Skip to content

networkregistry

Files

Name
networkregistry/NetworkMembershipFilter.hpp
Application-layer gossip membership gate (D-07 replacement). Per the owner direction recorded in deferred-items.md section 3 (2026-09-02), the NetworkRegistry membership is NOT injected into libp2p (no gater allow-list inside the vendored fork); instead peer/membership filtering happens at the SuperGenius application layer, at message-handling points that consult the NetworkRegistry's cached membership (its GetCurrentPeers() PeerId set). This header provides that predicate: a fail-closed MembershipFilter built from a weak_ptr to a NetworkRegistry – an expired registry denies, an empty membership set denies (the 15-05 fail-closed posture: empty membership NEVER fails open), else the peer's base58 id is tested against the cached member set on every call (per-message consultation, so runtime membership widening admits previously denied peers with no filter reinstall). The gossip ingest enforcement lives in PubSubBroadcasterExt::OnMessage (src/crdt/globaldb), which stores a plain std::function and mirrors – but never calls – AuthorizeGossipSender: only this header couples the crdt and networkregistry layers (layering rule).
networkregistry/NetworkRegistry.cpp
Implementation of the SecureCRDT-backed per-privateNetworkId membership registry (D-03, D-06): TPR-majority bootstrap, cached self-governance, secret-free records.
networkregistry/NetworkRegistry.hpp
SecureCRDT-backed per-privateNetworkId membership registry (D-06). A child trust domain whose bootstrap record is signed by a majority of the GLOBAL TrustedPeerRegistry and which, once confirmed, governs itself from its own cached member set and quorum – a single member can never admit itself unilaterally. Built entirely on the existing SecureCrdt/SecureCrdtRegistry/ ISignedCRDTData machinery (no bespoke signature protocol), mirroring the TrustedPeerRegistry lifecycle (Pattern 3). Serialized records carry ONLY non-secret metadata (D-03): the libp2p PeerId allow-list (consumed by the 15-05 connection gater), the member signing addresses, and key version/ fingerprint – never raw private-network credential material.

Updated on 2026-10-06 at 13:34:21 +0000