Skip to content

trustedpeer/TrustedPeerRegistry.hpp

Genesis-seeded, quorum-updatable trusted-peer set built entirely on top of Phase 9's SecureCrdt/SecureCrdtRegistry/ISignedCRDTData machinery. This is the first real (non-test) consumer of the SecureCRDT layer, and the signer-set-source dependency Phase 11 (BURN_BASIS_POINTS) will build on (TPR-01, TPR-02, TPR-03). More...

Namespaces

Name
sgns
sgns::trustedpeer

Classes

Name
class sgns::trustedpeer::TrustedPeerListPayload
ISignedCRDTData payload type carrying the trusted-peer list. Serialization is a newline-joined encoding of the peer address list (addresses are 128-char hex strings and never contain ' '). Verify() performs structural validation ONLY (non-empty, no duplicates, each entry exactly 128 lowercase-hex characters) – it never diffs against any cached/mutable state (Pitfall 4).
class sgns::trustedpeer::TrustedPeerRegistry
Genesis-seeded, in-memory-cached, quorum-updatable trusted-peer set. Delegates ALL signature/quorum logic to SecureCrdt / SecureCrdtRegistry – no bespoke signature/quorum logic exists here (TPR-03).

Functions

Name
OUTCOME_HPP_DECLARE_ERROR_2(sgns::trustedpeer , TrustedPeerRegistry::Error )

Detailed Description

Genesis-seeded, quorum-updatable trusted-peer set built entirely on top of Phase 9's SecureCrdt/SecureCrdtRegistry/ISignedCRDTData machinery. This is the first real (non-test) consumer of the SecureCRDT layer, and the signer-set-source dependency Phase 11 (BURN_BASIS_POINTS) will build on (TPR-01, TPR-02, TPR-03).

Date: 2026-07-24 Henrique A. Klein ([email protected])

Functions Documentation

function OUTCOME_HPP_DECLARE_ERROR_2

OUTCOME_HPP_DECLARE_ERROR_2(
    sgns::trustedpeer ,
    TrustedPeerRegistry::Error 
)

Source code

#ifndef SGNS_TRUSTEDPEER_TRUSTEDPEERREGISTRY_HPP
#define SGNS_TRUSTEDPEER_TRUSTEDPEERREGISTRY_HPP

#include <cstdint>
#include <functional>
#include <memory>
#include <optional>
#include <shared_mutex>
#include <string>
#include <vector>

#include "base/logger.hpp"
#include "crdt/hierarchical_key.hpp"
#include "outcome/outcome.hpp"
#include "peerregistry/PeerRegistry.hpp"
#include "securecrdt/ISignedCRDTData.hpp"
#include "securecrdt/SecureCrdt.hpp"
#include "securecrdt/SecureCrdtRegistry.hpp"
#include "trustedpeer/GenesisManifest.hpp"
#include "trustedpeer/QuorumPolicy.hpp"
#include "trustedpeer/TrustStateStore.hpp"

namespace sgns::trustedpeer
{
    class TrustedPeerListPayload : public sgns::securecrdt::ISignedCRDTData
    {
    public:
        TrustedPeerListPayload() = default;

        explicit TrustedPeerListPayload( std::vector<std::string> peers );

        static std::optional<TrustedPeerListPayload> FromBytes( const std::vector<uint8_t> &bytes );

        std::vector<uint8_t> SerializeToBytes() const override;
        bool DeserializeFromBytes( const std::vector<uint8_t> &bytes ) override;
        bool Verify( const std::vector<uint8_t> &payload ) const override;
        void Apply() override;

        const std::vector<std::string> &GetPeers() const
        {
            return peers_;
        }

    private:
        std::vector<std::string> peers_;
    };

    class TrustedPeerRegistry : public sgns::peerregistry::PeerRegistry,
                                public std::enable_shared_from_this<TrustedPeerRegistry>
    {
    public:
        enum class Error : uint8_t
        {
            NOT_CONFIRMED = 0,
            INVALID_CANDIDATE,
            SIGNING_UNAVAILABLE,
        };

        using SignCallback = std::function<std::vector<uint8_t>( const std::vector<uint8_t> & )>;

        TrustedPeerRegistry( std::shared_ptr<sgns::securecrdt::SecureCrdt> secure_crdt,
                             std::vector<std::string>                      genesis_peers,
                             std::string                                   bootstrapper_address,
                             uint64_t                                      quorum_threshold,
                             sgns::crdt::HierarchicalKey                   base_key );

        ~TrustedPeerRegistry();

        static outcome::result<std::shared_ptr<TrustedPeerRegistry>> New(
            std::shared_ptr<sgns::securecrdt::SecureCrdt> secure_crdt,
            std::vector<std::string>                      genesis_peers,
            std::string                                   bootstrapper_address,
            uint64_t                                      quorum_threshold,
            sgns::crdt::HierarchicalKey base_key = sgns::crdt::HierarchicalKey( "trusted-peer-registry" ) );

        static outcome::result<std::shared_ptr<TrustedPeerRegistry>> NewProduction(
            std::shared_ptr<sgns::securecrdt::SecureCrdt> secure_crdt,
            std::shared_ptr<TrustStateStore>              trust_store,
            GenesisManifest                               reviewed_manifest,
            std::vector<uint8_t>                          bootstrap_manifest_signature,
            std::string                                   local_signer_address,
            SignCallback                                  sign_callback,
            std::string                                   policy_domain = "trusted-peer" );

        outcome::result<sgns::securecrdt::CandidateId> SubmitReviewedGenesisApproval();
        outcome::result<bool> TryActivateReviewedGenesisCandidate( const sgns::securecrdt::CandidateId &candidate_id );
        outcome::result<std::vector<sgns::securecrdt::CandidateId>> ListPendingPolicyCandidates() const;
        outcome::result<sgns::securecrdt::CandidateId> ProposePolicyCandidate( const QuorumPolicyState &candidate );
        outcome::result<sgns::securecrdt::CandidateId> ApprovePolicyCandidate(
            const sgns::securecrdt::CandidateId &candidate_id );
        outcome::result<bool> TryActivatePolicyCandidate( const sgns::securecrdt::CandidateId &candidate_id );
        outcome::result<ConfirmedTrustSnapshot> GetConfirmedSnapshot() const;

        [[nodiscard]] static std::optional<sgns::securecrdt::CandidateCore> PolicyCandidateCore(
            const QuorumPolicyState &candidate,
            const std::string       &domain = "trusted-peer" );

        outcome::result<void> SeedGenesis( const std::vector<std::string> &genesis_peers,
                                           const std::vector<uint8_t>     &ephemeral_signature );

        outcome::result<void> ProposeMembershipChange( const std::vector<std::string> &new_peers );

        outcome::result<void> SignMembershipChange( const std::string          &signer_address,
                                                    const std::vector<uint8_t> &signature );

        outcome::result<bool> TryConfirm();

        outcome::result<sgns::securecrdt::SignerSetSnapshot> CurrentSignerSet() const override;

        std::vector<std::string> GetCurrentPeers() const override;

        sgns::crdt::HierarchicalKey BaseKey() const override
        {
            return base_key_;
        }

        bool IsGenesisConfirmed() const;

        void Unregister();

    private:
        bool RegisterSignerSetSource();

        outcome::result<sgns::securecrdt::SignerSetSnapshot> ResolveSignerSet() const;

        bool                                                              RegisterProductionDomains();
        outcome::result<sgns::securecrdt::CandidateAuthorizationSnapshot> ResolveGenesisAuthorization() const;
        outcome::result<sgns::securecrdt::CandidateAuthorizationSnapshot> ResolvePolicyAuthorization() const;
        outcome::result<sgns::securecrdt::CandidateId>                    SubmitLocalApproval(
                               const sgns::securecrdt::CandidateCore &core );
        void PublishSnapshot( const ConfirmedTrustSnapshot &snapshot );

        std::shared_ptr<sgns::securecrdt::SecureCrdt> secure_crdt_;
        sgns::crdt::HierarchicalKey                   base_key_;
        std::string                                   bootstrapper_address_;
        uint64_t                                      quorum_threshold_;

        mutable std::shared_mutex cache_mutex_;
        std::vector<std::string>  cached_peers_;
        bool                      genesis_confirmed_ = false;
        int                       registry_token_    = 0;

        bool                             production_mode_ = false;
        std::shared_ptr<TrustStateStore> trust_store_;
        GenesisManifest                  reviewed_manifest_;
        std::vector<uint8_t>             bootstrap_manifest_signature_;
        std::string                      local_signer_address_;
        SignCallback                     sign_callback_;
        std::string                      policy_domain_  = "trusted-peer";
        std::string                      genesis_domain_ = "trusted-peer-genesis";

        sgns::base::Logger logger_ = sgns::base::createLogger( "TrustedPeerRegistry" );
    };
} // namespace sgns::trustedpeer

OUTCOME_HPP_DECLARE_ERROR_2( sgns::trustedpeer, TrustedPeerRegistry::Error );

#endif // SGNS_TRUSTEDPEER_TRUSTEDPEERREGISTRY_HPP

Updated on 2026-10-10 at 04:54:24 +0000