ade_node
RED- Purpose
The node binary + library entry. Owns argv parsing, the node lifecycle, and the mode drivers dispatched by
main():--mode wire_only,--mode admission,--mode key_gen_kes,--mode produce,--mode node(node_lifecycle, the single lifecycle owner), plus the judge-facingade mithril snapshot fetchacquisition command. Carries the full N-F-C…N-AO--mode nodelive surface, the AUTOMATIC ECA epoch-boundary activation (maybe_activate_epoch_boundary, keyed on canonical state, NOT a flag — theepoch_*orchestration modules), and the native-Mithril FirstRun route. NEW this refresh — LIVE-FORGE-HARDENING (shell-only): S1 extracted the participantRollBackarm into the sharedpub(crate) resolve_and_apply_peer_rollback(innode_lifecycle.rs) and rewiredrun_node_sync's former_ => UnexpectedRollback(node_sync.rs) to it, so the--mode nodeforge path now follows a legal within-kwithin-epoch live rollback through the SAME machinery as the participant path (materialize_rolled_back_state→commit_rollback→WalEntry::RollBack), byte-identical, with thepending_reselectionfence set/cleared around the apply; S2 madewarm_start_recoveryand the forwardrecovered_node_schedulederive the candidate-freeze RSW from the durable seed sidecar (security_paramk →praos_rsw_slots) via the singlesidecar_freeze_rswhelper, with the restart-CLI RSW kept ONLY as a fail-closed cross-check. Also NEW:mithril_fetch(RED snapshot ACQUISITION — the only step that talks to Mithril;ade node runthen consumes a purely-local verified directory) andops_log(RED write-only operational telemetry).#![deny(unsafe_code)]preserved with ZERO local allows.- Interprets
argv (closed mode set); operator key/genesis/opcert paths; a peer's tag-24-wrapped BlockFetch
MsgBlock; each peer item as a peer-taggedNodeSyncItem. Rollback (S1):resolve_and_apply_peer_rollbackinterprets a peerRollBackwardPointagainst the durable store — a within-kwithin-epoch in-store target is applied durably (canonical target = STORED slot+hash,DC-NODE-29);Point::Origin/ unknown hash / peer-slot ≠ stored-slot / deeper thank/ below the seed anchor keep their exact typed halts. ECA:epoch_wire::extract_source_windowinterprets the DURABLE ChainDB range (no peer/network/CLI);derive_authoritative_candidatereplays the validated window over a FRESH scratch checkpoint;verify_live_readinessis an INDEPENDENT non-authoritative cross-check. Native Mithril:native_firstrun::native_first_run_bootstrapinterprets the operator-supplied files (manifest + V2 state + V2 tables + Shelley genesis) into the bootstrapped authority through the closed native composition;mithril_fetchdownloads + verifies a snapshot directory.- MUST NOT
All carry-forward
--mode nodeprohibitions (closed mode set; single lifecycle owner viabootstrap_initial_state; durable-tip ONLY viapump_block; content-blind planner; the serve-as-projection / forge-on-followed-tip / receive-idempotency fences; the PHASE4-N-AODC-NODE-34…41SELECT-driver fences; the MEMOP-MEM-02exit-35 fail-closed +ade_mem_diag-behind-the-toggle +#![deny(unsafe_code)]zero-allows fences). ECA (DC-EPOCH-05..14/DC-EVIEW-08): NO build- or runtime-level switch may decide WHETHER epoch-view activation occurs (there is NOEVIEW_ACTIVATION_ARMEDconst /armedparam /if !armedguard anywhere incrates/); activation is AUTOMATIC and DETERMINISTIC, the ONLY gate being the activation predicate over canonical durable state; the candidate's source window comes from the canonical DURABLE selected chain ONLY (never wall-clock, never a peer fetch); activation is ONE atomic durable-before-visible path holding exactly ONEActiveEpochAuthoritycrossed Seed→Promoted IN PLACE; a failure after the predicate is a TERMINAL halt, never a seed fallback; at most ONE canonically-bound view per target epoch (recovery re-derives + promotes only on byte-identical recompute). NATIVE MITHRIL (DC-MITHRIL-07): the native FirstRun route MUST FORBID--json-seed-path/--consensus-inputs-path(NativeRouteForbiddenFlag), require manifest + state + tables + Shelley-genesis, and route through the single native composition — no cardano-cli, no JSON seed, no convenience fallback. NEW — LIVE-FORGE-HARDENING (shell-only, no BLUE edit): (S1, INV-FH-1/2/3/4) the forge path follows ONLY a peer rollback whose target is in the durable store, withink, on the canonical chain, AND at/after the current promoted authority's epoch-start slot; every genuinely-illegal rollback (Origin, unknown hash, slot mismatch, beyond-k, below-anchor, or one that would un-cross an epoch boundary against an already-promoted authority) keeps its exact typed halt — the fail-closed posture is strictly widened-correct, not relaxed; the forge path MUST NOT forge across a pending rollback (pending_reselectionset around the apply,DC-NODE-27/28) and MUST reuse the SHAREDresolve_and_apply_peer_rollback(no second rollback path). (S2)warm_start_recovery+recovered_node_scheduleMUST derive the candidate-freeze RSW from the durable sidecarsecurity_paramthrough the single BLUEpraos_rsw_slots(the store is the SOLE freeze authority on both the recovery-replay AND forward-loop paths); the restart-CLI RSW is a fail-closed cross-check ONLY (a mismatch is terminal), never the source; a v5 sidecar surfaces the TYPEDConsensusInputsSchemaUnsupported{required:6}(re-bootstrap, not corruption), and a missingsecurity_paramfails closed (MissingField, no fabricated default).mithril_fetch/ops_logMUST NOT influence any authoritative state, transition, replay, or consensus decision.- Inbound deps
None (binary + integration tests).
- Outbound deps
ade_types,ade_core(consensus::{fork_choice::select_best_chain, header_validate, candidate, header_summary, events::Point, era_schedule::{EraSchedule, praos_rsw_slots}, ledger_view::LedgerView, vrf_cert::ActiveSlotsCoeff, SecurityParam}),ade_crypto,ade_ledger(block_validity::*,state::LedgerState,fingerprint::*,rollback::{materialize::*, admission::*},wal::{WalEntry, event::*}, the reduced-view / native-Mithril families,frozen_leadership::{FrozenLeadershipPoolDistr, to_pool_distr_view},epoch_accumulator::*,bootstrap_bridge::*,seed_consensus_inputs::{SeedEpochConsensusInputs, SEED_CINPUT_SCHEMA_VERSION},mempool::ingress::mempool_ingress,pump_blockviaforward_sync),ade_runtime(chaindb::{ChainDb, ReducedUtxoCheckpoint, reduced_window_driver, transient_epoch_view, epoch_accumulator_store, epoch_accumulator_advance},mithril_native_assembly::*,mithril_bootstrap,admission::*),ade_network,ade_codec,mimalloc(binary-only),ade_mem_diag(binary-only, behind the toggle),serde,serde_json,tokio. Dev-deps:ade_testkit,tempfile.- Entry points
main();ade_node::run_node_lifecycle(--mode node);ade_node::node_lifecycle::{run_relay_loop, ForgeActivation, resolve_and_apply_peer_rollback, sidecar_freeze_rsw, recovered_node_schedule, warm_start_recovery, apply_chain_event, run_participant_sync, dispatch_competing_fork_choice, prove_fork_switch, apply_fork_switch, maybe_activate_epoch_boundary, first_run_native_mithril_bootstrap};ade_node::node_sync::{NodeBlockSource, NodeSyncItem, run_node_sync};ade_node::fair_merge::fair_merge; the ECA activation seam (epoch_wire::*,epoch_source_window::*,epoch_candidate::derive_candidate,epoch_activate::activate_at_boundary,epoch_activation::{ActiveEpochAuthority, activation_predicate, recover_active_view},epoch_rebind::decide_epoch_rebind);ade_node::native_firstrun::native_first_run_bootstrap;ade_node::mithril_fetch::{resolve_mithril_profile, MithrilProfile};ade_node::mem_measure::*;ade_node::convergence_evidence::*;ade_node::cli::{Cli, ProduceCli, Mode}.- Key modules
lib.rs,cli.rs,node.rs,main.rs(RED entry +#[global_allocator] mimalloc),node_lifecycle.rs(the--mode nodeowner + the fork-switch drivers + the AUTOMATIC EVIEW activation call + the native-Mithril route + the sharedresolve_and_apply_peer_rollback/sidecar_freeze_rsw/recovered_node_schedule/warm_start_recoveryhelpers),node_sync.rs(the forge-path rollback rewire),fair_merge.rs,admission/,mem_measure/, the PHASE4-N-AOcandidate_aggregator.rs/lca_walk.rs/selector_state.rs/post_switch_continuity.rs/fork_switch.rs,convergence_evidence.rs,admission_log/,epoch_wire.rs/epoch_source_window.rs/epoch_candidate.rs/epoch_activate.rs/epoch_activation.rs/epoch_rebind.rs,native_firstrun.rs,mithril_fetch.rs(NEW),ops_log.rs(NEW),operator_forge.rs/ba02_pass.rs/rehearsal_pass.rs/produce_mode.rs/wire_only.rs/key_gen.rs(RED).- Creates (RED-only)
Cli,CliError,ProduceCli,KeyGenKesCli,Mode(closed),NodeStartupInputs,NodeShutdownEvidence,NodeRunError, exit-code constants (incl.EXIT_LIVE_STATIC_UTXO_FP_INVALID = 35).node_lifecycle(RED):NodeStart,NodeLifecycleError(incl.NativeRouteForbiddenFlag,NativeFirstRun),ForgeActivation<'a>,run_relay_loop/run_relay_loop_with_sched, the sharedresolve_and_apply_peer_rollback+sidecar_freeze_rsw+recovered_node_schedule+warm_start_recoveryhelpers, the PHASE4-N-AO RED drivers.node_sync(RED): closedNodeBlockSource,NodeSyncItem { Block { peer, bytes } \| RollBack(Point) },NodeSyncError.fair_merge(RED): per-peer bounded lanes + deterministic round-robin merge. ECA (RED, NOT canonical-counted): theepoch_wire/epoch_source_window/epoch_candidate/epoch_activate/epoch_activation/epoch_rebinderror+outcome+authority types (ActiveEpochAuthority,ActiveEpochViewone-way Seed→Promoted,activation_predicate,EpochViewActivationError, …). Native Mithril (RED, NOT canonical-counted):native_firstrun::{NativeGenesisFacts, NativeFirstRunError, NativeGenesisParseError};mithril_fetch::{MithrilProfile, FetchError}. Plus the carried MEM + PHASE4-N-AO GREEN/RED surfaces.
Depends on
—
Depended on by
—
CI guards — 122
| Script | Enforces |
|---|---|
| ci_check_accumulator_refold_bound.sh | DC-EPOCH-26, DC-EPOCH-27, DC-EPOCH-28, DC-EPOCH-29, DC-EPOCH-30, DC-EPOCH-31 |
| ci_check_admission_log_vocabulary_closed.sh | DC-ADMIT-04, DC-ADMIT-10 |
| ci_check_admission_no_refscript_skip.sh | CN-ADMIT-02, DC-ADMIT-09 |
| ci_check_admission_runner_closure.sh | CN-ADMIT-01, DC-ADMIT-02, DC-ADMIT-03, DC-ADMIT-05 |
| ci_check_admission_runner_no_block_byte_map.sh | DC-WAL-05 |
| ci_check_admission_wire_pump_closure.sh | CN-PUMP-01, DC-ADMIT-12, DC-PUMP-01, DC-PUMP-02 |
| ci_check_admit_replay_equivalence.sh | DC-ADMIT-07 |
| ci_check_adversarial_false_accept_corpus.sh | DC-EVIDENCE-02 |
| ci_check_alloc_determinism_neutral.sh | DC-MEM-06 |
| ci_check_ba02_evidence_closed.sh | RO-LIVE-06 |
| ci_check_ba02_evidence_manifest_schema.sh | CN-OPERATOR-EVIDENCE-01, RO-LIVE-06 |
| ci_check_bnd_typed_stall_cause.sh | DC-EPOCH-39 |
| ci_check_bootstrap_rupd_fee_reduction.sh |
|
| ci_check_bootstrap_rupd_window_end.sh |
|
| ci_check_bounded_inbound_admission.sh | CN-MEM-01 |
| ci_check_bridge_nonce_freeze_differential.sh | DC-EPOCH-38 |
| ci_check_candidate_construction_validated.sh | DC-NODE-35 |
| ci_check_cert_evidence_only.sh | DC-NODE-21 |
| ci_check_collateral_balance_resolver.sh | DC-LEDGER-PHASE2-02, DC-LEDGER-PHASE2-03 |
| ci_check_consensus_input_provenance.sh | CN-CINPUT-02, CN-CINPUT-03, DC-CINPUT-02b |
| ci_check_convergence_evidence_emit_only.sh | DC-NODE-30 |
| ci_check_convergence_evidence_schema.sh | DC-EVIDENCE-03, DC-NODE-30 |
| ci_check_convergence_evidence_vocabulary_closed.sh | DC-ADMIT-04, DC-NODE-30 |
| ci_check_eview_activate.sh | DC-EPOCH-10 |
| ci_check_eview_activation_predicate.sh | DC-EPOCH-05, DC-EPOCH-07 |
| ci_check_eview_activation_recovery.sh | DC-EPOCH-06 |
| ci_check_eview_atomic_authority.sh | DC-EPOCH-14 |
| ci_check_eview_automatic_activation.sh | DC-EPOCH-13 |
| ci_check_eview_bootstrap_cert_state.sh | DC-EVIEW-09 |
| ci_check_eview_candidate.sh | DC-EPOCH-09 |
| ci_check_eview_epoch_rebind.sh | DC-EVIEW-11 |
| ci_check_eview_forecast_crossing.sh |
|
| ci_check_eview_leadership_complete.sh | DC-EPOCH-12, DC-EVIEW-05, DC-EVIEW-07, DC-EVIEW-12 |
| ci_check_eview_live_checkpoint.sh | DC-EPOCH-11 |
| ci_check_eview_refold_reseal.sh | DC-EPOCH-32, DC-EPOCH-33 |
| ci_check_eview_seed_sidecar_v4.sh | DC-CINPUT-06 |
| ci_check_eview_source_window.sh | DC-EPOCH-08 |
| ci_check_feed_leader_threshold_view.sh | DC-CINPUT-04 |
| ci_check_feed_tag24_unwrap.sh | CN-WIRE-12 |
| ci_check_followed_peer_tip_served_evidence.sh | DC-NODE-47 |
| ci_check_forge_followed_tip_admission.sh | DC-CONS-24, DC-NODE-14, DC-NODE-15, DC-NODE-20, DC-NODE-47 |
| ci_check_forge_intent_closed.sh | CN-NODE-03 |
| ci_check_forge_slot_authority.sh | DC-NODE-45, DC-NODE-46 |
| ci_check_forge_successor_evolved_spine.sh | DC-NODE-10 |
| ci_check_forged_durable_admit_via_pump.sh | DC-CONS-23, DC-NODE-12, DC-WAL-04 |
| ci_check_fork_choice_evidence_closed.sh | DC-EVIDENCE-04 |
| ci_check_fork_switch_never_abandons.sh | DC-NODE-37 |
| ci_check_forward_sync_fp_cache.sh | DC-MEM-11 |
| ci_check_frozen_leadership_authority.sh | S4-pre |
| ci_check_frozen_promotion_no_seed_window.sh | S4-L2 |
| ci_check_frozen_recovery_no_seed_window.sh | S4-L1 |
| ci_check_genesis_consistency_fixture_present.sh | CN-GENESIS-01, DC-NODE-05 |
| ci_check_genesis_successor_reachability.sh | CN-REHEARSAL-FIDELITY-01, DC-NODE-08 |
| ci_check_kes_envelope_closed.sh | DC-CRYPTO-06, DC-CRYPTO-07, OP-OPS-04 |
| ci_check_kes_evolution_before_sign.sh | DC-CRYPTO-10 |
| ci_check_kes_sum_compatibility.sh | DC-CRYPTO-04, DC-CRYPTO-05, DC-CRYPTO-07, DC-CRYPTO-08, DC-CRYPTO-09, OP-OPS-04 |
| ci_check_lagging_is_evidence_only.sh | DC-ADMIT-01, DC-ADMIT-06, DC-ADMIT-08 |
| ci_check_lca_anchor_walk.sh | DC-NODE-38 |
| ci_check_leader_check_authority.sh | CN-FORGE-02 |
| ci_check_live_feed_memory_bounds.sh | DC-LIVEMEM-01 |
| ci_check_live_fork_choice_apply.sh | DC-NODE-25, DC-NODE-26, DC-NODE-27 |
| ci_check_live_fork_choice_wiring.sh | DC-NODE-25, DC-NODE-28 |
| ci_check_live_ledger_view_epoch_window.sh | DC-ADMIT-10, DC-ADMIT-11, DC-VIEW-01 |
| ci_check_live_operator_pass_scaffold.sh | DC-EVIDENCE-01, RO-LIVE-05 |
| ci_check_live_selector_dispatch.sh | DC-NODE-36 |
| ci_check_local_durable_forge_base.sh | DC-NODE-20 |
| ci_check_loop_planner_closed.sh | CN-NODE-02, DC-NODE-05 |
| ci_check_mem_measure_evidence.sh | OP-MEM-01 |
| ci_check_mem_opt_s2_import_peak.sh | DC-MEM-06 |
| ci_check_mem_opt_s3_owned.sh | OP-MEM-02 |
| ci_check_missing_bridge_fail_closed.sh | DC-NODE-39 |
| ci_check_missing_bridge_refetch.sh | DC-NODE-41 |
| ci_check_n2n_handshake_versiondata_authority.sh | CN-WIRE-10 |
| ci_check_native_firstrun_no_cli_seed.sh | DC-MITHRIL-07 |
| ci_check_native_firstrun_reduced_checkpoint.sh |
|
| ci_check_no_independent_forge_codepath.sh | CN-FORGE-01 |
| ci_check_no_produce_mode_direct_transport_writes.sh | CN-OUTBOUND-RELAY-01 |
| ci_check_node_binary_uses_single_bootstrap.sh | DC-NODE-04 |
| ci_check_node_forge_single_epoch_fail_closed.sh | DC-EPOCH-03 |
| ci_check_node_path_fidelity.sh | CN-REHEARSAL-FIDELITY-01, DC-NODE-21 |
| ci_check_node_run_loop_containment.sh | CN-NODE-02, CN-NODE-03, DC-NODE-05, DC-NODE-06, DC-NODE-12, DC-SYNC-02, T-REC-03 |
| ci_check_node_sched_events_emit_only.sh | CN-NODE-04 |
| ci_check_node_serve_lifetime.sh | DC-NODE-09 |
| ci_check_node_sync_via_pump.sh | DC-SYNC-01, DC-SYNC-02 |
| ci_check_operator_forge_no_secret_leak.sh | CN-NODE-03 |
| ci_check_participant_forge_on_selected_head.sh | CN-FOLLOW-01, DC-FOLLOW-FORGE-01 |
| ci_check_participant_venue_inert.sh | DC-NODE-28 |
| ci_check_peer_identity_preserved.sh | DC-NODE-34 |
| ci_check_post_switch_convergence_window.sh | DC-EVIDENCE-05 |
| ci_check_praos_nonce_follow_evolution.sh |
|
| ci_check_private_key_custody.sh | DC-CRYPTO-03, DC-CRYPTO-04, DC-CRYPTO-05, DC-CRYPTO-08, OP-OPS-04 |
| ci_check_produce_mode_uses_bootstrap_initial_state.sh | CN-NODE-01, CN-PROD-02, CN-PROD-03 |
| ci_check_producer_coordinator_no_secrets.sh | CN-FORGE-01, CN-PROD-02 |
| ci_check_producer_corpus_present.sh | CN-CONS-06 |
| ci_check_producer_praos_vrf.sh | CN-FORGE-04 |
| ci_check_receive_detector_venue_split.sh | DC-NODE-23, DC-NODE-24 |
| ci_check_recovered_anchor_intersectable.sh | DC-NODE-14 |
| ci_check_recovered_ledger_pparams_sourced.sh | DC-CINPUT-02b |
| ci_check_recovery_fault_self_describing.sh | DC-NODE-44 |
| ci_check_rehearsal_manifest_schema.sh | CN-REHEARSAL-FIDELITY-01 |
| ci_check_rollback_materialize_eta0.sh | T-REC-06 |
| ci_check_rollback_retention_evidence.sh | DC-NODE-40 |
| ci_check_rollback_target_canonical_binding.sh | DC-NODE-29 |
| ci_check_serve_listener_magic_aware.sh | DC-NODE-07 |
| ci_check_served_chain_handoff_fence.sh | DC-NODE-06 |
| ci_check_served_chain_projection.sh | DC-NODE-06, DC-NODE-11, DC-NODE-13 |
| ci_check_server_paths_corpus_present.sh | RO-LIVE-01 |
| ci_check_settled_rewind_survives_recovery.sh | DC-EPOCH-35 |
| ci_check_sigma_denominator_authority.sh | DC-EPOCH-40 |
| ci_check_single_producer_extend_own_spine.sh | DC-NODE-18 |
| ci_check_single_serve_dispatch_authority.sh | DC-NODE-07 |
| ci_check_store_semantics_lock.sh | DC-EPOCH-40, DC-STORE-12 |
| ci_check_tag24_wire_authority.sh | CN-WIRE-08 |
| ci_check_unsigned_header_preimage_single_source.sh | CN-KES-HEADER-01, DC-CONS-18 |
| ci_check_utxo_fp_cache.sh | OP-MEM-02 |
| ci_check_venue_differential.sh | DC-EPOCH-37 |
| ci_check_wal_append_only.sh | CN-WAL-01, DC-ADMIT-05, DC-WAL-01 |
| ci_check_warm_start_re_entry.sh | DC-NODE-22 |
| ci_check_wire_liveness.sh | DC-PUMP-05, DC-PUMP-06, DC-PUMP-07, DC-PUMP-08, DC-PUMP-09, DC-PUMP-10 |
| ci_check_wire_only_event_vocabulary_closed.sh | RO-LIVE-04 |
| ci_check_wire_only_no_bootstrap.sh | RO-LIVE-04 |
| ci_check_wire_pump_fairness.sh | DC-PUMP-04 |
Related invariants — 143
| ID | Status | Statement |
|---|---|---|
| CN-ADMIT-01 | enforced | Single admission-mode entry authority: exactly one pub fn in ade_node::admission::runner::run_admission enters the admission tokio runner. No second e… |
| CN-ADMIT-02 | enforced | Single seed-to-snapshot bridge authority: exactly one pub fn in ade_node::admission::seed_to_snapshot converts the imported (UTxOState, ledger_fingerp… |
| CN-CINPUT-02 | enforced | The SeedEpochConsensusInputs sidecar MUST be populated ONLY through the single shared ade_runtime::seed_epoch_lineage::persist_seed_epoch_consensus_in… |
| CN-CINPUT-03 | enforced | Consume-side anti-laundering fence: on the node-lifecycle forge path the leadership view MUST be projected from the recovered SeedEpochConsensusInputs… |
| CN-CONS-06 | enforced | Cross-impl acceptance: blocks forged by Ade are accepted by cardano-node when delivered via N2N block-fetch / chain-sync. Evidence is operator-action:… |
| CN-FOLLOW-01 | enforced | Producer / follow authority separation. (a) DETERMINISTIC SELECTION: the same candidate set yields the same selected canonical durable tip (the AO / s… |
| CN-FORGE-01 | enforced | The producer-mode forge handler is a closed transition from CoordinatorEvent::RequestForge { slot, kes_period, ledger_snapshot_ref, chain_tip } to exa… |
| CN-FORGE-02 | enforced | Leader-check splits across the RED/BLUE color boundary: RED produces a VRF proof/output for the slot using the operator's VRF signing key; BLUE verifi… |
| CN-FORGE-04 | enforced | Producer-side Praos VRF construction must match the Conway/Praos validator authority: the leader VRF proof alpha, the leader-schedule evidence, the Le… |
| CN-KES-HEADER-01 | enforced | The KES signature in a forged block's header is over the canonical unsigned-header CBOR pre-image — the CBOR encoding of ShelleyHeaderBody (the first … |
| CN-MEM-01 | partial | Untrusted inbound work must be admitted through deterministic bounded policies before consuming scarce authoritative resources |
| CN-NODE-02 | enforced | `--mode node` is the single live-run lifecycle owner. The relay run loop may advance authoritative state ONLY by invoking existing closed seams (boots… |
| CN-NODE-03 | enforced | Operator-key ingress + forge-on flip for --mode node. Ingress constructs an operator-material-backed ForgeActivation STRICTLY through RED-parse -> BLU… |
| CN-NODE-04 | enforced | --mode node emits a CLOSED, allow-listed diagnostic event vocabulary for feed/forge scheduling: feed_unavailable{reason} with a closed reason enum, fo… |
| CN-OUTBOUND-RELAY-01 | enforced | OutboundCommand is the sole channel between produce_mode and MuxPump's outbound encoder. The closed enum carries typed ChainSyncServerMsg / BlockFetch… |
| CN-PEER-OUTBOUND-MAP-01 | enforced | Per-peer outbound senders are owned by an Arc<RwLock<BTreeMap<PeerId, mpsc::Sender<OutboundCommand>>>>. Listener (run_per_peer_session) inserts on Pee… |
| CN-PROD-02 | enforced | Producer slot loop never signs a block whose KES period has rotated past current_period. Slot → KES period is a pure function of (slot, genesis_kes_an… |
| CN-PROD-03 | enforced | produce_mode's forge base state is derived from bootstrap_initial_state (cold-start, fed the operator-seeded ledger from --json-seed + --consensus-inp… |
| CN-PROD-04 | enforced | Every CoordinatorEffect::BroadcastBlock reconstructs the AcceptedBlock from artifact.bytes through the BLUE self_accept authority against the pre-forg… |
| CN-REHEARSAL-FIDELITY-01 | enforced | Private-testnet accepted-block bounty dry-run fidelity (two coupled clauses; if either fails the rehearsal becomes misleading). (1) PATH FIDELITY: the… |
| CN-STORE-02 | partial | WAL entries, checkpoints, and recovered artifacts must be bound to exactly one anchor or bootstrap lineage |
| CN-WIRE-08 | enforced | N2N tag-24 CBOR-in-CBOR payload envelopes are constructed and stripped through ONE shared BLUE byte authority in ade_codec (wrap_tag24/unwrap_tag24). … |
| CN-WIRE-10 | enforced | Ade's serve-side N2N handshake RESPONDER must encode versionData / MsgAcceptVersion / query-reply in the closed Cardano NodeToNode wire grammar a real… |
| CN-WIRE-12 | enforced | Ade's FEED/receive-side BlockFetch path MUST remove the protocol tag-24 wrapper using the SINGLE ade_codec unwrap authority (decompose_blockfetch_bloc… |
| DC-ADMIT-01 | enforced | Closed AgreementVerdict sum (GREEN evidence, not authority): exactly four variants — Agreed{our_hash,peer_hash}, Lagging{our_slot,peer_slot}, Diverged… |
| DC-ADMIT-02 | enforced | Verdict emitted exactly once per admit-attempt: every successful admit path produces exactly one agreement_verdict JSONL event. Never twice for the sa… |
| DC-ADMIT-03 | enforced | Diverged + InputNotFound are authority-fatal at the binary boundary. Distinct exit codes: EXIT_LIVE_AGREEMENT_DIVERGED=30, EXIT_LIVE_INPUT_NOT_FOUND=3… |
| DC-ADMIT-04 | enforced | Closed AdmissionLogEvent vocabulary (8 variants: admission_started, snapshot_imported, bootstrap_complete, block_received, block_admitted, agreement_v… |
| DC-ADMIT-05 | enforced | Per-admit WAL append: every successful admit appends exactly one WalEntry::AdmitBlock to the configured WalStore. The entry's prior_fp chains to the p… |
| DC-ADMIT-06 | enforced | Verdict reducer is pure: verdict::derive(admit_outcome, peer_tip) is a pure function over closed input enums → closed output enum. No I/O, no clock, n… |
| DC-ADMIT-07 | enforced | Admit-replay-equivalence (true-tier): for every successful WalEntry::AdmitBlock transition, replay from the prior checkpoint plus WAL produces (a) the… |
| DC-ADMIT-08 | enforced | Lagging is evidence-state only: AgreementVerdict::Lagging means the local admitted chain is a prefix of the comparison target (peer's announced chain)… |
| DC-ADMIT-10 | enforced | Every admission JSONL block-event carries consensus_inputs_fingerprint. BlockAdmitted, AgreementVerdict, BootstrapComplete, and AdmissionStarted event… |
| DC-ADMIT-11 | enforced | Cross-epoch silent use forbidden. If a peer sends a block whose slot is outside [epoch_start_slot, epoch_end_slot], the runner MUST emit AdmissionHalt… |
| DC-ADMIT-12 | enforced | Undecodable peer bytes are Diverged (or PeerSentUndecodableBytes); never InputNotFound; never silent clean exit. C strengthens N-M-B's ProcessedBlock:… |
| DC-CINPUT-02b | enforced | PRODUCER CONSUMPTION (closes CE-A-4b). The node-lifecycle forge base is built from the recovered selected tip + the recovered SeedEpochConsensusInputs… |
| DC-CINPUT-04 | enforced | The receive/feed-path header-validation consensus view -- the LedgerView passed to block_validity -> validate_and_apply_header for Step 5 (VRF-keyhash… |
| DC-CINPUT-05 | enforced | Venue epoch geometry is DURABLE REPLAY AUTHORITY. A recovered store MUST replay using the epoch geometry (epoch_start_slot + epoch_length_slots) persi… |
| DC-CINPUT-06 | enforced | The durable consensus PROFILE includes genesis_hash + protocol_params_hash, persisted canonically in the v4 SeedEpochConsensusInputs sidecar and recov… |
| DC-CONS-23 | enforced | Own-forged stale-tip race safety by extend-only durable admit. An own-forged candidate is admitted to the durable tip ONLY if it EXTENDS the current d… |
| DC-CONS-24 | enforced | Forged parent hash byte-equals the peer-visible selected tip. The forged successor's prev_hash byte-equals the followed peer tip hash AND its block_no… |
| DC-CRYPTO-10 | enforced | The RED signing shell must evolve the operator KES signing key to the requested KES period before signing, using the existing deterministic Sum6KES up… |
| DC-EPOCH-03 | enforced | Single-epoch forge containment on the --mode node spine: in this forge path, a forge is valid only within the single recovered seed epoch. A candidate… |
| DC-EPOCH-05 | enforced | Epoch N+1 validation and leadership may NOT observe epoch-N seed inputs (S3f-4b). The active epoch view is a ONE-WAY ActiveEpochView transition: `Seed… |
| DC-EPOCH-06 | enforced | Activation is durable-before-visible and replay-identical (S3f-4c). The activation WAL record (EpochConsensusViewActivated) is written and made durabl… |
| DC-EPOCH-07 | enforced | A missing / stale / conflicting / mismatched candidate view causes TERMINAL fail-closed behaviour, NEVER fallback consensus (S3f-4b). The activation p… |
| DC-EPOCH-08 | enforced | The activation SOURCE WINDOW is named-role-typed, durable-lineage-pinned, and complete/ordered/bounded (S3f-4d-1). The window that produces an activat… |
| DC-EPOCH-09 | enforced | The activation candidate is derived ONLY from a validated source window, bound to the TARGET-epoch context (S3f-4d-2). derive_candidate drives the red… |
| DC-EPOCH-10 | enforced | The boundary activation orchestration is ONE atomic, ordered, durable-before-visible path (S3f-4d-3a). activate_at_boundary sequences, in order: valid… |
| DC-EPOCH-11 | declared | The live reduced-UTxO checkpoint (S3f-4d-mat) -- the authoritative reduced-stake state Ade maintains on the selected-chain admission path so it derive… |
| DC-EPOCH-13 | enforced | No semantic activation gate: no build- or runtime-level switch decides WHETHER the epoch-view activation occurs. There is no EVIEW_ACTIVATION_ARMED co… |
| DC-EPOCH-14 | enforced | Atomic epoch-authority transition + recovery. The node holds exactly ONE owned ActiveEpochAuthority -- the SOLE leadership + header-validation view so… |
| DC-EPOCH-15 | enforced | Forecast horizon <=> durable N+1 authority promotion. The relay loop's EraSchedule forecast horizon extends past an epoch boundary N->N+1 IF AND ONLY … |
| DC-EPOCH-16 | enforced | Rolling Praos chain-dep nonce evolution on the live follow path. Each validated followed header drives ONE indivisible BLUE nonce transition over {slo… |
| DC-EPOCH-17 | declared | Replay-derived per-boundary leadership authority on the live follow path. The activation seam (prepare_authority_for_candidate_slot) ADVANCES the prom… |
| DC-EPOCH-18 | enforced | Window-end bootstrap reward update for the seed+2 leadership authority. The first post-bootstrap replay-derived authority (seed+2, DC-EPOCH-17) is the… |
| DC-EPOCH-23 | enforced | Bootstrap reward-update fee-buffer authority (CE-3d). The one-shot bootstrap reward update applied at the seed->seed+1 boundary carries the certified … |
| DC-EPOCH-25 | declared | Self-contained frozen leadership authority (S4-pre). Cardano's leadership PoolDistr (nesPd) -- the per-pool (active_stake, vrf_keyhash) that decides t… |
| DC-EPOCH-26 | enforced | Settled rewind target. The epoch accumulator is NEVER rewound to a point within k of the durable tip: every rewind target is beyond the reach of an ad… |
| DC-EPOCH-27 | enforced | Lineage-bound rewind. A settled rewind target whose header hash no longer resolves canonically at its slot -- a point the chain has ABANDONED -- is RE… |
| DC-EPOCH-32 | enforced | Boundary seal reads a POSITIONED checkpoint. The boundary mark and the reduced-checkpoint commitment sealed into a frozen-leadership object are captur… |
| DC-EPOCH-33 | enforced | Refold re-seal identity. Re-deriving an epoch boundary the node has already crossed re-seals a frozen-leadership object byte-identical to the one the … |
| DC-EPOCH-35 | enforced | A bounded settled rewind survives the recovery pass that follows a durable rollback. After the ChainDb rollback COMMITS -- never before -- the settled… |
| DC-EPOCH-37 | enforced | Authoritative epoch semantics must be proven PER VENUE, not inferred from a mainnet-shaped corpus. Every venue in the closed node-side registry (`nati… |
| DC-EPOCH-38 | enforced | The Praos candidate-freeze / nonce surface must be proven across SEED-POSITION x VENUE, not once per venue. `eta0(N+1)` is committed from the candidat… |
| DC-EPOCH-39 | enforced | A stall's CAUSE is typed, and only a real epoch transition may enter boundary machinery. Advancing the durable accumulator over one block yields exact… |
| DC-EPOCH-40 | partial | Leadership sigma denominator authority (SLICE LV-1). The leader-check sigma denominator is the SNAPSHOT's total active stake -- cardano's `pdTotalActi… |
| DC-EVIDENCE-01 | enforced | Operator-pass live evidence: the C5 live operator pass against the local docker cardano-node-preprod peer produces a JSONL transcript containing AT LE… |
| DC-EVIDENCE-02 | enforced | Adversarial false-accept rejection across 4 mandatory mutation classes: 1. Body byte flip preserving envelope shape 2. Header body-hash mismatch … |
| DC-EVIDENCE-04 | enforced | Closed fork-choice convergence evidence (PHASE4-N-AO S9; promotes the live SELECT proof from stderr diagnostics to registry-grade evidence). The live … |
| DC-EVIDENCE-05 | enforced | Replayable post-switch branch-continuity verdict (PHASE4-N-AO S10). After a ForkChoiceWin adoption at tip X, a GREEN pure reducer derive_post_switch_c… |
| DC-EVIEW-09 | enforced | The manifest-bound bootstrap cert-state import (S3f-2 prerequisite). The seed (SeedEpochConsensusInputs, the compact per-POOL active epoch consensus v… |
| DC-EVIEW-11 | enforced | The deterministic, fail-closed epoch-rebind seam (S3f-3), strengthening DC-EPOCH-03. DC-EPOCH-03 fails the forge closed past the seed-epoch boundary (… |
| DC-EVIEW-12 | enforced | The leadership-complete, self-contained EpochConsensusView (ECA-0b). The candidate view is the production authority for cross-epoch leadership: every … |
| DC-FOLLOW-FORGE-01 | enforced | Participant forge-decision mechanics. The keyed Participant venue uses an initial-catch-up -> extend forge mode mirroring the single-producer two-stat… |
| DC-FORGE-01 | enforced | Given the same canonical input set (slot, eta0, vrf_vk, vrf_proof_or_output, LeaderScheduleAnswer), verify_and_evaluate_leader produces a byte-identic… |
| DC-LEDGER-PHASE2-03 | enforced | A phase-2-invalid transaction contributes its consumed collateral and NOTHING else. For a tx in the block's invalid_transactions set the accumulator a… |
| DC-LIVEMEM-01 | enforced | Live-feed bounded memory (operational-hardening; NOT BLUE consensus law). Peer-driven memory on the live --mode node feed is bounded BEFORE authoritat… |
| DC-MEM-06 | partial | The UTxO/ledger state fingerprint is computed by the canonical CBOR encoder over canonically-encoded (fixed-width big-endian) keys, NEVER from a stora… |
| DC-MEM-11 | enforced | The network forward-sync / forge per-block admit MUST derive the WAL post_fp from the CACHED UTxO-component fingerprint (ForwardSyncState.utxo_fp_cach… |
| DC-MITHRIL-07 | enforced | The live `--mode node` FirstRun arm INVOKES the native Mithril bootstrap path (DC-MITHRIL-03 / S1b) from live snapshot files -- it routes the verified… |
| DC-MITHRIL-08 | enforced | The native Mithril FirstRun is BOUNDARY-COMPLETE: when the decoded cert-state carries delegations (the EVIEW package), native_first_run_bootstrap buil… |
| DC-NODE-04 | enforced | Authority-fatal halt + shutdown-resume identity: authoritative errors (chain_write failure on a committed rollback, SnapshotDecodeError::UnknownVersio… |
| DC-NODE-05 | enforced | Forge-slot discipline on the --mode node relay run-loop. A forge is attempted at most once per SlotNo and never for a slot <= the last forged slot (no… |
| DC-NODE-06 | enforced | Self-accept -> serve handoff on the --mode node relay spine (sibling serve task, shape B). Only a BLUE self-accepted forged artifact may enter the sib… |
| DC-NODE-07 | enforced | Node-spine live serve-to-peer. --mode node serves real peers ONLY from the G-B self-accepted ServedChainView (the read side of the single ServedChainH… |
| DC-NODE-08 | enforced | --mode node MAY forge the genesis-successor (FIRST) block from the recovered authoritative base when ChainDb::tip() AND the recovered tip (recovered.t… |
| DC-NODE-09 | enforced | Once --mode node has spawned a --listen serve task (run_node_serve_task) over a ServedChainView, the end of the upstream feed (the relay loop returnin… |
| DC-NODE-10 | enforced | After the feed validation/admission advances the node spine (a block ingested -> state.receive evolved), the next forge MUST derive the successor head… |
| DC-NODE-11 | enforced | Once --mode node has self-accepted and SERVED a genesis-successor block at block_no 0, it MUST NOT add/replace the served view (ServedChainView) with … |
| DC-NODE-12 | enforced | Own-forged durable admit chokepoint. A self-accepted forged block may become part of the durable chain ONLY by being submitted to the same durable adm… |
| DC-NODE-13 | enforced | Served view is a durable-chain projection. The ChainView served to followers (ChainSync header advertisement + BlockFetch body) is a deterministic PRO… |
| DC-NODE-14 | enforced | Every claimed forge parent must be servable or peer-intersectable in the durable served lineage. A --mode node forge may only build on a parent a Hask… |
| DC-NODE-15 | enforced | Forge admissibility requires the durable servable tip to equal the followed peer tip. A --mode node forge is admissible ONLY when durable_servable_tip… |
| DC-NODE-17 | declared | followed_peer_tip advances ONLY from a real observed peer ChainSync advertisement of the peer's selected tip, INCLUDING the self-adoption echo case wh… |
| DC-NODE-18 | enforced | Successor extension after an explicit adoption certificate (single-producer, single successor). After initial peer catch-up against a real peer tip (D… |
| DC-NODE-19 | declared | Single-producer forge-loop continuation after follow-link EOF. In an explicitly declared single-producer venue (VenueRole::SingleProducer) that has AL… |
| DC-NODE-20 | enforced | Local selected durable chain forge-base authority (rung-1 single-producer). In a declared rung-1 single-producer venue, after Ade self-admits a valid … |
| DC-NODE-21 | enforced | Adoption certificate is rung-1 evidence-only, never forge authority. The file-based operator adoption certificate is a rung-1 RED EVIDENCE-ONLY shim. … |
| DC-NODE-22 | enforced | Single-producer warm-start re-entry derives forge mode from the recovered local durable spine. In a declared rung-1 single-producer venue, if warm-sta… |
| DC-NODE-23 | enforced | Shared receive-side fork-choice detector (rung-2). A peer-origin candidate that is NOT already known as part of Ade's admitted durable spine / own-ser… |
| DC-NODE-24 | enforced | Venue-split fork-choice resolver (rung-2). The DC-NODE-23 detector's non-spine consequent is gated by venue and TOTAL over the closed venue set: Venue… |
| DC-NODE-25 | enforced | Live fork-choice durable application authority (rung-2). A ChainSelected / RolledBack outcome from the chain_selector orchestrator is applied to the d… |
| DC-NODE-26 | enforced | Decision / durable reconciliation (rung-2). After any applied receive decision, the chain_selector orchestrator's selector.current_tip EQUALS the dura… |
| DC-NODE-28 | enforced | No forge across unresolved re-selection (rung-2). Once a peer-origin candidate is classified NeedsForkChoice (DC-NODE-23) in a Participant venue, forg… |
| DC-NODE-29 | enforced | Live rollback target canonical binding (rung-2; AI-S6 H-1 remediation). For a peer RollBackward(point) on the live Participant path, the rollback targ… |
| DC-NODE-30 | enforced | Participant-path convergence evidence emission (PHASE4-N-AJ). The live `--mode node --participant-venue` rollback-follow path emits the existing close… |
| DC-NODE-31 | enforced | Recovered-anchor live-follow start authority (PHASE4-N-AK). After recovery from a non-Origin bootstrap anchor, the recovered store PERSISTS the bootst… |
| DC-NODE-32 | enforced | Recovered-anchor rollback boundary on the single-producer live-follow path (PHASE4-N-AK AK-S2). After recovery to a bare bootstrap anchor, the single-… |
| DC-NODE-33 | enforced | Participant-path recovered-anchor rollback boundary (PHASE4-N-AL) -- the participant MIRROR of DC-NODE-32. On the participant live-follow path (run_pa… |
| DC-NODE-34 | enforced | Peer-identity restoration (PHASE4-N-AO, SELECT foundation). The live receive path preserves the origin peer identity end-to-end: AdmissionPeerEvent (p… |
| DC-NODE-35 | enforced | BLUE-safe candidate construction (PHASE4-N-AO). A CandidateFragment fed to the BLUE fork-choice authority select_best_chain (DC-CONS-03) MUST be deriv… |
| DC-NODE-36 | enforced | Live single-selector dispatch (PHASE4-N-AO). The live participant NeedsForkChoice arm (today fail-closed in run_participant_sync, node_lifecycle.rs) r… |
| DC-NODE-37 | enforced | Fork-switch never-abandon (PHASE4-N-AO, SELECT primary invariant; the H-1 class at fork-choice scale). When select_best_chain picks a winner that fork… |
| DC-NODE-38 | enforced | Live multi-block fork-anchor discovery (PHASE4-N-AO S7; the live-geometry gap CE-AO-6 surfaced). A live competing branch is eligible for SELECT only w… |
| DC-NODE-39 | enforced | Post-ForkChoiceWin forward-follow continuity (PHASE4-N-AO S11). After a ForkChoiceWin adoption at tip X, Ade must continue receiving and admitting the… |
| DC-NODE-40 | enforced | Rolled-back branch evidence retention for the LCA walk (PHASE4-N-AO S13). Rolled-back blocks MAY be retained only as walk-visible EVIDENCE for future … |
| DC-NODE-41 | enforced | Missing-bridge range re-fetch for winner-descendant recovery (PHASE4-N-AO S14). When a post-ForkChoiceWin WINNING peer (the peer Ade just adopted from… |
| DC-NODE-42 | enforced | LIVE-FORGE-HARDENING S1 within-epoch forge-path rollback guard (INV-FH-4). On the --mode node forge / live-follow path (run_node_sync), a peer RollBac… |
| DC-NODE-43 | declared | Gap-free resume of a reconnected live feed. A reconnected per-peer session resumes chain-sync from the last block actually DELIVERED downstream, never… |
| DC-NODE-44 | enforced | A warm-start replay divergence (T-REC-05) must be SELF-DESCRIBING: the typed fault carries a `ReplayDivergenceReport` alongside the two fingerprints, … |
| DC-NODE-45 | enforced | ONE bootstrap-bound wall-clock -> absolute-slot authority on the authoritative --mode node producer path. (a) SOLE AUTHORITY: the forge derives its sl… |
| DC-NODE-46 | enforced | Every ADMITTED ForgeTick yields either a structured refusal or a leader-schedule decision. No admitted tick may disappear, and none may report a reaso… |
| DC-NODE-47 | partial | Followed-peer-tip possession evidence (SLICE B12). The forge-admissibility signal (FollowedPeerTipSignal) reports the STRONGEST available evidence tha… |
| DC-PROD-01 | enforced | Producer-mode evidence log emits a closed `ProducerLogEvent` vocabulary: handshake_ok, slot_tick, leader_elected, block_forged, block_served, peer_cha… |
| DC-PUMP-04 | enforced | Multi-peer wire-pump fairness (PHASE4-N-AO S8; the gap the S7 live retry surfaced). When multiple peers are connected to the participant receive path,… |
| DC-PUMP-08 | enforced | Reconnect policy is transport-only and TOTAL. should_reconnect_after is the single named authority classifying the wire pump's closed outcome sum: TRA… |
| DC-PUMP-09 | enforced | No bootstrap spin. Reconnect applies ONLY to a session that was established and then lost. An unparseable --peer, or a FIRST dial that fails, keeps th… |
| DC-PUMP-10 | enforced | Deterministic, bounded reconnect backoff. Re-dial pacing follows a fixed const escalating schedule (RECONNECT_BACKOFF_SECS) that is monotone non-decre… |
| DC-SYNC-02 | enforced | Continuous relay sync: every loop iteration preserves durable-before-advance (DC-SYNC-01) and advances the tip ONLY through run_node_sync -> pump_bloc… |
| DC-VIEW-01 | enforced | LiveLedgerView determinism + epoch-window guard. The view is constructed deterministically from LiveConsensusInputsCanonical. Two guards on every Led… |
| DC-WAL-04 | enforced | Forged-block WAL chain integrity. A forged AdmitBlock WAL entry's prior_fp MUST equal the current durable post_fp (the BootstrapAnchor's initial_ledge… |
| DC-WAL-05 | enforced | Received/followed-block durable-admit is BYTES-FIRST. The live admission runner (run_admission) MUST persist an admitted block's preserved ORIGINAL by… |
| OP-MEM-01 | partial | Mempool pressure and peer churn must not starve block validation, chain selection, or persistence (scheduling priority) |
| OP-MEM-02 | enforced | Ade's owned resident memory (Private_Dirty/RssAnon) under a representative venue stays clearly below the reference Haskell cardano-node's on the same … |
| OP-OPS-04 | enforced | Operator-supplied keys. Ade supports both KES key flows: (a) Ade-native `ade_node --mode key_gen_kes --out-file PATH` emitting an `ade.kes.seed.v1` en… |
| RO-LIVE-01 | partial | A Haskell cardano-node peer issuing RequestRange covering an Ade-forged block receives, via the producer-side block-fetch server, bytes that pass that… |
| RO-LIVE-04 | enforced | Live wire-smoke pass: operator runs `ade_node --mode wire_only --peer ADDR --network NAME` against a private cardano-node peer. The binary opens TCP, … |
| RO-LIVE-05 | enforced | Live admission-agreement pass: operator runs `ade_node` against a private cardano-node peer with admission enabled (bootstrap loads a real initial led… |
| RO-LIVE-06 | enforced | BA-02 peer-acceptance evidence closure (SCHEMA + CORRELATION MECHANICS ONLY). The BA-02 evidence surface is a closed, versioned manifest (Ba02Manifest… |
| T-REC-03 | enforced | Loop-as-replay: the same recovered/bootstrapped state + the same ordered canonical block feed (NodeBlockSource) + the same deterministic loop inputs +… |
| T-REC-05 | enforced | Replay/recovery equivalence including forged admits. Same BootstrapAnchor + same WAL (including forged AdmitBlock entries) -> byte-identical recovered… |
| T-REC-06 | enforced | Rollback-materialization replay-equivalence (PHASE4-N-AN). A block that validates during live admit (against the eta0-overlaid chain_dep, T-REC-04) MU… |