Documentation
¶
Overview ¶
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
Index ¶
- Constants
- func Cc001_reliance_on_dns(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc003_sql_injection_attacks(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc004_sybil_attacks_routing_vulnerability(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc005_content_poisoning_and_misrouting(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc006_node_churn_and_reconnection_logic(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc007_latency_and_reliability_trade_offs(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc008_legal_and_auditing_concerns(tx *generalv1.TransactionRequest, h int64, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc011_state_hash_consistency(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc012_node_identities(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc013_continuous_block_sequence_numbers(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc016_block_hash_integrity(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc017_transaction_hash_integrity(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc018_state_consistency(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc019_commit_consistency(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc020_byzantine_fault_detection(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc021_message_authenticity(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc022_network_partition_detection(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc024_redundant_storage_consistency(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc025_recovery_point_integrity(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc029_amount_field_consistency(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc031_executed_vs_finalized_transaction_count(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc032_block_size_consistency(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc035_merkle_root_reconstruction(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc036_transaction_and_metadata_correspondence(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc039_proof_of_consistency(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc047_phantom_write(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc048_lost_rollback(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc049_out_of_order_commit(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc050_replica_divergence(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc051_replay_detection_failure(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc052_inter_slab_drift(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc053_transaction_gap(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc054_clock_skew_violation(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc055_stale_read_write(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc056_write_amplification_error(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc061_state_bleed(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc062_metadata_omission(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc066_cyclic_transaction_dependency(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc067_orphaned_commit(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc069_nonce_reuse(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc072_anomaly_window_leak(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc075_transport_level_mismatch(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc076_double_acknowledgment(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc078_log_rewind_or_overwrite(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc079_query_path_drift(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc080_slab_compression_divergence(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc082_transaction_range_overlap(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc083_slow_commit_visibility(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc085_schema_drift_between_nodes(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc086_redundant_slab_execution(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc087_transaction_id_reordering(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc089_partial_crash_recovery(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc090_interceptor_state_desync(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc091_inverted_causality_via_metadata(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc092_multi_stage_transaction_collapse(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc093_metrics_telemetry_mismatch(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc094_immutable_slab_mutation(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc095_slab_boundary_drift(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc098_transaction_alias_collision(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc099_ledger_height_skew(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc103_trace_count_disagreement(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc104_stale_recovery_view(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc105_behavioral_drift_between_node_versions(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc106_replay_window_violation(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc107_context_detached_execution(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc108_unconsumed_compensation_logic(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc109_immutable_event_re_emission(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc112_partial_merkle_proof_failure(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc113_immutable_field_overwrite(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc122_cross_slab_state_corruption(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc123_inflight_transaction_loss(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc124_toctou_vulnerabilities(tx *generalv1.TransactionRequest, height int64, ...) *checks.CheckError
- func Cc125_resource_exhaustion_attacks(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
- func Cc130_bpd_violation_listener(ctx context.Context, prov *providers.ProviderRegistry) *checks.CheckError
- func ChainRoot(fedID string, height int64) (string, bool, error)
- func Register(r *checks.Registry)
- func RegisterDefault(reg *Registry, _ any, configPath string) error
- func SetChainRootProvider(fn ChainRootProvider)
- type AnchorTSProvider
- type ChainRootProvider
- type CheckFunc
- type Registry
- type TraceTx
Constants ¶
const AgreedTransactionsPerBlock = 1024
const MaxHeightDrift = 10
const ( // SlabSize defines the number of blocks that constitute a single slab. // This value is critical for checks that operate on slab boundaries. SlabSize = 24 // As per README.md, K = 24 Blocks in a single Ultimate Registration/Checking Phase )
Variables ¶
This section is empty.
Functions ¶
func Cc001_reliance_on_dns ¶
func Cc001_reliance_on_dns(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc001_reliance_on_dns is a placeholder for a check that would verify the security of DNS usage in the system.
func Cc003_sql_injection_attacks ¶
func Cc003_sql_injection_attacks(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc003_sql_injection_attacks detects potential SQL injection attacks.
func Cc004_sybil_attacks_routing_vulnerability ¶
func Cc004_sybil_attacks_routing_vulnerability(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc004_sybil_attacks_routing_vulnerability — STUBBED in the 23-field collapse (2026-05-23). Original check verified nonce reuse via CoreMeta.Nonce; that field was removed. Replay protection now relies on CheckTx + signature verification at the gateway interceptor + entnum scoping rather than a per-tx nonce. Restore this check when the nonce-based path is re-introduced (Phase D — signature verification).
func Cc005_content_poisoning_and_misrouting ¶
func Cc005_content_poisoning_and_misrouting(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc005_content_poisoning_and_misrouting detects malicious content or incorrect routing.
func Cc006_node_churn_and_reconnection_logic ¶
func Cc006_node_churn_and_reconnection_logic(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc006_node_churn_and_reconnection_logic monitors the stability of node connections by checking for an excessive number of reconnections, which could indicate network instability or a denial-of-service attack.
func Cc007_latency_and_reliability_trade_offs ¶
func Cc007_latency_and_reliability_trade_offs(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc007_latency_and_reliability_trade_offs detects if a node is exhibiting significantly lower latency than its peers, which might indicate it is skipping reliability checks.
func Cc008_legal_and_auditing_concerns ¶
func Cc008_legal_and_auditing_concerns(tx *generalv1.TransactionRequest, h int64, prov *providers.ProviderRegistry) *checks.CheckError
cc008_legal_and_auditing_concerns ensures transactions contain necessary metadata for auditing.
func Cc011_state_hash_consistency ¶
func Cc011_state_hash_consistency(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc011_state_hash_consistency ensures all nodes agree on the state of the system after each block.
func Cc012_node_identities ¶
func Cc012_node_identities(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
cc012_node_identities ensures that the node ID specified in the transaction metadata matches the actual ID of the node processing the transaction.
func Cc013_continuous_block_sequence_numbers ¶
func Cc013_continuous_block_sequence_numbers(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
cc013_continuous_block_sequence_numbers validates that the blockchain is not missing any blocks. For any given block height N > 1, it ensures that block N-1 exists.
func Cc016_block_hash_integrity ¶
func Cc016_block_hash_integrity(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
cc016_block_hash_integrity validates the cryptographic link between consecutive blocks.
func Cc017_transaction_hash_integrity ¶
func Cc017_transaction_hash_integrity(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
cc017_transaction_hash_integrity verifies that the transaction's data has not been tampered with.
func Cc018_state_consistency ¶
func Cc018_state_consistency(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
cc018_state_consistency ensures the final state is consistent with the preregistered state.
func Cc019_commit_consistency ¶
func Cc019_commit_consistency(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
cc019_commit_consistency ensures consistency between EXECUTE and COMMIT phases.
func Cc020_byzantine_fault_detection ¶
func Cc020_byzantine_fault_detection(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
cc020_byzantine_fault_detection analyzes discrepancies in node responses.
func Cc021_message_authenticity ¶
func Cc021_message_authenticity(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
cc021_message_authenticity verifies the cryptographic signature of a transaction.
func Cc022_network_partition_detection ¶
func Cc022_network_partition_detection(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
cc022_network_partition_detection detects if a transaction has not been seen by all expected nodes.
func Cc024_redundant_storage_consistency ¶
func Cc024_redundant_storage_consistency(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
cc024_redundant_storage_consistency verifies data replicated to secondary storage is consistent.
func Cc025_recovery_point_integrity ¶
func Cc025_recovery_point_integrity(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
cc025_recovery_point_integrity validates the current state against the last known good state.
func Cc029_amount_field_consistency ¶
func Cc029_amount_field_consistency(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
cc029_amount_field_consistency ensures amount arrays remain constant between Pre and Post-Registration.
func Cc031_executed_vs_finalized_transaction_count ¶
func Cc031_executed_vs_finalized_transaction_count(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc031_executed_vs_finalized_transaction_count ensures that for every transaction in a block, a corresponding execution result exists from the consensus engine.
func Cc032_block_size_consistency ¶
func Cc032_block_size_consistency(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
cc032_block_size_consistency verifies that the number of transactions in a block matches the network constant.
func Cc035_merkle_root_reconstruction ¶
func Cc035_merkle_root_reconstruction(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
cc035_merkle_root_reconstruction validates the integrity of the transaction data that forms the Merkle Root anchor. It fetches all transactions for a given block, reconstructs the Merkle tree, and compares the calculated root with the one stored in the block header.
func Cc036_transaction_and_metadata_correspondence ¶
func Cc036_transaction_and_metadata_correspondence(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc036_transaction_and_metadata_correspondence verifies that the metadata inside a transaction is not out of sync with the transaction's top-level properties.
func Cc039_proof_of_consistency ¶
func Cc039_proof_of_consistency(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc039_proof_of_consistency validates the append-only evolution of a Merkle root.
func Cc047_phantom_write ¶
func Cc047_phantom_write(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc047_phantom_write — STUBBED in the 23-field collapse (2026-05-23). Original check verified that a committed write resulted in a record existing in the data-receiving table, looked up via CoreMeta.ClassAKey; that field was removed in the metadata collapse. Record identity now lives in CoreMeta.RecordId (104-bit deterministic PK from INSERT...RETURNING), so this check should be rewired to use RecordId against the (Database, Schema, Table) tuple. Restore this check once the RecordId-based row-lookup path is wired.
func Cc048_lost_rollback ¶
func Cc048_lost_rollback(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc048_lost_rollback — STUBBED in the 23-field collapse (2026-05-23). Original check verified that an aborted transaction left no artifact row in the data-receiving table, keyed by CoreMeta.ClassAKey and gated on CoreMeta.OpCodeAbort; both fields were removed in the metadata collapse. Abort semantics moved to the workflow sequencer envelope; row identity moved to CoreMeta.RecordId. Restore this check when those signals are re-exposed in the new transaction-state surface.
func Cc049_out_of_order_commit ¶
func Cc049_out_of_order_commit(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc049_out_of_order_commit — STUBBED in the 23-field collapse (2026-05-23). Original check enforced monotonically-increasing CoreMeta.OrgTxSequence per-org; that field was removed in the metadata collapse. Per-org ordering is now established by CometBFT consensus + (BlockHeight, tx index within block) at the goldbftd layer, so a metadata-level sequence is no longer needed. Do not restore unless an org-level sequence is reintroduced for cross-network attribution.
func Cc050_replica_divergence ¶
func Cc050_replica_divergence(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
cc050_replica_divergence ensures the transaction outcome is identical across all nodes.
func Cc051_replay_detection_failure ¶
func Cc051_replay_detection_failure(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc051_replay_detection_failure prevents a transaction from being replayed across the federation.
func Cc052_inter_slab_drift ¶
func Cc052_inter_slab_drift(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc052_inter_slab_drift ensures consistency between data slabs.
func Cc053_transaction_gap ¶
func Cc053_transaction_gap(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc053_transaction_gap — STUBBED in the 23-field collapse (2026-05-23). Original check detected gaps in CoreMeta.OrgTxSequence; that field was removed in the metadata collapse. Gap detection at the org level is now implicit in CometBFT consensus + block-height monotonicity at the goldbftd layer. Do not restore unless an org-level sequence is reintroduced for cross-network attribution.
func Cc054_clock_skew_violation ¶
func Cc054_clock_skew_violation(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc054_clock_skew_violation detects if a block's timestamp is too far in the future.
func Cc055_stale_read_write ¶
func Cc055_stale_read_write(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc055_stale_read_write prevents transactions from being processed based on old data.
func Cc056_write_amplification_error ¶
func Cc056_write_amplification_error(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc056_write_amplification_error detects if a single transaction results in too many db writes.
func Cc061_state_bleed ¶
func Cc061_state_bleed(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc061_state_bleed detects if the temporary state from a previous transaction check was not properly cleared, causing it to "bleed" into the current check.
func Cc062_metadata_omission ¶
func Cc062_metadata_omission(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc062_metadata_omission checks for transactions with missing critical metadata fields.
func Cc066_cyclic_transaction_dependency ¶
func Cc066_cyclic_transaction_dependency(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc066_cyclic_transaction_dependency detects if a transaction is part of a dependency cycle.
func Cc067_orphaned_commit ¶
func Cc067_orphaned_commit(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc067_orphaned_commit ensures that a committed transaction has a corresponding successful execution result.
func Cc069_nonce_reuse ¶
func Cc069_nonce_reuse(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc069_nonce_reuse prevents replay attacks by ensuring that a nonce is used only once.
func Cc072_anomaly_window_leak ¶
func Cc072_anomaly_window_leak(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc072_anomaly_window_leak detects temporal ordering violations between dependent transactions.
func Cc075_transport_level_mismatch ¶
func Cc075_transport_level_mismatch(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc075_transport_level_mismatch ensures consistency between application and transport IDs.
func Cc076_double_acknowledgment ¶
func Cc076_double_acknowledgment(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc076_double_acknowledgment prevents a single transaction from being acknowledged more than once.
func Cc078_log_rewind_or_overwrite ¶
func Cc078_log_rewind_or_overwrite(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc078_log_rewind_or_overwrite detects if an immutable log has been tampered with.
func Cc079_query_path_drift ¶
func Cc079_query_path_drift(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc079_query_path_drift detects if the execution plan for a query has changed unexpectedly.
func Cc080_slab_compression_divergence ¶
func Cc080_slab_compression_divergence(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc080_slab_compression_divergence ensures all nodes produce an identical compressed slab.
func Cc082_transaction_range_overlap ¶
func Cc082_transaction_range_overlap(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc082_transaction_range_overlap detects if any transaction from the previous block is in the current block.
func Cc083_slow_commit_visibility ¶
func Cc083_slow_commit_visibility(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc083_slow_commit_visibility detects if any node is significantly lagging in block height.
func Cc085_schema_drift_between_nodes ¶
func Cc085_schema_drift_between_nodes(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc085_schema_drift_between_nodes verifies that all nodes have the same database schema.
func Cc086_redundant_slab_execution ¶
func Cc086_redundant_slab_execution(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc086_redundant_slab_execution detects if a slab of transactions is processed more than once.
func Cc087_transaction_id_reordering ¶
func Cc087_transaction_id_reordering(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc087_transaction_id_reordering — STUBBED in the 23-field collapse (2026-05-23). Original check detected per-client reordering within a block by comparing CoreMeta.OrgTxSequence values across txs; that field was removed in the metadata collapse. Per-client ordering is now enforced upstream by the gateway/CometBFT ingestion path (Entnum + block-deterministic ordering), so a metadata-level sequence is redundant. Do not restore unless an org-level sequence is reintroduced.
func Cc089_partial_crash_recovery ¶
func Cc089_partial_crash_recovery(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc089_partial_crash_recovery detects if a recovered node has an incomplete state for a block.
func Cc090_interceptor_state_desync ¶
func Cc090_interceptor_state_desync(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc090_interceptor_state_desync detects if the interceptor state has diverged from the final state.
func Cc091_inverted_causality_via_metadata ¶
func Cc091_inverted_causality_via_metadata(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc091_inverted_causality_via_metadata — STUBBED in the 23-field collapse (2026-05-23). Original check cross-validated CoreMeta.BlockHeight against the actual ABCI height and asserted a sanity bound on CoreMeta.OrgTxSequence vs CoreMeta.BlockHeight; OrgTxSequence was removed in the metadata collapse, so the second half of the check no longer compiles. The BlockHeight cross check is still meaningful and should be re-introduced as a separate lightweight check; do that as part of restoring this slot.
func Cc092_multi_stage_transaction_collapse ¶
func Cc092_multi_stage_transaction_collapse(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc092_multi_stage_transaction_collapse detects if intermediate stages of a multi-stage transaction are missing.
func Cc093_metrics_telemetry_mismatch ¶
func Cc093_metrics_telemetry_mismatch(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc093_metrics_telemetry_mismatch detects if nodes report inconsistent operational metrics.
func Cc094_immutable_slab_mutation ¶
func Cc094_immutable_slab_mutation(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc094_immutable_slab_mutation ensures a transaction does not write to a finalized slab.
func Cc095_slab_boundary_drift ¶
func Cc095_slab_boundary_drift(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc095_slab_boundary_drift ensures all nodes agree on slab boundaries.
func Cc098_transaction_alias_collision ¶
func Cc098_transaction_alias_collision(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc098_transaction_alias_collision detects if two different transactions use the same alias.
func Cc099_ledger_height_skew ¶
func Cc099_ledger_height_skew(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc099_ledger_height_skew detects if any node's block height is significantly different.
func Cc103_trace_count_disagreement ¶
func Cc103_trace_count_disagreement(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc103_trace_count_disagreement ensures all nodes have the same number of transaction traces.
func Cc104_stale_recovery_view ¶
func Cc104_stale_recovery_view(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc104_stale_recovery_view ensures that the data in a recovery point is not excessively old.
func Cc105_behavioral_drift_between_node_versions ¶
func Cc105_behavioral_drift_between_node_versions(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc105_behavioral_drift_between_node_versions detects if different software versions of nodes in the network produce different outcomes for the same transaction, indicating a non-deterministic bug or an unhandled breaking change.
func Cc106_replay_window_violation ¶
func Cc106_replay_window_violation(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc106_replay_window_violation ensures a transaction is not replayed outside a predefined window.
func Cc107_context_detached_execution ¶
func Cc107_context_detached_execution(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc107_context_detached_execution — STUBBED in the 23-field collapse (2026-05-23). Original check verified that a transaction's CoreMeta.SessionId resolves to a live session via the SessionContextProvider; that field was removed in the metadata collapse. Session validation now happens at the gateway auth.Verifier layer (Identity → Meta.Entnum), so an end-of-block session re-check is redundant. Restore if a session-bound execution invariant becomes load-bearing again.
func Cc108_unconsumed_compensation_logic ¶
func Cc108_unconsumed_compensation_logic(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc108_unconsumed_compensation_logic — STUBBED in the 23-field collapse (2026-05-23). Original check fired on CoreMeta.OpCodeAbort + FED_TRANSFER_REQUEST and verified that a compensating action had been recorded; OpCodeAbort was removed in the metadata collapse, and the feds layer itself was collapsed on 2026-05-22 so FED_TRANSFER_REQUEST is no longer a live request type. Saga/compensation tracking will resurface in the workflow sequencer envelope. Restore (and rewire to the sequencer) when that lands.
func Cc109_immutable_event_re_emission ¶
func Cc109_immutable_event_re_emission(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc109_immutable_event_re_emission prevents an immutable event from being emitted more than once with different data.
func Cc112_partial_merkle_proof_failure ¶
func Cc112_partial_merkle_proof_failure(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc112_partial_merkle_proof_failure verifies the Merkle proof for a transaction.
func Cc113_immutable_field_overwrite ¶
func Cc113_immutable_field_overwrite(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc113_immutable_field_overwrite — STUBBED in the 23-field collapse (2026-05-23). Original check compared a transaction's CoreMeta.SourceAccountId and CoreMeta.TargetAccountId against the pre-registered trace to detect post-hoc overwrites; both fields were removed in the metadata collapse. Banking-style payment fields are no longer first-class CoreMeta — they live in domain-specific payment envelopes. Restore (and rewire to the payment envelope) when the new payment schema is in place.
func Cc122_cross_slab_state_corruption ¶
func Cc122_cross_slab_state_corruption(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc122_cross_slab_state_corruption detects if state from one slab incorrectly influences another.
func Cc123_inflight_transaction_loss ¶
func Cc123_inflight_transaction_loss(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc123_inflight_transaction_loss detects if preregistered transactions were lost after a failover.
func Cc124_toctou_vulnerabilities ¶
func Cc124_toctou_vulnerabilities(tx *generalv1.TransactionRequest, height int64, prov *providers.ProviderRegistry) *checks.CheckError
Cc124_toctou_vulnerabilities attempts to detect Time-of-Check to Time-of-Use race conditions.
func Cc125_resource_exhaustion_attacks ¶
func Cc125_resource_exhaustion_attacks(height int64, txs types.Txs, prov *providers.ProviderRegistry) *checks.CheckError
Cc125_resource_exhaustion_attacks monitors node metrics for signs of resource exhaustion attacks.
func Cc130_bpd_violation_listener ¶
func Cc130_bpd_violation_listener(ctx context.Context, prov *providers.ProviderRegistry) *checks.CheckError
Cc130_bpd_violation_listener is a continuous check that polls the BPDViolationListener for member-class BPD violations and surfaces them at the fed/agg/tophats tier. This check does NOT run on the member-class checker (chubbychecker-joint) — it is intended for non-member tiers that need visibility into Overseer governance failures without running the BPD checks themselves.
When a catastrophic BPD violation is detected at the member level, this check propagates it as a CatastrophicFailure so the higher tier can trigger its own escalation/halt logic.
func RegisterDefault ¶
RegisterDefault matches what your main_BAK.go expects. It *only* enables/disables named checks; it does NOT auto-register checks. (Checks should call reg.Register(...) from their own init() or from a central binder.)
func SetChainRootProvider ¶
func SetChainRootProvider(fn ChainRootProvider)
Types ¶
type AnchorTSProvider ¶
AnchorTSProvider is used by checks that need an "anchor timestamp" for a given height. If compilation later shows the call-site expects a different signature, adjust this typedef ONLY (don’t touch every check).
type ChainRootProvider ¶
type Registry ¶
type Registry struct {
// contains filtered or unexported fields
}
Registry holds checks and an optional enabled-set.
func DefaultRegistry ¶
func DefaultRegistry() *Registry
DefaultRegistry matches what your main_BAK.go calls.
func NewRegistry ¶
func NewRegistry() *Registry
func (*Registry) EnableOnly ¶
type TraceTx ¶
type TraceTx struct {
Phase string `json:"phase,omitempty"`
TxUUID string `json:"tx_uuid,omitempty"`
UUID string `json:"uuid,omitempty"` // some traces use uuid instead of tx_uuid
Amount string `json:"amount,omitempty"`
Currency string `json:"currency,omitempty"`
BlockHash string `json:"block_hash,omitempty"`
PrevBlockHash string `json:"prev_block_hash,omitempty"`
NodeID string `json:"node_id,omitempty"`
SchemaVer string `json:"schema_version,omitempty"`
Timestamp string `json:"timestamp,omitempty"`
}
TraceTx is a tolerant “minimum” trace envelope. Add fields as you need them. Unknown JSON fields are ignored automatically.
Source Files
¶
- cc001_reliance-on-dns.go
- cc003_sql-injection-attacks.go
- cc004_sybil-attacks-routing-vulnerability.go
- cc005_content-poisoning-and-misrouting.go
- cc006_node-churn-and-reconnection-logic.go
- cc007_latency-and-reliability-trade-offs.go
- cc008_legal-and-auditing-concerns.go
- cc011_state-hash-consistency.go
- cc012_node-identities.go
- cc013_continuous-block-sequence-numbers.go
- cc016_block-hash-integrity.go
- cc017_transaction-hash-integrity.go
- cc018_state-consistency.go
- cc019_commit-consistency.go
- cc020_byzantine-fault-detection.go
- cc021_message-authenticity.go
- cc022_network-partition-detection.go
- cc024_redundant-storage-consistency.go
- cc025_recovery-point-integrity.go
- cc029_amount-field-consistency.go
- cc031_executed_vs_finalized_transaction_count.go
- cc032_transactions-per-block-count.go
- cc035_merkle-root_reconstruction.go
- cc036_transaction-and-metadata-correspondence.go
- cc039_proof-of-consistency.go
- cc047_phantom-write.go
- cc048_lost-rollback.go
- cc049_out_of_order-commit.go
- cc050_replica-divergence.go
- cc051_replay-detection-failure.go
- cc052_inter-slab-drift.go
- cc053_transaction-gap.go
- cc054_clock-skew-violation.go
- cc055_stale-read-write.go
- cc056_write-amplification-error.go
- cc061_state-bleed.go
- cc062_metadata-omission.go
- cc066_cyclic-transaction-dependency.go
- cc067_orphaned-commit.go
- cc069_nonce-reuse.go
- cc072_anomaly-window-leak.go
- cc075_transport-level-mismatch.go
- cc076_double-acknowledgment.go
- cc078_log-rewind-or-overwrite.go
- cc079_query-path-drift.go
- cc080_slab-compression-divergence.go
- cc082_transaction_range_overlap.go
- cc083_slow-commit-visibility.go
- cc085_schema-drift-between-nodes.go
- cc086_redundant-slab-execution.go
- cc087_transaction-id-reordering.go
- cc089_partial-crash-recovery.go
- cc090_interceptor-state-desync.go
- cc091_inverted-causality_via_metadata.go
- cc092_multi-stage-transaction-collapse.go
- cc093_metrics-telemetry-mismatch.go
- cc094_immutable-slab-mutation.go
- cc095_slab-boundary-drift.go
- cc098_transaction-alias-collision.go
- cc099_ledger-height-skew.go
- cc103_trace-count-disagreement.go
- cc104_stale-recovery-view.go
- cc105_behavioral-drift-between-node-versions.go
- cc106_replay-window-violation.go
- cc107_context-detached-execution.go
- cc108_unconsumed-compensation-logic.go
- cc109_immutable-event-re-emission.go
- cc112_partial-merkle-proof-failure.go
- cc113_immutable-field-overwrite.go
- cc122_cross_slab_state_corruption.go
- cc123_inflight_transaction_loss.go
- cc124_toctou_vulnerabilities.go
- cc125_resource_exhaustion_attacks.go
- cc130_bpd-violation-listener.go
- constants.go
- helpers.go
- registry.go
- registry_replace.go
- registry_v3.go
- trace_parse.go