Modules / ade_runtime

ade_runtime

RED
RED crate
Purpose

The imperative shell — moves bytes, owns sockets/files/clocks/keys, drives tokio tasks. Hosts: producer-mode key custody; the N2N network drivers; the node orchestrator runners; the receive/rollback/admission shells; the streaming seed-import importer; the WAL/consensus-inputs importers; ChainDB + recovery shells; the durable-chain serve projection; the pump_block hash-exact idempotency gate (the sole durable admit); the recovered-anchor surface; the dormant redb UTxO anchor + the FINGERPRINT_VERSION=2 open-check. The reduced-window + epoch-accumulator durable orchestration: chaindb::reduced_window_driver (RED orchestration over the GREEN reduced_utxo_checkpoint) + the GREEN chaindb::transient_epoch_view, plus NEW chaindb::{epoch_accumulator_store, epoch_accumulator_advance} — the durable persistence + forward-fold walk that advances the BLUE EpochAccumulator over (last_advanced, tip] and crosses boundaries from the durable reduced checkpoint materialized at the EXACT boundary point (DC-EPOCH-20/22). Native Mithril: mithril_native_assembly (the RED authority transition — the PURE assemble_native_mithril_seed + bootstrap_from_native_mithril_snapshot routing through the single closed mithril_bootstrap::bootstrap_from_mithril_snapshot → bootstrap_initial_state + sidecar + recovered-anchor + WAL commit). The BLUE core, the serve projection, and pump_block are reused byte-unchanged.

Interprets

Canonicalizes peer bytes/files for the BLUE core: key loaders; genesis_parser::parse_shelley_genesis (parses securityParam → k); seed_import::import_cardano_cli_json_utxo (STREAMING); admission::*; bootstrap::restore_seed_epoch_consensus_inputs; recovered_anchor::load_recovered_anchor_point; the dormant redb anchor + the FINGERPRINT_VERSION open-check. Reduced-window + epoch-accumulator: reduced_window_driver::drive_window_aggregate applies each block's reduced_block_delta (== reduce(track_utxo)) into the durable checkpoint + advances cert/delegation state via process_block_certificates; epoch_accumulator_advance::{advance_accumulator_over_chaindb, cross_accumulator_over_boundary_block} folds apply_selected_block over the durable selected-chain prefix and crosses each boundary from the durable reduced checkpoint at the exact boundary point (idempotent AlreadyCrossed at/before the last-crossed tip). Native Mithril: assemble_native_mithril_seed interprets the verified manifest + S1a state + Stage-2 tables UTxO + genesis constants into the COMPLETE authoritative seed, point-coherence as a TERMINAL gate.

MUST NOT

(1) Modify BLUE state directly or construct semantic types from raw bytes. (2) Bypass canonical validation. (3) producer::signing RED-confined custody (+ kes_sign_header_advancing evolve-before-sign). (4)–(8) producer / outbound / serve / listener / projection / keep-alive fences. (9, DC-SYNC-01/DC-NODE-16) forward_sync::pump_block — refuse to advance the tip before StoreBlockBytes + AppendWal; HASH-keyed already-have skip; the SOLE durable admit. (9b–9d) seed_import streaming-fingerprint + the dormant redb anchor pure-storage discipline + the FINGERPRINT_VERSION fail-closed open-check. (9e, DC-EVIEW-04/DC-EPOCH-11) chaindb::reduced_utxo_checkpoint stays a GREEN durable CACHE (reconstructible by replay, NEVER authority, NEVER on the live follow/forge path); reduced_window_driver clones the LedgerState per window call (NEVER the hot path) and MUST reuse reduced_block_delta + process_block_certificates, never a parallel reimplementation. (9f, DC-EPOCH-20/22) NEW — the epoch-accumulator durable advance: epoch_accumulator_advance MUST advance the FOUR derived authorities (ChainDB/WAL block record, Praos chain-dep state, EpochAccumulator transition, reduced checkpoint) from the SAME selected-chain prefix atomically-or-rematerialized — NO resumed split authority; the live epoch-boundary stake mark MUST be captured ONLY from the durable reduced checkpoint materialized at the EXACT boundary point (the last durable block of the closing epoch), never at a later catch-up tip and never via a per-block stake scan; it MUST reuse the BLUE apply_selected_block (never a parallel non-UTxO transition). (9g, DC-MITHRIL-03/07) mithril_native_assembly sources each field from its single declared source, admits NO cardano-cli / JSON / operator seed / convenience fallback, enforces point coherence as a terminal gate, and routes persistence through the single closed mithril_bootstrap::bootstrap_from_mithril_snapshot → bootstrap_initial_state composition (no bootable partial authority on an interrupted import). (10)–(22) mithril_import / genesis_bootstrap / recovery::restart / bootstrap / chaindb recovered-anchor / clock / consensus_inputs / rollback-preservation fences.

Inbound deps

ade_node, ade_core_interop, ade_testkit (dev/integration).

Outbound deps

ade_types, ade_core, ade_crypto, ade_codec, ade_ledger (reduced_*, the native-Mithril decoders, epoch_accumulator::*, frozen_leadership::*, bootstrap_bridge::*, bootstrap_reward_update::*, delegation::*, seed_consensus_inputs::*, rollback/anchor deps), ade_network, redb, serde, serde_json, bech32, base58, cardano-crypto, ed25519-dalek, tokio (dev-deps: tokio ["test-util"], tempfile, ade_testkit).

Entry points

ade_runtime::producer::*, ade_runtime::admission::*, ade_runtime::network::*, ade_runtime::orchestrator::*, ade_runtime::bootstrap::*, ade_runtime::recovered_anchor::*, ade_runtime::seed_consensus_merge::*, ade_runtime::consensus_inputs::{*, cert_state_extract::*, canonical::*}, ade_runtime::seed_import::*, ade_runtime::{forward_sync (incl. pump::pump_block), mithril_import, mithril_bootstrap, genesis_bootstrap, recovery::restart, clock, wal, bootstrap_anchor}::*, ade_runtime::mithril_native_assembly::{assemble_native_mithril_seed, bootstrap_from_native_mithril_snapshot}, ade_runtime::chaindb::{ChainDb, get_block_by_hash, iter_from_slot, reduced_utxo_checkpoint::*, reduced_window_driver::*, transient_epoch_view::*, epoch_accumulator_store::*, epoch_accumulator_advance::{advance_accumulator_over_chaindb, cross_accumulator_over_boundary_block}}.

Key modules

producer/, network/, orchestrator/, admission/, receive/, rollback/, seed_import/, consensus_inputs/ (cert_state_extract.rs, canonical.rs, importer.rs — S2 security_param, protocol_params.rs), wal/, chaindb/ (redb schema; bounded serve primitives; utxo_anchor.rs/utxo_key.rs; reduced_utxo_checkpoint.rs; reduced_window_driver.rs; transient_epoch_view.rs; epoch_accumulator_store.rs + epoch_accumulator_advance.rs — NEW), forward_sync/ (pump.rs), mithril_import/, mithril_native_assembly.rs, seed_consensus_merge.rs, mithril_bootstrap.rs, genesis_bootstrap.rs, recovery/, bootstrap.rs, recovered_anchor.rs, clock.rs, consensus/ (chain_selector.rs, genesis_parser.rs).

Creates (RED-only)

KesSecret, VrfSigningKey, ColdSigningKey custody wrappers; KeyLoadError; MuxTransportHandle consumers; OutboundCommand (closed); DispatchError (closed); ServerPeerStates; ProducerShell; AdmissionPeerEvent (closed); AdmissionWirePumpError (closed); KEEP_ALIVE_CADENCE; SystemClock / DeterministicClock; LiveConsensusInputsCanonical (now carries security_param — S2); BootstrapState; BootstrapError; ChainDbServedSource<'a>; CappedSlotRange; MAX_SERVE_RANGE_BLOCKS = 256; UtxoFingerprint; JsonSeedError (closed); ChainDbError::FingerprintVersionMismatch. Reduced-window + epoch-accumulator (RED, NOT canonical-counted): chaindb::reduced_window_driver::{WindowDriverError, CheckpointAdvanceError} + chaindb::epoch_accumulator_store::* (the durable leadership-schema-versioned accumulator store) + chaindb::epoch_accumulator_advance::* (advance_accumulator_over_chaindb, cross_accumulator_over_boundary_block) + the GREEN reduced_utxo_checkpoint / transient_epoch_view. Native Mithril (RED, NOT canonical-counted): mithril_native_assembly::{VerifiedManifestBinding, NativeGenesisConstants (now carries security_param), NativeMithrilSeed, MithrilNativeAssemblyError (closed), NativeMithrilBootstrapError (closed)}; consensus_inputs::cert_state_extract::CertExtractError (closed).

Depends on

—

Depended on by

—

Sub-trees — 4 GREEN-by-content

consensus_inputs::{cert_state_extract, protocol_params, canonical}

Pure cardano-cli JSON → BLUE CertState / ProtocolParameters (era-aware MinUtxoRule); canonical_from_raw the single import funnel (S2: requires security_param, fail-closed MissingField).

MUST NOT:

Silently default a malformed/missing field; use a float path; collapse the era-faithful MinUtxoRule distinction.

ci_check_native_nonutxo_decode.sh, ci_check_recovered_ledger_pparams_sourced.sh

forward_sync::reducer , `producer::{coordinator, chain_evolution, self_accepted_handoff}`, `clock`, `orchestrator::{mod,event,state,core}`, `rollback::{cadence,…}`, `seed_import`, `consensus_inputs`, `admission::`

Carried GREEN reducers/planners over BLUE (forward-sync lifecycle, producer coordinator, linear chain-evolution typestate, deterministic clock, orchestrator core, snapshot cadence, streaming seed-import, operator consensus-inputs importer, admission verdict/agreement reducer).

MUST NOT:

Emit AdvanceTip before durability; own signing material; mint AcceptedBlock; advance on disagreement; read wall-clock; open event vocabulary; order-dependent fingerprint; emit RED verdicts; treat lagging as success.

ci_check_forward_sync_chokepoint_only.sh, ci_check_forward_sync_fp_cache.sh, ci_check_producer_coordinator_no_secrets.sh, ci_check_prevhash_single_wire_authority.sh, ci_check_clock_seam.sh, ci_check_orchestrator_core_purity.sh, ci_check_snapshot_cadence_purity.sh, ci_check_seed_import_closure.sh, ci_check_mem_opt_s2_import_peak.sh, ci_check_live_consensus_inputs_closure.sh, ci_check_admission_runner_closure.sh

mithril_native_assembly::assemble_native_mithril_seed `DC-MITHRIL-03`

The PURE assembly half of the native Mithril authority transition — maps each seed field from its single declared source (verified manifest + S1a non-UTxO state + Stage-2 tables UTxO + genesis constants), enforces point coherence as a TERMINAL gate.

MUST NOT:

Source any field from anything but its single declared source; admit a cardano-cli / JSON / operator seed / convenience fallback; assemble on a point/epoch/network/era mismatch.

ci_check_mithril_authority_transition.sh

seed_consensus_merge

Pure mapping (BTreeMap only) lifting a verified-bootstrap LiveConsensusInputsCanonical + minted anchor fp + seed epoch into the BLUE SeedEpochConsensusInputs (now carries security_param — S2).

MUST NOT:

Affect authoritative outputs; default-fill on a provenance gap (a pool in pool_distribution but absent from pool_vrf_keyhashes is a structured error, never a zero-hash fill); carry the recovered eta0 as anything but verbatim.

ci_check_seed_consensus_inputs_merge.sh

CI guards — 122

ScriptEnforces
ci_check_accumulator_refold_bound.sh DC-EPOCH-26, DC-EPOCH-27, DC-EPOCH-28, DC-EPOCH-29, DC-EPOCH-30, DC-EPOCH-31
ci_check_admission_no_red_verdicts.sh DC-PUMP-01
ci_check_admission_no_refscript_skip.sh CN-ADMIT-02, DC-ADMIT-09
ci_check_admission_wire_pump_closure.sh CN-PUMP-01, DC-ADMIT-12, DC-PUMP-01, DC-PUMP-02
ci_check_admitted_block_closure.sh CN-CONS-07, CN-CONS-08, CN-PROTO-07
ci_check_alloc_determinism_neutral.sh DC-MEM-06
ci_check_block_fetch_server_closure.sh DC-CONS-17, DC-PROTO-07
ci_check_bnd_typed_stall_cause.sh DC-EPOCH-39
ci_check_bootstrap_anchor_closure.sh CN-ANCHOR-01, DC-ANCHOR-01
ci_check_bootstrap_closure.sh CN-NODE-01
ci_check_bootstrap_rupd_window_end.sh

DC-EPOCH-18 (B3c)

ci_check_broadcast_to_served_purity.sh DC-CONS-17, DC-CONS-18, DC-PROTO-07
ci_check_chain_sync_server_closure.sh DC-PROTO-07, DC-PROTO-08
ci_check_chaindb_contract.sh CN-STORE-04, CN-STORE-05, DC-STORE-02, DC-STORE-03
ci_check_chaindb_crash_safety.sh CN-STORE-03, DC-STORE-01, T-REC-01
ci_check_clock_seam.sh DC-NODE-03, DC-SESS-05
ci_check_collateral_balance_resolver.sh DC-LEDGER-PHASE2-02, DC-LEDGER-PHASE2-03
ci_check_collateral_retention_positioning.sh DC-LEDGER-PHASE2-04
ci_check_consensus_closed_enums.sh CN-CONS-02, DC-CONS-03, DC-CONS-04, DC-CONS-05, DC-CONS-06, DC-CONS-09, DC-CONS-10, DC-CONSENSUS-01, DC-MEM-01, DC-MEM-02, DC-TXV-01, DC-TXV-02, DC-TXV-03, DC-TXV-04, DC-TXV-05, DC-VAL-01, DC-VAL-02, DC-VAL-03, DC-VAL-04, DC-VAL-05, DC-VAL-06, T-DET-01
ci_check_consensus_input_provenance.sh CN-CINPUT-02, CN-CINPUT-03, DC-CINPUT-02b
ci_check_conway_deposit_params_bootstrap.sh

DC-CINPUT-07 (band 9)

ci_check_eview_leadership_complete.sh DC-EPOCH-12, DC-EVIEW-05, DC-EVIEW-07, DC-EVIEW-12
ci_check_eview_pool_lifecycle.sh DC-EVIEW-13
ci_check_eview_reduced_utxo_checkpoint.sh DC-EVIEW-04
ci_check_eview_refold_reseal.sh DC-EPOCH-32, DC-EPOCH-33
ci_check_eview_seed_sidecar_v4.sh DC-CINPUT-06
ci_check_eview_stake_aggregation.sh DC-EVIEW-05
ci_check_eview_window_driver.sh DC-EVIEW-10
ci_check_eview_windowed_advance.sh DC-EVIEW-04b
ci_check_feed_tag24_unwrap.sh CN-WIRE-12
ci_check_followed_peer_tip_served_evidence.sh DC-NODE-47
ci_check_forbidden_patterns.sh DC-LEDGER-08, T-CORE-01, T-CORE-02, T-DET-01
ci_check_forge_followed_tip_admission.sh DC-CONS-24, DC-NODE-14, DC-NODE-15, DC-NODE-20, DC-NODE-47
ci_check_forge_slot_authority.sh DC-NODE-45, DC-NODE-46
ci_check_forged_durable_admit_via_pump.sh DC-CONS-23, DC-NODE-12, DC-WAL-04
ci_check_forward_sync_chokepoint_only.sh DC-SYNC-01
ci_check_forward_sync_fp_cache.sh DC-MEM-11
ci_check_frozen_leadership_authority.sh

S4-pre

ci_check_frozen_promotion_no_seed_window.sh

S4-L2

ci_check_frozen_recovery_no_seed_window.sh

S4-L1

ci_check_genesis_consistency_fixture_present.sh CN-GENESIS-01, DC-NODE-05
ci_check_genesis_successor_reachability.sh CN-REHEARSAL-FIDELITY-01, DC-NODE-08
ci_check_keep_alive_wire_only.sh DC-PUMP-03
ci_check_kes_envelope_closed.sh DC-CRYPTO-06, DC-CRYPTO-07, OP-OPS-04
ci_check_kes_evolution_before_sign.sh DC-CRYPTO-10
ci_check_kes_sum_compatibility.sh DC-CRYPTO-04, DC-CRYPTO-05, DC-CRYPTO-07, DC-CRYPTO-08, DC-CRYPTO-09, OP-OPS-04
ci_check_ledger_determinism.sh DC-LEDGER-01, DC-LEDGER-02, T-DET-01
ci_check_ledgerdb_state_decode.sh DC-MITHRIL-04
ci_check_ledgerdb_tables_decode.sh DC-MITHRIL-05
ci_check_lifecycle_owner_uses_bootstrap_initial_state.sh DC-CINPUT-01
ci_check_live_consensus_inputs_closure.sh CN-CONS-IN-01, DC-CONS-IN-01
ci_check_live_consensus_inputs_fingerprint.sh CN-CONS-IN-01, DC-CONS-IN-02
ci_check_live_feed_memory_bounds.sh DC-LIVEMEM-01
ci_check_live_fork_choice_apply.sh DC-NODE-25, DC-NODE-26, DC-NODE-27
ci_check_live_fork_choice_wiring.sh DC-NODE-25, DC-NODE-28
ci_check_live_ledger_view_epoch_window.sh DC-ADMIT-10, DC-ADMIT-11, DC-VIEW-01
ci_check_live_operator_pass_scaffold.sh DC-EVIDENCE-01, RO-LIVE-05
ci_check_mem_opt_s2_import_peak.sh DC-MEM-06
ci_check_mithril_authority_transition.sh DC-MITHRIL-03
ci_check_mithril_documented_evidence.sh RO-MITHRIL-IMPORT-01
ci_check_mithril_seed_point_independence.sh CN-MITHRIL-01, DC-MITHRIL-02, RO-MITHRIL-IMPORT-01
ci_check_mithril_uses_bootstrap_initial_state.sh CN-MITHRIL-01, DC-GENESIS-SRC-01, DC-MITHRIL-01, RO-MITHRIL-IMPORT-01
ci_check_n2n_server_no_signing_dep.sh CN-PROD-01
ci_check_no_async_in_blue.sh DC-CORE-01
ci_check_no_chaindb_in_consensus_blue.sh DC-CONS-03, DC-CONS-05, DC-CONS-07, DC-CONSENSUS-01
ci_check_no_density_in_fork_choice.sh CN-CONS-01, CN-CONS-02, CN-CONS-03, CN-CONS-05, DC-CONS-03, DC-CONSENSUS-01, T-CONS-01
ci_check_no_float_in_consensus.sh CN-CONS-05, DC-CONS-03, DC-CONS-08, T-CORE-02
ci_check_no_parallel_header_splitter.sh CN-PROTO-06, DC-CONS-16, DC-CONS-18
ci_check_no_produce_mode_direct_transport_writes.sh CN-OUTBOUND-RELAY-01
ci_check_no_producer_body_encoder.sh DC-CONS-16
ci_check_node_forge_real_cli_ingress.sh CN-GENESIS-01, CN-OPCERT-01
ci_check_node_mode_closure.sh CN-NODE-01
ci_check_node_path_fidelity.sh CN-REHEARSAL-FIDELITY-01, DC-NODE-21
ci_check_node_run_loop_containment.sh CN-NODE-02, CN-NODE-03, DC-NODE-05, DC-NODE-06, DC-NODE-12, DC-SYNC-02, T-REC-03
ci_check_node_sync_via_pump.sh DC-SYNC-01, DC-SYNC-02
ci_check_orchestrator_core_purity.sh DC-NODE-03
ci_check_peer_session_isolation.sh DC-NODE-01
ci_check_persistent_writer_no_parallel_cadence.sh DC-NODE-02
ci_check_post_switch_convergence_window.sh DC-EVIDENCE-05
ci_check_praos_nonce_follow_evolution.sh

DC-EPOCH-16 (ECA-B1/B2)

ci_check_prevhash_single_wire_authority.sh CN-WIRE-09
ci_check_private_key_custody.sh DC-CRYPTO-03, DC-CRYPTO-04, DC-CRYPTO-05, DC-CRYPTO-08, OP-OPS-04
ci_check_produce_mode_uses_bootstrap_initial_state.sh CN-NODE-01, CN-PROD-02, CN-PROD-03
ci_check_producer_coordinator_no_secrets.sh CN-FORGE-01, CN-PROD-02
ci_check_producer_corpus_present.sh CN-CONS-06
ci_check_receive_idempotency.sh DC-NODE-16
ci_check_receive_orchestrator_no_producer_dep.sh DC-CONS-20
ci_check_receive_paths_corpus_present.sh RO-LIVE-02
ci_check_receive_reducer_closure.sh CN-CONS-07, CN-CONS-08, DC-CONS-13, DC-CONS-16, DC-CONS-19, DC-CONS-20, DC-PROTO-09
ci_check_receive_replay_purity.sh DC-PROTO-09
ci_check_recovered_anchor_intersectable.sh DC-NODE-14
ci_check_recovery_contract.sh DC-STORE-05, T-REC-01, T-REC-02
ci_check_rehearsal_manifest_schema.sh CN-REHEARSAL-FIDELITY-01
ci_check_rollback_materialize_closure.sh CN-STORE-07, DC-CONS-20, DC-CONS-22
ci_check_rollback_target_canonical_binding.sh DC-NODE-29
ci_check_scheduler_closure.sh OP-OPS-05
ci_check_seed_import_closure.sh CN-SEED-01, DC-SEED-01
ci_check_seed_import_full_preprod_support.sh CN-SEED-01, DC-SEED-01
ci_check_self_accept_gate.sh CN-CONS-07
ci_check_serve_listener_magic_aware.sh DC-NODE-07
ci_check_serve_range_bounded.sh DC-SERVEMEM-01
ci_check_served_chain_closure.sh CN-CONS-07
ci_check_served_chain_handoff_fence.sh DC-NODE-06
ci_check_served_chain_projection.sh DC-NODE-06, DC-NODE-11, DC-NODE-13
ci_check_server_paths_corpus_present.sh RO-LIVE-01
ci_check_session_no_unbounded.sh DC-SESS-04
ci_check_settled_rewind_survives_recovery.sh DC-EPOCH-35
ci_check_settled_triple_integrity.sh DC-EPOCH-34
ci_check_single_serve_dispatch_authority.sh DC-NODE-07
ci_check_snapshot_cadence_purity.sh DC-STORE-07
ci_check_snapshot_encoder_closure.sh CN-STORE-08, DC-CONS-21, DC-STORE-08, DC-STORE-09
ci_check_snapshot_pool_set_inclusion.sh

DC-EPOCH-24 (CE-3d)

ci_check_store_semantics_gate.sh DC-STORE-10, DC-STORE-11
ci_check_tables_to_utxostate.sh DC-MITHRIL-06
ci_check_transient_view_memory_ceiling.sh DC-EVIEW-01
ci_check_transient_view_no_fallback.sh DC-EVIEW-01
ci_check_transient_view_not_live.sh DC-EVIEW-01
ci_check_unsigned_header_preimage_single_source.sh CN-KES-HEADER-01, DC-CONS-18
ci_check_utxo_fp_v2.sh DC-MEM-10
ci_check_wal_append_only.sh CN-WAL-01, DC-ADMIT-05, DC-WAL-01
ci_check_warmstart_eta0_overlay.sh

ECA-B (band 7)

ci_check_wire_liveness.sh DC-PUMP-05, DC-PUMP-06, DC-PUMP-07, DC-PUMP-08, DC-PUMP-09, DC-PUMP-10

Related invariants — 140

IDStatusStatement
CN-ANCHOR-01 enforced Single BootstrapAnchor mint authority: exactly one pub fn in ade_runtime::bootstrap_anchor::mint produces a BootstrapAnchor with all 6 fields populate…
CN-CINPUT-02 enforced The SeedEpochConsensusInputs sidecar MUST be populated ONLY through the single shared ade_runtime::seed_epoch_lineage::persist_seed_epoch_consensus_in…
CN-CONS-06 enforced Cross-impl acceptance: blocks forged by Ade are accepted by cardano-node when delivered via N2N block-fetch / chain-sync. Evidence is operator-action:…
CN-CONS-07 enforced Self-acceptance bridge + serve provenance. A forged block is NOT eligible for RED broadcast unless Ade's own header validator (PHASE4-N-B path) and bo…
CN-CONS-IN-01 enforced Single LiveConsensusInputs importer authority: exactly one pub fn ade_runtime::consensus_inputs::importer::import_live_consensus_inputs converts a car…
CN-GENESIS-01 enforced The Shelley genesis closed-contract parser accepts a real cardano-cli `shelley-genesis.json` and produces a canonical `GenesisAnchor`. Required fields…
CN-KES-HEADER-01 enforced The KES signature in a forged block's header is over the canonical unsigned-header CBOR pre-image — the CBOR encoding of ShelleyHeaderBody (the first …
CN-MITHRIL-01 enforced A Mithril-sourced seed may bootstrap only after a verified binding: the Mithril manifest's attested {network_magic, genesis_hash, certified_point, cer…
CN-NODE-01 enforced Single bootstrap authority: exactly one pub fn in ade_runtime::bootstrap returns the initial (LedgerState, PraosChainDepState, ChainDb tip) at node st…
CN-OPCERT-01 enforced The opcert envelope parser accepts a real cardano-cli `node.opcert` text envelope (closed type check `NodeOperationalCertificate` + CBOR array(2) shap…
CN-OUTBOUND-RELAY-01 enforced OutboundCommand is the sole channel between produce_mode and MuxPump's outbound encoder. The closed enum carries typed ChainSyncServerMsg / BlockFetch…
CN-PEER-OUTBOUND-MAP-01 enforced Per-peer outbound senders are owned by an Arc<RwLock<BTreeMap<PeerId, mpsc::Sender<OutboundCommand>>>>. Listener (run_per_peer_session) inserts on Pee…
CN-PROD-01 enforced Producer-mode listener completes the N2N handshake (CN-SESS-02) on every accepted inbound connection before any mini-protocol traffic is exchanged. Pr…
CN-PROD-02 enforced Producer slot loop never signs a block whose KES period has rotated past current_period. Slot → KES period is a pure function of (slot, genesis_kes_an…
CN-PROD-03 enforced produce_mode's forge base state is derived from bootstrap_initial_state (cold-start, fed the operator-seeded ledger from --json-seed + --consensus-inp…
CN-PROD-04 enforced Every CoordinatorEffect::BroadcastBlock reconstructs the AcceptedBlock from artifact.bytes through the BLUE self_accept authority against the pre-forg…
CN-PUMP-01 enforced Single admission wire-pump entry per peer: exactly one pub async fn ade_runtime::admission::wire_pump::run_admission_wire_pump drives the per-peer pum…
CN-REHEARSAL-FIDELITY-01 enforced Private-testnet accepted-block bounty dry-run fidelity (two coupled clauses; if either fails the rehearsal becomes misleading). (1) PATH FIDELITY: the…
CN-SEED-01 enforced Single JSON seed-importer authority: exactly one pub fn in ade_runtime::seed_import::import_cardano_cli_json_utxo converts a cardano-cli `query utxo -…
CN-STORE-03 enforced Crash recovery must produce the same authoritative state as clean replay over the accepted canonical inputs
CN-STORE-04 enforced Checkpoints must be atomic: fully committed and valid, or absent
CN-STORE-05 enforced Finalized provenance must be append-only, auditable, and replay-derivable
CN-WAL-01 enforced Single WAL append authority: WalStore::append is the SOLE mutation method on any WalStore impl. No truncate/rewrite/replace method exists on the trait…
CN-WIRE-09 enforced The Shelley-and-later header_body `prev_hash` field is the closed wire grammar `$hash32 / null` (cardano-ledger PrevHash = GenesisHash | BlockHash). A…
CN-WIRE-12 enforced Ade's FEED/receive-side BlockFetch path MUST remove the protocol tag-24 wrapper using the SINGLE ade_codec unwrap authority (decompose_blockfetch_bloc…
DC-ADMIT-09 enforced Admission code paths do not add partial reference-script support, permissive ref-script skipping, or any seed-import fallback. N-M-A's fail-fast on Js…
DC-CINPUT-01 enforced WARM-START VERIFICATION CAPABILITY (authority surface — NOT production restart). The seed-epoch consensus-input import is a canonical, replay-reconstr…
DC-CINPUT-03 enforced The producer Praos VRF leader/header input is `praos_vrf_input(slot, eta0)` = `blake2b256(slot_be8 ‖ eta0_32)` (= cardano `mkInputVRF`), where eta0 is…
DC-CINPUT-05 enforced Venue epoch geometry is DURABLE REPLAY AUTHORITY. A recovered store MUST replay using the epoch geometry (epoch_start_slot + epoch_length_slots) persi…
DC-CINPUT-06 enforced The durable consensus PROFILE includes genesis_hash + protocol_params_hash, persisted canonically in the v4 SeedEpochConsensusInputs sidecar and recov…
DC-CINPUT-07 declared Conway deposit-parameter bootstrap authority. The Conway-only deposit params (drep_deposit / gov_action_deposit / drep_activity) are DECODED from the …
DC-CONS-03 enforced Praos chain selection ordering: block number first, then Praos TiebreakerView (slot, issuer, op-cert issue number, VRF output). Density-based ordering…
DC-CONS-07 enforced BLUE consensus must consume the HFC schedule only as a typed EraSchedule value anchored to BootstrapAnchorHash. Genesis text parsing happens in RED; B…
DC-CONS-16 enforced Forged header.body_hash MUST equal blake2b_256(forged_body_wire_bytes), where forged_body_wire_bytes are produced by the single Cardano-compatible can…
DC-CONS-17 enforced Block bytes delivered via producer-side block-fetch Block{bytes} are byte-identical to AcceptedBlock.as_bytes() for the AcceptedBlock that cleared sel…
DC-CONS-18 enforced Header bytes announced via chain-sync RollForward{header,tip} are the header sub-segment of the AcceptedBlock whose body bytes are subsequently servab…
DC-CONS-20 enforced ChainDb-ledger-chain_dep lockstep: a successful receive-side admission updates ChainDb, LedgerState, and PraosChainDepState as one structural transiti…
DC-CONS-21 enforced Snapshot encode/decode round-trip equivalence: for any reachable (LedgerState, PraosChainDepState), decode(encode(state)) yields a state whose ade_led…
DC-CONS-IN-01 enforced Closed importer error sum: Io | Json | BadField | MissingField | BadHashHex | BadEpochWindow | BadPoolDistribution | EraNotSupported. No Option field …
DC-CONS-IN-02 enforced Canonical fingerprint: LiveConsensusInputsCanonical.fingerprint is Blake2b-256 over a canonical CBOR encoding of every field in declared order. Same J…
DC-CONSENSUS-01 enforced Chain selection is deterministic and matches Haskell node behavior
DC-CORE-01 enforced BLUE authoritative crates are sync-only: no async fn, .await, tokio::, async_std::, Future, futures::, task spawning, async channels, or timers. Async…
DC-CRYPTO-03 enforced VRF signing transcript equivalence and verification symmetry. For canonical inputs (slot, epoch_nonce, vrf_signing_key, vrf_role) the RED signer produ…
DC-CRYPTO-04 enforced KES signing transcript equivalence and verification symmetry. For canonical inputs (kes_secret, period, msg) the RED signer produces a KesSignature by…
DC-CRYPTO-05 enforced KES evolution discipline: evolve(k_i) -> k_{i+1} is one-way. The evolved key signs period i+1 and MUST NOT sign for period i. RED kes_sign is forbidde…
DC-CRYPTO-06 enforced Ade-native KES envelope is the sole accepted hot-signing-key envelope format. Closed grammar `ade.kes.seed.v1`: load-bearing fields {`format`, `role`,…
DC-CRYPTO-07 enforced cardano-cli's `KesSigningKey_ed25519_kes_2^6` envelope (the upstream `Sum6KES` expanded-tree serialization, 608 bytes for a fresh key) is loadable via…
DC-CRYPTO-10 enforced The RED signing shell must evolve the operator KES signing key to the requested KES period before signing, using the existing deterministic Sum6KES up…
DC-EPOCH-16 enforced Rolling Praos chain-dep nonce evolution on the live follow path. Each validated followed header drives ONE indivisible BLUE nonce transition over {slo…
DC-EPOCH-18 enforced Window-end bootstrap reward update for the seed+2 leadership authority. The first post-bootstrap replay-derived authority (seed+2, DC-EPOCH-17) is the…
DC-EPOCH-24 enforced Snapshot pool-set inclusion = cardano's ssActiveStake NonZero membership (CE-3d). The per-epoch stake snapshot (mark/set/go) INCLUDES a registered+del…
DC-EPOCH-25 declared Self-contained frozen leadership authority (S4-pre). Cardano's leadership PoolDistr (nesPd) -- the per-pool (active_stake, vrf_keyhash) that decides t…
DC-EPOCH-26 enforced Settled rewind target. The epoch accumulator is NEVER rewound to a point within k of the durable tip: every rewind target is beyond the reach of an ad…
DC-EPOCH-28 enforced Leadership coherence across a rewind. A rewind restores CURRENT_LEADERSHIP_BY_EPOCH to exactly the epochs valid at the rewind point, so no sealed lead…
DC-EPOCH-29 enforced Uncertified after rewind. A rewind clears LAST_ADVANCED_POINT and drops the pending boundary-mark binding, so the store is UNCERTIFIED until a canonic…
DC-EPOCH-30 enforced Bounded post-rollback refold. Post-rollback re-derivation is bounded by ~2k and is INDEPENDENT OF NODE UPTIME. The settled rewind point is never more …
DC-EPOCH-31 enforced Rewind replay equivalence. Refolding from the settled rewind point yields state byte-identical to folding straight through from the bootstrap baseline…
DC-EPOCH-32 enforced Boundary seal reads a POSITIONED checkpoint. The boundary mark and the reduced-checkpoint commitment sealed into a frozen-leadership object are captur…
DC-EPOCH-34 enforced Settled-triple integrity. The settled rewind triple (accumulator blob + settled point + settled leadership) is bound by a domain-separated, length-pre…
DC-EPOCH-35 enforced A bounded settled rewind survives the recovery pass that follows a durable rollback. After the ChainDb rollback COMMITS -- never before -- the settled…
DC-EPOCH-39 enforced A stall's CAUSE is typed, and only a real epoch transition may enter boundary machinery. Advancing the durable accumulator over one block yields exact…
DC-EVIDENCE-01 enforced Operator-pass live evidence: the C5 live operator pass against the local docker cardano-node-preprod peer produces a JSONL transcript containing AT LE…
DC-EVIDENCE-05 enforced Replayable post-switch branch-continuity verdict (PHASE4-N-AO S10). After a ForkChoiceWin adoption at tip X, a GREEN pure reducer derive_post_switch_c…
DC-EVIEW-01 enforced Transient epoch-view replay storage is GREEN / non-authoritative substrate. A bounded, disk-backed, TRANSIENT redb store (TransientEpochViewStore) may…
DC-EVIEW-04 enforced The durable reduced-UTxO checkpoint -- the "minimal native state" (S3b Option B). A disk-backed redb store of TxIn -> (Coin, ReducedStakeRef), built f…
DC-EVIEW-04b enforced The windowed advance (S3b-2): advance the durable reduced-UTxO checkpoint (DC-EVIEW-04) per epoch boundary by replaying the epoch's admitted blocks, a…
DC-EVIEW-05 enforced Per-pool stake aggregation (S3c, the linchpin). aggregate_pool_stake computes the next-epoch per-pool active stake from the single ledger authority's …
DC-EVIEW-10 enforced The window driver (S3f-2): advance the reduced UTxO checkpoint + the cert/delegation state forward over a window of ordered blocks, then aggregate per…
DC-EVIEW-13 enforced Cardano-faithful pool lifecycle in the reduced window (ECA-0a). The cert-state pool lifecycle matches cardano-ledger (Pool.hs/PoolReap.hs/Epoch.hs/Sna…
DC-GENESIS-01 enforced Given the same canonical Shelley genesis JSON bytes + the same operator-supplied kes_anchor_slot, parse_shelley_genesis produces a byte-identical Gene…
DC-GENESIS-SRC-01 enforced A controlled genesis enters initial state ONLY through the single closed bootstrap_initial_state authority (genesis_initial); the genesis->initial-sta…
DC-LEDGER-PHASE2-02 enforced The accumulator consumes a RESOLVED SCALAR; it does not own a UTxO. The ADA a phase-2-invalid transaction consumes is collAdaBalance = sum(value(colla…
DC-LEDGER-PHASE2-03 enforced A phase-2-invalid transaction contributes its consumed collateral and NOTHING else. For a tx in the block's invalid_transactions set the accumulator a…
DC-LEDGER-PHASE2-04 enforced The UTxO authority RETAINS what it destroys on another reader's behalf. A collateral value is authoritative only within [create(x), B), where B is the…
DC-LIVEMEM-01 enforced Live-feed bounded memory (operational-hardening; NOT BLUE consensus law). Peer-driven memory on the live --mode node feed is bounded BEFORE authoritat…
DC-MEM-06 partial The UTxO/ledger state fingerprint is computed by the canonical CBOR encoder over canonically-encoded (fixed-width big-endian) keys, NEVER from a stora…
DC-MEM-10 enforced The v2 UTxO fingerprint component is a NAMED commutative set commitment (Ristretto255 ECMH) binding (TxIn, TxOut) over the canonical encodings, domain…
DC-MEM-11 enforced The network forward-sync / forge per-block admit MUST derive the WAL post_fp from the CACHED UTxO-component fingerprint (ForwardSyncState.utxo_fp_cach…
DC-MITHRIL-02 enforced For Mithril bootstrap, the BootstrapAnchor seed_point MUST be derived from the operator-provided independent seed-point extraction inputs, not from th…
DC-MITHRIL-03 enforced The native Mithril AUTHORITY TRANSITION assembles the COMPLETE authoritative seed (LedgerState + PraosChainDepState + a NATIVE LiveConsensusInputsCano…
DC-MITHRIL-04 enforced Native V2 LedgerDB `state` decode is faithful, fail-closed, and non-emitting. The cardano-node V2 (utxohd-mem, tablesCodecVersion 1) LedgerDB `state` …
DC-MITHRIL-05 enforced Faithful Word64 multi-asset quantity on the snapshot-import path. The native V2 LedgerDB `tables` MemPack TxOut decode keeps every multi-asset quantit…
DC-MITHRIL-06 enforced The Stage-2 `tables` (MemPack-decoded TxOuts) materialize into Ade's authoritative `UTxOState` with hash-critical bytes PRESERVED and full Word64 quan…
DC-NODE-01 enforced Per-peer session isolation: one peer session's failure (decode error, validity reject, rollback-too-deep, protocol violation) halts only that peer's s…
DC-NODE-02 enforced Persistent-writer cadence fidelity: the orchestrator's persistent-snapshot writer calls PersistentSnapshotCache::capture only on the schedule emitted …
DC-NODE-03 enforced Clock-injection seam + replay equivalence: the orchestrator depends on a Clock trait yielding now() and tick_stream(). No SystemTime::now() or tokio::…
DC-NODE-06 enforced Self-accept -> serve handoff on the --mode node relay spine (sibling serve task, shape B). Only a BLUE self-accepted forged artifact may enter the sib…
DC-NODE-07 enforced Node-spine live serve-to-peer. --mode node serves real peers ONLY from the G-B self-accepted ServedChainView (the read side of the single ServedChainH…
DC-NODE-11 enforced Once --mode node has self-accepted and SERVED a genesis-successor block at block_no 0, it MUST NOT add/replace the served view (ServedChainView) with …
DC-NODE-12 enforced Own-forged durable admit chokepoint. A self-accepted forged block may become part of the durable chain ONLY by being submitted to the same durable adm…
DC-NODE-13 enforced Served view is a durable-chain projection. The ChainView served to followers (ChainSync header advertisement + BlockFetch body) is a deterministic PRO…
DC-NODE-14 enforced Every claimed forge parent must be servable or peer-intersectable in the durable served lineage. A --mode node forge may only build on a parent a Hask…
DC-NODE-16 enforced Receive idempotency: a peer-delivered block already durably present byte-identically in the ChainDb (same slot, same hash) is an idempotent no-op at t…
DC-NODE-25 enforced Live fork-choice durable application authority (rung-2). A ChainSelected / RolledBack outcome from the chain_selector orchestrator is applied to the d…
DC-NODE-29 enforced Live rollback target canonical binding (rung-2; AI-S6 H-1 remediation). For a peer RollBackward(point) on the live Participant path, the rollback targ…
DC-NODE-31 enforced Recovered-anchor live-follow start authority (PHASE4-N-AK). After recovery from a non-Origin bootstrap anchor, the recovered store PERSISTS the bootst…
DC-NODE-32 enforced Recovered-anchor rollback boundary on the single-producer live-follow path (PHASE4-N-AK AK-S2). After recovery to a bare bootstrap anchor, the single-…
DC-NODE-33 enforced Participant-path recovered-anchor rollback boundary (PHASE4-N-AL) -- the participant MIRROR of DC-NODE-32. On the participant live-follow path (run_pa…
DC-NODE-45 enforced ONE bootstrap-bound wall-clock -> absolute-slot authority on the authoritative --mode node producer path. (a) SOLE AUTHORITY: the forge derives its sl…
DC-NODE-46 enforced Every ADMITTED ForgeTick yields either a structured refusal or a leader-schedule decision. No admitted tick may disappear, and none may report a reaso…
DC-NODE-47 partial Followed-peer-tip possession evidence (SLICE B12). The forge-admissibility signal (FollowedPeerTipSignal) reports the STRONGEST available evidence tha…
DC-OPCERT-01 enforced Given the same canonical envelope bytes, parse_opcert_envelope produces a byte-identical DecodedOpCertEnvelope across runs. Replay-equivalence anchor …
DC-OUTBOUND-FIFO-01 enforced The per-peer outbound channel preserves FIFO order: OutboundCommands enqueued for PeerId(p) in order O₁..Oₙ arrive at the peer's TCP socket in the sam…
DC-PROD-01 enforced Producer-mode evidence log emits a closed `ProducerLogEvent` vocabulary: handshake_ok, slot_tick, leader_elected, block_forged, block_served, peer_cha…
DC-PROD-02 enforced Coordinator slot-tick + forge-result stream replay-equivalence. For a fixed initial CoordinatorState, fixed canonical slot-tick sequence, fixed ledger…
DC-PROD-03 enforced Producer chain-forward continuity + replay. The GREEN ChainEvolution linear typestate threads each forge's post-state (post-ledger, post-chain_dep, ne…
DC-PROTO-07 enforced Given canonical inputs (negotiated_version, peer_message_sequence, broadcast_arrival_sequence, session_event_sequence), the producer-side chain-sync /…
DC-PROTO-09 enforced Receive-side transcript determinism: given canonical inputs (initial_ledger, initial_chain_dep, initial_chaindb, event_sequence), the bridge reducer's…
DC-PUMP-01 enforced Wire pump emits AdmissionPeerEvent::{Block, TipUpdate, Disconnected} only. It MUST NOT synthesize AgreementVerdict values or any validity claim. The v…
DC-PUMP-02 enforced A CLOSED authority event is emitted on every chain-sync reply carrying a Tip: TipUpdate for IntersectFound / IntersectNotFound / RollForward; the DIST…
DC-PUMP-03 enforced Wire-pump keep-alive client (PHASE4-N-AM). The admission wire pump (run_admission_wire_pump -- the SOLE per-peer pump, CN-PUMP-01) runs the N2N keep-a…
DC-PUMP-05 enforced Cooperative keep-alive liveness under downstream backpressure. No stall of the downstream consumer -- of ANY duration or cause (block application, epo…
DC-PUMP-06 enforced Ordered pump progression under backpressure. The sequence of AdmissionPeerEvents delivered to events_out is identical to the unstalled pump for the sa…
DC-PUMP-07 enforced Bounded deferral, fail closed. Peer frames held while the pump waits for downstream capacity are bounded by the fixed, closed, non-configurable MAX_DE…
DC-SEED-01 enforced Canonical UtxoFingerprint determinism: the imported UTxOState uses BTreeMap<TxIn, TxOut> iteration order; UtxoFingerprint is Blake2b-256 over canonica…
DC-SERVEMEM-01 enforced Peer-driven serve range work is bounded. The --mode node serve path must not materialize an unbounded chain range, perform per-block full-index scans,…
DC-SESS-04 enforced Backpressure discipline: every per-peer + per-mini-protocol channel is bounded; queue overflow is fail-fast `TransportError::BackpressureExceeded` rat…
DC-SESS-05 enforced Wire-layer clock injection: the session reducer + dispatch table contain no SystemTime / Instant::now / tokio::time reads. Keep-alive is driven by the…
DC-SNAPSHOT-01 enforced ServedChainHandle::push_atomic is deterministic in its argument order: the same sequence of push_atomic(a₀), push_atomic(a₁), ..., push_atomic(aₙ) pro…
DC-STORE-01 enforced Recovery from power-loss produces replay-equivalent state
DC-STORE-02 enforced Append-only provenance for finalized data
DC-STORE-03 enforced Atomic snapshots (fully written or absent)
DC-STORE-05 enforced Recovery is snapshot + forward replay (not full genesis replay): load most recent valid snapshot, replay forward from ImmutableDB tip
DC-STORE-07 enforced Snapshot cadence determinism: the decision to take a snapshot at slot S is a pure function of (slot, block_no, cadence_params, last_snapshot). Same ca…
DC-STORE-10 enforced Replay equivalence requires the persisted authority store and the binary to agree on the MEANING of the bytes, not merely on their layout. Every durab…
DC-STORE-11 enforced The semantics marker is PER-ARTIFACT, and every authority artifact must agree with the binary independently. `chain.db` (with the WAL written in locks…
DC-SYNC-01 enforced During network forward-sync, a block's preserved wire bytes and its WAL entry MUST be durable before the chain tip advances to it, and admission is ch…
DC-VIEW-01 enforced LiveLedgerView determinism + epoch-window guard. The view is constructed deterministically from LiveConsensusInputsCanonical. Two guards on every Led…
DC-WAL-03 enforced Anchor + WAL replay-equivalence: replaying (BootstrapAnchor + WAL entries 1..N) against (initial_ledger from import + per-entry block bytes) produces …
OP-OPS-04 enforced Operator-supplied keys. Ade supports both KES key flows: (a) Ade-native `ade_node --mode key_gen_kes --out-file PATH` emitting an `ade.kes.seed.v1` en…
OP-OPS-05 enforced Slot-deadline forging SLA. Forge + self-accept + N2N hand-off must complete within the slot's deadline (1s on mainnet, smaller on testnets). Operation…
RO-LIVE-01 partial A Haskell cardano-node peer issuing RequestRange covering an Ade-forged block receives, via the producer-side block-fetch server, bytes that pass that…
RO-LIVE-02 partial A cardano-node peer's RollForward + BlockDelivered stream, consumed by the receive bridge, produces a ChainDb tip equal to the peer's announced tip at…
RO-LIVE-05 enforced Live admission-agreement pass: operator runs `ade_node` against a private cardano-node peer with admission enabled (bootstrap loads a real initial led…
RO-MITHRIL-IMPORT-01 enforced Ade imports a Mithril-authenticated snapshot as an alternative to the cardano-cli JSON seed. Provides cryptographic provenance for the seed artifact (…
T-DET-01 enforced Same canonical inputs -> same authoritative bytes (per Byte Authority Model)
T-REC-01 enforced Recovery is replay-equivalent: restart produces byte-identical state to clean run
T-REC-02 enforced All authoritative state derivable by replay from inputs
T-REC-04 enforced The WarmStart-recovered forge `chain_dep.epoch_nonce` (eta0) MUST come from the imported/recovered consensus input, never from a snapshot placeholder …
T-REC-05 enforced Replay/recovery equivalence including forged admits. Same BootstrapAnchor + same WAL (including forged AdmitBlock entries) -> byte-identical recovered…