ade_testkit
GREEN- Purpose
GREEN deterministic TEST / CORPUS infrastructure for the workspace — the oracle/differential harness, the validity & tx-validity corpora, the consensus & governance replay corpora, the producer reference vectors, the snapshot/genesis/ledger diff loaders,
consensus::ledger_view_stub::LedgerViewStub, the Plutus-conformance harness, and (NEW)harness::immutabledb_witness(the local preview ImmutableDB corpus-extraction witness). The home ofreplay_cmd = cargo test -p ade_testkit. The differential ORACLE vscardano-cli query stake-snapshot(stakeSet) at ≥2 Conway boundaries is the declared LIVE acceptance gate for the reduced/epoch-accumulator stake authority; the native Mithril V2 decoders are corpus-tested against real preprod LedgerDB samples. Note:consensus_stream_replaycurrently has 4 KNOWN-PRE-EXISTING failures (an in-flight ECA-B rolling-nonce corpus issue) — a corpus/test-fixture matter, not a module-structure concern.- Creates
GREEN test/corpus value types — NONE canonical-counted:
ConwayValidityCorpus+ loaders,BlockReplay/TxReplay, the adversarial mutation enums,OracleManifest/RegressionCorpus,DifferentialReport,Transcript,LedgerViewStub/EpochStakeFixture/PoolFixture,VrfReferenceVector/KesReferenceVector,ImmutableDbWitness. All GREEN.- Interprets
Committed reference corpora + oracle dumps + the Plutus-conformance manifest + the native LedgerDB V2 corpus samples + the local ImmutableDB, for the test harness only. Evidence inputs, never runtime authority.
- MUST NOT
(1) Be a production runtime dependency — GREEN dev-dep /
#[cfg(test)]-scoped; MUST NOT be promoted onto a hashed/persisted/consensus path. (2) Affect authoritative outputs or introduce nondeterminism. (3) Construct semantic types bypassing canonical decoders. (4,DC-COMPAT-01) Compare an Ade-internal-state fingerprint to a Haskell-serialized-state hash. (5) Commit secret key material. (6) Overstate semantic truth.- Inbound deps
ade_core(dev),ade_ledger(dev),ade_network(dev),ade_runtime(dev),ade_node(dev),ade_core_interop(plain — the RED-leaf interop/test driver).- Outbound deps
ade_core,ade_ledger,ade_plutus,ade_crypto,ade_codec,ade_types,ade_runtime,cardano-crypto,blake2,ed25519-dalek,serde,serde_json,toml.- Entry points
ade_testkit::validity::*,ade_testkit::tx_validity::*,ade_testkit::consensus::*,ade_testkit::governance::*,ade_testkit::harness::{snapshot_loader, immutabledb_witness}::*,ade_testkit::mempool::ingress_replay::*.- Key modules
consensus/,governance/,harness/(incl.immutabledb_witness.rs),mempool/ingress_replay.rs,producer/,tx_validity/,validity/.
Depends on
—
Depended on by
—
CI guards — 16
| Script | Enforces |
|---|---|
| ci_check_consensus_closed_enums.sh | CN-CONS-02, DC-CONS-03, DC-CONS-04, DC-CONS-05, DC-CONS-06, DC-CONS-09, DC-CONS-10, DC-CONSENSUS-01, DC-MEM-01, DC-MEM-02, DC-TXV-01, DC-TXV-02, DC-TXV-03, DC-TXV-04, DC-TXV-05, DC-VAL-01, DC-VAL-02, DC-VAL-03, DC-VAL-04, DC-VAL-05, DC-VAL-06, T-DET-01 |
| ci_check_conway_deposit_params_bootstrap.sh |
|
| ci_check_credential_discriminant_closed.sh |
|
| ci_check_differential_divergence.sh | DC-LEDGER-02, DC-LEDGER-03, T-CONSERV-01, T-NOSPEND-01 |
| ci_check_forbidden_patterns.sh | DC-LEDGER-08, T-CORE-01, T-CORE-02, T-DET-01 |
| ci_check_forge_purity.sh | DC-CONS-13, DC-CONS-14, DC-CONS-15, DC-LEDGER-12 |
| ci_check_ledger_determinism.sh | DC-LEDGER-01, DC-LEDGER-02, T-DET-01 |
| ci_check_mempool_ingress_replay.sh | DC-MEM-04 |
| ci_check_no_haskell_fingerprint_equality.sh | DC-COMPAT-01 |
| ci_check_no_private_keys_in_corpus.sh | DC-CONS-14 |
| ci_check_plutus_conformance.sh | CN-PLUTUS-01 |
| ci_check_plutus_eval_purity.sh | CN-PLUTUS-01, CN-PLUTUS-04 |
| ci_check_producer_corpus_present.sh | CN-CONS-06 |
| ci_check_proposal_procedures_closed.sh | DC-LEDGER-11 |
| ci_check_ref_provenance.sh | DC-REF-01 |
| ci_check_sync_evidence_manifest_schema.sh | RO-SYNC-EVIDENCE-01 |
Related invariants — 17
| ID | Status | Statement |
|---|---|---|
| CN-CONS-06 | enforced | Cross-impl acceptance: blocks forged by Ade are accepted by cardano-node when delivered via N2N block-fetch / chain-sync. Evidence is operator-action:… |
| CN-PLUTUS-01 | enforced | Same script + same redeemers/datum/context + same cost model must produce identical result and budget accounting |
| DC-CINPUT-07 | declared | Conway deposit-parameter bootstrap authority. The Conway-only deposit params (drep_deposit / gov_action_deposit / drep_activity) are DECODED from the … |
| DC-COMPAT-01 | enforced | Cardano compatibility is proven ONLY on observable surfaces — per-block accept/reject verdict, selected tip hash, block hashes, cardano-cli query-utxo… |
| DC-CONS-14 | enforced | Forge byte-equality across replays. For two replays of an identical canonical ProducerTick stream over the same initial LedgerState, forge_block produ… |
| DC-DIFF-01 | partial | Differential harness must localize first divergence point between Ade and reference oracle |
| DC-LEDGER-02 | partial | Same genesis + same blocks = byte-identical ledger state |
| DC-LEDGER-10 | enforced | Credential identity is faithful end-to-end: a stake/committee/DRep credential is a closed sum over {KeyHash, ScriptHash} of a 28-byte hash, never a ta… |
| DC-LEDGER-11 | enforced | proposal_procedures MUST NOT remain an opaque byte field in the authoritative Conway tx-body shape. ConwayTxBody.proposal_procedures is Option<Vec<Pro… |
| DC-MEM-01 | enforced | Mempool acceptance rules must not contradict block/ledger acceptance rules |
| DC-MEM-04 | enforced | Replaying the same ordered ingress trace against the same base ledger state produces a byte-identical sequence of (MempoolState, AdmitOutcome) pairs. |
| DC-REF-01 | partial | Every claimed equivalence check must identify its reference source, extraction method, and reproducibility path |
| DC-TXV-03 | enforced | Ade's Valid/Invalid verdict for a transaction equals the reference cardano-node verdict, including the reason class where the reference exposes it. Es… |
| DC-VAL-04 | enforced | Ade's Valid/Invalid verdict for a block equals the reference cardano-node verdict, including the reason class where the reference exposes it. Establis… |
| DC-VAL-06 | enforced | Every crypto-input, field-size, and structural check on the authority path rejects (produces Invalid) on wrong size or shape and never silently skips.… |
| RO-SYNC-EVIDENCE-01 | partial | A committed snapshot->tip sync-evidence manifest carries the closed schema (oracle versions, chain point, fixture refs, sha256, diff/acceptance result… |
| T-DET-01 | enforced | Same canonical inputs -> same authoritative bytes (per Byte Authority Model) |