Modules / ade_testkit

ade_testkit

GREEN
GREEN crate GREEN — deterministic test/corpus infrastructure; dev-dep / #[cfg(test)]-scoped
Purpose

GREEN deterministic TEST / CORPUS infrastructure for the workspace — the oracle/differential harness, the validity & tx-validity corpora, the consensus & governance replay corpora, the producer reference vectors, the snapshot/genesis/ledger diff loaders, consensus::ledger_view_stub::LedgerViewStub, the Plutus-conformance harness, and (NEW) harness::immutabledb_witness (the local preview ImmutableDB corpus-extraction witness). The home of replay_cmd = cargo test -p ade_testkit. The differential ORACLE vs cardano-cli query stake-snapshot (stakeSet) at ≥2 Conway boundaries is the declared LIVE acceptance gate for the reduced/epoch-accumulator stake authority; the native Mithril V2 decoders are corpus-tested against real preprod LedgerDB samples. Note: consensus_stream_replay currently has 4 KNOWN-PRE-EXISTING failures (an in-flight ECA-B rolling-nonce corpus issue) — a corpus/test-fixture matter, not a module-structure concern.

Creates

GREEN test/corpus value types — NONE canonical-counted: ConwayValidityCorpus + loaders, BlockReplay/TxReplay, the adversarial mutation enums, OracleManifest/RegressionCorpus, DifferentialReport, Transcript, LedgerViewStub/EpochStakeFixture/PoolFixture, VrfReferenceVector/KesReferenceVector, ImmutableDbWitness. All GREEN.

Interprets

Committed reference corpora + oracle dumps + the Plutus-conformance manifest + the native LedgerDB V2 corpus samples + the local ImmutableDB, for the test harness only. Evidence inputs, never runtime authority.

MUST NOT

(1) Be a production runtime dependency — GREEN dev-dep / #[cfg(test)]-scoped; MUST NOT be promoted onto a hashed/persisted/consensus path. (2) Affect authoritative outputs or introduce nondeterminism. (3) Construct semantic types bypassing canonical decoders. (4, DC-COMPAT-01) Compare an Ade-internal-state fingerprint to a Haskell-serialized-state hash. (5) Commit secret key material. (6) Overstate semantic truth.

Inbound deps

ade_core (dev), ade_ledger (dev), ade_network (dev), ade_runtime (dev), ade_node (dev), ade_core_interop (plain — the RED-leaf interop/test driver).

Outbound deps

ade_core, ade_ledger, ade_plutus, ade_crypto, ade_codec, ade_types, ade_runtime, cardano-crypto, blake2, ed25519-dalek, serde, serde_json, toml.

Entry points

ade_testkit::validity::*, ade_testkit::tx_validity::*, ade_testkit::consensus::*, ade_testkit::governance::*, ade_testkit::harness::{snapshot_loader, immutabledb_witness}::*, ade_testkit::mempool::ingress_replay::*.

Key modules

consensus/, governance/, harness/ (incl. immutabledb_witness.rs), mempool/ingress_replay.rs, producer/, tx_validity/, validity/.

Depends on

—

Depended on by

—

CI guards — 16

ScriptEnforces
ci_check_consensus_closed_enums.sh CN-CONS-02, DC-CONS-03, DC-CONS-04, DC-CONS-05, DC-CONS-06, DC-CONS-09, DC-CONS-10, DC-CONSENSUS-01, DC-MEM-01, DC-MEM-02, DC-TXV-01, DC-TXV-02, DC-TXV-03, DC-TXV-04, DC-TXV-05, DC-VAL-01, DC-VAL-02, DC-VAL-03, DC-VAL-04, DC-VAL-05, DC-VAL-06, T-DET-01
ci_check_conway_deposit_params_bootstrap.sh

DC-CINPUT-07 (band 9)

ci_check_credential_discriminant_closed.sh

DC-LEDGER-10 (band 7)

ci_check_differential_divergence.sh DC-LEDGER-02, DC-LEDGER-03, T-CONSERV-01, T-NOSPEND-01
ci_check_forbidden_patterns.sh DC-LEDGER-08, T-CORE-01, T-CORE-02, T-DET-01
ci_check_forge_purity.sh DC-CONS-13, DC-CONS-14, DC-CONS-15, DC-LEDGER-12
ci_check_ledger_determinism.sh DC-LEDGER-01, DC-LEDGER-02, T-DET-01
ci_check_mempool_ingress_replay.sh DC-MEM-04
ci_check_no_haskell_fingerprint_equality.sh DC-COMPAT-01
ci_check_no_private_keys_in_corpus.sh DC-CONS-14
ci_check_plutus_conformance.sh CN-PLUTUS-01
ci_check_plutus_eval_purity.sh CN-PLUTUS-01, CN-PLUTUS-04
ci_check_producer_corpus_present.sh CN-CONS-06
ci_check_proposal_procedures_closed.sh DC-LEDGER-11
ci_check_ref_provenance.sh DC-REF-01
ci_check_sync_evidence_manifest_schema.sh RO-SYNC-EVIDENCE-01

Related invariants — 17

IDStatusStatement
CN-CONS-06 enforced Cross-impl acceptance: blocks forged by Ade are accepted by cardano-node when delivered via N2N block-fetch / chain-sync. Evidence is operator-action:…
CN-PLUTUS-01 enforced Same script + same redeemers/datum/context + same cost model must produce identical result and budget accounting
DC-CINPUT-07 declared Conway deposit-parameter bootstrap authority. The Conway-only deposit params (drep_deposit / gov_action_deposit / drep_activity) are DECODED from the …
DC-COMPAT-01 enforced Cardano compatibility is proven ONLY on observable surfaces — per-block accept/reject verdict, selected tip hash, block hashes, cardano-cli query-utxo…
DC-CONS-14 enforced Forge byte-equality across replays. For two replays of an identical canonical ProducerTick stream over the same initial LedgerState, forge_block produ…
DC-DIFF-01 partial Differential harness must localize first divergence point between Ade and reference oracle
DC-LEDGER-02 partial Same genesis + same blocks = byte-identical ledger state
DC-LEDGER-10 enforced Credential identity is faithful end-to-end: a stake/committee/DRep credential is a closed sum over {KeyHash, ScriptHash} of a 28-byte hash, never a ta…
DC-LEDGER-11 enforced proposal_procedures MUST NOT remain an opaque byte field in the authoritative Conway tx-body shape. ConwayTxBody.proposal_procedures is Option<Vec<Pro…
DC-MEM-01 enforced Mempool acceptance rules must not contradict block/ledger acceptance rules
DC-MEM-04 enforced Replaying the same ordered ingress trace against the same base ledger state produces a byte-identical sequence of (MempoolState, AdmitOutcome) pairs.
DC-REF-01 partial Every claimed equivalence check must identify its reference source, extraction method, and reproducibility path
DC-TXV-03 enforced Ade's Valid/Invalid verdict for a transaction equals the reference cardano-node verdict, including the reason class where the reference exposes it. Es…
DC-VAL-04 enforced Ade's Valid/Invalid verdict for a block equals the reference cardano-node verdict, including the reason class where the reference exposes it. Establis…
DC-VAL-06 enforced Every crypto-input, field-size, and structural check on the authority path rejects (produces Invalid) on wrong size or shape and never silently skips.…
RO-SYNC-EVIDENCE-01 partial A committed snapshot->tip sync-evidence manifest carries the closed schema (oracle versions, chain point, fixture refs, sha256, diff/acceptance result…
T-DET-01 enforced Same canonical inputs -> same authoritative bytes (per Byte Authority Model)