Modules / ade_ledger

ade_ledger

BLUE
BLUE crate
Purpose

The functional core (ledger half): stateless ledger rules for every era; B1 block-validity verdict; B2 tx-validity + mempool admission; the single BLUE wire-ingress chokepoint mempool::ingress::mempool_ingress; the BLUE producer authority; the single body-hash authority; the receive/rollback authorities; the canonical UTxO state + the owned-lookup seam / bounded overlay / versioned v2 fingerprint machinery; the snapshot/bootstrap-anchor/genesis/seed-epoch authorities; the reduced-view core (stake_ref/pointer_resolve/reduced_*/reduced_epoch_view/bootstrap_manifest); the native Mithril V2 decoders (ledgerdb_state/ledgerdb_tables/mithril_utxo_materialize); the value/param types (value, pparams::MinUtxoRule). NEW this refresh — the self-sustaining-ledger BLUE core (LIVE-LEDGER-EPOCH-TRANSITION + REDUCED-VALIDATION-BOUNDARY-PLANE + CE3D + Conway governance): epoch_accumulator (the small durable non-UTxO authority + the apply_selected_block transition contract — LedgerState MINUS full UTxO PLUS the two-buffer nesBprev/nesBcur model; DC-EPOCH-19/21/24); frozen_leadership (the self-contained FrozenLeadershipPoolDistr = cardano's nesPd; DC-EPOCH-25); reduced_boundary (the typed ReducedBoundaryProjection a track_utxo=false follower produces at a Conway boundary); rollback/admission (the BLUE admit_rollback recovery rail — LIVE-LEDGER-EPOCH-TRANSITION S5); bootstrap_bridge (the ONE-TIME seed→seed+1 BootstrapNextEpochAuthority; DC-EPOCH-15); bootstrap_reward_update (the seed→seed+1 reward update carrying the certified snapshot's feeSS/deltaF; DC-EPOCH-18/23); cred (the single stake-credential CBOR-discriminant authority, functions only); the Conway ratification/enactment growth in governance.rs. ade_ledger is 220 → 275 (+55) — all pure.

Creates

275 public types. Load-bearing carried: BlockValidityError, BlockVerdict, LedgerState, UTxOState, TxOut, WalEntry (closed — AdmitBlock \| SeedEpochConsensusInputsImported \| RollBack \| EpochConsensusViewActivated), LedgerFingerprint, MempoolState, ProducerTick, ForgedBlock, SeedEpochConsensusInputs (+security_param: u64 this refresh — S2 sidecar v6, SEED_CINPUT_SCHEMA_VERSION = 6, FIELDS_OUTER 14), BootstrapAnchor, RecoveredAnchorPoint, the reduced-view / native-Mithril families, value::{MultiAsset, AssetName, Value}, pparams::MinUtxoRule. NEW this refresh: epoch_accumulator::{EpochAccumulator, SeedError, SelectedBlockCtx, LedgerTransitionError, EpochBoundaryEffect, BoundaryFreezeInputs, BoundaryBaseStake, PostRupdRewards<'a>, EpochAccumulatorCodecError}; frozen_leadership::{LeadershipPoolEntry, FrozenLeadershipPoolDistr, FrozenLeadershipError}; reduced_boundary::{ReducedBlockWindow, ReducedEpochProgress, ReducedCertProjection, ReducedGovernanceProjection, ReducedBoundaryProjection, FullEpochBoundaryResult, LedgerBoundaryVerdict, LedgerValidityCapability}; rollback::admission::{RollbackPoint, RollbackAdmissionError, RecoveryAction}; bootstrap_bridge::{BridgeSourceKind, BootstrapNextEpochAuthority, BridgeCodecError}; bootstrap_reward_update::{BootstrapRewardUpdate, BootstrapRupdError}; the Conway-governance governance::{RatificationResult, RatificationObservation, RemovalCause, RemovedProposal, DepositReturn, PParamsDelta, PrevPParamActionDelta, ConwayGovernanceEpochPlan, MalformedGovDetail, UnsupportedActionKind, GovernanceTerminal, ConwayGovernanceEpochInput<'a>, ExecUnitsParamUpdate, ExecUnitsUpdateError, EnactmentEffects, …}.

Interprets

Canonical decoded blocks/txs/certs/snapshots; block_validity produces the per-block verdict + post-state; mempool_ingress is the sole BLUE chokepoint; the reduced-view + native-Mithril decode points (ledgerdb_state::decode_native_nonutxo_state, ledgerdb_tables::read_txout, mithril_utxo_materialize::materialize_tables_to_utxo, bootstrap_manifest::verify_and_import_cert_state, EpochConsensusView::{bind, verify_canonical_hash, matches}). NEW: epoch_accumulator::apply_selected_block(prior, block_bytes, ctx) — the total/deterministic/replay-equivalent non-UTxO transition (boundary effects in cardano NEWEPOCH order FIRST, then within-epoch cert/withdrawal/issuer/fee effects), reusing rules::apply_epoch_boundary_with_registrations + process_block_certificates + delegation::apply_bootstrap_reward_deltas; build_boundary_mark_snapshot (the boundary mark = registered+delegated credential IFF combined active stake NON-ZERO — DC-EPOCH-24); frozen_leadership::to_pool_distr_view (leadership PoolDistr read DIRECTLY from the frozen distr); reduced_boundary (the typed reduced projection); rollback::admission::admit_rollback (pure/total/fail-closed target admissibility); bootstrap_bridge (seed+1 view from the imported MARK snapshot ALONE); bootstrap_reward_update (the seed-boundary reward update + deltaF fee-pot reduction).

MUST NOT

All carry-forward ledger prohibitions (no I/O, no clock, closed cert/governance enums, single body-hash recipe; producer::* fences; rollback::materialize the SOLE rolled-back-state authority; block_validity the single block verdict authority; the MEM DC-MEM-05..10 fences; the reduced-view DC-EVIEW-02..07/09 fences; the native-Mithril DC-MITHRIL-01/06 fences; DC-LEDGER-VALUE-01 non-negative Word64 output-quantity domain; DC-LEDGER-PARAMS-01 era-faithful MinUtxoRule). NEW this refresh: (epoch_accumulator, DC-EPOCH-19/21) apply_selected_block MUST derive EVERY future epoch transition WITHOUT another Mithril import / CLI oracle / injected authority; it carries ONLY non-UTxO facts (the stake-bearing UTxO stays in the disk-backed reduced checkpoint) — it MUST NOT hold a full UTxO map, and the boundary MUST reuse the single canonical apply_epoch_boundary_with_registrations POOLREAP block (future-pool adoption, reap, deposit refund, delegation-clear) in the cardano NEWEPOCH order, never a parallel reimplementation; the two-buffer model MUST feed prev_* (nesBprev) to the boundary, not the just-finished nesBcur. (frozen_leadership, DC-EPOCH-25) the leadership PoolDistr (nesPd) MUST be answered by the self-contained FrozenLeadershipPoolDistr and by NOTHING else — to_pool_distr_view reads stake AND VRF DIRECTLY from it, NEVER from active cert_state.pool.pools / the go snapshot / future_pools / the retiring map; it MUST include zero-stake registered pools AND retired/POOLREAP'd pools whose VRF is absent from active state (deriving leadership from go + active params is a DISPROVEN hypothesis). (reduced_boundary, I-RVB-1) a ReducedBoundaryProjection and a FullEpochBoundaryResult are DISTINCT, non-interchangeable types — the projection is NOT a LedgerState, cannot be widened into one, cannot be serialized as an accumulator snapshot, and cannot be fingerprinted as full authority; a track_utxo=false boundary MUST NOT emit a reward-only stub mark (proven to leak into recovery persistence + WAL fingerprints). (rollback::admission, LIVE-LEDGER-EPOCH-TRANSITION S5) admit_rollback MUST fail closed (typed RollbackAdmissionError, never a silent rematerialization) on an inadmissible target — a split lineage, a rollback deeper than the immutable point (k-BLOCK-bound = tip − k), or below the sealed anchor; it is NOT fork-choice (admits/rejects one target, never selects among competing forks). (bootstrap_bridge, DC-EPOCH-15) the seed→seed+1 bridge view MUST come from the imported snapshot's MARK stake snapshot ALONE (source_kind = ImportedMarkSnapshot), never nesPd / a window replay / an oracle; the selector reads target_epoch == seed+1 ⇒ bridge, ≥ seed+2 ⇒ replay. (bootstrap_reward_update, DC-EPOCH-18/23) the one-shot seed-boundary reward update MUST carry the certified snapshot's feeSS (deltaF) and reduce the accumulated fee pot by it EXACTLY ONCE. (governance, DC-GOV-01 / DC-CINPUT-07 — declared) a removed governance proposal's deposit is refunded to its recorded return address ONLY when Ade can PROVE from canonical state + Conway rules that it could NOT have ratified or enacted, else fail closed (terminal); the Conway deposit params (gov_action_deposit/drep_deposit/drep_activity) are DECODED from the certified snapshot's Conway curPParams at the verified positions, never defaulted.

Inbound deps

ade_testkit, ade_core_interop, ade_runtime (reduced-window driver + the epoch-accumulator durable advance + native-Mithril assembly + the durable reduced checkpoint), ade_node (epoch-activation orchestration + frozen-leadership promotion + native FirstRun + the S2 seed-sidecar codec via SeedEpochConsensusInputs).

Outbound deps

ade_types (incl. mary::value::OutputAssetQuantity), ade_crypto (utxo_set_commitment + blake2b_256), ade_codec (address::pointer::*, the cbor::* primitives, wrap_tag24), ade_plutus, ade_core (consensus::{SecurityParam, events::Point, vrf_cert::ActiveSlotsCoeff, era_schedule::*}), minicbor, num-bigint, num-integer, num-traits. Dev-dep: ade_testkit.

Entry points

ade_ledger::block_validity::*, ade_ledger::state::LedgerState, ade_ledger::utxo::{TxOut, UTxOState}, ade_ledger::{fingerprint, utxo_overlay, pre_resolve, tx_validity, mempool, producer, receive, rollback, snapshot, wal, seed_consensus_inputs, bootstrap_anchor, recovered_anchor_point}::*, the reduced-view + native-Mithril families, NEW: ade_ledger::epoch_accumulator::{EpochAccumulator, apply_selected_block, build_boundary_mark_snapshot, EpochBoundaryEffect, LedgerTransitionError}, ade_ledger::frozen_leadership::{FrozenLeadershipPoolDistr, LeadershipPoolEntry, to_pool_distr_view, from_seed_epoch_consensus_inputs, encode_frozen_leadership, decode_frozen_leadership}, ade_ledger::reduced_boundary::{ReducedBoundaryProjection, LedgerBoundaryVerdict, LedgerValidityCapability}, ade_ledger::rollback::admission::{admit_rollback, RollbackAdmissionError, RecoveryAction}, ade_ledger::bootstrap_bridge::{BootstrapNextEpochAuthority, BridgeSourceKind}, ade_ledger::bootstrap_reward_update::BootstrapRewardUpdate, ade_ledger::governance::*.

Key modules

block_validity/, tx_validity/, mempool/, cert_classify/, consensus_view.rs, delegation.rs (DelegationState/CertState + apply_bootstrap_reward_deltas), governance.rs (Conway ratify/enact authority — grew this refresh), producer/, block_body_hash.rs, receive/, rollback/ (incl. admission.rs — the S5 recovery rail), snapshot/ (incl. cert_state.rs, chain_dep.rs), epoch.rs, rules.rs (apply_epoch_boundary_with_registrations — the single canonical POOLREAP block), wal/ (event.rs — the 4-variant closed WalEntry), utxo.rs + utxo_overlay.rs + pre_resolve.rs + fingerprint.rs (MEM), value.rs, pparams.rs, the reduced-view stake_ref.rs/pointer_resolve.rs/reduced_utxo.rs/reduced_advance.rs/reduced_aggregate.rs/reduced_snapshot.rs/reduced_epoch_view.rs/bootstrap_manifest.rs, the native-Mithril mithril_utxo_materialize.rs/ledgerdb_state.rs/ledgerdb_tables.rs, seed_consensus_inputs.rs (the GREEN v6 sidecar codec), NEW: epoch_accumulator.rs, frozen_leadership.rs, reduced_boundary.rs, bootstrap_bridge.rs, bootstrap_reward_update.rs, cred.rs, state.rs, plutus_eval.rs.

Depends on

—

Depended on by

—

CI guards — 99

ScriptEnforces
ci_check_admitted_block_closure.sh CN-CONS-07, CN-CONS-08, CN-PROTO-07
ci_check_block_fetch_server_closure.sh DC-CONS-17, DC-PROTO-07
ci_check_bnd_typed_stall_cause.sh DC-EPOCH-39
ci_check_bootstrap_anchor_closure.sh CN-ANCHOR-01, DC-ANCHOR-01
ci_check_bootstrap_rupd_fee_reduction.sh

DC-EPOCH-23 (CE-3d)

ci_check_bootstrap_rupd_window_end.sh

DC-EPOCH-18 (B3c)

ci_check_bridge_nonce_freeze_differential.sh DC-EPOCH-38
ci_check_broadcast_to_served_purity.sh DC-CONS-17, DC-CONS-18, DC-PROTO-07
ci_check_collateral_balance_resolver.sh DC-LEDGER-PHASE2-02, DC-LEDGER-PHASE2-03
ci_check_collateral_retention_positioning.sh DC-LEDGER-PHASE2-04
ci_check_consensus_closed_enums.sh CN-CONS-02, DC-CONS-03, DC-CONS-04, DC-CONS-05, DC-CONS-06, DC-CONS-09, DC-CONS-10, DC-CONSENSUS-01, DC-MEM-01, DC-MEM-02, DC-TXV-01, DC-TXV-02, DC-TXV-03, DC-TXV-04, DC-TXV-05, DC-VAL-01, DC-VAL-02, DC-VAL-03, DC-VAL-04, DC-VAL-05, DC-VAL-06, T-DET-01
ci_check_conway_cert_classification_closed.sh DC-TXV-06
ci_check_conway_deposit_params_bootstrap.sh

DC-CINPUT-07 (band 9)

ci_check_credential_discriminant_closed.sh

DC-LEDGER-10 (band 7)

ci_check_dependency_boundary.sh T-BOUND-02, T-CORE-01
ci_check_deposit_param_authority.sh DC-TXV-07
ci_check_differential_divergence.sh DC-LEDGER-02, DC-LEDGER-03, T-CONSERV-01, T-NOSPEND-01
ci_check_epoch_agreement.sh DC-EPOCH-36
ci_check_eview_activation_wal.sh DC-EPOCH-04
ci_check_eview_activation.sh DC-EVIEW-08
ci_check_eview_bootstrap_cert_state.sh DC-EVIEW-09
ci_check_eview_leadership_complete.sh DC-EPOCH-12, DC-EVIEW-05, DC-EVIEW-07, DC-EVIEW-12
ci_check_eview_pointer_compat.sh DC-EVIEW-03
ci_check_eview_pool_lifecycle.sh DC-EVIEW-13
ci_check_eview_reduced_utxo_checkpoint.sh DC-EVIEW-04
ci_check_eview_refold_reseal.sh DC-EPOCH-32, DC-EPOCH-33
ci_check_eview_seed_sidecar_v4.sh DC-CINPUT-06
ci_check_eview_stability_gate.sh DC-EVIEW-06
ci_check_eview_stake_aggregation.sh DC-EVIEW-05
ci_check_eview_stake_ref_classification.sh DC-EVIEW-02
ci_check_eview_view_binding.sh DC-EVIEW-07
ci_check_eview_windowed_advance.sh DC-EVIEW-04b
ci_check_feed_leader_threshold_view.sh DC-CINPUT-04
ci_check_forbidden_patterns.sh DC-LEDGER-08, T-CORE-01, T-CORE-02, T-DET-01
ci_check_forge_decode_round_trip.sh CN-FORGE-03
ci_check_forge_purity.sh DC-CONS-13, DC-CONS-14, DC-CONS-15, DC-LEDGER-12
ci_check_forged_durable_admit_via_pump.sh DC-CONS-23, DC-NODE-12, DC-WAL-04
ci_check_frozen_leadership_authority.sh

S4-pre

ci_check_frozen_promotion_no_seed_window.sh

S4-L2

ci_check_frozen_recovery_no_seed_window.sh

S4-L1

ci_check_gov_cert_accumulation_closed.sh DC-LEDGER-09
ci_check_hash_uses_wire_bytes.sh T-ENC-01
ci_check_header_body_binding.sh CN-CONS-04
ci_check_hfc_translation.sh DC-EPOCH-02
ci_check_ledger_determinism.sh DC-LEDGER-01, DC-LEDGER-02, T-DET-01
ci_check_ledgerdb_state_decode.sh DC-MITHRIL-04
ci_check_ledgerdb_tables_decode.sh DC-MITHRIL-05
ci_check_lifecycle_owner_uses_bootstrap_initial_state.sh DC-CINPUT-01
ci_check_live_fork_choice_apply.sh DC-NODE-25, DC-NODE-26, DC-NODE-27
ci_check_live_fork_choice_wiring.sh DC-NODE-25, DC-NODE-28
ci_check_mem_opt_s3_owned.sh OP-MEM-02
ci_check_mempool_ingress_closure.sh DC-MEM-03
ci_check_mempool_ingress_replay.sh DC-MEM-04
ci_check_mithril_documented_evidence.sh RO-MITHRIL-IMPORT-01
ci_check_mithril_seed_point_independence.sh CN-MITHRIL-01, DC-MITHRIL-02, RO-MITHRIL-IMPORT-01
ci_check_mithril_uses_bootstrap_initial_state.sh CN-MITHRIL-01, DC-GENESIS-SRC-01, DC-MITHRIL-01, RO-MITHRIL-IMPORT-01
ci_check_native_nonutxo_decode.sh DC-LEDGER-PARAMS-01
ci_check_no_float_in_consensus.sh CN-CONS-05, DC-CONS-03, DC-CONS-08, T-CORE-02
ci_check_no_independent_forge_codepath.sh CN-FORGE-01
ci_check_no_parallel_header_splitter.sh CN-PROTO-06, DC-CONS-16, DC-CONS-18
ci_check_no_private_keys_in_corpus.sh DC-CONS-14
ci_check_no_producer_body_encoder.sh DC-CONS-16
ci_check_no_semantic_cfg.sh T-BUILD-01
ci_check_node_run_loop_containment.sh CN-NODE-02, CN-NODE-03, DC-NODE-05, DC-NODE-06, DC-NODE-12, DC-SYNC-02, T-REC-03
ci_check_overlay_utxo_s2a.sh DC-MEM-07
ci_check_phase2_invalid_utxo_effect.sh DC-LEDGER-PHASE2-01
ci_check_plutus_budget_cap.sh CN-PLUTUS-02, DC-LEDGER-03
ci_check_plutus_oracle_no_false_accept.sh DC-LEDGER-03
ci_check_praos_nonce_follow_evolution.sh

DC-EPOCH-16 (ECA-B1/B2)

ci_check_prevhash_single_wire_authority.sh CN-WIRE-09
ci_check_producer_coordinator_no_secrets.sh CN-FORGE-01, CN-PROD-02
ci_check_receive_orchestrator_no_producer_dep.sh DC-CONS-20
ci_check_receive_reducer_closure.sh CN-CONS-07, CN-CONS-08, DC-CONS-13, DC-CONS-16, DC-CONS-19, DC-CONS-20, DC-PROTO-09
ci_check_receive_replay_purity.sh DC-PROTO-09
ci_check_recover_follow_wal_lineage.sh DC-WAL-02
ci_check_recovery_fault_self_describing.sh DC-NODE-44
ci_check_required_signer_closure.sh CN-LEDGER-09, DC-LEDGER-05
ci_check_rollback_materialize_closure.sh CN-STORE-07, DC-CONS-20, DC-CONS-22
ci_check_rollback_materialize_eta0.sh T-REC-06
ci_check_self_accept_gate.sh CN-CONS-07
ci_check_served_chain_closure.sh CN-CONS-07
ci_check_served_chain_handoff_fence.sh DC-NODE-06
ci_check_served_chain_projection.sh DC-NODE-06, DC-NODE-11, DC-NODE-13
ci_check_sigma_denominator_authority.sh DC-EPOCH-40
ci_check_snapshot_encoder_closure.sh CN-STORE-08, DC-CONS-21, DC-STORE-08, DC-STORE-09
ci_check_snapshot_pool_set_inclusion.sh

DC-EPOCH-24 (CE-3d)

ci_check_store_semantics_gate.sh DC-STORE-10, DC-STORE-11
ci_check_store_semantics_lock.sh DC-EPOCH-40, DC-STORE-12
ci_check_tables_to_utxostate.sh DC-MITHRIL-06
ci_check_unsigned_header_preimage_single_source.sh CN-KES-HEADER-01, DC-CONS-18
ci_check_utxo_fp_cache.sh OP-MEM-02
ci_check_utxo_fp_v2.sh DC-MEM-10
ci_check_utxo_lookup_owned.sh DC-MEM-09
ci_check_value_quantity_domain.sh DC-LEDGER-VALUE-01
ci_check_venue_constant_containment.sh DC-LEDGER-13
ci_check_venue_differential.sh DC-EPOCH-37
ci_check_wal_append_only.sh CN-WAL-01, DC-ADMIT-05, DC-WAL-01
ci_check_wal_rollback_replay_equiv.sh DC-NODE-27
ci_check_warmstart_eta0_overlay.sh

ECA-B (band 7)

Related invariants — 137

IDStatusStatement
CN-ANCHOR-01 enforced Single BootstrapAnchor mint authority: exactly one pub fn in ade_runtime::bootstrap_anchor::mint produces a BootstrapAnchor with all 6 fields populate…
CN-CINPUT-01 enforced The seed-epoch consensus inputs (epoch, active-slots coefficient, total active stake, and the per-pool active-stake + registered VRF keyhash distribut…
CN-CONS-04 enforced Header validation must bind exactly to the accepted body and consensus context
CN-CONS-07 enforced Self-acceptance bridge + serve provenance. A forged block is NOT eligible for RED broadcast unless Ade's own header validator (PHASE4-N-B path) and bo…
CN-CONS-08 enforced Receive-side single admission authority: every block that lands in ChainDb via the receive path passed block_validity with BlockValidityVerdict::Valid…
CN-EPOCH-01 partial Stake, rewards, parameter changes, and governance effects may activate only at protocol-defined epoch boundaries
CN-FORGE-01 enforced The producer-mode forge handler is a closed transition from CoordinatorEvent::RequestForge { slot, kes_period, ledger_snapshot_ref, chain_tip } to exa…
CN-FORGE-03 enforced Producer/validator codec symmetry: forge_block emits the era-tagged [era, block] envelope (era = Conway discriminant 7) via the single canonical ade_c…
CN-KES-HEADER-01 enforced The KES signature in a forged block's header is over the canonical unsigned-header CBOR pre-image — the CBOR encoding of ShelleyHeaderBody (the first …
CN-LEDGER-09 partial Witnesses must bind exactly to the intended body, certificates, withdrawals, governance actions, and scripts for the era
CN-MITHRIL-01 enforced A Mithril-sourced seed may bootstrap only after a verified binding: the Mithril manifest's attested {network_magic, genesis_hash, certified_point, cer…
CN-PLUTUS-02 declared Budget exhaustion and script failure must have a single deterministic failure shape
CN-PREIMAGE-FIXTURE-01 enforced For every block in ade_testkit::validity::corpus::ConwayValidityCorpus, Ade's unsigned_header_pre_image(...) (with inputs derived from decode_block(bl…
CN-PROD-04 enforced Every CoordinatorEffect::BroadcastBlock reconstructs the AcceptedBlock from artifact.bytes through the BLUE self_accept authority against the pre-forg…
CN-PROTO-06 enforced The producer-side session orchestrator can only construct outgoing mini-protocol messages tagged with Server agency. Client-originated messages from t…
CN-PROTO-07 enforced Receive-side agency closure: the receive bridge consumes only peer-originated ForkChoiceSignal and BatchDeliveryEvent values valid for the client-role…
CN-STORE-07 enforced Single materialize authority for rolled-back state: the function that materializes (LedgerState, PraosChainDepState) at a target point uses ONLY one S…
CN-STORE-08 enforced Single encoder authority: encode_ledger_state + decode_ledger_state + encode_chain_dep + decode_chain_dep + encode_snapshot + decode_snapshot are the …
CN-WAL-01 enforced Single WAL append authority: WalStore::append is the SOLE mutation method on any WalStore impl. No truncate/rewrite/replace method exists on the trait…
CN-WIRE-09 enforced The Shelley-and-later header_body `prev_hash` field is the closed wire grammar `$hash32 / null` (cardano-ledger PrevHash = GenesisHash | BlockHash). A…
DC-ANCHOR-01 enforced BootstrapAnchor canonical CBOR round-trip: encode + decode preserves all 6 fields byte-identically. SCHEMA_VERSION = 1 in the encoded bytes; unknown v…
DC-CINPUT-01 enforced WARM-START VERIFICATION CAPABILITY (authority surface — NOT production restart). The seed-epoch consensus-input import is a canonical, replay-reconstr…
DC-CINPUT-02a enforced PROJECTION EQUIVALENCE. The recovered SeedEpochConsensusInputs projects deterministically to the leadership-consumed PoolDistrView (the full LedgerVie…
DC-CINPUT-03 enforced The producer Praos VRF leader/header input is `praos_vrf_input(slot, eta0)` = `blake2b256(slot_be8 ‖ eta0_32)` (= cardano `mkInputVRF`), where eta0 is…
DC-CINPUT-04 enforced The receive/feed-path header-validation consensus view -- the LedgerView passed to block_validity -> validate_and_apply_header for Step 5 (VRF-keyhash…
DC-CINPUT-05 enforced Venue epoch geometry is DURABLE REPLAY AUTHORITY. A recovered store MUST replay using the epoch geometry (epoch_start_slot + epoch_length_slots) persi…
DC-CINPUT-06 enforced The durable consensus PROFILE includes genesis_hash + protocol_params_hash, persisted canonically in the v4 SeedEpochConsensusInputs sidecar and recov…
DC-CINPUT-07 declared Conway deposit-parameter bootstrap authority. The Conway-only deposit params (drep_deposit / gov_action_deposit / drep_activity) are DECODED from the …
DC-CONS-13 enforced Forge is pure given a canonical ProducerTick. forge_block has no wall-clock, no rand, no HashMap iteration, no I/O, no locale, and no ambient state. A…
DC-CONS-14 enforced Forge byte-equality across replays. For two replays of an identical canonical ProducerTick stream over the same initial LedgerState, forge_block produ…
DC-CONS-15 enforced Forge is invoked only when leader-check passes. forge_block is a forbidden transition for ticks where is_leader(state, vrf_output, sigma, asc) == fals…
DC-CONS-16 enforced Forged header.body_hash MUST equal blake2b_256(forged_body_wire_bytes), where forged_body_wire_bytes are produced by the single Cardano-compatible can…
DC-CONS-17 enforced Block bytes delivered via producer-side block-fetch Block{bytes} are byte-identical to AcceptedBlock.as_bytes() for the AcceptedBlock that cleared sel…
DC-CONS-18 enforced Header bytes announced via chain-sync RollForward{header,tip} are the header sub-segment of the AcceptedBlock whose body bytes are subsequently servab…
DC-CONS-19 enforced Receive-side header-body sourcing coherence: when BlockDelivered {block_bytes} arrives at the receive bridge, the decoded header bytes of block_bytes …
DC-CONS-20 enforced ChainDb-ledger-chain_dep lockstep: a successful receive-side admission updates ChainDb, LedgerState, and PraosChainDepState as one structural transiti…
DC-CONS-21 enforced Snapshot encode/decode round-trip equivalence: for any reachable (LedgerState, PraosChainDepState), decode(encode(state)) yields a state whose ade_led…
DC-CONS-22 enforced Replay-forward correctness: given state_at_slot_S and the ordered block sequence blocks(S+1..=T) from ChainDb, the replay-forward driver yields a stat…
DC-CONS-23 enforced Own-forged stale-tip race safety by extend-only durable admit. An own-forged candidate is admitted to the durable tip ONLY if it EXTENDS the current d…
DC-CONSENSUS-02 partial Leadership verification is pure
DC-EPOCH-01 partial Conway governance timing: proposals accumulate during epoch, ratification and enactment are atomic at epoch boundary, pulsing distributes DRep stake c…
DC-EPOCH-02 enforced Hard fork transitions triggered at deterministic slot/epoch boundaries; era translation functions mandatory; forecast horizon extends to era boundary
DC-EPOCH-04 enforced For a target epoch, AT MOST ONE canonically bound EpochConsensusView may activate (S3f-4a substrate). A distinct WalEntry::EpochConsensusViewActivated…
DC-EPOCH-12 enforced The promoted-epoch PoolDistrView is derived EXCLUSIVELY from the sealed EpochConsensusView + the bound-commitment- checked consensus profile (ECA-0b).…
DC-EPOCH-16 enforced Rolling Praos chain-dep nonce evolution on the live follow path. Each validated followed header drives ONE indivisible BLUE nonce transition over {slo…
DC-EPOCH-18 enforced Window-end bootstrap reward update for the seed+2 leadership authority. The first post-bootstrap replay-derived authority (seed+2, DC-EPOCH-17) is the…
DC-EPOCH-23 enforced Bootstrap reward-update fee-buffer authority (CE-3d). The one-shot bootstrap reward update applied at the seed->seed+1 boundary carries the certified …
DC-EPOCH-24 enforced Snapshot pool-set inclusion = cardano's ssActiveStake NonZero membership (CE-3d). The per-epoch stake snapshot (mark/set/go) INCLUDES a registered+del…
DC-EPOCH-25 declared Self-contained frozen leadership authority (S4-pre). Cardano's leadership PoolDistr (nesPd) -- the per-pool (active_stake, vrf_keyhash) that decides t…
DC-EPOCH-33 enforced Refold re-seal identity. Re-deriving an epoch boundary the node has already crossed re-seals a frozen-leadership object byte-identical to the one the …
DC-EPOCH-36 enforced After the epoch-boundary decision for a block at `slot`, the ledger's epoch MUST equal the venue era schedule's epoch for that slot. A disagreement in…
DC-EPOCH-37 enforced Authoritative epoch semantics must be proven PER VENUE, not inferred from a mainnet-shaped corpus. Every venue in the closed node-side registry (`nati…
DC-EPOCH-38 enforced The Praos candidate-freeze / nonce surface must be proven across SEED-POSITION x VENUE, not once per venue. `eta0(N+1)` is committed from the candidat…
DC-EPOCH-39 enforced A stall's CAUSE is typed, and only a real epoch transition may enter boundary machinery. Advancing the durable accumulator over one block yields exact…
DC-EPOCH-40 partial Leadership sigma denominator authority (SLICE LV-1). The leader-check sigma denominator is the SNAPSHOT's total active stake -- cardano's `pdTotalActi…
DC-EVIEW-02 enforced Typed, era-gated stake-reference classification. Given canonical address bytes and a TYPED era / protocol-version context BOUND to the block being pro…
DC-EVIEW-03 enforced Era-parameterized pointer decoding + pre-Conway resolution, matching cardano-ledger EXACTLY (the wire authority -- CIP-19 is silent on canonicality, s…
DC-EVIEW-04 enforced The durable reduced-UTxO checkpoint -- the "minimal native state" (S3b Option B). A disk-backed redb store of TxIn -> (Coin, ReducedStakeRef), built f…
DC-EVIEW-04b enforced The windowed advance (S3b-2): advance the durable reduced-UTxO checkpoint (DC-EVIEW-04) per epoch boundary by replaying the epoch's admitted blocks, a…
DC-EVIEW-05 enforced Per-pool stake aggregation (S3c, the linchpin). aggregate_pool_stake computes the next-epoch per-pool active stake from the single ledger authority's …
DC-EVIEW-06 enforced Snapshot formation + the k-immutability stability gate (S3d). form_mark_snapshot converts the S3c per-pool aggregate (StakeByPool) into the MARK Stake…
DC-EVIEW-07 enforced The bound, immutable EpochConsensusView (S3e). EpochConsensusView::bind emits the compact next-epoch consensus view from the finalized snapshot (S3d),…
DC-EVIEW-08 declared Activation -- the live-path consumption of Ade's self-derived next-epoch view. MECHANISM (IMPLEMENTED + AUTOMATIC): the boundary activation is wired i…
DC-EVIEW-09 enforced The manifest-bound bootstrap cert-state import (S3f-2 prerequisite). The seed (SeedEpochConsensusInputs, the compact per-POOL active epoch consensus v…
DC-EVIEW-12 enforced The leadership-complete, self-contained EpochConsensusView (ECA-0b). The candidate view is the production authority for cross-epoch leadership: every …
DC-EVIEW-13 enforced Cardano-faithful pool lifecycle in the reduced window (ECA-0a). The cert-state pool lifecycle matches cardano-ledger (Pool.hs/PoolReap.hs/Epoch.hs/Sna…
DC-GENESIS-SRC-01 enforced A controlled genesis enters initial state ONLY through the single closed bootstrap_initial_state authority (genesis_initial); the genesis->initial-sta…
DC-KES-HEADER-01 enforced unsigned_header_pre_image(slot, block_no, prev_hash, vrf_data, opcert, kes_period, hot_vkey, body_hash, body_size, protocol_version) is a pure BLUE fu…
DC-LEDGER-01 enforced apply_block(state, block) is pure and deterministic
DC-LEDGER-02 partial Same genesis + same blocks = byte-identical ledger state
DC-LEDGER-03 partial Tx/block validity agrees with Haskell node on all tested inputs
DC-LEDGER-04 partial Epoch boundary computations (stake snapshots, rewards) match Haskell
DC-LEDGER-05 partial Witness binding is era-specific: Byron TxWitness, Shelley+ WitsVKey/Scripts/BootstrapWitnesses, Alonzo+ Redeemers/Datums, Conway governance witnesses
DC-LEDGER-08 enforced Conway cert-state accumulation is a closed, total, era-versioned transition: for each block at track_utxo, certificates decode through the era-correct…
DC-LEDGER-09 enforced Conway governance-certificate accumulation is a closed, total, era-versioned transition into ConwayGovState: every governance-affecting Conway cert th…
DC-LEDGER-10 enforced Credential identity is faithful end-to-end: a stake/committee/DRep credential is a closed sum over {KeyHash, ScriptHash} of a 28-byte hash, never a ta…
DC-LEDGER-12 enforced Every tx in a forged block is admissible via ade_ledger::mempool::admit against the base ledger state, in the snapshot's canonical accumulating order.…
DC-LEDGER-13 enforced MAINNET Shelley constants (SHELLEY_START_SLOT / SHELLEY_START_EPOCH / SHELLEY_EPOCH_LENGTH) may enter a computation ONLY through the explicitly-named …
DC-LEDGER-PARAMS-01 enforced Imported protocol parameters are preserved era-faithfully and are NEVER semantically remapped across eras. The shared `ProtocolParameters` carries the…
DC-LEDGER-PHASE2-01 enforced One authoritative UTxO effect per transaction, gated by phase-2 validity. The UTxO effect of a transaction is derived in exactly ONE place from the ca…
DC-LEDGER-PHASE2-02 enforced The accumulator consumes a RESOLVED SCALAR; it does not own a UTxO. The ADA a phase-2-invalid transaction consumes is collAdaBalance = sum(value(colla…
DC-LEDGER-PHASE2-03 enforced A phase-2-invalid transaction contributes its consumed collateral and NOTHING else. For a tx in the block's invalid_transactions set the accumulator a…
DC-LEDGER-PHASE2-04 enforced The UTxO authority RETAINS what it destroys on another reader's behalf. A collateral value is authoritative only within [create(x), B), where B is the…
DC-LEDGER-VALUE-01 enforced Ade's authoritative UTxO OUTPUT asset quantity preserves the full non-negative Cardano Word64 domain (0 ..= 2^64-1) via the `OutputAssetQuantity(u64)`…
DC-MEM-01 enforced Mempool acceptance rules must not contradict block/ledger acceptance rules
DC-MEM-02 enforced Overload shedding follows deterministic policy, not timing-dependent collapse
DC-MEM-03 enforced Tx ingress reduces to a closed IngressEvent before BLUE mempool admission; the source variant is evidence/policy/replay metadata only and MUST NOT cha…
DC-MEM-04 enforced Replaying the same ordered ingress trace against the same base ledger state produces a byte-identical sequence of (MempoolState, AdmitOutcome) pairs.
DC-MEM-07 partial The in-memory portion of the UTxO (read cache + last-k changelog) is bounded by fixed, closed, non-configurable constants; memory pressure cannot grow…
DC-MEM-09 enforced The authoritative UTxO lookup interface returns OWNED values (Option<TxOut>), never a borrow into storage. This is the precondition for a swappable UT…
DC-MEM-10 enforced The v2 UTxO fingerprint component is a NAMED commutative set commitment (Ristretto255 ECMH) binding (TxIn, TxOut) over the canonical encodings, domain…
DC-MITHRIL-01 enforced verify_mithril_binding is a pure deterministic BLUE predicate over its inputs (the manifest report + the anchor) — no I/O, no clock, no HashMap, no fl…
DC-MITHRIL-04 enforced Native V2 LedgerDB `state` decode is faithful, fail-closed, and non-emitting. The cardano-node V2 (utxohd-mem, tablesCodecVersion 1) LedgerDB `state` …
DC-MITHRIL-05 enforced Faithful Word64 multi-asset quantity on the snapshot-import path. The native V2 LedgerDB `tables` MemPack TxOut decode keeps every multi-asset quantit…
DC-MITHRIL-06 enforced The Stage-2 `tables` (MemPack-decoded TxOuts) materialize into Ade's authoritative `UTxOState` with hash-critical bytes PRESERVED and full Word64 quan…
DC-NODE-06 enforced Self-accept -> serve handoff on the --mode node relay spine (sibling serve task, shape B). Only a BLUE self-accepted forged artifact may enter the sib…
DC-NODE-11 enforced Once --mode node has self-accepted and SERVED a genesis-successor block at block_no 0, it MUST NOT add/replace the served view (ServedChainView) with …
DC-NODE-13 enforced Served view is a durable-chain projection. The ChainView served to followers (ChainSync header advertisement + BlockFetch body) is a deterministic PRO…
DC-NODE-25 enforced Live fork-choice durable application authority (rung-2). A ChainSelected / RolledBack outcome from the chain_selector orchestrator is applied to the d…
DC-NODE-27 enforced Rollback+reselection replay-equivalence (rung-2). The ordered live receive-event sequence (RollForward headers, RollBackward points, body deliveries) …
DC-NODE-31 enforced Recovered-anchor live-follow start authority (PHASE4-N-AK). After recovery from a non-Origin bootstrap anchor, the recovered store PERSISTS the bootst…
DC-NODE-44 enforced A warm-start replay divergence (T-REC-05) must be SELF-DESCRIBING: the typed fault carries a `ReplayDivergenceReport` alongside the two fingerprints, …
DC-PROTO-09 enforced Receive-side transcript determinism: given canonical inputs (initial_ledger, initial_chain_dep, initial_chaindb, event_sequence), the bridge reducer's…
DC-STORE-08 enforced Snapshot encoder canonicality: encode_snapshot(s) is byte-identical across runs. Encoder uses BTreeMap iteration only; no HashMap, no wall-clock, no f…
DC-STORE-09 enforced Snapshot bytes carry a closed u32 version tag (initial == 1) and the source state's blake2b-256 fingerprint. Decoder reads the version tag first and r…
DC-STORE-10 enforced Replay equivalence requires the persisted authority store and the binary to agree on the MEANING of the bytes, not merely on their layout. Every durab…
DC-STORE-12 enforced The semantics version may not be left to memory. The declared semantics-bearing surface (`ci/store-semantics-surface.lock`) is content-hashed, and any…
DC-TXV-01 enforced tx_validity is a pure function of (LedgerState, tx_cbor). No wall-clock, arrival order, HashMap/HashSet iteration, float, or ambient state may influen…
DC-TXV-02 enforced A transaction is Valid iff both phase-1 (structural + UTxO rules + witnesses) and phase-2 (Plutus, when scripts are present) accept it. No path may pr…
DC-TXV-03 enforced Ade's Valid/Invalid verdict for a transaction equals the reference cardano-node verdict, including the reason class where the reference exposes it. Es…
DC-TXV-04 enforced A Valid transaction yields an applied LedgerState' (the mempool's accumulating view); an Invalid transaction leaves the input state unchanged plus a s…
DC-TXV-05 enforced For each era, required_signers(state, tx_body) is a closed, explicit, era-versioned function over every signer source (resolved input payment credenti…
DC-TXV-06 enforced For each era, the certificate-deposit classification map(state, cert) is a closed, total, era-versioned function: every certificate variant resolves t…
DC-TXV-07 enforced All deposit/refund amounts used by Conway transaction value-conservation accounting must be sourced from canonical ledger protocol parameters or expli…
DC-VAL-01 enforced A block's validity verdict is a pure function of (LedgerState, PraosChainDepState, EraSchedule, LedgerView, block_cbor). No wall-clock, arrival order,…
DC-VAL-02 enforced A block is Valid iff both the consensus header authority (validate_and_apply_header) and the ledger body authority (apply_block_with_verdicts) accept …
DC-VAL-03 enforced The header is validated before the body; body validation never runs on a header-invalid block. The first failing authority determines the reason (fail…
DC-VAL-04 enforced Ade's Valid/Invalid verdict for a block equals the reference cardano-node verdict, including the reason class where the reference exposes it. Establis…
DC-VAL-05 enforced A Valid block yields evolved (LedgerState', PraosChainDepState'); an Invalid block yields the unchanged input states plus a structured reason. No part…
DC-VAL-06 enforced Every crypto-input, field-size, and structural check on the authority path rejects (produces Invalid) on wrong size or shape and never silently skips.…
DC-WAL-01 enforced WAL is append-only by type: the WalStore trait carries no method named truncate / rewrite / replace / delete / clear. CI grep enforces across the work…
DC-WAL-02 enforced WAL fingerprint-chain integrity: every WalEntry::AdmitBlock has prior_fp == previous entry's post_fp (or anchor's initial_ledger_fingerprint for the f…
DC-WAL-03 enforced Anchor + WAL replay-equivalence: replaying (BootstrapAnchor + WAL entries 1..N) against (initial_ledger from import + per-entry block bytes) produces …
DC-WAL-04 enforced Forged-block WAL chain integrity. A forged AdmitBlock WAL entry's prior_fp MUST equal the current durable post_fp (the BootstrapAnchor's initial_ledge…
OP-MEM-02 enforced Ade's owned resident memory (Private_Dirty/RssAnon) under a representative venue stays clearly below the reference Haskell cardano-node's on the same …
RO-MITHRIL-IMPORT-01 enforced Ade imports a Mithril-authenticated snapshot as an alternative to the cardano-cli JSON seed. Provides cryptographic provenance for the seed artifact (…
T-BUILD-01 enforced No semantic build variability in authoritative code
T-CONSERV-01 enforced UTxO and asset conservation must hold for every accepted transition, except where protocol rules explicitly authorize mint, burn, rewards, or treasury…
T-CORE-01 enforced Authoritative logic is pure, side-effect-free, and replayable
T-CORE-02 enforced No wall-clock, unseeded randomness, floats, or nondeterministic collections in authoritative paths
T-DET-01 enforced Same canonical inputs -> same authoritative bytes (per Byte Authority Model)
T-ENC-01 partial All persisted/hashed/transmitted data uses canonical encoding
T-EPOCH-01 partial Exactly one authoritative committee and governance interpretation per epoch
T-ERR-01 partial Errors in authoritative paths are structured, comparable, canonical
T-NOSPEND-01 enforced No input or equivalent spend authority may be consumed more than once in an accepted canonical chain
T-REC-04 enforced The WarmStart-recovered forge `chain_dep.epoch_nonce` (eta0) MUST come from the imported/recovered consensus input, never from a snapshot placeholder …
T-REC-06 enforced Rollback-materialization replay-equivalence (PHASE4-N-AN). A block that validates during live admit (against the eta0-overlaid chain_dep, T-REC-04) MU…