ade_runtime
RED- Purpose
The imperative shell — moves bytes, owns sockets/files/clocks/keys, drives tokio tasks. Hosts: producer-mode key custody; the N2N network drivers; the node orchestrator runners; the receive/rollback/admission shells; the streaming seed-import importer; the WAL/consensus-inputs importers; ChainDB + recovery shells; the durable-chain serve projection; the
pump_blockhash-exact idempotency gate (the sole durable admit); the recovered-anchor surface; the dormant redb UTxO anchor + theFINGERPRINT_VERSION=2open-check. The reduced-window + epoch-accumulator durable orchestration:chaindb::reduced_window_driver(RED orchestration over the GREENreduced_utxo_checkpoint) + the GREENchaindb::transient_epoch_view, plus NEWchaindb::{epoch_accumulator_store, epoch_accumulator_advance}— the durable persistence + forward-fold walk that advances the BLUEEpochAccumulatorover(last_advanced, tip]and crosses boundaries from the durable reduced checkpoint materialized at the EXACT boundary point (DC-EPOCH-20/22). Native Mithril:mithril_native_assembly(the RED authority transition — the PUREassemble_native_mithril_seed+bootstrap_from_native_mithril_snapshotrouting through the single closedmithril_bootstrap::bootstrap_from_mithril_snapshot→bootstrap_initial_state+ sidecar + recovered-anchor + WAL commit). The BLUE core, the serve projection, andpump_blockare reused byte-unchanged.- Interprets
Canonicalizes peer bytes/files for the BLUE core: key loaders;
genesis_parser::parse_shelley_genesis(parsessecurityParam→ k);seed_import::import_cardano_cli_json_utxo(STREAMING);admission::*;bootstrap::restore_seed_epoch_consensus_inputs;recovered_anchor::load_recovered_anchor_point; the dormant redb anchor + theFINGERPRINT_VERSIONopen-check. Reduced-window + epoch-accumulator:reduced_window_driver::drive_window_aggregateapplies each block'sreduced_block_delta(==reduce(track_utxo)) into the durable checkpoint + advances cert/delegation state viaprocess_block_certificates;epoch_accumulator_advance::{advance_accumulator_over_chaindb, cross_accumulator_over_boundary_block}foldsapply_selected_blockover the durable selected-chain prefix and crosses each boundary from the durable reduced checkpoint at the exact boundary point (idempotentAlreadyCrossedat/before the last-crossed tip). Native Mithril:assemble_native_mithril_seedinterprets the verified manifest + S1a state + Stage-2 tables UTxO + genesis constants into the COMPLETE authoritative seed, point-coherence as a TERMINAL gate.- MUST NOT
(1) Modify BLUE state directly or construct semantic types from raw bytes. (2) Bypass canonical validation. (3)
producer::signingRED-confined custody (+kes_sign_header_advancingevolve-before-sign). (4)–(8) producer / outbound / serve / listener / projection / keep-alive fences. (9,DC-SYNC-01/DC-NODE-16)forward_sync::pump_block— refuse to advance the tip beforeStoreBlockBytes+AppendWal; HASH-keyed already-have skip; the SOLE durable admit. (9b–9d)seed_importstreaming-fingerprint + the dormant redb anchor pure-storage discipline + theFINGERPRINT_VERSIONfail-closed open-check. (9e,DC-EVIEW-04/DC-EPOCH-11)chaindb::reduced_utxo_checkpointstays a GREEN durable CACHE (reconstructible by replay, NEVER authority, NEVER on the live follow/forge path);reduced_window_driverclones theLedgerStateper window call (NEVER the hot path) and MUST reusereduced_block_delta+process_block_certificates, never a parallel reimplementation. (9f,DC-EPOCH-20/22) NEW — the epoch-accumulator durable advance:epoch_accumulator_advanceMUST advance the FOUR derived authorities (ChainDB/WAL block record, Praos chain-dep state,EpochAccumulatortransition, reduced checkpoint) from the SAME selected-chain prefix atomically-or-rematerialized — NO resumed split authority; the live epoch-boundary stake mark MUST be captured ONLY from the durable reduced checkpoint materialized at the EXACT boundary point (the last durable block of the closing epoch), never at a later catch-up tip and never via a per-block stake scan; it MUST reuse the BLUEapply_selected_block(never a parallel non-UTxO transition). (9g,DC-MITHRIL-03/07)mithril_native_assemblysources each field from its single declared source, admits NO cardano-cli / JSON / operator seed / convenience fallback, enforces point coherence as a terminal gate, and routes persistence through the single closedmithril_bootstrap::bootstrap_from_mithril_snapshot→bootstrap_initial_statecomposition (no bootable partial authority on an interrupted import). (10)–(22)mithril_import/genesis_bootstrap/recovery::restart/bootstrap/chaindbrecovered-anchor / clock / consensus_inputs / rollback-preservation fences.- Inbound deps
ade_node,ade_core_interop,ade_testkit(dev/integration).- Outbound deps
ade_types,ade_core,ade_crypto,ade_codec,ade_ledger(reduced_*, the native-Mithril decoders,epoch_accumulator::*,frozen_leadership::*,bootstrap_bridge::*,bootstrap_reward_update::*,delegation::*,seed_consensus_inputs::*, rollback/anchor deps),ade_network,redb,serde,serde_json,bech32,base58,cardano-crypto,ed25519-dalek,tokio(dev-deps:tokio["test-util"],tempfile,ade_testkit).- Entry points
ade_runtime::producer::*,ade_runtime::admission::*,ade_runtime::network::*,ade_runtime::orchestrator::*,ade_runtime::bootstrap::*,ade_runtime::recovered_anchor::*,ade_runtime::seed_consensus_merge::*,ade_runtime::consensus_inputs::{*, cert_state_extract::*, canonical::*},ade_runtime::seed_import::*,ade_runtime::{forward_sync (incl. pump::pump_block), mithril_import, mithril_bootstrap, genesis_bootstrap, recovery::restart, clock, wal, bootstrap_anchor}::*,ade_runtime::mithril_native_assembly::{assemble_native_mithril_seed, bootstrap_from_native_mithril_snapshot},ade_runtime::chaindb::{ChainDb, get_block_by_hash, iter_from_slot, reduced_utxo_checkpoint::*, reduced_window_driver::*, transient_epoch_view::*, epoch_accumulator_store::*, epoch_accumulator_advance::{advance_accumulator_over_chaindb, cross_accumulator_over_boundary_block}}.- Key modules
producer/,network/,orchestrator/,admission/,receive/,rollback/,seed_import/,consensus_inputs/(cert_state_extract.rs,canonical.rs,importer.rs— S2security_param,protocol_params.rs),wal/,chaindb/(redb schema; bounded serve primitives;utxo_anchor.rs/utxo_key.rs;reduced_utxo_checkpoint.rs;reduced_window_driver.rs;transient_epoch_view.rs;epoch_accumulator_store.rs+epoch_accumulator_advance.rs— NEW),forward_sync/(pump.rs),mithril_import/,mithril_native_assembly.rs,seed_consensus_merge.rs,mithril_bootstrap.rs,genesis_bootstrap.rs,recovery/,bootstrap.rs,recovered_anchor.rs,clock.rs,consensus/(chain_selector.rs,genesis_parser.rs).- Creates (RED-only)
KesSecret,VrfSigningKey,ColdSigningKeycustody wrappers;KeyLoadError;MuxTransportHandleconsumers;OutboundCommand(closed);DispatchError(closed);ServerPeerStates;ProducerShell;AdmissionPeerEvent(closed);AdmissionWirePumpError(closed);KEEP_ALIVE_CADENCE;SystemClock/DeterministicClock;LiveConsensusInputsCanonical(now carriessecurity_param— S2);BootstrapState;BootstrapError;ChainDbServedSource<'a>;CappedSlotRange;MAX_SERVE_RANGE_BLOCKS = 256;UtxoFingerprint;JsonSeedError(closed);ChainDbError::FingerprintVersionMismatch. Reduced-window + epoch-accumulator (RED, NOT canonical-counted):chaindb::reduced_window_driver::{WindowDriverError, CheckpointAdvanceError}+chaindb::epoch_accumulator_store::*(the durable leadership-schema-versioned accumulator store) +chaindb::epoch_accumulator_advance::*(advance_accumulator_over_chaindb,cross_accumulator_over_boundary_block) + the GREENreduced_utxo_checkpoint/transient_epoch_view. Native Mithril (RED, NOT canonical-counted):mithril_native_assembly::{VerifiedManifestBinding, NativeGenesisConstants (now carriessecurity_param), NativeMithrilSeed, MithrilNativeAssemblyError (closed), NativeMithrilBootstrapError (closed)};consensus_inputs::cert_state_extract::CertExtractError (closed).
Depends on
—
Depended on by
—
Sub-trees — 4 GREEN-by-content
Pure cardano-cli JSON → BLUE CertState / ProtocolParameters (era-aware MinUtxoRule); canonical_from_raw the single import funnel (S2: requires security_param, fail-closed MissingField).
Silently default a malformed/missing field; use a float path; collapse the era-faithful MinUtxoRule distinction.
ci_check_native_nonutxo_decode.sh, ci_check_recovered_ledger_pparams_sourced.sh
Carried GREEN reducers/planners over BLUE (forward-sync lifecycle, producer coordinator, linear chain-evolution typestate, deterministic clock, orchestrator core, snapshot cadence, streaming seed-import, operator consensus-inputs importer, admission verdict/agreement reducer).
Emit AdvanceTip before durability; own signing material; mint AcceptedBlock; advance on disagreement; read wall-clock; open event vocabulary; order-dependent fingerprint; emit RED verdicts; treat lagging as success.
ci_check_forward_sync_chokepoint_only.sh, ci_check_forward_sync_fp_cache.sh, ci_check_producer_coordinator_no_secrets.sh, ci_check_prevhash_single_wire_authority.sh, ci_check_clock_seam.sh, ci_check_orchestrator_core_purity.sh, ci_check_snapshot_cadence_purity.sh, ci_check_seed_import_closure.sh, ci_check_mem_opt_s2_import_peak.sh, ci_check_live_consensus_inputs_closure.sh, ci_check_admission_runner_closure.sh
The PURE assembly half of the native Mithril authority transition — maps each seed field from its single declared source (verified manifest + S1a non-UTxO state + Stage-2 tables UTxO + genesis constants), enforces point coherence as a TERMINAL gate.
Source any field from anything but its single declared source; admit a cardano-cli / JSON / operator seed / convenience fallback; assemble on a point/epoch/network/era mismatch.
ci_check_mithril_authority_transition.sh
Pure mapping (BTreeMap only) lifting a verified-bootstrap LiveConsensusInputsCanonical + minted anchor fp + seed epoch into the BLUE SeedEpochConsensusInputs (now carries security_param — S2).
Affect authoritative outputs; default-fill on a provenance gap (a pool in pool_distribution but absent from pool_vrf_keyhashes is a structured error, never a zero-hash fill); carry the recovered eta0 as anything but verbatim.
ci_check_seed_consensus_inputs_merge.sh
CI guards — 122
| Script | Enforces |
|---|---|
| ci_check_accumulator_refold_bound.sh | DC-EPOCH-26, DC-EPOCH-27, DC-EPOCH-28, DC-EPOCH-29, DC-EPOCH-30, DC-EPOCH-31 |
| ci_check_admission_no_red_verdicts.sh | DC-PUMP-01 |
| ci_check_admission_no_refscript_skip.sh | CN-ADMIT-02, DC-ADMIT-09 |
| ci_check_admission_wire_pump_closure.sh | CN-PUMP-01, DC-ADMIT-12, DC-PUMP-01, DC-PUMP-02 |
| ci_check_admitted_block_closure.sh | CN-CONS-07, CN-CONS-08, CN-PROTO-07 |
| ci_check_alloc_determinism_neutral.sh | DC-MEM-06 |
| ci_check_block_fetch_server_closure.sh | DC-CONS-17, DC-PROTO-07 |
| ci_check_bnd_typed_stall_cause.sh | DC-EPOCH-39 |
| ci_check_bootstrap_anchor_closure.sh | CN-ANCHOR-01, DC-ANCHOR-01 |
| ci_check_bootstrap_closure.sh | CN-NODE-01 |
| ci_check_bootstrap_rupd_window_end.sh |
|
| ci_check_broadcast_to_served_purity.sh | DC-CONS-17, DC-CONS-18, DC-PROTO-07 |
| ci_check_chain_sync_server_closure.sh | DC-PROTO-07, DC-PROTO-08 |
| ci_check_chaindb_contract.sh | CN-STORE-04, CN-STORE-05, DC-STORE-02, DC-STORE-03 |
| ci_check_chaindb_crash_safety.sh | CN-STORE-03, DC-STORE-01, T-REC-01 |
| ci_check_clock_seam.sh | DC-NODE-03, DC-SESS-05 |
| ci_check_collateral_balance_resolver.sh | DC-LEDGER-PHASE2-02, DC-LEDGER-PHASE2-03 |
| ci_check_collateral_retention_positioning.sh | DC-LEDGER-PHASE2-04 |
| ci_check_consensus_closed_enums.sh | CN-CONS-02, DC-CONS-03, DC-CONS-04, DC-CONS-05, DC-CONS-06, DC-CONS-09, DC-CONS-10, DC-CONSENSUS-01, DC-MEM-01, DC-MEM-02, DC-TXV-01, DC-TXV-02, DC-TXV-03, DC-TXV-04, DC-TXV-05, DC-VAL-01, DC-VAL-02, DC-VAL-03, DC-VAL-04, DC-VAL-05, DC-VAL-06, T-DET-01 |
| ci_check_consensus_input_provenance.sh | CN-CINPUT-02, CN-CINPUT-03, DC-CINPUT-02b |
| ci_check_conway_deposit_params_bootstrap.sh |
|
| ci_check_eview_leadership_complete.sh | DC-EPOCH-12, DC-EVIEW-05, DC-EVIEW-07, DC-EVIEW-12 |
| ci_check_eview_pool_lifecycle.sh | DC-EVIEW-13 |
| ci_check_eview_reduced_utxo_checkpoint.sh | DC-EVIEW-04 |
| ci_check_eview_refold_reseal.sh | DC-EPOCH-32, DC-EPOCH-33 |
| ci_check_eview_seed_sidecar_v4.sh | DC-CINPUT-06 |
| ci_check_eview_stake_aggregation.sh | DC-EVIEW-05 |
| ci_check_eview_window_driver.sh | DC-EVIEW-10 |
| ci_check_eview_windowed_advance.sh | DC-EVIEW-04b |
| ci_check_feed_tag24_unwrap.sh | CN-WIRE-12 |
| ci_check_followed_peer_tip_served_evidence.sh | DC-NODE-47 |
| ci_check_forbidden_patterns.sh | DC-LEDGER-08, T-CORE-01, T-CORE-02, T-DET-01 |
| ci_check_forge_followed_tip_admission.sh | DC-CONS-24, DC-NODE-14, DC-NODE-15, DC-NODE-20, DC-NODE-47 |
| ci_check_forge_slot_authority.sh | DC-NODE-45, DC-NODE-46 |
| ci_check_forged_durable_admit_via_pump.sh | DC-CONS-23, DC-NODE-12, DC-WAL-04 |
| ci_check_forward_sync_chokepoint_only.sh | DC-SYNC-01 |
| ci_check_forward_sync_fp_cache.sh | DC-MEM-11 |
| ci_check_frozen_leadership_authority.sh | S4-pre |
| ci_check_frozen_promotion_no_seed_window.sh | S4-L2 |
| ci_check_frozen_recovery_no_seed_window.sh | S4-L1 |
| ci_check_genesis_consistency_fixture_present.sh | CN-GENESIS-01, DC-NODE-05 |
| ci_check_genesis_successor_reachability.sh | CN-REHEARSAL-FIDELITY-01, DC-NODE-08 |
| ci_check_keep_alive_wire_only.sh | DC-PUMP-03 |
| ci_check_kes_envelope_closed.sh | DC-CRYPTO-06, DC-CRYPTO-07, OP-OPS-04 |
| ci_check_kes_evolution_before_sign.sh | DC-CRYPTO-10 |
| ci_check_kes_sum_compatibility.sh | DC-CRYPTO-04, DC-CRYPTO-05, DC-CRYPTO-07, DC-CRYPTO-08, DC-CRYPTO-09, OP-OPS-04 |
| ci_check_ledger_determinism.sh | DC-LEDGER-01, DC-LEDGER-02, T-DET-01 |
| ci_check_ledgerdb_state_decode.sh | DC-MITHRIL-04 |
| ci_check_ledgerdb_tables_decode.sh | DC-MITHRIL-05 |
| ci_check_lifecycle_owner_uses_bootstrap_initial_state.sh | DC-CINPUT-01 |
| ci_check_live_consensus_inputs_closure.sh | CN-CONS-IN-01, DC-CONS-IN-01 |
| ci_check_live_consensus_inputs_fingerprint.sh | CN-CONS-IN-01, DC-CONS-IN-02 |
| ci_check_live_feed_memory_bounds.sh | DC-LIVEMEM-01 |
| ci_check_live_fork_choice_apply.sh | DC-NODE-25, DC-NODE-26, DC-NODE-27 |
| ci_check_live_fork_choice_wiring.sh | DC-NODE-25, DC-NODE-28 |
| ci_check_live_ledger_view_epoch_window.sh | DC-ADMIT-10, DC-ADMIT-11, DC-VIEW-01 |
| ci_check_live_operator_pass_scaffold.sh | DC-EVIDENCE-01, RO-LIVE-05 |
| ci_check_mem_opt_s2_import_peak.sh | DC-MEM-06 |
| ci_check_mithril_authority_transition.sh | DC-MITHRIL-03 |
| ci_check_mithril_documented_evidence.sh | RO-MITHRIL-IMPORT-01 |
| ci_check_mithril_seed_point_independence.sh | CN-MITHRIL-01, DC-MITHRIL-02, RO-MITHRIL-IMPORT-01 |
| ci_check_mithril_uses_bootstrap_initial_state.sh | CN-MITHRIL-01, DC-GENESIS-SRC-01, DC-MITHRIL-01, RO-MITHRIL-IMPORT-01 |
| ci_check_n2n_server_no_signing_dep.sh | CN-PROD-01 |
| ci_check_no_async_in_blue.sh | DC-CORE-01 |
| ci_check_no_chaindb_in_consensus_blue.sh | DC-CONS-03, DC-CONS-05, DC-CONS-07, DC-CONSENSUS-01 |
| ci_check_no_density_in_fork_choice.sh | CN-CONS-01, CN-CONS-02, CN-CONS-03, CN-CONS-05, DC-CONS-03, DC-CONSENSUS-01, T-CONS-01 |
| ci_check_no_float_in_consensus.sh | CN-CONS-05, DC-CONS-03, DC-CONS-08, T-CORE-02 |
| ci_check_no_parallel_header_splitter.sh | CN-PROTO-06, DC-CONS-16, DC-CONS-18 |
| ci_check_no_produce_mode_direct_transport_writes.sh | CN-OUTBOUND-RELAY-01 |
| ci_check_no_producer_body_encoder.sh | DC-CONS-16 |
| ci_check_node_forge_real_cli_ingress.sh | CN-GENESIS-01, CN-OPCERT-01 |
| ci_check_node_mode_closure.sh | CN-NODE-01 |
| ci_check_node_path_fidelity.sh | CN-REHEARSAL-FIDELITY-01, DC-NODE-21 |
| ci_check_node_run_loop_containment.sh | CN-NODE-02, CN-NODE-03, DC-NODE-05, DC-NODE-06, DC-NODE-12, DC-SYNC-02, T-REC-03 |
| ci_check_node_sync_via_pump.sh | DC-SYNC-01, DC-SYNC-02 |
| ci_check_orchestrator_core_purity.sh | DC-NODE-03 |
| ci_check_peer_session_isolation.sh | DC-NODE-01 |
| ci_check_persistent_writer_no_parallel_cadence.sh | DC-NODE-02 |
| ci_check_post_switch_convergence_window.sh | DC-EVIDENCE-05 |
| ci_check_praos_nonce_follow_evolution.sh |
|
| ci_check_prevhash_single_wire_authority.sh | CN-WIRE-09 |
| ci_check_private_key_custody.sh | DC-CRYPTO-03, DC-CRYPTO-04, DC-CRYPTO-05, DC-CRYPTO-08, OP-OPS-04 |
| ci_check_produce_mode_uses_bootstrap_initial_state.sh | CN-NODE-01, CN-PROD-02, CN-PROD-03 |
| ci_check_producer_coordinator_no_secrets.sh | CN-FORGE-01, CN-PROD-02 |
| ci_check_producer_corpus_present.sh | CN-CONS-06 |
| ci_check_receive_idempotency.sh | DC-NODE-16 |
| ci_check_receive_orchestrator_no_producer_dep.sh | DC-CONS-20 |
| ci_check_receive_paths_corpus_present.sh | RO-LIVE-02 |
| ci_check_receive_reducer_closure.sh | CN-CONS-07, CN-CONS-08, DC-CONS-13, DC-CONS-16, DC-CONS-19, DC-CONS-20, DC-PROTO-09 |
| ci_check_receive_replay_purity.sh | DC-PROTO-09 |
| ci_check_recovered_anchor_intersectable.sh | DC-NODE-14 |
| ci_check_recovery_contract.sh | DC-STORE-05, T-REC-01, T-REC-02 |
| ci_check_rehearsal_manifest_schema.sh | CN-REHEARSAL-FIDELITY-01 |
| ci_check_rollback_materialize_closure.sh | CN-STORE-07, DC-CONS-20, DC-CONS-22 |
| ci_check_rollback_target_canonical_binding.sh | DC-NODE-29 |
| ci_check_scheduler_closure.sh | OP-OPS-05 |
| ci_check_seed_import_closure.sh | CN-SEED-01, DC-SEED-01 |
| ci_check_seed_import_full_preprod_support.sh | CN-SEED-01, DC-SEED-01 |
| ci_check_self_accept_gate.sh | CN-CONS-07 |
| ci_check_serve_listener_magic_aware.sh | DC-NODE-07 |
| ci_check_serve_range_bounded.sh | DC-SERVEMEM-01 |
| ci_check_served_chain_closure.sh | CN-CONS-07 |
| ci_check_served_chain_handoff_fence.sh | DC-NODE-06 |
| ci_check_served_chain_projection.sh | DC-NODE-06, DC-NODE-11, DC-NODE-13 |
| ci_check_server_paths_corpus_present.sh | RO-LIVE-01 |
| ci_check_session_no_unbounded.sh | DC-SESS-04 |
| ci_check_settled_rewind_survives_recovery.sh | DC-EPOCH-35 |
| ci_check_settled_triple_integrity.sh | DC-EPOCH-34 |
| ci_check_single_serve_dispatch_authority.sh | DC-NODE-07 |
| ci_check_snapshot_cadence_purity.sh | DC-STORE-07 |
| ci_check_snapshot_encoder_closure.sh | CN-STORE-08, DC-CONS-21, DC-STORE-08, DC-STORE-09 |
| ci_check_snapshot_pool_set_inclusion.sh |
|
| ci_check_store_semantics_gate.sh | DC-STORE-10, DC-STORE-11 |
| ci_check_tables_to_utxostate.sh | DC-MITHRIL-06 |
| ci_check_transient_view_memory_ceiling.sh | DC-EVIEW-01 |
| ci_check_transient_view_no_fallback.sh | DC-EVIEW-01 |
| ci_check_transient_view_not_live.sh | DC-EVIEW-01 |
| ci_check_unsigned_header_preimage_single_source.sh | CN-KES-HEADER-01, DC-CONS-18 |
| ci_check_utxo_fp_v2.sh | DC-MEM-10 |
| ci_check_wal_append_only.sh | CN-WAL-01, DC-ADMIT-05, DC-WAL-01 |
| ci_check_warmstart_eta0_overlay.sh | ECA-B (band 7) |
| ci_check_wire_liveness.sh | DC-PUMP-05, DC-PUMP-06, DC-PUMP-07, DC-PUMP-08, DC-PUMP-09, DC-PUMP-10 |
Related invariants — 140
| ID | Status | Statement |
|---|---|---|
| CN-ANCHOR-01 | enforced | Single BootstrapAnchor mint authority: exactly one pub fn in ade_runtime::bootstrap_anchor::mint produces a BootstrapAnchor with all 6 fields populate… |
| CN-CINPUT-02 | enforced | The SeedEpochConsensusInputs sidecar MUST be populated ONLY through the single shared ade_runtime::seed_epoch_lineage::persist_seed_epoch_consensus_in… |
| CN-CONS-06 | enforced | Cross-impl acceptance: blocks forged by Ade are accepted by cardano-node when delivered via N2N block-fetch / chain-sync. Evidence is operator-action:… |
| CN-CONS-07 | enforced | Self-acceptance bridge + serve provenance. A forged block is NOT eligible for RED broadcast unless Ade's own header validator (PHASE4-N-B path) and bo… |
| CN-CONS-IN-01 | enforced | Single LiveConsensusInputs importer authority: exactly one pub fn ade_runtime::consensus_inputs::importer::import_live_consensus_inputs converts a car… |
| CN-GENESIS-01 | enforced | The Shelley genesis closed-contract parser accepts a real cardano-cli `shelley-genesis.json` and produces a canonical `GenesisAnchor`. Required fields… |
| CN-KES-HEADER-01 | enforced | The KES signature in a forged block's header is over the canonical unsigned-header CBOR pre-image — the CBOR encoding of ShelleyHeaderBody (the first … |
| CN-MITHRIL-01 | enforced | A Mithril-sourced seed may bootstrap only after a verified binding: the Mithril manifest's attested {network_magic, genesis_hash, certified_point, cer… |
| CN-NODE-01 | enforced | Single bootstrap authority: exactly one pub fn in ade_runtime::bootstrap returns the initial (LedgerState, PraosChainDepState, ChainDb tip) at node st… |
| CN-OPCERT-01 | enforced | The opcert envelope parser accepts a real cardano-cli `node.opcert` text envelope (closed type check `NodeOperationalCertificate` + CBOR array(2) shap… |
| CN-OUTBOUND-RELAY-01 | enforced | OutboundCommand is the sole channel between produce_mode and MuxPump's outbound encoder. The closed enum carries typed ChainSyncServerMsg / BlockFetch… |
| CN-PEER-OUTBOUND-MAP-01 | enforced | Per-peer outbound senders are owned by an Arc<RwLock<BTreeMap<PeerId, mpsc::Sender<OutboundCommand>>>>. Listener (run_per_peer_session) inserts on Pee… |
| CN-PROD-01 | enforced | Producer-mode listener completes the N2N handshake (CN-SESS-02) on every accepted inbound connection before any mini-protocol traffic is exchanged. Pr… |
| CN-PROD-02 | enforced | Producer slot loop never signs a block whose KES period has rotated past current_period. Slot → KES period is a pure function of (slot, genesis_kes_an… |
| CN-PROD-03 | enforced | produce_mode's forge base state is derived from bootstrap_initial_state (cold-start, fed the operator-seeded ledger from --json-seed + --consensus-inp… |
| CN-PROD-04 | enforced | Every CoordinatorEffect::BroadcastBlock reconstructs the AcceptedBlock from artifact.bytes through the BLUE self_accept authority against the pre-forg… |
| CN-PUMP-01 | enforced | Single admission wire-pump entry per peer: exactly one pub async fn ade_runtime::admission::wire_pump::run_admission_wire_pump drives the per-peer pum… |
| CN-REHEARSAL-FIDELITY-01 | enforced | Private-testnet accepted-block bounty dry-run fidelity (two coupled clauses; if either fails the rehearsal becomes misleading). (1) PATH FIDELITY: the… |
| CN-SEED-01 | enforced | Single JSON seed-importer authority: exactly one pub fn in ade_runtime::seed_import::import_cardano_cli_json_utxo converts a cardano-cli `query utxo -… |
| CN-STORE-03 | enforced | Crash recovery must produce the same authoritative state as clean replay over the accepted canonical inputs |
| CN-STORE-04 | enforced | Checkpoints must be atomic: fully committed and valid, or absent |
| CN-STORE-05 | enforced | Finalized provenance must be append-only, auditable, and replay-derivable |
| CN-WAL-01 | enforced | Single WAL append authority: WalStore::append is the SOLE mutation method on any WalStore impl. No truncate/rewrite/replace method exists on the trait… |
| CN-WIRE-09 | enforced | The Shelley-and-later header_body `prev_hash` field is the closed wire grammar `$hash32 / null` (cardano-ledger PrevHash = GenesisHash | BlockHash). A… |
| CN-WIRE-12 | enforced | Ade's FEED/receive-side BlockFetch path MUST remove the protocol tag-24 wrapper using the SINGLE ade_codec unwrap authority (decompose_blockfetch_bloc… |
| DC-ADMIT-09 | enforced | Admission code paths do not add partial reference-script support, permissive ref-script skipping, or any seed-import fallback. N-M-A's fail-fast on Js… |
| DC-CINPUT-01 | enforced | WARM-START VERIFICATION CAPABILITY (authority surface — NOT production restart). The seed-epoch consensus-input import is a canonical, replay-reconstr… |
| DC-CINPUT-03 | enforced | The producer Praos VRF leader/header input is `praos_vrf_input(slot, eta0)` = `blake2b256(slot_be8 ‖ eta0_32)` (= cardano `mkInputVRF`), where eta0 is… |
| DC-CINPUT-05 | enforced | Venue epoch geometry is DURABLE REPLAY AUTHORITY. A recovered store MUST replay using the epoch geometry (epoch_start_slot + epoch_length_slots) persi… |
| DC-CINPUT-06 | enforced | The durable consensus PROFILE includes genesis_hash + protocol_params_hash, persisted canonically in the v4 SeedEpochConsensusInputs sidecar and recov… |
| DC-CINPUT-07 | declared | Conway deposit-parameter bootstrap authority. The Conway-only deposit params (drep_deposit / gov_action_deposit / drep_activity) are DECODED from the … |
| DC-CONS-03 | enforced | Praos chain selection ordering: block number first, then Praos TiebreakerView (slot, issuer, op-cert issue number, VRF output). Density-based ordering… |
| DC-CONS-07 | enforced | BLUE consensus must consume the HFC schedule only as a typed EraSchedule value anchored to BootstrapAnchorHash. Genesis text parsing happens in RED; B… |
| DC-CONS-16 | enforced | Forged header.body_hash MUST equal blake2b_256(forged_body_wire_bytes), where forged_body_wire_bytes are produced by the single Cardano-compatible can… |
| DC-CONS-17 | enforced | Block bytes delivered via producer-side block-fetch Block{bytes} are byte-identical to AcceptedBlock.as_bytes() for the AcceptedBlock that cleared sel… |
| DC-CONS-18 | enforced | Header bytes announced via chain-sync RollForward{header,tip} are the header sub-segment of the AcceptedBlock whose body bytes are subsequently servab… |
| DC-CONS-20 | enforced | ChainDb-ledger-chain_dep lockstep: a successful receive-side admission updates ChainDb, LedgerState, and PraosChainDepState as one structural transiti… |
| DC-CONS-21 | enforced | Snapshot encode/decode round-trip equivalence: for any reachable (LedgerState, PraosChainDepState), decode(encode(state)) yields a state whose ade_led… |
| DC-CONS-IN-01 | enforced | Closed importer error sum: Io | Json | BadField | MissingField | BadHashHex | BadEpochWindow | BadPoolDistribution | EraNotSupported. No Option field … |
| DC-CONS-IN-02 | enforced | Canonical fingerprint: LiveConsensusInputsCanonical.fingerprint is Blake2b-256 over a canonical CBOR encoding of every field in declared order. Same J… |
| DC-CONSENSUS-01 | enforced | Chain selection is deterministic and matches Haskell node behavior |
| DC-CORE-01 | enforced | BLUE authoritative crates are sync-only: no async fn, .await, tokio::, async_std::, Future, futures::, task spawning, async channels, or timers. Async… |
| DC-CRYPTO-03 | enforced | VRF signing transcript equivalence and verification symmetry. For canonical inputs (slot, epoch_nonce, vrf_signing_key, vrf_role) the RED signer produ… |
| DC-CRYPTO-04 | enforced | KES signing transcript equivalence and verification symmetry. For canonical inputs (kes_secret, period, msg) the RED signer produces a KesSignature by… |
| DC-CRYPTO-05 | enforced | KES evolution discipline: evolve(k_i) -> k_{i+1} is one-way. The evolved key signs period i+1 and MUST NOT sign for period i. RED kes_sign is forbidde… |
| DC-CRYPTO-06 | enforced | Ade-native KES envelope is the sole accepted hot-signing-key envelope format. Closed grammar `ade.kes.seed.v1`: load-bearing fields {`format`, `role`,… |
| DC-CRYPTO-07 | enforced | cardano-cli's `KesSigningKey_ed25519_kes_2^6` envelope (the upstream `Sum6KES` expanded-tree serialization, 608 bytes for a fresh key) is loadable via… |
| DC-CRYPTO-10 | enforced | The RED signing shell must evolve the operator KES signing key to the requested KES period before signing, using the existing deterministic Sum6KES up… |
| DC-EPOCH-16 | enforced | Rolling Praos chain-dep nonce evolution on the live follow path. Each validated followed header drives ONE indivisible BLUE nonce transition over {slo… |
| DC-EPOCH-18 | enforced | Window-end bootstrap reward update for the seed+2 leadership authority. The first post-bootstrap replay-derived authority (seed+2, DC-EPOCH-17) is the… |
| DC-EPOCH-24 | enforced | Snapshot pool-set inclusion = cardano's ssActiveStake NonZero membership (CE-3d). The per-epoch stake snapshot (mark/set/go) INCLUDES a registered+del… |
| DC-EPOCH-25 | declared | Self-contained frozen leadership authority (S4-pre). Cardano's leadership PoolDistr (nesPd) -- the per-pool (active_stake, vrf_keyhash) that decides t… |
| DC-EPOCH-26 | enforced | Settled rewind target. The epoch accumulator is NEVER rewound to a point within k of the durable tip: every rewind target is beyond the reach of an ad… |
| DC-EPOCH-28 | enforced | Leadership coherence across a rewind. A rewind restores CURRENT_LEADERSHIP_BY_EPOCH to exactly the epochs valid at the rewind point, so no sealed lead… |
| DC-EPOCH-29 | enforced | Uncertified after rewind. A rewind clears LAST_ADVANCED_POINT and drops the pending boundary-mark binding, so the store is UNCERTIFIED until a canonic… |
| DC-EPOCH-30 | enforced | Bounded post-rollback refold. Post-rollback re-derivation is bounded by ~2k and is INDEPENDENT OF NODE UPTIME. The settled rewind point is never more … |
| DC-EPOCH-31 | enforced | Rewind replay equivalence. Refolding from the settled rewind point yields state byte-identical to folding straight through from the bootstrap baseline… |
| DC-EPOCH-32 | enforced | Boundary seal reads a POSITIONED checkpoint. The boundary mark and the reduced-checkpoint commitment sealed into a frozen-leadership object are captur… |
| DC-EPOCH-34 | enforced | Settled-triple integrity. The settled rewind triple (accumulator blob + settled point + settled leadership) is bound by a domain-separated, length-pre… |
| DC-EPOCH-35 | enforced | A bounded settled rewind survives the recovery pass that follows a durable rollback. After the ChainDb rollback COMMITS -- never before -- the settled… |
| DC-EPOCH-39 | enforced | A stall's CAUSE is typed, and only a real epoch transition may enter boundary machinery. Advancing the durable accumulator over one block yields exact… |
| DC-EVIDENCE-01 | enforced | Operator-pass live evidence: the C5 live operator pass against the local docker cardano-node-preprod peer produces a JSONL transcript containing AT LE… |
| DC-EVIDENCE-05 | enforced | Replayable post-switch branch-continuity verdict (PHASE4-N-AO S10). After a ForkChoiceWin adoption at tip X, a GREEN pure reducer derive_post_switch_c… |
| DC-EVIEW-01 | enforced | Transient epoch-view replay storage is GREEN / non-authoritative substrate. A bounded, disk-backed, TRANSIENT redb store (TransientEpochViewStore) may… |
| DC-EVIEW-04 | enforced | The durable reduced-UTxO checkpoint -- the "minimal native state" (S3b Option B). A disk-backed redb store of TxIn -> (Coin, ReducedStakeRef), built f… |
| DC-EVIEW-04b | enforced | The windowed advance (S3b-2): advance the durable reduced-UTxO checkpoint (DC-EVIEW-04) per epoch boundary by replaying the epoch's admitted blocks, a… |
| DC-EVIEW-05 | enforced | Per-pool stake aggregation (S3c, the linchpin). aggregate_pool_stake computes the next-epoch per-pool active stake from the single ledger authority's … |
| DC-EVIEW-10 | enforced | The window driver (S3f-2): advance the reduced UTxO checkpoint + the cert/delegation state forward over a window of ordered blocks, then aggregate per… |
| DC-EVIEW-13 | enforced | Cardano-faithful pool lifecycle in the reduced window (ECA-0a). The cert-state pool lifecycle matches cardano-ledger (Pool.hs/PoolReap.hs/Epoch.hs/Sna… |
| DC-GENESIS-01 | enforced | Given the same canonical Shelley genesis JSON bytes + the same operator-supplied kes_anchor_slot, parse_shelley_genesis produces a byte-identical Gene… |
| DC-GENESIS-SRC-01 | enforced | A controlled genesis enters initial state ONLY through the single closed bootstrap_initial_state authority (genesis_initial); the genesis->initial-sta… |
| DC-LEDGER-PHASE2-02 | enforced | The accumulator consumes a RESOLVED SCALAR; it does not own a UTxO. The ADA a phase-2-invalid transaction consumes is collAdaBalance = sum(value(colla… |
| DC-LEDGER-PHASE2-03 | enforced | A phase-2-invalid transaction contributes its consumed collateral and NOTHING else. For a tx in the block's invalid_transactions set the accumulator a… |
| DC-LEDGER-PHASE2-04 | enforced | The UTxO authority RETAINS what it destroys on another reader's behalf. A collateral value is authoritative only within [create(x), B), where B is the… |
| DC-LIVEMEM-01 | enforced | Live-feed bounded memory (operational-hardening; NOT BLUE consensus law). Peer-driven memory on the live --mode node feed is bounded BEFORE authoritat… |
| DC-MEM-06 | partial | The UTxO/ledger state fingerprint is computed by the canonical CBOR encoder over canonically-encoded (fixed-width big-endian) keys, NEVER from a stora… |
| DC-MEM-10 | enforced | The v2 UTxO fingerprint component is a NAMED commutative set commitment (Ristretto255 ECMH) binding (TxIn, TxOut) over the canonical encodings, domain… |
| DC-MEM-11 | enforced | The network forward-sync / forge per-block admit MUST derive the WAL post_fp from the CACHED UTxO-component fingerprint (ForwardSyncState.utxo_fp_cach… |
| DC-MITHRIL-02 | enforced | For Mithril bootstrap, the BootstrapAnchor seed_point MUST be derived from the operator-provided independent seed-point extraction inputs, not from th… |
| DC-MITHRIL-03 | enforced | The native Mithril AUTHORITY TRANSITION assembles the COMPLETE authoritative seed (LedgerState + PraosChainDepState + a NATIVE LiveConsensusInputsCano… |
| DC-MITHRIL-04 | enforced | Native V2 LedgerDB `state` decode is faithful, fail-closed, and non-emitting. The cardano-node V2 (utxohd-mem, tablesCodecVersion 1) LedgerDB `state` … |
| DC-MITHRIL-05 | enforced | Faithful Word64 multi-asset quantity on the snapshot-import path. The native V2 LedgerDB `tables` MemPack TxOut decode keeps every multi-asset quantit… |
| DC-MITHRIL-06 | enforced | The Stage-2 `tables` (MemPack-decoded TxOuts) materialize into Ade's authoritative `UTxOState` with hash-critical bytes PRESERVED and full Word64 quan… |
| DC-NODE-01 | enforced | Per-peer session isolation: one peer session's failure (decode error, validity reject, rollback-too-deep, protocol violation) halts only that peer's s… |
| DC-NODE-02 | enforced | Persistent-writer cadence fidelity: the orchestrator's persistent-snapshot writer calls PersistentSnapshotCache::capture only on the schedule emitted … |
| DC-NODE-03 | enforced | Clock-injection seam + replay equivalence: the orchestrator depends on a Clock trait yielding now() and tick_stream(). No SystemTime::now() or tokio::… |
| DC-NODE-06 | enforced | Self-accept -> serve handoff on the --mode node relay spine (sibling serve task, shape B). Only a BLUE self-accepted forged artifact may enter the sib… |
| DC-NODE-07 | enforced | Node-spine live serve-to-peer. --mode node serves real peers ONLY from the G-B self-accepted ServedChainView (the read side of the single ServedChainH… |
| DC-NODE-11 | enforced | Once --mode node has self-accepted and SERVED a genesis-successor block at block_no 0, it MUST NOT add/replace the served view (ServedChainView) with … |
| DC-NODE-12 | enforced | Own-forged durable admit chokepoint. A self-accepted forged block may become part of the durable chain ONLY by being submitted to the same durable adm… |
| DC-NODE-13 | enforced | Served view is a durable-chain projection. The ChainView served to followers (ChainSync header advertisement + BlockFetch body) is a deterministic PRO… |
| DC-NODE-14 | enforced | Every claimed forge parent must be servable or peer-intersectable in the durable served lineage. A --mode node forge may only build on a parent a Hask… |
| DC-NODE-16 | enforced | Receive idempotency: a peer-delivered block already durably present byte-identically in the ChainDb (same slot, same hash) is an idempotent no-op at t… |
| DC-NODE-25 | enforced | Live fork-choice durable application authority (rung-2). A ChainSelected / RolledBack outcome from the chain_selector orchestrator is applied to the d… |
| DC-NODE-29 | enforced | Live rollback target canonical binding (rung-2; AI-S6 H-1 remediation). For a peer RollBackward(point) on the live Participant path, the rollback targ… |
| DC-NODE-31 | enforced | Recovered-anchor live-follow start authority (PHASE4-N-AK). After recovery from a non-Origin bootstrap anchor, the recovered store PERSISTS the bootst… |
| DC-NODE-32 | enforced | Recovered-anchor rollback boundary on the single-producer live-follow path (PHASE4-N-AK AK-S2). After recovery to a bare bootstrap anchor, the single-… |
| DC-NODE-33 | enforced | Participant-path recovered-anchor rollback boundary (PHASE4-N-AL) -- the participant MIRROR of DC-NODE-32. On the participant live-follow path (run_pa… |
| DC-NODE-45 | enforced | ONE bootstrap-bound wall-clock -> absolute-slot authority on the authoritative --mode node producer path. (a) SOLE AUTHORITY: the forge derives its sl… |
| DC-NODE-46 | enforced | Every ADMITTED ForgeTick yields either a structured refusal or a leader-schedule decision. No admitted tick may disappear, and none may report a reaso… |
| DC-NODE-47 | partial | Followed-peer-tip possession evidence (SLICE B12). The forge-admissibility signal (FollowedPeerTipSignal) reports the STRONGEST available evidence tha… |
| DC-OPCERT-01 | enforced | Given the same canonical envelope bytes, parse_opcert_envelope produces a byte-identical DecodedOpCertEnvelope across runs. Replay-equivalence anchor … |
| DC-OUTBOUND-FIFO-01 | enforced | The per-peer outbound channel preserves FIFO order: OutboundCommands enqueued for PeerId(p) in order O₁..Oₙ arrive at the peer's TCP socket in the sam… |
| DC-PROD-01 | enforced | Producer-mode evidence log emits a closed `ProducerLogEvent` vocabulary: handshake_ok, slot_tick, leader_elected, block_forged, block_served, peer_cha… |
| DC-PROD-02 | enforced | Coordinator slot-tick + forge-result stream replay-equivalence. For a fixed initial CoordinatorState, fixed canonical slot-tick sequence, fixed ledger… |
| DC-PROD-03 | enforced | Producer chain-forward continuity + replay. The GREEN ChainEvolution linear typestate threads each forge's post-state (post-ledger, post-chain_dep, ne… |
| DC-PROTO-07 | enforced | Given canonical inputs (negotiated_version, peer_message_sequence, broadcast_arrival_sequence, session_event_sequence), the producer-side chain-sync /… |
| DC-PROTO-09 | enforced | Receive-side transcript determinism: given canonical inputs (initial_ledger, initial_chain_dep, initial_chaindb, event_sequence), the bridge reducer's… |
| DC-PUMP-01 | enforced | Wire pump emits AdmissionPeerEvent::{Block, TipUpdate, Disconnected} only. It MUST NOT synthesize AgreementVerdict values or any validity claim. The v… |
| DC-PUMP-02 | enforced | A CLOSED authority event is emitted on every chain-sync reply carrying a Tip: TipUpdate for IntersectFound / IntersectNotFound / RollForward; the DIST… |
| DC-PUMP-03 | enforced | Wire-pump keep-alive client (PHASE4-N-AM). The admission wire pump (run_admission_wire_pump -- the SOLE per-peer pump, CN-PUMP-01) runs the N2N keep-a… |
| DC-PUMP-05 | enforced | Cooperative keep-alive liveness under downstream backpressure. No stall of the downstream consumer -- of ANY duration or cause (block application, epo… |
| DC-PUMP-06 | enforced | Ordered pump progression under backpressure. The sequence of AdmissionPeerEvents delivered to events_out is identical to the unstalled pump for the sa… |
| DC-PUMP-07 | enforced | Bounded deferral, fail closed. Peer frames held while the pump waits for downstream capacity are bounded by the fixed, closed, non-configurable MAX_DE… |
| DC-SEED-01 | enforced | Canonical UtxoFingerprint determinism: the imported UTxOState uses BTreeMap<TxIn, TxOut> iteration order; UtxoFingerprint is Blake2b-256 over canonica… |
| DC-SERVEMEM-01 | enforced | Peer-driven serve range work is bounded. The --mode node serve path must not materialize an unbounded chain range, perform per-block full-index scans,… |
| DC-SESS-04 | enforced | Backpressure discipline: every per-peer + per-mini-protocol channel is bounded; queue overflow is fail-fast `TransportError::BackpressureExceeded` rat… |
| DC-SESS-05 | enforced | Wire-layer clock injection: the session reducer + dispatch table contain no SystemTime / Instant::now / tokio::time reads. Keep-alive is driven by the… |
| DC-SNAPSHOT-01 | enforced | ServedChainHandle::push_atomic is deterministic in its argument order: the same sequence of push_atomic(a₀), push_atomic(a₁), ..., push_atomic(aₙ) pro… |
| DC-STORE-01 | enforced | Recovery from power-loss produces replay-equivalent state |
| DC-STORE-02 | enforced | Append-only provenance for finalized data |
| DC-STORE-03 | enforced | Atomic snapshots (fully written or absent) |
| DC-STORE-05 | enforced | Recovery is snapshot + forward replay (not full genesis replay): load most recent valid snapshot, replay forward from ImmutableDB tip |
| DC-STORE-07 | enforced | Snapshot cadence determinism: the decision to take a snapshot at slot S is a pure function of (slot, block_no, cadence_params, last_snapshot). Same ca… |
| DC-STORE-10 | enforced | Replay equivalence requires the persisted authority store and the binary to agree on the MEANING of the bytes, not merely on their layout. Every durab… |
| DC-STORE-11 | enforced | The semantics marker is PER-ARTIFACT, and every authority artifact must agree with the binary independently. `chain.db` (with the WAL written in locks… |
| DC-SYNC-01 | enforced | During network forward-sync, a block's preserved wire bytes and its WAL entry MUST be durable before the chain tip advances to it, and admission is ch… |
| DC-VIEW-01 | enforced | LiveLedgerView determinism + epoch-window guard. The view is constructed deterministically from LiveConsensusInputsCanonical. Two guards on every Led… |
| DC-WAL-03 | enforced | Anchor + WAL replay-equivalence: replaying (BootstrapAnchor + WAL entries 1..N) against (initial_ledger from import + per-entry block bytes) produces … |
| OP-OPS-04 | enforced | Operator-supplied keys. Ade supports both KES key flows: (a) Ade-native `ade_node --mode key_gen_kes --out-file PATH` emitting an `ade.kes.seed.v1` en… |
| OP-OPS-05 | enforced | Slot-deadline forging SLA. Forge + self-accept + N2N hand-off must complete within the slot's deadline (1s on mainnet, smaller on testnets). Operation… |
| RO-LIVE-01 | partial | A Haskell cardano-node peer issuing RequestRange covering an Ade-forged block receives, via the producer-side block-fetch server, bytes that pass that… |
| RO-LIVE-02 | partial | A cardano-node peer's RollForward + BlockDelivered stream, consumed by the receive bridge, produces a ChainDb tip equal to the peer's announced tip at… |
| RO-LIVE-05 | enforced | Live admission-agreement pass: operator runs `ade_node` against a private cardano-node peer with admission enabled (bootstrap loads a real initial led… |
| RO-MITHRIL-IMPORT-01 | enforced | Ade imports a Mithril-authenticated snapshot as an alternative to the cardano-cli JSON seed. Provides cryptographic provenance for the seed artifact (… |
| T-DET-01 | enforced | Same canonical inputs -> same authoritative bytes (per Byte Authority Model) |
| T-REC-01 | enforced | Recovery is replay-equivalent: restart produces byte-identical state to clean run |
| T-REC-02 | enforced | All authoritative state derivable by replay from inputs |
| T-REC-04 | enforced | The WarmStart-recovered forge `chain_dep.epoch_nonce` (eta0) MUST come from the imported/recovered consensus input, never from a snapshot placeholder … |
| T-REC-05 | enforced | Replay/recovery equivalence including forged admits. Same BootstrapAnchor + same WAL (including forged AdmitBlock entries) -> byte-identical recovered… |