ade_network
MIXED- Purpose
Owns the Cardano Ouroboros mini-protocol authority — the closed wire grammar (CBOR codecs) and pure state machines for all N2N + N2C mini-protocols, plus the BLUE mux frame primitive (
mux/frame.rs) and the producer-side server-role reducers. Owns the per-protocol tag-24 composition authorities, theblock_fetch/grammar, thekeep_alive/grammar, and thetx_submission/grammar (DC-PROTO-11, real-capture-locked). (Noade_networkchange across the span — BLUE submodules 111, byte-stable.)- Creates
111 BLUE canonical types:
mux/frame.rs5,codec/40 (incl. closedArrayHead,TxSubmissionTxId),handshake/9,chain_sync/11,block_fetch/10,tx_submission/5,keep_alive/5,peer_sharing/5,n2c/21.- Interprets
Mini-protocol wire frames;
mux::frame::decode_frameis the single frame decode authority; per-protocol*_transitionreducers consume decoded messages; the tag-24 composers;decode_find_intersect_points; thetx_submissioncodec.- MUST NOT
(1) single
encode_frame/decode_frame. (2) singlen2n_transition+n2c_transition. (3) closedAcceptedMiniProtocolregistry. (4) no socket I/O in BLUE submodules. (5) no async/tokio in BLUE submodules. (6) depend on no workspace crate beyondade_codec+ade_types. (7) server reducers no parallel header split / no signing. (8) tag-24 composition delegates to the singleade_codecauthority. (8b–8g)n2n_supported_for_magic/encode_n2n_version_params/ArrayHead/ FindIntersect cursor /keep_alive/codec::tx_submissionfences.- Inbound deps
ade_runtime,ade_node,ade_core_interop,ade_testkit.- Outbound deps
ade_types,ade_codec. No external deps in BLUE submodules.- Entry points
ade_network::mux::frame::{encode_frame, decode_frame},ade_network::handshake::{n2n_transition, n2c_transition},ade_network::codec::{chain_sync, block_fetch, handshake, version}::*,ade_network::chain_sync::server::*,ade_network::block_fetch::server::*,ade_network::keep_alive::*,ade_network::tx_submission::*,ade_network::{peer_sharing, n2c}::*.- Key modules
mux/frame.rs,codec/,handshake/,chain_sync/,block_fetch/,tx_submission/,keep_alive/,peer_sharing/,n2c/.
- Purpose
The RED live-capture binaries (non-
session, non-mux::frame) used for wire-evidence extraction against a real cardano-node.- MUST NOT
(1) Construct semantic types from raw bytes. (2) Overstate semantic truth in captured evidence.
- Inbound deps
None (binaries).
- Outbound deps
ade_codec,ade_types,tokio.
Depends on
—
Depended on by
—
CI guards — 27
| Script | Enforces |
|---|---|
| ci_check_block_fetch_server_closure.sh | DC-CONS-17, DC-PROTO-07 |
| ci_check_broadcast_to_served_purity.sh | DC-CONS-17, DC-CONS-18, DC-PROTO-07 |
| ci_check_cbor_round_trip.sh | T-ENC-03 |
| ci_check_ce_n_a_5_proof.sh | DC-PROTO-05 |
| ci_check_chain_sync_server_closure.sh | DC-PROTO-07, DC-PROTO-08 |
| ci_check_chainsync_findintersect_compat.sh | CN-WIRE-11 |
| ci_check_clock_seam.sh | DC-NODE-03, DC-SESS-05 |
| ci_check_codec_message_closed.sh | CN-WIRE-07 |
| ci_check_feed_tag24_unwrap.sh | CN-WIRE-12 |
| ci_check_handshake_closure.sh | CN-SESS-02 |
| ci_check_keep_alive_wire_only.sh | DC-PUMP-03 |
| ci_check_live_feed_memory_bounds.sh | DC-LIVEMEM-01 |
| ci_check_mini_protocol_id_registry_closed.sh | DC-SESS-02 |
| ci_check_mini_protocol_surface.sh | DC-PROTO-03, DC-PROTO-04 |
| ci_check_mini_protocol_transition_purity.sh | DC-PROTO-01, DC-PROTO-06 |
| ci_check_mux_frame_closure.sh | CN-SESS-01 |
| ci_check_n2n_handshake_versiondata_authority.sh | CN-WIRE-10 |
| ci_check_no_parallel_header_splitter.sh | CN-PROTO-06, DC-CONS-16, DC-CONS-18 |
| ci_check_outbound_segmentation.sh | CN-SESS-05 |
| ci_check_serve_listener_magic_aware.sh | DC-NODE-07 |
| ci_check_session_core_closure.sh | CN-SESS-03, DC-SESS-01, DC-SESS-03 |
| ci_check_session_no_unbounded.sh | DC-SESS-04 |
| ci_check_session_proto_reassembly.sh | CN-SESS-04, DC-SESS-06 |
| ci_check_single_serve_dispatch_authority.sh | DC-NODE-07 |
| ci_check_tag24_wire_authority.sh | CN-WIRE-08 |
| ci_check_tx_submission2_real_capture.sh | DC-PROTO-02, DC-PROTO-11 |
| ci_check_unsigned_header_preimage_single_source.sh | CN-KES-HEADER-01, DC-CONS-18 |
Related invariants — 34
| ID | Status | Statement |
|---|---|---|
| CN-PROTO-06 | enforced | The producer-side session orchestrator can only construct outgoing mini-protocol messages tagged with Server agency. Client-originated messages from t… |
| CN-SESS-01 | enforced | Single mux frame authority: ade_network::mux::frame::{encode_frame, decode_frame} is the SOLE pub fn pair encoding/decoding `MuxFrame` to/from bytes i… |
| CN-SESS-02 | enforced | Single handshake authority: ade_network::handshake::n2n_transition is the SOLE pub fn driving the N2N handshake state machine. ade_network::handshake:… |
| CN-SESS-03 | enforced | Single session step authority: ade_network::session::core::step is the SOLE pub fn reducing (SessionState, ByteChunkIn) -> (SessionState, Vec<SessionE… |
| CN-SESS-04 | enforced | Session reducer per-mini-protocol payload reassembly: the GREEN session reducer maintains one accumulating Vec<u8> buffer per AcceptedMiniProtocol var… |
| CN-SESS-05 | enforced | Outbound mini-protocol payloads larger than MAX_PAYLOAD are segmented into ordered mux frames, each no larger than MAX_PAYLOAD, preserving mini-protoc… |
| CN-SNAPSHOT-02 | enforced | A RequestRange covering a slot range that is not entirely present in ServedChainSnapshot MUST return NoBlocks per the Cardano block-fetch protocol's f… |
| CN-WIRE-07 | enforced | Each protocol-visible message must decode into one closed, versioned message type |
| CN-WIRE-08 | enforced | N2N tag-24 CBOR-in-CBOR payload envelopes are constructed and stripped through ONE shared BLUE byte authority in ade_codec (wrap_tag24/unwrap_tag24). … |
| CN-WIRE-10 | enforced | Ade's serve-side N2N handshake RESPONDER must encode versionData / MsgAcceptVersion / query-reply in the closed Cardano NodeToNode wire grammar a real… |
| CN-WIRE-11 | enforced | Ade's serve-side ChainSync server must be wire-compatible with a real cardano-node follower's MsgFindIntersect, in two halves, served from the SINGLE … |
| CN-WIRE-12 | enforced | Ade's FEED/receive-side BlockFetch path MUST remove the protocol tag-24 wrapper using the SINGLE ade_codec unwrap authority (decompose_blockfetch_bloc… |
| DC-CONS-17 | enforced | Block bytes delivered via producer-side block-fetch Block{bytes} are byte-identical to AcceptedBlock.as_bytes() for the AcceptedBlock that cleared sel… |
| DC-CONS-18 | enforced | Header bytes announced via chain-sync RollForward{header,tip} are the header sub-segment of the AcceptedBlock whose body bytes are subsequently servab… |
| DC-LIVEMEM-01 | enforced | Live-feed bounded memory (operational-hardening; NOT BLUE consensus law). Peer-driven memory on the live --mode node feed is bounded BEFORE authoritat… |
| DC-NODE-07 | enforced | Node-spine live serve-to-peer. --mode node serves real peers ONLY from the G-B self-accepted ServedChainView (the read side of the single ServedChainH… |
| DC-PROTO-01 | enforced | Protocol state machines have deterministic transitions |
| DC-PROTO-02 | enforced | Transcript-equivalent miniprotocol behavior with Haskell node |
| DC-PROTO-03 | enforced | Full N2N mini-protocol surface: Handshake, ChainSync, BlockFetch, TxSubmission2, KeepAlive, PeerSharing |
| DC-PROTO-04 | enforced | Full N2C mini-protocol surface: Handshake, LocalChainSync, LocalTxSubmission, LocalStateQuery, LocalTxMonitor |
| DC-PROTO-05 | declared | Version negotiation is closed: enumerated N2N/N2C versions, explicit handshake, deterministic refusal on mismatch |
| DC-PROTO-06 | enforced | BLUE mini-protocol transitions are pure functions of (canonical prior state, canonical input message, selected protocol version, deterministic configu… |
| DC-PROTO-07 | enforced | Given canonical inputs (negotiated_version, peer_message_sequence, broadcast_arrival_sequence, session_event_sequence), the producer-side chain-sync /… |
| DC-PROTO-08 | enforced | Once chain-sync enters a state where the server holds agency, the pure per-session reducer must return exactly one of: a legal RollForward, a legal Ro… |
| DC-PROTO-10 | enforced | Chain-sync server FindIntersect cursor: after the producer chain-sync server answers IntersectFound(point), its read cursor (last_announced) IS that p… |
| DC-PROTO-11 | enforced | TxSubmission2 codec accepts + byte-identically preserves cardano-node's REAL wire form for the txid/tx messages: each txId is era-tagged [eraIndex, ha… |
| DC-PUMP-03 | enforced | Wire-pump keep-alive client (PHASE4-N-AM). The admission wire pump (run_admission_wire_pump -- the SOLE per-peer pump, CN-PUMP-01) runs the N2N keep-a… |
| DC-SESS-01 | enforced | Handshake-before-traffic: no mini-protocol frame reaches the orchestrator inbox until the handshake state machine has emitted Accepted. Type-state: a … |
| DC-SESS-02 | enforced | Closed mini-protocol id registry: the dispatch table over `MiniProtocolId` is a closed `match` on a closed `AcceptedMiniProtocol` enum. Unknown ids re… |
| DC-SESS-03 | enforced | Per-mini-protocol ordering + session replay equivalence: replaying the same byte chunks through `session::core::step` yields byte-identical outbound f… |
| DC-SESS-04 | enforced | Backpressure discipline: every per-peer + per-mini-protocol channel is bounded; queue overflow is fail-fast `TransportError::BackpressureExceeded` rat… |
| DC-SESS-05 | enforced | Wire-layer clock injection: the session reducer + dispatch table contain no SystemTime / Instant::now / tokio::time reads. Keep-alive is driven by the… |
| DC-SESS-06 | enforced | Replay equivalence under fragmented inbound streams: two reducer runs over the same byte-chunk sequence (including inputs where single CBOR items span… |
| T-ENC-03 | enforced | Round-trip identity: encode(decode(bytes)) == bytes for valid encodings |