trustedpeer/TrustedPeerRegistry.hpp¶
Genesis-seeded, quorum-updatable trusted-peer set built entirely on top of Phase 9's SecureCrdt/SecureCrdtRegistry/ISignedCRDTData machinery. This is the first real (non-test) consumer of the SecureCRDT layer, and the signer-set-source dependency Phase 11 (BURN_BASIS_POINTS) will build on (TPR-01, TPR-02, TPR-03). More...
Namespaces¶
| Name |
|---|
| sgns |
| sgns::trustedpeer |
Classes¶
| Name | |
|---|---|
| class | sgns::trustedpeer::TrustedPeerListPayload ISignedCRDTData payload type carrying the trusted-peer list. Serialization is a newline-joined encoding of the peer address list (addresses are 128-char hex strings and never contain ' '). Verify() performs structural validation ONLY (non-empty, no duplicates, each entry exactly 128 lowercase-hex characters) – it never diffs against any cached/mutable state (Pitfall 4). |
| class | sgns::trustedpeer::TrustedPeerRegistry Genesis-seeded, in-memory-cached, quorum-updatable trusted-peer set. Delegates ALL signature/quorum logic to SecureCrdt / SecureCrdtRegistry – no bespoke signature/quorum logic exists here (TPR-03). |
Functions¶
| Name | |
|---|---|
| OUTCOME_HPP_DECLARE_ERROR_2(sgns::trustedpeer , TrustedPeerRegistry::Error ) |
Detailed Description¶
Genesis-seeded, quorum-updatable trusted-peer set built entirely on top of Phase 9's SecureCrdt/SecureCrdtRegistry/ISignedCRDTData machinery. This is the first real (non-test) consumer of the SecureCRDT layer, and the signer-set-source dependency Phase 11 (BURN_BASIS_POINTS) will build on (TPR-01, TPR-02, TPR-03).
Date: 2026-07-24 Henrique A. Klein ([email protected])
Functions Documentation¶
function OUTCOME_HPP_DECLARE_ERROR_2¶
Source code¶
#ifndef SGNS_TRUSTEDPEER_TRUSTEDPEERREGISTRY_HPP
#define SGNS_TRUSTEDPEER_TRUSTEDPEERREGISTRY_HPP
#include <cstdint>
#include <functional>
#include <memory>
#include <optional>
#include <shared_mutex>
#include <string>
#include <vector>
#include "base/logger.hpp"
#include "crdt/hierarchical_key.hpp"
#include "outcome/outcome.hpp"
#include "peerregistry/PeerRegistry.hpp"
#include "securecrdt/ISignedCRDTData.hpp"
#include "securecrdt/SecureCrdt.hpp"
#include "securecrdt/SecureCrdtRegistry.hpp"
#include "trustedpeer/GenesisManifest.hpp"
#include "trustedpeer/QuorumPolicy.hpp"
#include "trustedpeer/TrustStateStore.hpp"
namespace sgns::trustedpeer
{
class TrustedPeerListPayload : public sgns::securecrdt::ISignedCRDTData
{
public:
TrustedPeerListPayload() = default;
explicit TrustedPeerListPayload( std::vector<std::string> peers );
static std::optional<TrustedPeerListPayload> FromBytes( const std::vector<uint8_t> &bytes );
std::vector<uint8_t> SerializeToBytes() const override;
bool DeserializeFromBytes( const std::vector<uint8_t> &bytes ) override;
bool Verify( const std::vector<uint8_t> &payload ) const override;
void Apply() override;
const std::vector<std::string> &GetPeers() const
{
return peers_;
}
private:
std::vector<std::string> peers_;
};
class TrustedPeerRegistry : public sgns::peerregistry::PeerRegistry,
public std::enable_shared_from_this<TrustedPeerRegistry>
{
public:
enum class Error : uint8_t
{
NOT_CONFIRMED = 0,
INVALID_CANDIDATE,
SIGNING_UNAVAILABLE,
};
using SignCallback = std::function<std::vector<uint8_t>( const std::vector<uint8_t> & )>;
TrustedPeerRegistry( std::shared_ptr<sgns::securecrdt::SecureCrdt> secure_crdt,
std::vector<std::string> genesis_peers,
std::string bootstrapper_address,
uint64_t quorum_threshold,
sgns::crdt::HierarchicalKey base_key );
~TrustedPeerRegistry();
static outcome::result<std::shared_ptr<TrustedPeerRegistry>> New(
std::shared_ptr<sgns::securecrdt::SecureCrdt> secure_crdt,
std::vector<std::string> genesis_peers,
std::string bootstrapper_address,
uint64_t quorum_threshold,
sgns::crdt::HierarchicalKey base_key = sgns::crdt::HierarchicalKey( "trusted-peer-registry" ) );
static outcome::result<std::shared_ptr<TrustedPeerRegistry>> NewProduction(
std::shared_ptr<sgns::securecrdt::SecureCrdt> secure_crdt,
std::shared_ptr<TrustStateStore> trust_store,
GenesisManifest reviewed_manifest,
std::vector<uint8_t> bootstrap_manifest_signature,
std::string local_signer_address,
SignCallback sign_callback,
std::string policy_domain = "trusted-peer" );
outcome::result<sgns::securecrdt::CandidateId> SubmitReviewedGenesisApproval();
outcome::result<bool> TryActivateReviewedGenesisCandidate( const sgns::securecrdt::CandidateId &candidate_id );
outcome::result<std::vector<sgns::securecrdt::CandidateId>> ListPendingPolicyCandidates() const;
outcome::result<sgns::securecrdt::CandidateId> ProposePolicyCandidate( const QuorumPolicyState &candidate );
outcome::result<sgns::securecrdt::CandidateId> ApprovePolicyCandidate(
const sgns::securecrdt::CandidateId &candidate_id );
outcome::result<bool> TryActivatePolicyCandidate( const sgns::securecrdt::CandidateId &candidate_id );
outcome::result<ConfirmedTrustSnapshot> GetConfirmedSnapshot() const;
[[nodiscard]] static std::optional<sgns::securecrdt::CandidateCore> PolicyCandidateCore(
const QuorumPolicyState &candidate,
const std::string &domain = "trusted-peer" );
outcome::result<void> SeedGenesis( const std::vector<std::string> &genesis_peers,
const std::vector<uint8_t> &ephemeral_signature );
outcome::result<void> ProposeMembershipChange( const std::vector<std::string> &new_peers );
outcome::result<void> SignMembershipChange( const std::string &signer_address,
const std::vector<uint8_t> &signature );
outcome::result<bool> TryConfirm();
outcome::result<sgns::securecrdt::SignerSetSnapshot> CurrentSignerSet() const override;
std::vector<std::string> GetCurrentPeers() const override;
sgns::crdt::HierarchicalKey BaseKey() const override
{
return base_key_;
}
bool IsGenesisConfirmed() const;
void Unregister();
private:
bool RegisterSignerSetSource();
outcome::result<sgns::securecrdt::SignerSetSnapshot> ResolveSignerSet() const;
bool RegisterProductionDomains();
outcome::result<sgns::securecrdt::CandidateAuthorizationSnapshot> ResolveGenesisAuthorization() const;
outcome::result<sgns::securecrdt::CandidateAuthorizationSnapshot> ResolvePolicyAuthorization() const;
outcome::result<sgns::securecrdt::CandidateId> SubmitLocalApproval(
const sgns::securecrdt::CandidateCore &core );
void PublishSnapshot( const ConfirmedTrustSnapshot &snapshot );
std::shared_ptr<sgns::securecrdt::SecureCrdt> secure_crdt_;
sgns::crdt::HierarchicalKey base_key_;
std::string bootstrapper_address_;
uint64_t quorum_threshold_;
mutable std::shared_mutex cache_mutex_;
std::vector<std::string> cached_peers_;
bool genesis_confirmed_ = false;
int registry_token_ = 0;
bool production_mode_ = false;
std::shared_ptr<TrustStateStore> trust_store_;
GenesisManifest reviewed_manifest_;
std::vector<uint8_t> bootstrap_manifest_signature_;
std::string local_signer_address_;
SignCallback sign_callback_;
std::string policy_domain_ = "trusted-peer";
std::string genesis_domain_ = "trusted-peer-genesis";
sgns::base::Logger logger_ = sgns::base::createLogger( "TrustedPeerRegistry" );
};
} // namespace sgns::trustedpeer
OUTCOME_HPP_DECLARE_ERROR_2( sgns::trustedpeer, TrustedPeerRegistry::Error );
#endif // SGNS_TRUSTEDPEER_TRUSTEDPEERREGISTRY_HPP
Updated on 2026-10-10 at 04:54:24 +0000