Agent skill

Ledger Gotchas

by txpipe in txpipe/dolos

Reference of non-obvious Cardano ledger behaviors that have caused bugs in Dolos.

Apache-2.0Auto-check passedDevelopment

Install Ledger Gotchas

skills CLI
$ npx skills add txpipe/dolos --skill ledger-gotchas -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install txpipe/dolos ledger-gotchas --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/txpipe/dolos.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ledger-gotchas .claude/skills/ledger-gotchas && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ledger-gotchas
GitHub stars
138
Token cost
~2.8k tokens
SKILL.md length
1,453 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
Apache-2.0

At a glance

Reference of non-obvious Cardano ledger behaviors that have caused bugs in Dolos.

  • Works in 3 steps: applyRUpd -- rewards applied to accounts → SNAP -- new mark snapshot captured;… → POOLREAP -- pools retired, deposits…
  • Development work in your project
  • SKILL.md covers Certificate Processing Order, NEWEPOCH Sub-Rule Ordering, EpochValue Snapshot Write… and DBSync epoch_stake Mapping, plus 14 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ledger Gotchas is an agent skill from txpipe/dolos. Reference of non-obvious Cardano ledger behaviors that have caused bugs in Dolos. Consult when debugging epoch pots mismatches or implementing new ledger logic.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. The licence is Apache-2.0.

When your agent uses it

  • Development work in your project

Example prompts

  • “/ledger-gotchas”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. applyRUpd -- rewards applied to accounts
  2. SNAP -- new mark snapshot captured; future pool params become current
  3. POOLREAP -- pools retired, deposits refunded

What it can do on your machine

Read from SKILL.md and the folder at commit 7e973ea. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ledger Gotchas loads about 2.8k tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 1,453 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~44
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from txpipe/dolos at commit 7e973ea, republished under its Apache-2.0 licence (© txpipe). 1,453 words, ~2,835 tokens.

Download SKILL.mdSave it as .claude/skills/ledger-gotchas/SKILL.md (or your agent's skills folder).
name
ledger-gotchas
description
Reference of non-obvious Cardano ledger behaviors that have caused bugs in Dolos. Consult when debugging epoch pots mismatches or implementing new ledger logic.
user-invocable
false

Cardano Ledger Gotchas

Non-obvious behaviors in the Cardano ledger that differ from naive expectations. Each of these has caused at least one bug in Dolos. When debugging a mismatch or implementing new ledger logic, check this list first.


Certificate Processing Order

Gotcha: There is NO priority system for certificates. The Haskell ledger processes certificates in the exact order they appear in the block (tx order, then cert order within tx). A deregistration in tx 7 followed by a registration in tx 10 results in the account being registered.

What went wrong: Dolos had a priority() method that sorted deltas (registration=0, deregistration=5), causing certificates to apply out of order. A dereg+reg in the same slot resulted in the account appearing deregistered.

Rule: Always apply deltas in natural block traversal order. Never sort or reorder them.


NEWEPOCH Sub-Rule Ordering

Gotcha: The three NEWEPOCH sub-rules execute in this exact order:

  1. applyRUpd -- rewards applied to accounts
  2. SNAP -- new mark snapshot captured; future pool params become current
  3. POOLREAP -- pools retired, deposits refunded

Consequence: SNAP happens BEFORE POOLREAP. Pool deposit refunds from POOLREAP are NOT captured in the mark snapshot for that transition. They first appear in the NEXT epoch's mark.

Consequence: SNAP moves future pool params to current BEFORE POOLREAP runs. So when POOLREAP refunds a deposit, it uses the new pool params (potentially a different reward account than when the pool was originally registered).


EpochValue Snapshot Write Targets

Gotcha: Different operations write to different snapshot slots, which propagate to mark at different times.

OperationWrites toAppears in mark
unwrap_live_mut()liveNext transition (E+1)
scheduled_or_default()nextTwo transitions later (E+2)

EWRAP reward visitors use unwrap_live_mut() (writes to live). EWRAP refund visitors (pool deposits, proposal deposits) use scheduled_or_default() (writes to next). This means refunds and rewards propagate to the stake snapshot at different times.


DBSync epoch_stake Mapping

Gotcha: epoch_stake.epoch_no = N corresponds to the set snapshot at epoch N, which equals the mark snapshot captured at NEWEPOCH N-1, which reflects account state as of the end of epoch N-2.

This is the stake distribution used for leader election in epoch N. When comparing dolos stake against DBSync at performance_epoch = subject_epoch - 2, the fixture filename is stake-{performance_epoch}.csv.


Pre-Alonzo MIR Overwrite (protocol < 5)

Gotcha: Before Alonzo, MIR certificates for the same address OVERWRITE previous values rather than accumulating. Haskell uses Map.union (pre-Alonzo) vs Map.unionWith (<>) (Alonzo+).

Example: Two MIR certs for the same address: 100M then 32M. Pre-Alonzo result = 32M (last wins). Alonzo+ result = 132M (sum).

Rule: When protocol_version < 5, set overwrite = true on EnqueueMir. Only the last MIR per address per epoch is applied.


Pre-Allegra Reward Deduplication (protocol < 3)

Gotcha: Before Allegra, each stake address receives at most ONE reward per epoch, even if delegated to multiple pools. The Haskell ledger uses Set.deleteFindMin to keep the minimum element per the Ord Reward instance.

Ord Reward rules:

  1. LeaderReward < MemberReward (leader wins over member)
  2. Same type: smaller pool ID (by hash bytes) wins

Rule: When protocol < 3, if an account has multiple rewards, keep the one with the smallest (reward_type, pool_id) tuple. Leader < Member, then lexicographic pool hash comparison.


Eta Calculation: Pool Blocks Only

Gotcha: The eta (η) monetary expansion calculation uses only pool-produced blocks, NOT total blocks. Federated/OBFT blocks are excluded.

η = min(1, pool_blocks / ((1-d) × f × L))

The Haskell ledger's BlocksMade map only tracks stake pool blocks. Using total blocks_minted (which includes federated blocks) inflates η and produces ~2.75% higher rewards during the decentralization transition.

Rule: Sum blocks_minted from individual pool snapshots only. Do not use rolling.mark().blocks_minted.


Unspendable Rewards: Two Filter Points, Two Destinations

Gotcha: Rewards for unregistered accounts are filtered at TWO different points, with different routing:

Filter 1: At RUPD time (stability window)
  • Protocol < 7 (pre-Babbage): Unregistered accounts are excluded from reward calculation entirely (hardforkBabbageForgoRewardPrefilter). Their would-be rewards stay in reserves (never leave the reward pot).
  • Protocol >= 7 (Babbage+): Rewards are calculated for ALL accounts regardless of registration.
Filter 2: At EWRAP time (epoch boundary)
  • Accounts that were registered at RUPD but deregistered by EWRAP have their rewards routed to treasury. This happens regardless of protocol version.
  • This matches frTotalUnregistered → casTreasury in applyRUpdFiltered.

Rule: EWRAP-filtered rewards ALWAYS go to treasury. Never route them to reserves based on protocol version.


RUPD Fires at randomnessStabilisationWindow, Not stabilityWindow

Gotcha: RUPD fires at 4k/f slots into the epoch (randomness stability window = 172,800 on mainnet), NOT at 3k/f (stability window = 129,600).

Accounts that deregister between 3k/f and 4k/f are still registered when RUPD runs. If you use the wrong boundary, these accounts are incorrectly excluded from reward calculation.


Pre-Conway Proposal Timing

Gotcha: Pre-Conway (protocol 0-8) update proposals usually follow a 1-epoch lag: ratified in the submission epoch, enacted at EWRAP, effect at ESTART of next epoch. The RatifiedCurrentEpoch fallback handles this.

Exceptions:

  • Proposals submitted one epoch before their target d-parameter epoch need explicit Ratified(target_epoch) entries to avoid enacting one epoch too early.
  • Split-quorum proposals (submitted across two epochs) need Ratified() set to the epoch where quorum was actually reached.
  • The preview v7→v8 transition anomalously shows a 2-epoch lag.

Conway Governance Proposals Must Be Hardcoded

Gotcha: Dolos doesn't implement DRep governance voting. All Conway proposal outcomes (ratified/canceled/expired) are hardcoded in crates/cardano/src/hacks.rs. Missing entries cause:

  • Wrong deposit refund timing (proposal expires instead of being enacted)
  • Missed treasury withdrawals
  • Committee/constitution not updated

Rule: Ratified(enacted_epoch - 1) from DBSync's gov_action_proposal.enacted_epoch. Dropped proposals that expired naturally (dropped_epoch = expired_epoch + 1) don't need entries; the Unknown outcome lets them expire via max_epoch.


Show full SKILL.md (562 more words)Show less

Pool Deposit Refund Account

Gotcha: When a pool retires, the deposit is refunded to the pool's reward account. But pools can be re-registered with a different reward account. The refund goes to whichever reward account is current at POOLREAP time (after SNAP has already moved future params to current).

Check the full pool_update history in DBSync -- active_epoch_no determines when new params take effect. The last update active before the retirement epoch determines the refund recipient.


Pointer Addresses

Gotcha: Pointer addresses encode (slot, tx_idx, cert_idx) to reference a stake registration certificate. Many on-chain pointer addresses contain intentionally garbage values (e.g., (12, 12, 12)) that point to nonexistent registrations. These map to None (no stake rights).

Dolos resolves pointers via a hardcoded lookup table in hacks.rs. New valid pointers must be resolved by querying DBSync's stake_registration table.


Pointer Address Overflow Values

Gotcha: Pointer address components are encoded as variable-length integers in the address bytes, but Cardano decodes them as unbounded integers. Values can overflow u64 or contain astronomically large numbers like 18446744073709551615 (u64::MAX) or 16292793057. These are NOT necessarily invalid -- some overflow pointers resolve to real stake credentials on-chain.

Example from mainnet:

  • (18446744073709551615, 1221092, 2) → maps to a VALID AddrKeyhash
  • (16292793057, 1011302, 20) → maps to None

Resolution: The standard DBSync SQL query (WHERE block.slot_no = <SLOT>) won't work for overflow pointers since the slot is invalid. Instead, use a block explorer to look up the full bech32 address (addr1g...) -- explorers typically show the resolved stake address. Multiple pointer addresses can share the same payment credential but have different pointer tuples; each tuple needs its own mapping entry.


Deposit Constants by Network

ConstantMainnetPreprod/Preview
Pool deposit500,000,000 lovelace500,000,000 lovelace
Key deposit2,000,000 lovelace2,000,000 lovelace

When a delegation/stake diff is off by exactly one of these constants, it's almost certainly a deposit refund or registration timing issue.


Pots Invariant

The total lovelace in the system is always exactly 45,000,000,000,000,000 (45 billion ADA):

reserves + treasury + utxos + rewards + fees + obligations = max_supply

If any pot is wrong, the error must appear somewhere else with opposite sign. Use this invariant to cross-check: if treasury is too low by X, then X must be too high in some other pot (usually reserves or rewards).


Single Stake Error Cascades Into Many Reward Diffs

Gotcha: A single account's stake being off by N lovelace changes that pool's total stake, which changes the reward calculation for ALL the pool's delegators -- producing hundreds or thousands of ±1 lovelace rounding differences.

How to recognize:

  • stake diff shows 1 account off by an exact amount (e.g., 3,001,337)
  • delegation diff shows 1 pool's total off by the same amount
  • rewards diff shows many ±1 differences, all for delegators of that same pool
  • epochs diff shows reserves/rewards off by a small amount (net rounding effect)

Rule: When you see this pattern, ignore the reward diffs entirely. Find and fix the single stake root cause, and all diffs resolve together.


Mismatch Diagnosis by Work Unit

Gotcha: The shape of a mismatch tells you which work unit is wrong:

SymptomLikely work unit
Equal and opposite deltas between rewards and treasuryEWRAP -- unspendable reward routing
Rewards match but pots don'tEWRAP/ESTART -- pot aggregation or unspendable handling
Only a subset of pools/accounts affectedROLL -- registration/retirement window or pool parameter update timing
Rounded or exact small deltaRUPD/EWRAP -- conditional logic or boundary condition
Thousands of ±1 reward diffs for one poolROLL/ESTART -- single stake error cascade (see above)

© txpipe, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/ledger-gotchas of txpipe/dolos.

Open the folder on GitHubat commit 7e973ea

Compare with similar skills

Ledger Gotchas next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ledger Gotchas compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ledger Gotchas this skilltxpipe/dolos138—~2.8kAutomated safety check: PassApache-2.0
Vercel Composition Patternssupabase/supabase111k59 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 59 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from txpipe/dolos

  • Systematic workflow for debugging Cardano ledger epoch pots mismatches in Dolos.

    138 GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • Update Docs

    txpipe/dolos

    Reconcile the user-facing documentation under docs/content/ with the current source-of-truth in the codebase.

    138 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Add Epoch Test

    txpipe/dolos

    Set up a new epochpots integration test with ground truth fixtures from DBSync

    138 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Add a missing pointer address mapping to hacks.rs by looking up the stake credential in DBSync

    138 GitHub stars~840 tokensUpdated today
    Auto-check passed
  • Dolos Pipeline

    txpipe/dolos

    Architecture of the Dolos processing pipeline — WorkUnit lifecycle, executor modes, CardanoWorkUnit variants, WorkBuffer state machine, and sequencing.

    138 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Update Proposals

    txpipe/dolos

    Update hardcoded Conway governance proposal mappings in hacks.rs by querying DBSync

    138 GitHub stars~1.6k tokensUpdated today
    Auto-check passed

Categories

Questions about Ledger Gotchas

What does Ledger Gotchas do?

Reference of non-obvious Cardano ledger behaviors that have caused bugs in Dolos. Ledger Gotchas is an agent skill from txpipe/dolos. Reference of non-obvious Cardano ledger behaviors that have caused bugs in Dolos.

When should I use Ledger Gotchas?

Ledger Gotchas fits situations like: development work in your project.

How do I install Ledger Gotchas in Claude Code?

Run `npx skills add txpipe/dolos --skill ledger-gotchas -a claude-code`. Or copy the skill folder (skills/ledger-gotchas in txpipe/dolos) into .claude/skills/ledger-gotchas in your project. Claude Code loads it when a task matches its description.

How do I install Ledger Gotchas in Codex?

Run `npx skills add txpipe/dolos --skill ledger-gotchas -a codex`. Or copy the skill folder (skills/ledger-gotchas in txpipe/dolos) into .agents/skills/ledger-gotchas in your project. Codex loads it when a task matches its description.

Can I use Ledger Gotchas in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add txpipe/dolos --skill ledger-gotchas -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ledger-gotchas, .gemini/skills/ledger-gotchas, .github/skills/ledger-gotchas and .opencode/skills/ledger-gotchas in your project.

What does Ledger Gotchas need to run?

SKILL.md names no scripts, command-line tools or credentials: Ledger Gotchas is instructions for the agent only.

Does Ledger Gotchas access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ledger Gotchas safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ledger Gotchas use?

Ledger Gotchas is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ledger Gotchas use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ledger Gotchas?

Skills that share tags, products or a category with Ledger Gotchas: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ledger Gotchas?

txpipe (a GitHub organization) maintains it in txpipe/dolos, which has 138 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 8, 2026.

Source: txpipe/dolos on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.