserde_json,toml.- Entry points
ade_codec::cbor::envelope::{decode_block_envelope, encode_block_envelope},ade_codec::{wrap_tag24, unwrap_tag24, TagEnvelopeError}, thecbor::{read_*, write_*_canonical, canonical_width, ContainerEncoding, IntWidth}primitives,ade_codec::traits::AdeEncode, per-eradecode_*_block(incl.conway::decode_conway_block),ade_codec::shelley::{opcert::*, tx_components::split_conway_tx_components, block::decode_prev_hash},ade_codec::address::{decode_address, pointer::{decode_pointer_address, Ptr, PointerDecodeError}}.- Key modules
cbor/(incl.envelope.rs,tag24.rs),byron/,shelley/(incl.block.rs,cert.rs,opcert.rs,tx_components.rs),allegra/,mary/,alonzo/,babbage/,conway/,address/(incl.pointer.rs),preserved.rs,traits.rs,primitives.rs,error.rs.
Depends on
—
Depended on by
—
CI guards — 11
| Script | Enforces |
|---|---|
| ci_check_cbor_round_trip.sh | T-ENC-03 |
| ci_check_conway_cert_classification_closed.sh | DC-TXV-06 |
| ci_check_credential_discriminant_closed.sh |
|
| ci_check_eview_pointer_compat.sh | DC-EVIEW-03 |
| ci_check_forbidden_patterns.sh | DC-LEDGER-08, T-CORE-01, T-CORE-02, T-DET-01 |
| ci_check_forge_decode_round_trip.sh | CN-FORGE-03 |
| ci_check_hash_uses_wire_bytes.sh | T-ENC-01 |
| ci_check_opcert_closed.sh | DC-CONS-11, DC-CONS-12 |
| ci_check_prevhash_single_wire_authority.sh | CN-WIRE-09 |
| ci_check_proposal_procedures_closed.sh | DC-LEDGER-11 |
| ci_check_tag24_wire_authority.sh | CN-WIRE-08 |
Related invariants — 11
| ID | Status | Statement |
|---|---|---|
| CN-FORGE-03 | enforced | Producer/validator codec symmetry: forge_block emits the era-tagged [era, block] envelope (era = Conway discriminant 7) via the single canonical ade_c… |
| CN-WIRE-08 | enforced | N2N tag-24 CBOR-in-CBOR payload envelopes are constructed and stripped through ONE shared BLUE byte authority in ade_codec (wrap_tag24/unwrap_tag24). … |
| CN-WIRE-09 | enforced | The Shelley-and-later header_body `prev_hash` field is the closed wire grammar `$hash32 / null` (cardano-ledger PrevHash = GenesisHash | BlockHash). A… |
| DC-CONS-11 | enforced | OpCert kes_period field equals the KES period at the forged slot under an operator-supplied anchor. period_at_slot(slot, anchor) = (slot - anchor) / s… |
| DC-EVIEW-03 | enforced | Era-parameterized pointer decoding + pre-Conway resolution, matching cardano-ledger EXACTLY (the wire authority -- CIP-19 is silent on canonicality, s… |
| DC-LEDGER-08 | enforced | Conway cert-state accumulation is a closed, total, era-versioned transition: for each block at track_utxo, certificates decode through the era-correct… |
| DC-LEDGER-10 | enforced | Credential identity is faithful end-to-end: a stake/committee/DRep credential is a closed sum over {KeyHash, ScriptHash} of a 28-byte hash, never a ta… |
| DC-LEDGER-11 | enforced | proposal_procedures MUST NOT remain an opaque byte field in the authoritative Conway tx-body shape. ConwayTxBody.proposal_procedures is Option<Vec<Pro… |
| DC-TXV-06 | enforced | For each era, the certificate-deposit classification map(state, cert) is a closed, total, era-versioned function: every certificate variant resolves t… |
| T-ENC-01 | partial | All persisted/hashed/transmitted data uses canonical encoding |
| T-ENC-03 | enforced | Round-trip identity: encode(decode(bytes)) == bytes for valid encodings |