ade_ledger
BLUE- Purpose
The functional core (ledger half): stateless ledger rules for every era; B1 block-validity verdict; B2 tx-validity + mempool admission; the single BLUE wire-ingress chokepoint
mempool::ingress::mempool_ingress; the BLUE producer authority; the single body-hash authority; the receive/rollback authorities; the canonical UTxO state + the owned-lookup seam / bounded overlay / versioned v2 fingerprint machinery; the snapshot/bootstrap-anchor/genesis/seed-epoch authorities; the reduced-view core (stake_ref/pointer_resolve/reduced_*/reduced_epoch_view/bootstrap_manifest); the native Mithril V2 decoders (ledgerdb_state/ledgerdb_tables/mithril_utxo_materialize); the value/param types (value,pparams::MinUtxoRule). NEW this refresh — the self-sustaining-ledger BLUE core (LIVE-LEDGER-EPOCH-TRANSITION + REDUCED-VALIDATION-BOUNDARY-PLANE + CE3D + Conway governance):epoch_accumulator(the small durable non-UTxO authority + theapply_selected_blocktransition contract — LedgerState MINUS full UTxO PLUS the two-buffernesBprev/nesBcurmodel;DC-EPOCH-19/21/24);frozen_leadership(the self-containedFrozenLeadershipPoolDistr= cardano'snesPd;DC-EPOCH-25);reduced_boundary(the typedReducedBoundaryProjectionatrack_utxo=falsefollower produces at a Conway boundary);rollback/admission(the BLUEadmit_rollbackrecovery rail — LIVE-LEDGER-EPOCH-TRANSITION S5);bootstrap_bridge(the ONE-TIME seed→seed+1BootstrapNextEpochAuthority;DC-EPOCH-15);bootstrap_reward_update(the seed→seed+1 reward update carrying the certified snapshot'sfeeSS/deltaF;DC-EPOCH-18/23);cred(the single stake-credential CBOR-discriminant authority, functions only); the Conway ratification/enactment growth ingovernance.rs.ade_ledgeris 220 → 275 (+55) — all pure.- Creates
275 public types. Load-bearing carried:
BlockValidityError,BlockVerdict,LedgerState,UTxOState,TxOut,WalEntry(closed —AdmitBlock \| SeedEpochConsensusInputsImported \| RollBack \| EpochConsensusViewActivated),LedgerFingerprint,MempoolState,ProducerTick,ForgedBlock,SeedEpochConsensusInputs(+security_param: u64this refresh — S2 sidecar v6,SEED_CINPUT_SCHEMA_VERSION = 6,FIELDS_OUTER14),BootstrapAnchor,RecoveredAnchorPoint, the reduced-view / native-Mithril families,value::{MultiAsset, AssetName, Value},pparams::MinUtxoRule. NEW this refresh:epoch_accumulator::{EpochAccumulator, SeedError, SelectedBlockCtx, LedgerTransitionError, EpochBoundaryEffect, BoundaryFreezeInputs, BoundaryBaseStake, PostRupdRewards<'a>, EpochAccumulatorCodecError};frozen_leadership::{LeadershipPoolEntry, FrozenLeadershipPoolDistr, FrozenLeadershipError};reduced_boundary::{ReducedBlockWindow, ReducedEpochProgress, ReducedCertProjection, ReducedGovernanceProjection, ReducedBoundaryProjection, FullEpochBoundaryResult, LedgerBoundaryVerdict, LedgerValidityCapability};rollback::admission::{RollbackPoint, RollbackAdmissionError, RecoveryAction};bootstrap_bridge::{BridgeSourceKind, BootstrapNextEpochAuthority, BridgeCodecError};bootstrap_reward_update::{BootstrapRewardUpdate, BootstrapRupdError}; the Conway-governancegovernance::{RatificationResult, RatificationObservation, RemovalCause, RemovedProposal, DepositReturn, PParamsDelta, PrevPParamActionDelta, ConwayGovernanceEpochPlan, MalformedGovDetail, UnsupportedActionKind, GovernanceTerminal, ConwayGovernanceEpochInput<'a>, ExecUnitsParamUpdate, ExecUnitsUpdateError, EnactmentEffects, …}.- Interprets
Canonical decoded blocks/txs/certs/snapshots;
block_validityproduces the per-block verdict + post-state;mempool_ingressis the sole BLUE chokepoint; the reduced-view + native-Mithril decode points (ledgerdb_state::decode_native_nonutxo_state,ledgerdb_tables::read_txout,mithril_utxo_materialize::materialize_tables_to_utxo,bootstrap_manifest::verify_and_import_cert_state,EpochConsensusView::{bind, verify_canonical_hash, matches}). NEW:epoch_accumulator::apply_selected_block(prior, block_bytes, ctx)— the total/deterministic/replay-equivalent non-UTxO transition (boundary effects in cardano NEWEPOCH order FIRST, then within-epoch cert/withdrawal/issuer/fee effects), reusingrules::apply_epoch_boundary_with_registrations+process_block_certificates+delegation::apply_bootstrap_reward_deltas;build_boundary_mark_snapshot(the boundary mark = registered+delegated credential IFF combined active stake NON-ZERO —DC-EPOCH-24);frozen_leadership::to_pool_distr_view(leadership PoolDistr read DIRECTLY from the frozen distr);reduced_boundary(the typed reduced projection);rollback::admission::admit_rollback(pure/total/fail-closed target admissibility);bootstrap_bridge(seed+1 view from the imported MARK snapshot ALONE);bootstrap_reward_update(the seed-boundary reward update + deltaF fee-pot reduction).- MUST NOT
All carry-forward ledger prohibitions (no I/O, no clock, closed cert/governance enums, single body-hash recipe;
producer::*fences;rollback::materializethe SOLE rolled-back-state authority;block_validitythe single block verdict authority; the MEMDC-MEM-05..10fences; the reduced-viewDC-EVIEW-02..07/09fences; the native-MithrilDC-MITHRIL-01/06fences;DC-LEDGER-VALUE-01non-negative Word64 output-quantity domain;DC-LEDGER-PARAMS-01era-faithfulMinUtxoRule). NEW this refresh: (epoch_accumulator,DC-EPOCH-19/21)apply_selected_blockMUST derive EVERY future epoch transition WITHOUT another Mithril import / CLI oracle / injected authority; it carries ONLY non-UTxO facts (the stake-bearing UTxO stays in the disk-backed reduced checkpoint) — it MUST NOT hold a full UTxO map, and the boundary MUST reuse the single canonicalapply_epoch_boundary_with_registrationsPOOLREAP block (future-pool adoption, reap, deposit refund, delegation-clear) in the cardano NEWEPOCH order, never a parallel reimplementation; the two-buffer model MUST feedprev_*(nesBprev) to the boundary, not the just-finishednesBcur. (frozen_leadership,DC-EPOCH-25) the leadership PoolDistr (nesPd) MUST be answered by the self-containedFrozenLeadershipPoolDistrand by NOTHING else —to_pool_distr_viewreads stake AND VRF DIRECTLY from it, NEVER from activecert_state.pool.pools/ thegosnapshot /future_pools/ theretiringmap; it MUST include zero-stake registered pools AND retired/POOLREAP'd pools whose VRF is absent from active state (deriving leadership fromgo+ active params is a DISPROVEN hypothesis). (reduced_boundary, I-RVB-1) aReducedBoundaryProjectionand aFullEpochBoundaryResultare DISTINCT, non-interchangeable types — the projection is NOT aLedgerState, cannot be widened into one, cannot be serialized as an accumulator snapshot, and cannot be fingerprinted as full authority; atrack_utxo=falseboundary MUST NOT emit a reward-only stub mark (proven to leak into recovery persistence + WAL fingerprints). (rollback::admission, LIVE-LEDGER-EPOCH-TRANSITION S5)admit_rollbackMUST fail closed (typedRollbackAdmissionError, never a silent rematerialization) on an inadmissible target — a split lineage, a rollback deeper than the immutable point (k-BLOCK-bound = tip − k), or below the sealed anchor; it is NOT fork-choice (admits/rejects one target, never selects among competing forks). (bootstrap_bridge,DC-EPOCH-15) the seed→seed+1 bridge view MUST come from the imported snapshot's MARK stake snapshot ALONE (source_kind = ImportedMarkSnapshot), nevernesPd/ a window replay / an oracle; the selector readstarget_epoch == seed+1 ⇒ bridge,≥ seed+2 ⇒ replay. (bootstrap_reward_update,DC-EPOCH-18/23) the one-shot seed-boundary reward update MUST carry the certified snapshot'sfeeSS(deltaF) and reduce the accumulated fee pot by it EXACTLY ONCE. (governance,DC-GOV-01/DC-CINPUT-07— declared) a removed governance proposal's deposit is refunded to its recorded return address ONLY when Ade can PROVE from canonical state + Conway rules that it could NOT have ratified or enacted, else fail closed (terminal); the Conway deposit params (gov_action_deposit/drep_deposit/drep_activity) are DECODED from the certified snapshot's ConwaycurPParamsat the verified positions, never defaulted.- Inbound deps
ade_testkit,ade_core_interop,ade_runtime(reduced-window driver + the epoch-accumulator durable advance + native-Mithril assembly + the durable reduced checkpoint),ade_node(epoch-activation orchestration + frozen-leadership promotion + native FirstRun + the S2 seed-sidecar codec viaSeedEpochConsensusInputs).- Outbound deps
ade_types(incl.mary::value::OutputAssetQuantity),ade_crypto(utxo_set_commitment+blake2b_256),ade_codec(address::pointer::*, thecbor::*primitives,wrap_tag24),ade_plutus,ade_core(consensus::{SecurityParam, events::Point, vrf_cert::ActiveSlotsCoeff, era_schedule::*}),minicbor,num-bigint,num-integer,num-traits. Dev-dep:ade_testkit.- Entry points
ade_ledger::block_validity::*,ade_ledger::state::LedgerState,ade_ledger::utxo::{TxOut, UTxOState},ade_ledger::{fingerprint, utxo_overlay, pre_resolve, tx_validity, mempool, producer, receive, rollback, snapshot, wal, seed_consensus_inputs, bootstrap_anchor, recovered_anchor_point}::*, the reduced-view + native-Mithril families, NEW:ade_ledger::epoch_accumulator::{EpochAccumulator, apply_selected_block, build_boundary_mark_snapshot, EpochBoundaryEffect, LedgerTransitionError},ade_ledger::frozen_leadership::{FrozenLeadershipPoolDistr, LeadershipPoolEntry, to_pool_distr_view, from_seed_epoch_consensus_inputs, encode_frozen_leadership, decode_frozen_leadership},ade_ledger::reduced_boundary::{ReducedBoundaryProjection, LedgerBoundaryVerdict, LedgerValidityCapability},ade_ledger::rollback::admission::{admit_rollback, RollbackAdmissionError, RecoveryAction},ade_ledger::bootstrap_bridge::{BootstrapNextEpochAuthority, BridgeSourceKind},ade_ledger::bootstrap_reward_update::BootstrapRewardUpdate,ade_ledger::governance::*.- Key modules
block_validity/,tx_validity/,mempool/,cert_classify/,consensus_view.rs,delegation.rs(DelegationState/CertState+apply_bootstrap_reward_deltas),governance.rs(Conway ratify/enact authority — grew this refresh),producer/,block_body_hash.rs,receive/,rollback/(incl.admission.rs— the S5 recovery rail),snapshot/(incl.cert_state.rs,chain_dep.rs),epoch.rs,rules.rs(apply_epoch_boundary_with_registrations— the single canonical POOLREAP block),wal/(event.rs— the 4-variant closedWalEntry),utxo.rs+utxo_overlay.rs+pre_resolve.rs+fingerprint.rs(MEM),value.rs,pparams.rs, the reduced-viewstake_ref.rs/pointer_resolve.rs/reduced_utxo.rs/reduced_advance.rs/reduced_aggregate.rs/reduced_snapshot.rs/reduced_epoch_view.rs/bootstrap_manifest.rs, the native-Mithrilmithril_utxo_materialize.rs/ledgerdb_state.rs/ledgerdb_tables.rs,seed_consensus_inputs.rs(the GREEN v6 sidecar codec), NEW:epoch_accumulator.rs,frozen_leadership.rs,reduced_boundary.rs,bootstrap_bridge.rs,bootstrap_reward_update.rs,cred.rs,state.rs,plutus_eval.rs.
Depends on
—
Depended on by
—
CI guards — 99
| Script | Enforces |
|---|---|
| ci_check_admitted_block_closure.sh | CN-CONS-07, CN-CONS-08, CN-PROTO-07 |
| ci_check_block_fetch_server_closure.sh | DC-CONS-17, DC-PROTO-07 |
| ci_check_bnd_typed_stall_cause.sh | DC-EPOCH-39 |
| ci_check_bootstrap_anchor_closure.sh | CN-ANCHOR-01, DC-ANCHOR-01 |
| ci_check_bootstrap_rupd_fee_reduction.sh |
|
| ci_check_bootstrap_rupd_window_end.sh |
|
| ci_check_bridge_nonce_freeze_differential.sh | DC-EPOCH-38 |
| ci_check_broadcast_to_served_purity.sh | DC-CONS-17, DC-CONS-18, DC-PROTO-07 |
| ci_check_collateral_balance_resolver.sh | DC-LEDGER-PHASE2-02, DC-LEDGER-PHASE2-03 |
| ci_check_collateral_retention_positioning.sh | DC-LEDGER-PHASE2-04 |
| ci_check_consensus_closed_enums.sh | CN-CONS-02, DC-CONS-03, DC-CONS-04, DC-CONS-05, DC-CONS-06, DC-CONS-09, DC-CONS-10, DC-CONSENSUS-01, DC-MEM-01, DC-MEM-02, DC-TXV-01, DC-TXV-02, DC-TXV-03, DC-TXV-04, DC-TXV-05, DC-VAL-01, DC-VAL-02, DC-VAL-03, DC-VAL-04, DC-VAL-05, DC-VAL-06, T-DET-01 |
| ci_check_conway_cert_classification_closed.sh | DC-TXV-06 |
| ci_check_conway_deposit_params_bootstrap.sh |
|
| ci_check_credential_discriminant_closed.sh |
|
| ci_check_dependency_boundary.sh | T-BOUND-02, T-CORE-01 |
| ci_check_deposit_param_authority.sh | DC-TXV-07 |
| ci_check_differential_divergence.sh | DC-LEDGER-02, DC-LEDGER-03, T-CONSERV-01, T-NOSPEND-01 |
| ci_check_epoch_agreement.sh | DC-EPOCH-36 |
| ci_check_eview_activation_wal.sh | DC-EPOCH-04 |
| ci_check_eview_activation.sh | DC-EVIEW-08 |
| ci_check_eview_bootstrap_cert_state.sh | DC-EVIEW-09 |
| ci_check_eview_leadership_complete.sh | DC-EPOCH-12, DC-EVIEW-05, DC-EVIEW-07, DC-EVIEW-12 |
| ci_check_eview_pointer_compat.sh | DC-EVIEW-03 |
| ci_check_eview_pool_lifecycle.sh | DC-EVIEW-13 |
| ci_check_eview_reduced_utxo_checkpoint.sh | DC-EVIEW-04 |
| ci_check_eview_refold_reseal.sh | DC-EPOCH-32, DC-EPOCH-33 |
| ci_check_eview_seed_sidecar_v4.sh | DC-CINPUT-06 |
| ci_check_eview_stability_gate.sh | DC-EVIEW-06 |
| ci_check_eview_stake_aggregation.sh | DC-EVIEW-05 |
| ci_check_eview_stake_ref_classification.sh | DC-EVIEW-02 |
| ci_check_eview_view_binding.sh | DC-EVIEW-07 |
| ci_check_eview_windowed_advance.sh | DC-EVIEW-04b |
| ci_check_feed_leader_threshold_view.sh | DC-CINPUT-04 |
| ci_check_forbidden_patterns.sh | DC-LEDGER-08, T-CORE-01, T-CORE-02, T-DET-01 |
| ci_check_forge_decode_round_trip.sh | CN-FORGE-03 |
| ci_check_forge_purity.sh | DC-CONS-13, DC-CONS-14, DC-CONS-15, DC-LEDGER-12 |
| ci_check_forged_durable_admit_via_pump.sh | DC-CONS-23, DC-NODE-12, DC-WAL-04 |
| ci_check_frozen_leadership_authority.sh | S4-pre |
| ci_check_frozen_promotion_no_seed_window.sh | S4-L2 |
| ci_check_frozen_recovery_no_seed_window.sh | S4-L1 |
| ci_check_gov_cert_accumulation_closed.sh | DC-LEDGER-09 |
| ci_check_hash_uses_wire_bytes.sh | T-ENC-01 |
| ci_check_header_body_binding.sh | CN-CONS-04 |
| ci_check_hfc_translation.sh | DC-EPOCH-02 |
| ci_check_ledger_determinism.sh | DC-LEDGER-01, DC-LEDGER-02, T-DET-01 |
| ci_check_ledgerdb_state_decode.sh | DC-MITHRIL-04 |
| ci_check_ledgerdb_tables_decode.sh | DC-MITHRIL-05 |
| ci_check_lifecycle_owner_uses_bootstrap_initial_state.sh | DC-CINPUT-01 |
| ci_check_live_fork_choice_apply.sh | DC-NODE-25, DC-NODE-26, DC-NODE-27 |
| ci_check_live_fork_choice_wiring.sh | DC-NODE-25, DC-NODE-28 |
| ci_check_mem_opt_s3_owned.sh | OP-MEM-02 |
| ci_check_mempool_ingress_closure.sh | DC-MEM-03 |
| ci_check_mempool_ingress_replay.sh | DC-MEM-04 |
| ci_check_mithril_documented_evidence.sh | RO-MITHRIL-IMPORT-01 |
| ci_check_mithril_seed_point_independence.sh | CN-MITHRIL-01, DC-MITHRIL-02, RO-MITHRIL-IMPORT-01 |
| ci_check_mithril_uses_bootstrap_initial_state.sh | CN-MITHRIL-01, DC-GENESIS-SRC-01, DC-MITHRIL-01, RO-MITHRIL-IMPORT-01 |
| ci_check_native_nonutxo_decode.sh | DC-LEDGER-PARAMS-01 |
| ci_check_no_float_in_consensus.sh | CN-CONS-05, DC-CONS-03, DC-CONS-08, T-CORE-02 |
| ci_check_no_independent_forge_codepath.sh | CN-FORGE-01 |
| ci_check_no_parallel_header_splitter.sh | CN-PROTO-06, DC-CONS-16, DC-CONS-18 |
| ci_check_no_private_keys_in_corpus.sh | DC-CONS-14 |
| ci_check_no_producer_body_encoder.sh | DC-CONS-16 |
| ci_check_no_semantic_cfg.sh | T-BUILD-01 |
| ci_check_node_run_loop_containment.sh | CN-NODE-02, CN-NODE-03, DC-NODE-05, DC-NODE-06, DC-NODE-12, DC-SYNC-02, T-REC-03 |
| ci_check_overlay_utxo_s2a.sh | DC-MEM-07 |
| ci_check_phase2_invalid_utxo_effect.sh | DC-LEDGER-PHASE2-01 |
| ci_check_plutus_budget_cap.sh | CN-PLUTUS-02, DC-LEDGER-03 |
| ci_check_plutus_oracle_no_false_accept.sh | DC-LEDGER-03 |
| ci_check_praos_nonce_follow_evolution.sh |
|
| ci_check_prevhash_single_wire_authority.sh | CN-WIRE-09 |
| ci_check_producer_coordinator_no_secrets.sh | CN-FORGE-01, CN-PROD-02 |
| ci_check_receive_orchestrator_no_producer_dep.sh | DC-CONS-20 |
| ci_check_receive_reducer_closure.sh | CN-CONS-07, CN-CONS-08, DC-CONS-13, DC-CONS-16, DC-CONS-19, DC-CONS-20, DC-PROTO-09 |
| ci_check_receive_replay_purity.sh | DC-PROTO-09 |
| ci_check_recover_follow_wal_lineage.sh | DC-WAL-02 |
| ci_check_recovery_fault_self_describing.sh | DC-NODE-44 |
| ci_check_required_signer_closure.sh | CN-LEDGER-09, DC-LEDGER-05 |
| ci_check_rollback_materialize_closure.sh | CN-STORE-07, DC-CONS-20, DC-CONS-22 |
| ci_check_rollback_materialize_eta0.sh | T-REC-06 |
| ci_check_self_accept_gate.sh | CN-CONS-07 |
| ci_check_served_chain_closure.sh | CN-CONS-07 |
| ci_check_served_chain_handoff_fence.sh | DC-NODE-06 |
| ci_check_served_chain_projection.sh | DC-NODE-06, DC-NODE-11, DC-NODE-13 |
| ci_check_sigma_denominator_authority.sh | DC-EPOCH-40 |
| ci_check_snapshot_encoder_closure.sh | CN-STORE-08, DC-CONS-21, DC-STORE-08, DC-STORE-09 |
| ci_check_snapshot_pool_set_inclusion.sh |
|
| ci_check_store_semantics_gate.sh | DC-STORE-10, DC-STORE-11 |
| ci_check_store_semantics_lock.sh | DC-EPOCH-40, DC-STORE-12 |
| ci_check_tables_to_utxostate.sh | DC-MITHRIL-06 |
| ci_check_unsigned_header_preimage_single_source.sh | CN-KES-HEADER-01, DC-CONS-18 |
| ci_check_utxo_fp_cache.sh | OP-MEM-02 |
| ci_check_utxo_fp_v2.sh | DC-MEM-10 |
| ci_check_utxo_lookup_owned.sh | DC-MEM-09 |
| ci_check_value_quantity_domain.sh | DC-LEDGER-VALUE-01 |
| ci_check_venue_constant_containment.sh | DC-LEDGER-13 |
| ci_check_venue_differential.sh | DC-EPOCH-37 |
| ci_check_wal_append_only.sh | CN-WAL-01, DC-ADMIT-05, DC-WAL-01 |
| ci_check_wal_rollback_replay_equiv.sh | DC-NODE-27 |
| ci_check_warmstart_eta0_overlay.sh | ECA-B (band 7) |
Related invariants — 137
| ID | Status | Statement |
|---|---|---|
| CN-ANCHOR-01 | enforced | Single BootstrapAnchor mint authority: exactly one pub fn in ade_runtime::bootstrap_anchor::mint produces a BootstrapAnchor with all 6 fields populate… |
| CN-CINPUT-01 | enforced | The seed-epoch consensus inputs (epoch, active-slots coefficient, total active stake, and the per-pool active-stake + registered VRF keyhash distribut… |
| CN-CONS-04 | enforced | Header validation must bind exactly to the accepted body and consensus context |
| CN-CONS-07 | enforced | Self-acceptance bridge + serve provenance. A forged block is NOT eligible for RED broadcast unless Ade's own header validator (PHASE4-N-B path) and bo… |
| CN-CONS-08 | enforced | Receive-side single admission authority: every block that lands in ChainDb via the receive path passed block_validity with BlockValidityVerdict::Valid… |
| CN-EPOCH-01 | partial | Stake, rewards, parameter changes, and governance effects may activate only at protocol-defined epoch boundaries |
| CN-FORGE-01 | enforced | The producer-mode forge handler is a closed transition from CoordinatorEvent::RequestForge { slot, kes_period, ledger_snapshot_ref, chain_tip } to exa… |
| CN-FORGE-03 | enforced | Producer/validator codec symmetry: forge_block emits the era-tagged [era, block] envelope (era = Conway discriminant 7) via the single canonical ade_c… |
| CN-KES-HEADER-01 | enforced | The KES signature in a forged block's header is over the canonical unsigned-header CBOR pre-image — the CBOR encoding of ShelleyHeaderBody (the first … |
| CN-LEDGER-09 | partial | Witnesses must bind exactly to the intended body, certificates, withdrawals, governance actions, and scripts for the era |
| CN-MITHRIL-01 | enforced | A Mithril-sourced seed may bootstrap only after a verified binding: the Mithril manifest's attested {network_magic, genesis_hash, certified_point, cer… |
| CN-PLUTUS-02 | declared | Budget exhaustion and script failure must have a single deterministic failure shape |
| CN-PREIMAGE-FIXTURE-01 | enforced | For every block in ade_testkit::validity::corpus::ConwayValidityCorpus, Ade's unsigned_header_pre_image(...) (with inputs derived from decode_block(bl… |
| CN-PROD-04 | enforced | Every CoordinatorEffect::BroadcastBlock reconstructs the AcceptedBlock from artifact.bytes through the BLUE self_accept authority against the pre-forg… |
| CN-PROTO-06 | enforced | The producer-side session orchestrator can only construct outgoing mini-protocol messages tagged with Server agency. Client-originated messages from t… |
| CN-PROTO-07 | enforced | Receive-side agency closure: the receive bridge consumes only peer-originated ForkChoiceSignal and BatchDeliveryEvent values valid for the client-role… |
| CN-STORE-07 | enforced | Single materialize authority for rolled-back state: the function that materializes (LedgerState, PraosChainDepState) at a target point uses ONLY one S… |
| CN-STORE-08 | enforced | Single encoder authority: encode_ledger_state + decode_ledger_state + encode_chain_dep + decode_chain_dep + encode_snapshot + decode_snapshot are the … |
| CN-WAL-01 | enforced | Single WAL append authority: WalStore::append is the SOLE mutation method on any WalStore impl. No truncate/rewrite/replace method exists on the trait… |
| CN-WIRE-09 | enforced | The Shelley-and-later header_body `prev_hash` field is the closed wire grammar `$hash32 / null` (cardano-ledger PrevHash = GenesisHash | BlockHash). A… |
| DC-ANCHOR-01 | enforced | BootstrapAnchor canonical CBOR round-trip: encode + decode preserves all 6 fields byte-identically. SCHEMA_VERSION = 1 in the encoded bytes; unknown v… |
| DC-CINPUT-01 | enforced | WARM-START VERIFICATION CAPABILITY (authority surface — NOT production restart). The seed-epoch consensus-input import is a canonical, replay-reconstr… |
| DC-CINPUT-02a | enforced | PROJECTION EQUIVALENCE. The recovered SeedEpochConsensusInputs projects deterministically to the leadership-consumed PoolDistrView (the full LedgerVie… |
| DC-CINPUT-03 | enforced | The producer Praos VRF leader/header input is `praos_vrf_input(slot, eta0)` = `blake2b256(slot_be8 ‖ eta0_32)` (= cardano `mkInputVRF`), where eta0 is… |
| DC-CINPUT-04 | enforced | The receive/feed-path header-validation consensus view -- the LedgerView passed to block_validity -> validate_and_apply_header for Step 5 (VRF-keyhash… |
| DC-CINPUT-05 | enforced | Venue epoch geometry is DURABLE REPLAY AUTHORITY. A recovered store MUST replay using the epoch geometry (epoch_start_slot + epoch_length_slots) persi… |
| DC-CINPUT-06 | enforced | The durable consensus PROFILE includes genesis_hash + protocol_params_hash, persisted canonically in the v4 SeedEpochConsensusInputs sidecar and recov… |
| DC-CINPUT-07 | declared | Conway deposit-parameter bootstrap authority. The Conway-only deposit params (drep_deposit / gov_action_deposit / drep_activity) are DECODED from the … |
| DC-CONS-13 | enforced | Forge is pure given a canonical ProducerTick. forge_block has no wall-clock, no rand, no HashMap iteration, no I/O, no locale, and no ambient state. A… |
| DC-CONS-14 | enforced | Forge byte-equality across replays. For two replays of an identical canonical ProducerTick stream over the same initial LedgerState, forge_block produ… |
| DC-CONS-15 | enforced | Forge is invoked only when leader-check passes. forge_block is a forbidden transition for ticks where is_leader(state, vrf_output, sigma, asc) == fals… |
| DC-CONS-16 | enforced | Forged header.body_hash MUST equal blake2b_256(forged_body_wire_bytes), where forged_body_wire_bytes are produced by the single Cardano-compatible can… |
| DC-CONS-17 | enforced | Block bytes delivered via producer-side block-fetch Block{bytes} are byte-identical to AcceptedBlock.as_bytes() for the AcceptedBlock that cleared sel… |
| DC-CONS-18 | enforced | Header bytes announced via chain-sync RollForward{header,tip} are the header sub-segment of the AcceptedBlock whose body bytes are subsequently servab… |
| DC-CONS-19 | enforced | Receive-side header-body sourcing coherence: when BlockDelivered {block_bytes} arrives at the receive bridge, the decoded header bytes of block_bytes … |
| DC-CONS-20 | enforced | ChainDb-ledger-chain_dep lockstep: a successful receive-side admission updates ChainDb, LedgerState, and PraosChainDepState as one structural transiti… |
| DC-CONS-21 | enforced | Snapshot encode/decode round-trip equivalence: for any reachable (LedgerState, PraosChainDepState), decode(encode(state)) yields a state whose ade_led… |
| DC-CONS-22 | enforced | Replay-forward correctness: given state_at_slot_S and the ordered block sequence blocks(S+1..=T) from ChainDb, the replay-forward driver yields a stat… |
| DC-CONS-23 | enforced | Own-forged stale-tip race safety by extend-only durable admit. An own-forged candidate is admitted to the durable tip ONLY if it EXTENDS the current d… |
| DC-CONSENSUS-02 | partial | Leadership verification is pure |
| DC-EPOCH-01 | partial | Conway governance timing: proposals accumulate during epoch, ratification and enactment are atomic at epoch boundary, pulsing distributes DRep stake c… |
| DC-EPOCH-02 | enforced | Hard fork transitions triggered at deterministic slot/epoch boundaries; era translation functions mandatory; forecast horizon extends to era boundary |
| DC-EPOCH-04 | enforced | For a target epoch, AT MOST ONE canonically bound EpochConsensusView may activate (S3f-4a substrate). A distinct WalEntry::EpochConsensusViewActivated… |
| DC-EPOCH-12 | enforced | The promoted-epoch PoolDistrView is derived EXCLUSIVELY from the sealed EpochConsensusView + the bound-commitment- checked consensus profile (ECA-0b).… |
| DC-EPOCH-16 | enforced | Rolling Praos chain-dep nonce evolution on the live follow path. Each validated followed header drives ONE indivisible BLUE nonce transition over {slo… |
| DC-EPOCH-18 | enforced | Window-end bootstrap reward update for the seed+2 leadership authority. The first post-bootstrap replay-derived authority (seed+2, DC-EPOCH-17) is the… |
| DC-EPOCH-23 | enforced | Bootstrap reward-update fee-buffer authority (CE-3d). The one-shot bootstrap reward update applied at the seed->seed+1 boundary carries the certified … |
| DC-EPOCH-24 | enforced | Snapshot pool-set inclusion = cardano's ssActiveStake NonZero membership (CE-3d). The per-epoch stake snapshot (mark/set/go) INCLUDES a registered+del… |
| DC-EPOCH-25 | declared | Self-contained frozen leadership authority (S4-pre). Cardano's leadership PoolDistr (nesPd) -- the per-pool (active_stake, vrf_keyhash) that decides t… |
| DC-EPOCH-33 | enforced | Refold re-seal identity. Re-deriving an epoch boundary the node has already crossed re-seals a frozen-leadership object byte-identical to the one the … |
| DC-EPOCH-36 | enforced | After the epoch-boundary decision for a block at `slot`, the ledger's epoch MUST equal the venue era schedule's epoch for that slot. A disagreement in… |
| DC-EPOCH-37 | enforced | Authoritative epoch semantics must be proven PER VENUE, not inferred from a mainnet-shaped corpus. Every venue in the closed node-side registry (`nati… |
| DC-EPOCH-38 | enforced | The Praos candidate-freeze / nonce surface must be proven across SEED-POSITION x VENUE, not once per venue. `eta0(N+1)` is committed from the candidat… |
| DC-EPOCH-39 | enforced | A stall's CAUSE is typed, and only a real epoch transition may enter boundary machinery. Advancing the durable accumulator over one block yields exact… |
| DC-EPOCH-40 | partial | Leadership sigma denominator authority (SLICE LV-1). The leader-check sigma denominator is the SNAPSHOT's total active stake -- cardano's `pdTotalActi… |
| DC-EVIEW-02 | enforced | Typed, era-gated stake-reference classification. Given canonical address bytes and a TYPED era / protocol-version context BOUND to the block being pro… |
| DC-EVIEW-03 | enforced | Era-parameterized pointer decoding + pre-Conway resolution, matching cardano-ledger EXACTLY (the wire authority -- CIP-19 is silent on canonicality, s… |
| DC-EVIEW-04 | enforced | The durable reduced-UTxO checkpoint -- the "minimal native state" (S3b Option B). A disk-backed redb store of TxIn -> (Coin, ReducedStakeRef), built f… |
| DC-EVIEW-04b | enforced | The windowed advance (S3b-2): advance the durable reduced-UTxO checkpoint (DC-EVIEW-04) per epoch boundary by replaying the epoch's admitted blocks, a… |
| DC-EVIEW-05 | enforced | Per-pool stake aggregation (S3c, the linchpin). aggregate_pool_stake computes the next-epoch per-pool active stake from the single ledger authority's … |
| DC-EVIEW-06 | enforced | Snapshot formation + the k-immutability stability gate (S3d). form_mark_snapshot converts the S3c per-pool aggregate (StakeByPool) into the MARK Stake… |
| DC-EVIEW-07 | enforced | The bound, immutable EpochConsensusView (S3e). EpochConsensusView::bind emits the compact next-epoch consensus view from the finalized snapshot (S3d),… |
| DC-EVIEW-08 | declared | Activation -- the live-path consumption of Ade's self-derived next-epoch view. MECHANISM (IMPLEMENTED + AUTOMATIC): the boundary activation is wired i… |
| DC-EVIEW-09 | enforced | The manifest-bound bootstrap cert-state import (S3f-2 prerequisite). The seed (SeedEpochConsensusInputs, the compact per-POOL active epoch consensus v… |
| DC-EVIEW-12 | enforced | The leadership-complete, self-contained EpochConsensusView (ECA-0b). The candidate view is the production authority for cross-epoch leadership: every … |
| DC-EVIEW-13 | enforced | Cardano-faithful pool lifecycle in the reduced window (ECA-0a). The cert-state pool lifecycle matches cardano-ledger (Pool.hs/PoolReap.hs/Epoch.hs/Sna… |
| DC-GENESIS-SRC-01 | enforced | A controlled genesis enters initial state ONLY through the single closed bootstrap_initial_state authority (genesis_initial); the genesis->initial-sta… |
| DC-KES-HEADER-01 | enforced | unsigned_header_pre_image(slot, block_no, prev_hash, vrf_data, opcert, kes_period, hot_vkey, body_hash, body_size, protocol_version) is a pure BLUE fu… |
| DC-LEDGER-01 | enforced | apply_block(state, block) is pure and deterministic |
| DC-LEDGER-02 | partial | Same genesis + same blocks = byte-identical ledger state |
| DC-LEDGER-03 | partial | Tx/block validity agrees with Haskell node on all tested inputs |
| DC-LEDGER-04 | partial | Epoch boundary computations (stake snapshots, rewards) match Haskell |
| DC-LEDGER-05 | partial | Witness binding is era-specific: Byron TxWitness, Shelley+ WitsVKey/Scripts/BootstrapWitnesses, Alonzo+ Redeemers/Datums, Conway governance witnesses |
| DC-LEDGER-08 | enforced | Conway cert-state accumulation is a closed, total, era-versioned transition: for each block at track_utxo, certificates decode through the era-correct… |
| DC-LEDGER-09 | enforced | Conway governance-certificate accumulation is a closed, total, era-versioned transition into ConwayGovState: every governance-affecting Conway cert th… |
| DC-LEDGER-10 | enforced | Credential identity is faithful end-to-end: a stake/committee/DRep credential is a closed sum over {KeyHash, ScriptHash} of a 28-byte hash, never a ta… |
| DC-LEDGER-12 | enforced | Every tx in a forged block is admissible via ade_ledger::mempool::admit against the base ledger state, in the snapshot's canonical accumulating order.… |
| DC-LEDGER-13 | enforced | MAINNET Shelley constants (SHELLEY_START_SLOT / SHELLEY_START_EPOCH / SHELLEY_EPOCH_LENGTH) may enter a computation ONLY through the explicitly-named … |
| DC-LEDGER-PARAMS-01 | enforced | Imported protocol parameters are preserved era-faithfully and are NEVER semantically remapped across eras. The shared `ProtocolParameters` carries the… |
| DC-LEDGER-PHASE2-01 | enforced | One authoritative UTxO effect per transaction, gated by phase-2 validity. The UTxO effect of a transaction is derived in exactly ONE place from the ca… |
| DC-LEDGER-PHASE2-02 | enforced | The accumulator consumes a RESOLVED SCALAR; it does not own a UTxO. The ADA a phase-2-invalid transaction consumes is collAdaBalance = sum(value(colla… |
| DC-LEDGER-PHASE2-03 | enforced | A phase-2-invalid transaction contributes its consumed collateral and NOTHING else. For a tx in the block's invalid_transactions set the accumulator a… |
| DC-LEDGER-PHASE2-04 | enforced | The UTxO authority RETAINS what it destroys on another reader's behalf. A collateral value is authoritative only within [create(x), B), where B is the… |
| DC-LEDGER-VALUE-01 | enforced | Ade's authoritative UTxO OUTPUT asset quantity preserves the full non-negative Cardano Word64 domain (0 ..= 2^64-1) via the `OutputAssetQuantity(u64)`… |
| DC-MEM-01 | enforced | Mempool acceptance rules must not contradict block/ledger acceptance rules |
| DC-MEM-02 | enforced | Overload shedding follows deterministic policy, not timing-dependent collapse |
| DC-MEM-03 | enforced | Tx ingress reduces to a closed IngressEvent before BLUE mempool admission; the source variant is evidence/policy/replay metadata only and MUST NOT cha… |
| DC-MEM-04 | enforced | Replaying the same ordered ingress trace against the same base ledger state produces a byte-identical sequence of (MempoolState, AdmitOutcome) pairs. |
| DC-MEM-07 | partial | The in-memory portion of the UTxO (read cache + last-k changelog) is bounded by fixed, closed, non-configurable constants; memory pressure cannot grow… |
| DC-MEM-09 | enforced | The authoritative UTxO lookup interface returns OWNED values (Option<TxOut>), never a borrow into storage. This is the precondition for a swappable UT… |
| DC-MEM-10 | enforced | The v2 UTxO fingerprint component is a NAMED commutative set commitment (Ristretto255 ECMH) binding (TxIn, TxOut) over the canonical encodings, domain… |
| DC-MITHRIL-01 | enforced | verify_mithril_binding is a pure deterministic BLUE predicate over its inputs (the manifest report + the anchor) — no I/O, no clock, no HashMap, no fl… |
| DC-MITHRIL-04 | enforced | Native V2 LedgerDB `state` decode is faithful, fail-closed, and non-emitting. The cardano-node V2 (utxohd-mem, tablesCodecVersion 1) LedgerDB `state` … |
| DC-MITHRIL-05 | enforced | Faithful Word64 multi-asset quantity on the snapshot-import path. The native V2 LedgerDB `tables` MemPack TxOut decode keeps every multi-asset quantit… |
| DC-MITHRIL-06 | enforced | The Stage-2 `tables` (MemPack-decoded TxOuts) materialize into Ade's authoritative `UTxOState` with hash-critical bytes PRESERVED and full Word64 quan… |
| DC-NODE-06 | enforced | Self-accept -> serve handoff on the --mode node relay spine (sibling serve task, shape B). Only a BLUE self-accepted forged artifact may enter the sib… |
| DC-NODE-11 | enforced | Once --mode node has self-accepted and SERVED a genesis-successor block at block_no 0, it MUST NOT add/replace the served view (ServedChainView) with … |
| DC-NODE-13 | enforced | Served view is a durable-chain projection. The ChainView served to followers (ChainSync header advertisement + BlockFetch body) is a deterministic PRO… |
| DC-NODE-25 | enforced | Live fork-choice durable application authority (rung-2). A ChainSelected / RolledBack outcome from the chain_selector orchestrator is applied to the d… |
| DC-NODE-27 | enforced | Rollback+reselection replay-equivalence (rung-2). The ordered live receive-event sequence (RollForward headers, RollBackward points, body deliveries) … |
| DC-NODE-31 | enforced | Recovered-anchor live-follow start authority (PHASE4-N-AK). After recovery from a non-Origin bootstrap anchor, the recovered store PERSISTS the bootst… |
| DC-NODE-44 | enforced | A warm-start replay divergence (T-REC-05) must be SELF-DESCRIBING: the typed fault carries a `ReplayDivergenceReport` alongside the two fingerprints, … |
| DC-PROTO-09 | enforced | Receive-side transcript determinism: given canonical inputs (initial_ledger, initial_chain_dep, initial_chaindb, event_sequence), the bridge reducer's… |
| DC-STORE-08 | enforced | Snapshot encoder canonicality: encode_snapshot(s) is byte-identical across runs. Encoder uses BTreeMap iteration only; no HashMap, no wall-clock, no f… |
| DC-STORE-09 | enforced | Snapshot bytes carry a closed u32 version tag (initial == 1) and the source state's blake2b-256 fingerprint. Decoder reads the version tag first and r… |
| DC-STORE-10 | enforced | Replay equivalence requires the persisted authority store and the binary to agree on the MEANING of the bytes, not merely on their layout. Every durab… |
| DC-STORE-12 | enforced | The semantics version may not be left to memory. The declared semantics-bearing surface (`ci/store-semantics-surface.lock`) is content-hashed, and any… |
| DC-TXV-01 | enforced | tx_validity is a pure function of (LedgerState, tx_cbor). No wall-clock, arrival order, HashMap/HashSet iteration, float, or ambient state may influen… |
| DC-TXV-02 | enforced | A transaction is Valid iff both phase-1 (structural + UTxO rules + witnesses) and phase-2 (Plutus, when scripts are present) accept it. No path may pr… |
| DC-TXV-03 | enforced | Ade's Valid/Invalid verdict for a transaction equals the reference cardano-node verdict, including the reason class where the reference exposes it. Es… |
| DC-TXV-04 | enforced | A Valid transaction yields an applied LedgerState' (the mempool's accumulating view); an Invalid transaction leaves the input state unchanged plus a s… |
| DC-TXV-05 | enforced | For each era, required_signers(state, tx_body) is a closed, explicit, era-versioned function over every signer source (resolved input payment credenti… |
| DC-TXV-06 | enforced | For each era, the certificate-deposit classification map(state, cert) is a closed, total, era-versioned function: every certificate variant resolves t… |
| DC-TXV-07 | enforced | All deposit/refund amounts used by Conway transaction value-conservation accounting must be sourced from canonical ledger protocol parameters or expli… |
| DC-VAL-01 | enforced | A block's validity verdict is a pure function of (LedgerState, PraosChainDepState, EraSchedule, LedgerView, block_cbor). No wall-clock, arrival order,… |
| DC-VAL-02 | enforced | A block is Valid iff both the consensus header authority (validate_and_apply_header) and the ledger body authority (apply_block_with_verdicts) accept … |
| DC-VAL-03 | enforced | The header is validated before the body; body validation never runs on a header-invalid block. The first failing authority determines the reason (fail… |
| DC-VAL-04 | enforced | Ade's Valid/Invalid verdict for a block equals the reference cardano-node verdict, including the reason class where the reference exposes it. Establis… |
| DC-VAL-05 | enforced | A Valid block yields evolved (LedgerState', PraosChainDepState'); an Invalid block yields the unchanged input states plus a structured reason. No part… |
| DC-VAL-06 | enforced | Every crypto-input, field-size, and structural check on the authority path rejects (produces Invalid) on wrong size or shape and never silently skips.… |
| DC-WAL-01 | enforced | WAL is append-only by type: the WalStore trait carries no method named truncate / rewrite / replace / delete / clear. CI grep enforces across the work… |
| DC-WAL-02 | enforced | WAL fingerprint-chain integrity: every WalEntry::AdmitBlock has prior_fp == previous entry's post_fp (or anchor's initial_ledger_fingerprint for the f… |
| DC-WAL-03 | enforced | Anchor + WAL replay-equivalence: replaying (BootstrapAnchor + WAL entries 1..N) against (initial_ledger from import + per-entry block bytes) produces … |
| DC-WAL-04 | enforced | Forged-block WAL chain integrity. A forged AdmitBlock WAL entry's prior_fp MUST equal the current durable post_fp (the BootstrapAnchor's initial_ledge… |
| OP-MEM-02 | enforced | Ade's owned resident memory (Private_Dirty/RssAnon) under a representative venue stays clearly below the reference Haskell cardano-node's on the same … |
| RO-MITHRIL-IMPORT-01 | enforced | Ade imports a Mithril-authenticated snapshot as an alternative to the cardano-cli JSON seed. Provides cryptographic provenance for the seed artifact (… |
| T-BUILD-01 | enforced | No semantic build variability in authoritative code |
| T-CONSERV-01 | enforced | UTxO and asset conservation must hold for every accepted transition, except where protocol rules explicitly authorize mint, burn, rewards, or treasury… |
| T-CORE-01 | enforced | Authoritative logic is pure, side-effect-free, and replayable |
| T-CORE-02 | enforced | No wall-clock, unseeded randomness, floats, or nondeterministic collections in authoritative paths |
| T-DET-01 | enforced | Same canonical inputs -> same authoritative bytes (per Byte Authority Model) |
| T-ENC-01 | partial | All persisted/hashed/transmitted data uses canonical encoding |
| T-EPOCH-01 | partial | Exactly one authoritative committee and governance interpretation per epoch |
| T-ERR-01 | partial | Errors in authoritative paths are structured, comparable, canonical |
| T-NOSPEND-01 | enforced | No input or equivalent spend authority may be consumed more than once in an accepted canonical chain |
| T-REC-04 | enforced | The WarmStart-recovered forge `chain_dep.epoch_nonce` (eta0) MUST come from the imported/recovered consensus input, never from a snapshot placeholder … |
| T-REC-06 | enforced | Rollback-materialization replay-equivalence (PHASE4-N-AN). A block that validates during live admit (against the eta0-overlaid chain_dep, T-REC-04) MU… |