Modules / ade_node

ade_node

RED
RED crate
Purpose

The node binary + library entry. Owns argv parsing, the node lifecycle, and the mode drivers dispatched by main(): --mode wire_only, --mode admission, --mode key_gen_kes, --mode produce, --mode node (node_lifecycle, the single lifecycle owner), plus the judge-facing ade mithril snapshot fetch acquisition command. Carries the full N-F-C…N-AO --mode node live surface, the AUTOMATIC ECA epoch-boundary activation (maybe_activate_epoch_boundary, keyed on canonical state, NOT a flag — the epoch_* orchestration modules), and the native-Mithril FirstRun route. NEW this refresh — LIVE-FORGE-HARDENING (shell-only): S1 extracted the participant RollBack arm into the shared pub(crate) resolve_and_apply_peer_rollback (in node_lifecycle.rs) and rewired run_node_sync's former _ => UnexpectedRollback (node_sync.rs) to it, so the --mode node forge path now follows a legal within-k within-epoch live rollback through the SAME machinery as the participant path (materialize_rolled_back_state → commit_rollback → WalEntry::RollBack), byte-identical, with the pending_reselection fence set/cleared around the apply; S2 made warm_start_recovery and the forward recovered_node_schedule derive the candidate-freeze RSW from the durable seed sidecar (security_param k → praos_rsw_slots) via the single sidecar_freeze_rsw helper, with the restart-CLI RSW kept ONLY as a fail-closed cross-check. Also NEW: mithril_fetch (RED snapshot ACQUISITION — the only step that talks to Mithril; ade node run then consumes a purely-local verified directory) and ops_log (RED write-only operational telemetry). #![deny(unsafe_code)] preserved with ZERO local allows.

Interprets

argv (closed mode set); operator key/genesis/opcert paths; a peer's tag-24-wrapped BlockFetch MsgBlock; each peer item as a peer-tagged NodeSyncItem. Rollback (S1): resolve_and_apply_peer_rollback interprets a peer RollBackward Point against the durable store — a within-k within-epoch in-store target is applied durably (canonical target = STORED slot+hash, DC-NODE-29); Point::Origin / unknown hash / peer-slot ≠ stored-slot / deeper than k / below the seed anchor keep their exact typed halts. ECA: epoch_wire::extract_source_window interprets the DURABLE ChainDB range (no peer/network/CLI); derive_authoritative_candidate replays the validated window over a FRESH scratch checkpoint; verify_live_readiness is an INDEPENDENT non-authoritative cross-check. Native Mithril: native_firstrun::native_first_run_bootstrap interprets the operator-supplied files (manifest + V2 state + V2 tables + Shelley genesis) into the bootstrapped authority through the closed native composition; mithril_fetch downloads + verifies a snapshot directory.

MUST NOT

All carry-forward --mode node prohibitions (closed mode set; single lifecycle owner via bootstrap_initial_state; durable-tip ONLY via pump_block; content-blind planner; the serve-as-projection / forge-on-followed-tip / receive-idempotency fences; the PHASE4-N-AO DC-NODE-34…41 SELECT-driver fences; the MEM OP-MEM-02 exit-35 fail-closed + ade_mem_diag-behind-the-toggle + #![deny(unsafe_code)] zero-allows fences). ECA (DC-EPOCH-05..14 / DC-EVIEW-08): NO build- or runtime-level switch may decide WHETHER epoch-view activation occurs (there is NO EVIEW_ACTIVATION_ARMED const / armed param / if !armed guard anywhere in crates/); activation is AUTOMATIC and DETERMINISTIC, the ONLY gate being the activation predicate over canonical durable state; the candidate's source window comes from the canonical DURABLE selected chain ONLY (never wall-clock, never a peer fetch); activation is ONE atomic durable-before-visible path holding exactly ONE ActiveEpochAuthority crossed Seed→Promoted IN PLACE; a failure after the predicate is a TERMINAL halt, never a seed fallback; at most ONE canonically-bound view per target epoch (recovery re-derives + promotes only on byte-identical recompute). NATIVE MITHRIL (DC-MITHRIL-07): the native FirstRun route MUST FORBID --json-seed-path / --consensus-inputs-path (NativeRouteForbiddenFlag), require manifest + state + tables + Shelley-genesis, and route through the single native composition — no cardano-cli, no JSON seed, no convenience fallback. NEW — LIVE-FORGE-HARDENING (shell-only, no BLUE edit): (S1, INV-FH-1/2/3/4) the forge path follows ONLY a peer rollback whose target is in the durable store, within k, on the canonical chain, AND at/after the current promoted authority's epoch-start slot; every genuinely-illegal rollback (Origin, unknown hash, slot mismatch, beyond-k, below-anchor, or one that would un-cross an epoch boundary against an already-promoted authority) keeps its exact typed halt — the fail-closed posture is strictly widened-correct, not relaxed; the forge path MUST NOT forge across a pending rollback (pending_reselection set around the apply, DC-NODE-27/28) and MUST reuse the SHARED resolve_and_apply_peer_rollback (no second rollback path). (S2) warm_start_recovery + recovered_node_schedule MUST derive the candidate-freeze RSW from the durable sidecar security_param through the single BLUE praos_rsw_slots (the store is the SOLE freeze authority on both the recovery-replay AND forward-loop paths); the restart-CLI RSW is a fail-closed cross-check ONLY (a mismatch is terminal), never the source; a v5 sidecar surfaces the TYPED ConsensusInputsSchemaUnsupported{required:6} (re-bootstrap, not corruption), and a missing security_param fails closed (MissingField, no fabricated default). mithril_fetch / ops_log MUST NOT influence any authoritative state, transition, replay, or consensus decision.

Inbound deps

None (binary + integration tests).

Outbound deps

ade_types, ade_core (consensus::{fork_choice::select_best_chain, header_validate, candidate, header_summary, events::Point, era_schedule::{EraSchedule, praos_rsw_slots}, ledger_view::LedgerView, vrf_cert::ActiveSlotsCoeff, SecurityParam}), ade_crypto, ade_ledger (block_validity::*, state::LedgerState, fingerprint::*, rollback::{materialize::*, admission::*}, wal::{WalEntry, event::*}, the reduced-view / native-Mithril families, frozen_leadership::{FrozenLeadershipPoolDistr, to_pool_distr_view}, epoch_accumulator::*, bootstrap_bridge::*, seed_consensus_inputs::{SeedEpochConsensusInputs, SEED_CINPUT_SCHEMA_VERSION}, mempool::ingress::mempool_ingress, pump_block via forward_sync), ade_runtime (chaindb::{ChainDb, ReducedUtxoCheckpoint, reduced_window_driver, transient_epoch_view, epoch_accumulator_store, epoch_accumulator_advance}, mithril_native_assembly::*, mithril_bootstrap, admission::*), ade_network, ade_codec, mimalloc (binary-only), ade_mem_diag (binary-only, behind the toggle), serde, serde_json, tokio. Dev-deps: ade_testkit, tempfile.

Entry points

main(); ade_node::run_node_lifecycle (--mode node); ade_node::node_lifecycle::{run_relay_loop, ForgeActivation, resolve_and_apply_peer_rollback, sidecar_freeze_rsw, recovered_node_schedule, warm_start_recovery, apply_chain_event, run_participant_sync, dispatch_competing_fork_choice, prove_fork_switch, apply_fork_switch, maybe_activate_epoch_boundary, first_run_native_mithril_bootstrap}; ade_node::node_sync::{NodeBlockSource, NodeSyncItem, run_node_sync}; ade_node::fair_merge::fair_merge; the ECA activation seam (epoch_wire::*, epoch_source_window::*, epoch_candidate::derive_candidate, epoch_activate::activate_at_boundary, epoch_activation::{ActiveEpochAuthority, activation_predicate, recover_active_view}, epoch_rebind::decide_epoch_rebind); ade_node::native_firstrun::native_first_run_bootstrap; ade_node::mithril_fetch::{resolve_mithril_profile, MithrilProfile}; ade_node::mem_measure::*; ade_node::convergence_evidence::*; ade_node::cli::{Cli, ProduceCli, Mode}.

Key modules

lib.rs, cli.rs, node.rs, main.rs (RED entry + #[global_allocator] mimalloc), node_lifecycle.rs (the --mode node owner + the fork-switch drivers + the AUTOMATIC EVIEW activation call + the native-Mithril route + the shared resolve_and_apply_peer_rollback / sidecar_freeze_rsw / recovered_node_schedule / warm_start_recovery helpers), node_sync.rs (the forge-path rollback rewire), fair_merge.rs, admission/, mem_measure/, the PHASE4-N-AO candidate_aggregator.rs/lca_walk.rs/selector_state.rs/post_switch_continuity.rs/fork_switch.rs, convergence_evidence.rs, admission_log/, epoch_wire.rs/epoch_source_window.rs/epoch_candidate.rs/epoch_activate.rs/epoch_activation.rs/epoch_rebind.rs, native_firstrun.rs, mithril_fetch.rs (NEW), ops_log.rs (NEW), operator_forge.rs/ba02_pass.rs/rehearsal_pass.rs/produce_mode.rs/wire_only.rs/key_gen.rs (RED).

Creates (RED-only)

Cli, CliError, ProduceCli, KeyGenKesCli, Mode (closed), NodeStartupInputs, NodeShutdownEvidence, NodeRunError, exit-code constants (incl. EXIT_LIVE_STATIC_UTXO_FP_INVALID = 35). node_lifecycle (RED): NodeStart, NodeLifecycleError (incl. NativeRouteForbiddenFlag, NativeFirstRun), ForgeActivation<'a>, run_relay_loop / run_relay_loop_with_sched, the shared resolve_and_apply_peer_rollback + sidecar_freeze_rsw + recovered_node_schedule + warm_start_recovery helpers, the PHASE4-N-AO RED drivers. node_sync (RED): closed NodeBlockSource, NodeSyncItem { Block { peer, bytes } \| RollBack(Point) }, NodeSyncError. fair_merge (RED): per-peer bounded lanes + deterministic round-robin merge. ECA (RED, NOT canonical-counted): the epoch_wire / epoch_source_window / epoch_candidate / epoch_activate / epoch_activation / epoch_rebind error+outcome+authority types (ActiveEpochAuthority, ActiveEpochView one-way Seed→Promoted, activation_predicate, EpochViewActivationError, …). Native Mithril (RED, NOT canonical-counted): native_firstrun::{NativeGenesisFacts, NativeFirstRunError, NativeGenesisParseError}; mithril_fetch::{MithrilProfile, FetchError}. Plus the carried MEM + PHASE4-N-AO GREEN/RED surfaces.

Depends on

—

Depended on by

—

CI guards — 122

ScriptEnforces
ci_check_accumulator_refold_bound.sh DC-EPOCH-26, DC-EPOCH-27, DC-EPOCH-28, DC-EPOCH-29, DC-EPOCH-30, DC-EPOCH-31
ci_check_admission_log_vocabulary_closed.sh DC-ADMIT-04, DC-ADMIT-10
ci_check_admission_no_refscript_skip.sh CN-ADMIT-02, DC-ADMIT-09
ci_check_admission_runner_closure.sh CN-ADMIT-01, DC-ADMIT-02, DC-ADMIT-03, DC-ADMIT-05
ci_check_admission_runner_no_block_byte_map.sh DC-WAL-05
ci_check_admission_wire_pump_closure.sh CN-PUMP-01, DC-ADMIT-12, DC-PUMP-01, DC-PUMP-02
ci_check_admit_replay_equivalence.sh DC-ADMIT-07
ci_check_adversarial_false_accept_corpus.sh DC-EVIDENCE-02
ci_check_alloc_determinism_neutral.sh DC-MEM-06
ci_check_ba02_evidence_closed.sh RO-LIVE-06
ci_check_ba02_evidence_manifest_schema.sh CN-OPERATOR-EVIDENCE-01, RO-LIVE-06
ci_check_bnd_typed_stall_cause.sh DC-EPOCH-39
ci_check_bootstrap_rupd_fee_reduction.sh

DC-EPOCH-23 (CE-3d)

ci_check_bootstrap_rupd_window_end.sh

DC-EPOCH-18 (B3c)

ci_check_bounded_inbound_admission.sh CN-MEM-01
ci_check_bridge_nonce_freeze_differential.sh DC-EPOCH-38
ci_check_candidate_construction_validated.sh DC-NODE-35
ci_check_cert_evidence_only.sh DC-NODE-21
ci_check_collateral_balance_resolver.sh DC-LEDGER-PHASE2-02, DC-LEDGER-PHASE2-03
ci_check_consensus_input_provenance.sh CN-CINPUT-02, CN-CINPUT-03, DC-CINPUT-02b
ci_check_convergence_evidence_emit_only.sh DC-NODE-30
ci_check_convergence_evidence_schema.sh DC-EVIDENCE-03, DC-NODE-30
ci_check_convergence_evidence_vocabulary_closed.sh DC-ADMIT-04, DC-NODE-30
ci_check_eview_activate.sh DC-EPOCH-10
ci_check_eview_activation_predicate.sh DC-EPOCH-05, DC-EPOCH-07
ci_check_eview_activation_recovery.sh DC-EPOCH-06
ci_check_eview_atomic_authority.sh DC-EPOCH-14
ci_check_eview_automatic_activation.sh DC-EPOCH-13
ci_check_eview_bootstrap_cert_state.sh DC-EVIEW-09
ci_check_eview_candidate.sh DC-EPOCH-09
ci_check_eview_epoch_rebind.sh DC-EVIEW-11
ci_check_eview_forecast_crossing.sh

DC-EPOCH-15 (ECA-5)

ci_check_eview_leadership_complete.sh DC-EPOCH-12, DC-EVIEW-05, DC-EVIEW-07, DC-EVIEW-12
ci_check_eview_live_checkpoint.sh DC-EPOCH-11
ci_check_eview_refold_reseal.sh DC-EPOCH-32, DC-EPOCH-33
ci_check_eview_seed_sidecar_v4.sh DC-CINPUT-06
ci_check_eview_source_window.sh DC-EPOCH-08
ci_check_feed_leader_threshold_view.sh DC-CINPUT-04
ci_check_feed_tag24_unwrap.sh CN-WIRE-12
ci_check_followed_peer_tip_served_evidence.sh DC-NODE-47
ci_check_forge_followed_tip_admission.sh DC-CONS-24, DC-NODE-14, DC-NODE-15, DC-NODE-20, DC-NODE-47
ci_check_forge_intent_closed.sh CN-NODE-03
ci_check_forge_slot_authority.sh DC-NODE-45, DC-NODE-46
ci_check_forge_successor_evolved_spine.sh DC-NODE-10
ci_check_forged_durable_admit_via_pump.sh DC-CONS-23, DC-NODE-12, DC-WAL-04
ci_check_fork_choice_evidence_closed.sh DC-EVIDENCE-04
ci_check_fork_switch_never_abandons.sh DC-NODE-37
ci_check_forward_sync_fp_cache.sh DC-MEM-11
ci_check_frozen_leadership_authority.sh

S4-pre

ci_check_frozen_promotion_no_seed_window.sh

S4-L2

ci_check_frozen_recovery_no_seed_window.sh

S4-L1

ci_check_genesis_consistency_fixture_present.sh CN-GENESIS-01, DC-NODE-05
ci_check_genesis_successor_reachability.sh CN-REHEARSAL-FIDELITY-01, DC-NODE-08
ci_check_kes_envelope_closed.sh DC-CRYPTO-06, DC-CRYPTO-07, OP-OPS-04
ci_check_kes_evolution_before_sign.sh DC-CRYPTO-10
ci_check_kes_sum_compatibility.sh DC-CRYPTO-04, DC-CRYPTO-05, DC-CRYPTO-07, DC-CRYPTO-08, DC-CRYPTO-09, OP-OPS-04
ci_check_lagging_is_evidence_only.sh DC-ADMIT-01, DC-ADMIT-06, DC-ADMIT-08
ci_check_lca_anchor_walk.sh DC-NODE-38
ci_check_leader_check_authority.sh CN-FORGE-02
ci_check_live_feed_memory_bounds.sh DC-LIVEMEM-01
ci_check_live_fork_choice_apply.sh DC-NODE-25, DC-NODE-26, DC-NODE-27
ci_check_live_fork_choice_wiring.sh DC-NODE-25, DC-NODE-28
ci_check_live_ledger_view_epoch_window.sh DC-ADMIT-10, DC-ADMIT-11, DC-VIEW-01
ci_check_live_operator_pass_scaffold.sh DC-EVIDENCE-01, RO-LIVE-05
ci_check_live_selector_dispatch.sh DC-NODE-36
ci_check_local_durable_forge_base.sh DC-NODE-20
ci_check_loop_planner_closed.sh CN-NODE-02, DC-NODE-05
ci_check_mem_measure_evidence.sh OP-MEM-01
ci_check_mem_opt_s2_import_peak.sh DC-MEM-06
ci_check_mem_opt_s3_owned.sh OP-MEM-02
ci_check_missing_bridge_fail_closed.sh DC-NODE-39
ci_check_missing_bridge_refetch.sh DC-NODE-41
ci_check_n2n_handshake_versiondata_authority.sh CN-WIRE-10
ci_check_native_firstrun_no_cli_seed.sh DC-MITHRIL-07
ci_check_native_firstrun_reduced_checkpoint.sh

DC-MITHRIL-08 (band 6)

ci_check_no_independent_forge_codepath.sh CN-FORGE-01
ci_check_no_produce_mode_direct_transport_writes.sh CN-OUTBOUND-RELAY-01
ci_check_node_binary_uses_single_bootstrap.sh DC-NODE-04
ci_check_node_forge_single_epoch_fail_closed.sh DC-EPOCH-03
ci_check_node_path_fidelity.sh CN-REHEARSAL-FIDELITY-01, DC-NODE-21
ci_check_node_run_loop_containment.sh CN-NODE-02, CN-NODE-03, DC-NODE-05, DC-NODE-06, DC-NODE-12, DC-SYNC-02, T-REC-03
ci_check_node_sched_events_emit_only.sh CN-NODE-04
ci_check_node_serve_lifetime.sh DC-NODE-09
ci_check_node_sync_via_pump.sh DC-SYNC-01, DC-SYNC-02
ci_check_operator_forge_no_secret_leak.sh CN-NODE-03
ci_check_participant_forge_on_selected_head.sh CN-FOLLOW-01, DC-FOLLOW-FORGE-01
ci_check_participant_venue_inert.sh DC-NODE-28
ci_check_peer_identity_preserved.sh DC-NODE-34
ci_check_post_switch_convergence_window.sh DC-EVIDENCE-05
ci_check_praos_nonce_follow_evolution.sh

DC-EPOCH-16 (ECA-B1/B2)

ci_check_private_key_custody.sh DC-CRYPTO-03, DC-CRYPTO-04, DC-CRYPTO-05, DC-CRYPTO-08, OP-OPS-04
ci_check_produce_mode_uses_bootstrap_initial_state.sh CN-NODE-01, CN-PROD-02, CN-PROD-03
ci_check_producer_coordinator_no_secrets.sh CN-FORGE-01, CN-PROD-02
ci_check_producer_corpus_present.sh CN-CONS-06
ci_check_producer_praos_vrf.sh CN-FORGE-04
ci_check_receive_detector_venue_split.sh DC-NODE-23, DC-NODE-24
ci_check_recovered_anchor_intersectable.sh DC-NODE-14
ci_check_recovered_ledger_pparams_sourced.sh DC-CINPUT-02b
ci_check_recovery_fault_self_describing.sh DC-NODE-44
ci_check_rehearsal_manifest_schema.sh CN-REHEARSAL-FIDELITY-01
ci_check_rollback_materialize_eta0.sh T-REC-06
ci_check_rollback_retention_evidence.sh DC-NODE-40
ci_check_rollback_target_canonical_binding.sh DC-NODE-29
ci_check_serve_listener_magic_aware.sh DC-NODE-07
ci_check_served_chain_handoff_fence.sh DC-NODE-06
ci_check_served_chain_projection.sh DC-NODE-06, DC-NODE-11, DC-NODE-13
ci_check_server_paths_corpus_present.sh RO-LIVE-01
ci_check_settled_rewind_survives_recovery.sh DC-EPOCH-35
ci_check_sigma_denominator_authority.sh DC-EPOCH-40
ci_check_single_producer_extend_own_spine.sh DC-NODE-18
ci_check_single_serve_dispatch_authority.sh DC-NODE-07
ci_check_store_semantics_lock.sh DC-EPOCH-40, DC-STORE-12
ci_check_tag24_wire_authority.sh CN-WIRE-08
ci_check_unsigned_header_preimage_single_source.sh CN-KES-HEADER-01, DC-CONS-18
ci_check_utxo_fp_cache.sh OP-MEM-02
ci_check_venue_differential.sh DC-EPOCH-37
ci_check_wal_append_only.sh CN-WAL-01, DC-ADMIT-05, DC-WAL-01
ci_check_warm_start_re_entry.sh DC-NODE-22
ci_check_wire_liveness.sh DC-PUMP-05, DC-PUMP-06, DC-PUMP-07, DC-PUMP-08, DC-PUMP-09, DC-PUMP-10
ci_check_wire_only_event_vocabulary_closed.sh RO-LIVE-04
ci_check_wire_only_no_bootstrap.sh RO-LIVE-04
ci_check_wire_pump_fairness.sh DC-PUMP-04

Related invariants — 143

IDStatusStatement
CN-ADMIT-01 enforced Single admission-mode entry authority: exactly one pub fn in ade_node::admission::runner::run_admission enters the admission tokio runner. No second e…
CN-ADMIT-02 enforced Single seed-to-snapshot bridge authority: exactly one pub fn in ade_node::admission::seed_to_snapshot converts the imported (UTxOState, ledger_fingerp…
CN-CINPUT-02 enforced The SeedEpochConsensusInputs sidecar MUST be populated ONLY through the single shared ade_runtime::seed_epoch_lineage::persist_seed_epoch_consensus_in…
CN-CINPUT-03 enforced Consume-side anti-laundering fence: on the node-lifecycle forge path the leadership view MUST be projected from the recovered SeedEpochConsensusInputs…
CN-CONS-06 enforced Cross-impl acceptance: blocks forged by Ade are accepted by cardano-node when delivered via N2N block-fetch / chain-sync. Evidence is operator-action:…
CN-FOLLOW-01 enforced Producer / follow authority separation. (a) DETERMINISTIC SELECTION: the same candidate set yields the same selected canonical durable tip (the AO / s…
CN-FORGE-01 enforced The producer-mode forge handler is a closed transition from CoordinatorEvent::RequestForge { slot, kes_period, ledger_snapshot_ref, chain_tip } to exa…
CN-FORGE-02 enforced Leader-check splits across the RED/BLUE color boundary: RED produces a VRF proof/output for the slot using the operator's VRF signing key; BLUE verifi…
CN-FORGE-04 enforced Producer-side Praos VRF construction must match the Conway/Praos validator authority: the leader VRF proof alpha, the leader-schedule evidence, the Le…
CN-KES-HEADER-01 enforced The KES signature in a forged block's header is over the canonical unsigned-header CBOR pre-image — the CBOR encoding of ShelleyHeaderBody (the first …
CN-MEM-01 partial Untrusted inbound work must be admitted through deterministic bounded policies before consuming scarce authoritative resources
CN-NODE-02 enforced `--mode node` is the single live-run lifecycle owner. The relay run loop may advance authoritative state ONLY by invoking existing closed seams (boots…
CN-NODE-03 enforced Operator-key ingress + forge-on flip for --mode node. Ingress constructs an operator-material-backed ForgeActivation STRICTLY through RED-parse -> BLU…
CN-NODE-04 enforced --mode node emits a CLOSED, allow-listed diagnostic event vocabulary for feed/forge scheduling: feed_unavailable{reason} with a closed reason enum, fo…
CN-OUTBOUND-RELAY-01 enforced OutboundCommand is the sole channel between produce_mode and MuxPump's outbound encoder. The closed enum carries typed ChainSyncServerMsg / BlockFetch…
CN-PEER-OUTBOUND-MAP-01 enforced Per-peer outbound senders are owned by an Arc<RwLock<BTreeMap<PeerId, mpsc::Sender<OutboundCommand>>>>. Listener (run_per_peer_session) inserts on Pee…
CN-PROD-02 enforced Producer slot loop never signs a block whose KES period has rotated past current_period. Slot → KES period is a pure function of (slot, genesis_kes_an…
CN-PROD-03 enforced produce_mode's forge base state is derived from bootstrap_initial_state (cold-start, fed the operator-seeded ledger from --json-seed + --consensus-inp…
CN-PROD-04 enforced Every CoordinatorEffect::BroadcastBlock reconstructs the AcceptedBlock from artifact.bytes through the BLUE self_accept authority against the pre-forg…
CN-REHEARSAL-FIDELITY-01 enforced Private-testnet accepted-block bounty dry-run fidelity (two coupled clauses; if either fails the rehearsal becomes misleading). (1) PATH FIDELITY: the…
CN-STORE-02 partial WAL entries, checkpoints, and recovered artifacts must be bound to exactly one anchor or bootstrap lineage
CN-WIRE-08 enforced N2N tag-24 CBOR-in-CBOR payload envelopes are constructed and stripped through ONE shared BLUE byte authority in ade_codec (wrap_tag24/unwrap_tag24). …
CN-WIRE-10 enforced Ade's serve-side N2N handshake RESPONDER must encode versionData / MsgAcceptVersion / query-reply in the closed Cardano NodeToNode wire grammar a real…
CN-WIRE-12 enforced Ade's FEED/receive-side BlockFetch path MUST remove the protocol tag-24 wrapper using the SINGLE ade_codec unwrap authority (decompose_blockfetch_bloc…
DC-ADMIT-01 enforced Closed AgreementVerdict sum (GREEN evidence, not authority): exactly four variants — Agreed{our_hash,peer_hash}, Lagging{our_slot,peer_slot}, Diverged…
DC-ADMIT-02 enforced Verdict emitted exactly once per admit-attempt: every successful admit path produces exactly one agreement_verdict JSONL event. Never twice for the sa…
DC-ADMIT-03 enforced Diverged + InputNotFound are authority-fatal at the binary boundary. Distinct exit codes: EXIT_LIVE_AGREEMENT_DIVERGED=30, EXIT_LIVE_INPUT_NOT_FOUND=3…
DC-ADMIT-04 enforced Closed AdmissionLogEvent vocabulary (8 variants: admission_started, snapshot_imported, bootstrap_complete, block_received, block_admitted, agreement_v…
DC-ADMIT-05 enforced Per-admit WAL append: every successful admit appends exactly one WalEntry::AdmitBlock to the configured WalStore. The entry's prior_fp chains to the p…
DC-ADMIT-06 enforced Verdict reducer is pure: verdict::derive(admit_outcome, peer_tip) is a pure function over closed input enums → closed output enum. No I/O, no clock, n…
DC-ADMIT-07 enforced Admit-replay-equivalence (true-tier): for every successful WalEntry::AdmitBlock transition, replay from the prior checkpoint plus WAL produces (a) the…
DC-ADMIT-08 enforced Lagging is evidence-state only: AgreementVerdict::Lagging means the local admitted chain is a prefix of the comparison target (peer's announced chain)…
DC-ADMIT-10 enforced Every admission JSONL block-event carries consensus_inputs_fingerprint. BlockAdmitted, AgreementVerdict, BootstrapComplete, and AdmissionStarted event…
DC-ADMIT-11 enforced Cross-epoch silent use forbidden. If a peer sends a block whose slot is outside [epoch_start_slot, epoch_end_slot], the runner MUST emit AdmissionHalt…
DC-ADMIT-12 enforced Undecodable peer bytes are Diverged (or PeerSentUndecodableBytes); never InputNotFound; never silent clean exit. C strengthens N-M-B's ProcessedBlock:…
DC-CINPUT-02b enforced PRODUCER CONSUMPTION (closes CE-A-4b). The node-lifecycle forge base is built from the recovered selected tip + the recovered SeedEpochConsensusInputs…
DC-CINPUT-04 enforced The receive/feed-path header-validation consensus view -- the LedgerView passed to block_validity -> validate_and_apply_header for Step 5 (VRF-keyhash…
DC-CINPUT-05 enforced Venue epoch geometry is DURABLE REPLAY AUTHORITY. A recovered store MUST replay using the epoch geometry (epoch_start_slot + epoch_length_slots) persi…
DC-CINPUT-06 enforced The durable consensus PROFILE includes genesis_hash + protocol_params_hash, persisted canonically in the v4 SeedEpochConsensusInputs sidecar and recov…
DC-CONS-23 enforced Own-forged stale-tip race safety by extend-only durable admit. An own-forged candidate is admitted to the durable tip ONLY if it EXTENDS the current d…
DC-CONS-24 enforced Forged parent hash byte-equals the peer-visible selected tip. The forged successor's prev_hash byte-equals the followed peer tip hash AND its block_no…
DC-CRYPTO-10 enforced The RED signing shell must evolve the operator KES signing key to the requested KES period before signing, using the existing deterministic Sum6KES up…
DC-EPOCH-03 enforced Single-epoch forge containment on the --mode node spine: in this forge path, a forge is valid only within the single recovered seed epoch. A candidate…
DC-EPOCH-05 enforced Epoch N+1 validation and leadership may NOT observe epoch-N seed inputs (S3f-4b). The active epoch view is a ONE-WAY ActiveEpochView transition: `Seed…
DC-EPOCH-06 enforced Activation is durable-before-visible and replay-identical (S3f-4c). The activation WAL record (EpochConsensusViewActivated) is written and made durabl…
DC-EPOCH-07 enforced A missing / stale / conflicting / mismatched candidate view causes TERMINAL fail-closed behaviour, NEVER fallback consensus (S3f-4b). The activation p…
DC-EPOCH-08 enforced The activation SOURCE WINDOW is named-role-typed, durable-lineage-pinned, and complete/ordered/bounded (S3f-4d-1). The window that produces an activat…
DC-EPOCH-09 enforced The activation candidate is derived ONLY from a validated source window, bound to the TARGET-epoch context (S3f-4d-2). derive_candidate drives the red…
DC-EPOCH-10 enforced The boundary activation orchestration is ONE atomic, ordered, durable-before-visible path (S3f-4d-3a). activate_at_boundary sequences, in order: valid…
DC-EPOCH-11 declared The live reduced-UTxO checkpoint (S3f-4d-mat) -- the authoritative reduced-stake state Ade maintains on the selected-chain admission path so it derive…
DC-EPOCH-13 enforced No semantic activation gate: no build- or runtime-level switch decides WHETHER the epoch-view activation occurs. There is no EVIEW_ACTIVATION_ARMED co…
DC-EPOCH-14 enforced Atomic epoch-authority transition + recovery. The node holds exactly ONE owned ActiveEpochAuthority -- the SOLE leadership + header-validation view so…
DC-EPOCH-15 enforced Forecast horizon <=> durable N+1 authority promotion. The relay loop's EraSchedule forecast horizon extends past an epoch boundary N->N+1 IF AND ONLY …
DC-EPOCH-16 enforced Rolling Praos chain-dep nonce evolution on the live follow path. Each validated followed header drives ONE indivisible BLUE nonce transition over {slo…
DC-EPOCH-17 declared Replay-derived per-boundary leadership authority on the live follow path. The activation seam (prepare_authority_for_candidate_slot) ADVANCES the prom…
DC-EPOCH-18 enforced Window-end bootstrap reward update for the seed+2 leadership authority. The first post-bootstrap replay-derived authority (seed+2, DC-EPOCH-17) is the…
DC-EPOCH-23 enforced Bootstrap reward-update fee-buffer authority (CE-3d). The one-shot bootstrap reward update applied at the seed->seed+1 boundary carries the certified …
DC-EPOCH-25 declared Self-contained frozen leadership authority (S4-pre). Cardano's leadership PoolDistr (nesPd) -- the per-pool (active_stake, vrf_keyhash) that decides t…
DC-EPOCH-26 enforced Settled rewind target. The epoch accumulator is NEVER rewound to a point within k of the durable tip: every rewind target is beyond the reach of an ad…
DC-EPOCH-27 enforced Lineage-bound rewind. A settled rewind target whose header hash no longer resolves canonically at its slot -- a point the chain has ABANDONED -- is RE…
DC-EPOCH-32 enforced Boundary seal reads a POSITIONED checkpoint. The boundary mark and the reduced-checkpoint commitment sealed into a frozen-leadership object are captur…
DC-EPOCH-33 enforced Refold re-seal identity. Re-deriving an epoch boundary the node has already crossed re-seals a frozen-leadership object byte-identical to the one the …
DC-EPOCH-35 enforced A bounded settled rewind survives the recovery pass that follows a durable rollback. After the ChainDb rollback COMMITS -- never before -- the settled…
DC-EPOCH-37 enforced Authoritative epoch semantics must be proven PER VENUE, not inferred from a mainnet-shaped corpus. Every venue in the closed node-side registry (`nati…
DC-EPOCH-38 enforced The Praos candidate-freeze / nonce surface must be proven across SEED-POSITION x VENUE, not once per venue. `eta0(N+1)` is committed from the candidat…
DC-EPOCH-39 enforced A stall's CAUSE is typed, and only a real epoch transition may enter boundary machinery. Advancing the durable accumulator over one block yields exact…
DC-EPOCH-40 partial Leadership sigma denominator authority (SLICE LV-1). The leader-check sigma denominator is the SNAPSHOT's total active stake -- cardano's `pdTotalActi…
DC-EVIDENCE-01 enforced Operator-pass live evidence: the C5 live operator pass against the local docker cardano-node-preprod peer produces a JSONL transcript containing AT LE…
DC-EVIDENCE-02 enforced Adversarial false-accept rejection across 4 mandatory mutation classes: 1. Body byte flip preserving envelope shape 2. Header body-hash mismatch …
DC-EVIDENCE-04 enforced Closed fork-choice convergence evidence (PHASE4-N-AO S9; promotes the live SELECT proof from stderr diagnostics to registry-grade evidence). The live …
DC-EVIDENCE-05 enforced Replayable post-switch branch-continuity verdict (PHASE4-N-AO S10). After a ForkChoiceWin adoption at tip X, a GREEN pure reducer derive_post_switch_c…
DC-EVIEW-09 enforced The manifest-bound bootstrap cert-state import (S3f-2 prerequisite). The seed (SeedEpochConsensusInputs, the compact per-POOL active epoch consensus v…
DC-EVIEW-11 enforced The deterministic, fail-closed epoch-rebind seam (S3f-3), strengthening DC-EPOCH-03. DC-EPOCH-03 fails the forge closed past the seed-epoch boundary (…
DC-EVIEW-12 enforced The leadership-complete, self-contained EpochConsensusView (ECA-0b). The candidate view is the production authority for cross-epoch leadership: every …
DC-FOLLOW-FORGE-01 enforced Participant forge-decision mechanics. The keyed Participant venue uses an initial-catch-up -> extend forge mode mirroring the single-producer two-stat…
DC-FORGE-01 enforced Given the same canonical input set (slot, eta0, vrf_vk, vrf_proof_or_output, LeaderScheduleAnswer), verify_and_evaluate_leader produces a byte-identic…
DC-LEDGER-PHASE2-03 enforced A phase-2-invalid transaction contributes its consumed collateral and NOTHING else. For a tx in the block's invalid_transactions set the accumulator a…
DC-LIVEMEM-01 enforced Live-feed bounded memory (operational-hardening; NOT BLUE consensus law). Peer-driven memory on the live --mode node feed is bounded BEFORE authoritat…
DC-MEM-06 partial The UTxO/ledger state fingerprint is computed by the canonical CBOR encoder over canonically-encoded (fixed-width big-endian) keys, NEVER from a stora…
DC-MEM-11 enforced The network forward-sync / forge per-block admit MUST derive the WAL post_fp from the CACHED UTxO-component fingerprint (ForwardSyncState.utxo_fp_cach…
DC-MITHRIL-07 enforced The live `--mode node` FirstRun arm INVOKES the native Mithril bootstrap path (DC-MITHRIL-03 / S1b) from live snapshot files -- it routes the verified…
DC-MITHRIL-08 enforced The native Mithril FirstRun is BOUNDARY-COMPLETE: when the decoded cert-state carries delegations (the EVIEW package), native_first_run_bootstrap buil…
DC-NODE-04 enforced Authority-fatal halt + shutdown-resume identity: authoritative errors (chain_write failure on a committed rollback, SnapshotDecodeError::UnknownVersio…
DC-NODE-05 enforced Forge-slot discipline on the --mode node relay run-loop. A forge is attempted at most once per SlotNo and never for a slot <= the last forged slot (no…
DC-NODE-06 enforced Self-accept -> serve handoff on the --mode node relay spine (sibling serve task, shape B). Only a BLUE self-accepted forged artifact may enter the sib…
DC-NODE-07 enforced Node-spine live serve-to-peer. --mode node serves real peers ONLY from the G-B self-accepted ServedChainView (the read side of the single ServedChainH…
DC-NODE-08 enforced --mode node MAY forge the genesis-successor (FIRST) block from the recovered authoritative base when ChainDb::tip() AND the recovered tip (recovered.t…
DC-NODE-09 enforced Once --mode node has spawned a --listen serve task (run_node_serve_task) over a ServedChainView, the end of the upstream feed (the relay loop returnin…
DC-NODE-10 enforced After the feed validation/admission advances the node spine (a block ingested -> state.receive evolved), the next forge MUST derive the successor head…
DC-NODE-11 enforced Once --mode node has self-accepted and SERVED a genesis-successor block at block_no 0, it MUST NOT add/replace the served view (ServedChainView) with …
DC-NODE-12 enforced Own-forged durable admit chokepoint. A self-accepted forged block may become part of the durable chain ONLY by being submitted to the same durable adm…
DC-NODE-13 enforced Served view is a durable-chain projection. The ChainView served to followers (ChainSync header advertisement + BlockFetch body) is a deterministic PRO…
DC-NODE-14 enforced Every claimed forge parent must be servable or peer-intersectable in the durable served lineage. A --mode node forge may only build on a parent a Hask…
DC-NODE-15 enforced Forge admissibility requires the durable servable tip to equal the followed peer tip. A --mode node forge is admissible ONLY when durable_servable_tip…
DC-NODE-17 declared followed_peer_tip advances ONLY from a real observed peer ChainSync advertisement of the peer's selected tip, INCLUDING the self-adoption echo case wh…
DC-NODE-18 enforced Successor extension after an explicit adoption certificate (single-producer, single successor). After initial peer catch-up against a real peer tip (D…
DC-NODE-19 declared Single-producer forge-loop continuation after follow-link EOF. In an explicitly declared single-producer venue (VenueRole::SingleProducer) that has AL…
DC-NODE-20 enforced Local selected durable chain forge-base authority (rung-1 single-producer). In a declared rung-1 single-producer venue, after Ade self-admits a valid …
DC-NODE-21 enforced Adoption certificate is rung-1 evidence-only, never forge authority. The file-based operator adoption certificate is a rung-1 RED EVIDENCE-ONLY shim. …
DC-NODE-22 enforced Single-producer warm-start re-entry derives forge mode from the recovered local durable spine. In a declared rung-1 single-producer venue, if warm-sta…
DC-NODE-23 enforced Shared receive-side fork-choice detector (rung-2). A peer-origin candidate that is NOT already known as part of Ade's admitted durable spine / own-ser…
DC-NODE-24 enforced Venue-split fork-choice resolver (rung-2). The DC-NODE-23 detector's non-spine consequent is gated by venue and TOTAL over the closed venue set: Venue…
DC-NODE-25 enforced Live fork-choice durable application authority (rung-2). A ChainSelected / RolledBack outcome from the chain_selector orchestrator is applied to the d…
DC-NODE-26 enforced Decision / durable reconciliation (rung-2). After any applied receive decision, the chain_selector orchestrator's selector.current_tip EQUALS the dura…
DC-NODE-28 enforced No forge across unresolved re-selection (rung-2). Once a peer-origin candidate is classified NeedsForkChoice (DC-NODE-23) in a Participant venue, forg…
DC-NODE-29 enforced Live rollback target canonical binding (rung-2; AI-S6 H-1 remediation). For a peer RollBackward(point) on the live Participant path, the rollback targ…
DC-NODE-30 enforced Participant-path convergence evidence emission (PHASE4-N-AJ). The live `--mode node --participant-venue` rollback-follow path emits the existing close…
DC-NODE-31 enforced Recovered-anchor live-follow start authority (PHASE4-N-AK). After recovery from a non-Origin bootstrap anchor, the recovered store PERSISTS the bootst…
DC-NODE-32 enforced Recovered-anchor rollback boundary on the single-producer live-follow path (PHASE4-N-AK AK-S2). After recovery to a bare bootstrap anchor, the single-…
DC-NODE-33 enforced Participant-path recovered-anchor rollback boundary (PHASE4-N-AL) -- the participant MIRROR of DC-NODE-32. On the participant live-follow path (run_pa…
DC-NODE-34 enforced Peer-identity restoration (PHASE4-N-AO, SELECT foundation). The live receive path preserves the origin peer identity end-to-end: AdmissionPeerEvent (p…
DC-NODE-35 enforced BLUE-safe candidate construction (PHASE4-N-AO). A CandidateFragment fed to the BLUE fork-choice authority select_best_chain (DC-CONS-03) MUST be deriv…
DC-NODE-36 enforced Live single-selector dispatch (PHASE4-N-AO). The live participant NeedsForkChoice arm (today fail-closed in run_participant_sync, node_lifecycle.rs) r…
DC-NODE-37 enforced Fork-switch never-abandon (PHASE4-N-AO, SELECT primary invariant; the H-1 class at fork-choice scale). When select_best_chain picks a winner that fork…
DC-NODE-38 enforced Live multi-block fork-anchor discovery (PHASE4-N-AO S7; the live-geometry gap CE-AO-6 surfaced). A live competing branch is eligible for SELECT only w…
DC-NODE-39 enforced Post-ForkChoiceWin forward-follow continuity (PHASE4-N-AO S11). After a ForkChoiceWin adoption at tip X, Ade must continue receiving and admitting the…
DC-NODE-40 enforced Rolled-back branch evidence retention for the LCA walk (PHASE4-N-AO S13). Rolled-back blocks MAY be retained only as walk-visible EVIDENCE for future …
DC-NODE-41 enforced Missing-bridge range re-fetch for winner-descendant recovery (PHASE4-N-AO S14). When a post-ForkChoiceWin WINNING peer (the peer Ade just adopted from…
DC-NODE-42 enforced LIVE-FORGE-HARDENING S1 within-epoch forge-path rollback guard (INV-FH-4). On the --mode node forge / live-follow path (run_node_sync), a peer RollBac…
DC-NODE-43 declared Gap-free resume of a reconnected live feed. A reconnected per-peer session resumes chain-sync from the last block actually DELIVERED downstream, never…
DC-NODE-44 enforced A warm-start replay divergence (T-REC-05) must be SELF-DESCRIBING: the typed fault carries a `ReplayDivergenceReport` alongside the two fingerprints, …
DC-NODE-45 enforced ONE bootstrap-bound wall-clock -> absolute-slot authority on the authoritative --mode node producer path. (a) SOLE AUTHORITY: the forge derives its sl…
DC-NODE-46 enforced Every ADMITTED ForgeTick yields either a structured refusal or a leader-schedule decision. No admitted tick may disappear, and none may report a reaso…
DC-NODE-47 partial Followed-peer-tip possession evidence (SLICE B12). The forge-admissibility signal (FollowedPeerTipSignal) reports the STRONGEST available evidence tha…
DC-PROD-01 enforced Producer-mode evidence log emits a closed `ProducerLogEvent` vocabulary: handshake_ok, slot_tick, leader_elected, block_forged, block_served, peer_cha…
DC-PUMP-04 enforced Multi-peer wire-pump fairness (PHASE4-N-AO S8; the gap the S7 live retry surfaced). When multiple peers are connected to the participant receive path,…
DC-PUMP-08 enforced Reconnect policy is transport-only and TOTAL. should_reconnect_after is the single named authority classifying the wire pump's closed outcome sum: TRA…
DC-PUMP-09 enforced No bootstrap spin. Reconnect applies ONLY to a session that was established and then lost. An unparseable --peer, or a FIRST dial that fails, keeps th…
DC-PUMP-10 enforced Deterministic, bounded reconnect backoff. Re-dial pacing follows a fixed const escalating schedule (RECONNECT_BACKOFF_SECS) that is monotone non-decre…
DC-SYNC-02 enforced Continuous relay sync: every loop iteration preserves durable-before-advance (DC-SYNC-01) and advances the tip ONLY through run_node_sync -> pump_bloc…
DC-VIEW-01 enforced LiveLedgerView determinism + epoch-window guard. The view is constructed deterministically from LiveConsensusInputsCanonical. Two guards on every Led…
DC-WAL-04 enforced Forged-block WAL chain integrity. A forged AdmitBlock WAL entry's prior_fp MUST equal the current durable post_fp (the BootstrapAnchor's initial_ledge…
DC-WAL-05 enforced Received/followed-block durable-admit is BYTES-FIRST. The live admission runner (run_admission) MUST persist an admitted block's preserved ORIGINAL by…
OP-MEM-01 partial Mempool pressure and peer churn must not starve block validation, chain selection, or persistence (scheduling priority)
OP-MEM-02 enforced Ade's owned resident memory (Private_Dirty/RssAnon) under a representative venue stays clearly below the reference Haskell cardano-node's on the same …
OP-OPS-04 enforced Operator-supplied keys. Ade supports both KES key flows: (a) Ade-native `ade_node --mode key_gen_kes --out-file PATH` emitting an `ade.kes.seed.v1` en…
RO-LIVE-01 partial A Haskell cardano-node peer issuing RequestRange covering an Ade-forged block receives, via the producer-side block-fetch server, bytes that pass that…
RO-LIVE-04 enforced Live wire-smoke pass: operator runs `ade_node --mode wire_only --peer ADDR --network NAME` against a private cardano-node peer. The binary opens TCP, …
RO-LIVE-05 enforced Live admission-agreement pass: operator runs `ade_node` against a private cardano-node peer with admission enabled (bootstrap loads a real initial led…
RO-LIVE-06 enforced BA-02 peer-acceptance evidence closure (SCHEMA + CORRELATION MECHANICS ONLY). The BA-02 evidence surface is a closed, versioned manifest (Ba02Manifest…
T-REC-03 enforced Loop-as-replay: the same recovered/bootstrapped state + the same ordered canonical block feed (NodeBlockSource) + the same deterministic loop inputs +…
T-REC-05 enforced Replay/recovery equivalence including forged admits. Same BootstrapAnchor + same WAL (including forged AdmitBlock entries) -> byte-identical recovered…
T-REC-06 enforced Rollback-materialization replay-equivalence (PHASE4-N-AN). A block that validates during live admit (against the eta0-overlaid chain_dep, T-REC-04) MU…