Skip to content

sgns::securecrdt

Classes

Name
struct sgns::securecrdt::CandidateApprovalRecord
struct sgns::securecrdt::CandidateAuthorizationSnapshot
struct sgns::securecrdt::CandidateCore
struct sgns::securecrdt::CandidateDomainEntry
struct sgns::securecrdt::CandidateId
struct sgns::securecrdt::CandidateKey
struct sgns::securecrdt::CandidateLimits
class sgns::securecrdt::ISignedCRDTData
Interface implemented by every CRDT-backed value that requires a quorum of authorized signers to create/update.
class sgns::securecrdt::SecureCrdt
Mandatory wrapper for reading/writing registered SecureCrdt keys.
class sgns::securecrdt::SecureCrdtRegistry
Thread-safe registry resolving a CRDT key to its policy entry.
struct sgns::securecrdt::SecureCrdtRegistryEntry
Policy entry describing how a registered key pattern is verified and instantiated.
struct sgns::securecrdt::SignerSetSnapshot
Snapshot of an authorized signer set and its required signature count, as produced by an injected SignerSetSource.

Types

Name
enum class uint8_t CandidateKind
using std::function< outcome::result< SignerSetSnapshot >(const std::string &base_key)> SignerSetSource
Injectable callback resolving the current authorized signer set for a given base_key. NOT hard-wired to TrustedPeerRegistry (which does not exist until Phase 10) - tests inject a fixed-list lambda.
using std::function< outcome::result< CandidateAuthorizationSnapshot >()> CandidateAuthorizationSource

Functions

Name
uint64_t MembershipQuorumFloor(size_t signer_set_size)
uint64_t BurnQuorumFloor(size_t signer_set_size)
outcome::result< void > ValidateThresholdAtFloor(uint64_t threshold, size_t signer_set_size, uint64_t floor)
outcome::result< void > ValidateMembershipQuorumThreshold(uint64_t threshold, size_t signer_set_size)
outcome::result< void > ValidateBurnQuorumThreshold(uint64_t threshold, size_t signer_set_size)
uint64_t StrictMajorityQuorumFloor(size_t signer_set_size)
Strict-majority safety floor, ceil(0.51 * signer_set_size): the minimum threshold that can never be met by a signer set alone without cooperation of more than half of its members. Returns 0 for an empty signer set (an empty set can never authorize anything – ValidateThresholdAtFloor rejects it).
outcome::result< void > ValidateQuorumThreshold(uint64_t threshold, size_t signer_set_size)
Validates threshold against the strict-majority floor ceil(0.51 * signer_set_size). Used by registries whose bootstrap authority is an external peer set (e.g. NetworkRegistry's TrustedPeerRegistry-majority bootstrap, D-06): the bootstrap record must carry signatures from strictly more than half of the authorizing set.

Types Documentation

enum CandidateKind

Enumerator Value Description
TrustPolicy 1
BurnConfig 2
TrustedPeerGenesis 3

using SignerSetSource

using sgns::securecrdt::SignerSetSource = typedef std::function<outcome::result<SignerSetSnapshot>( const std::string &base_key )>;

Injectable callback resolving the current authorized signer set for a given base_key. NOT hard-wired to TrustedPeerRegistry (which does not exist until Phase 10) - tests inject a fixed-list lambda.

using CandidateAuthorizationSource

using sgns::securecrdt::CandidateAuthorizationSource = typedef std::function<outcome::result<CandidateAuthorizationSnapshot>()>;

Return SecureCrdt::Error::CANDIDATE_AUTHORIZATION_PENDING when local trust prerequisites are missing, so incoming approvals can be retried safely.

Functions Documentation

function MembershipQuorumFloor

inline uint64_t MembershipQuorumFloor(
    size_t signer_set_size
)

function BurnQuorumFloor

inline uint64_t BurnQuorumFloor(
    size_t signer_set_size
)

function ValidateThresholdAtFloor

inline outcome::result< void > ValidateThresholdAtFloor(
    uint64_t threshold,
    size_t signer_set_size,
    uint64_t floor
)

function ValidateMembershipQuorumThreshold

inline outcome::result< void > ValidateMembershipQuorumThreshold(
    uint64_t threshold,
    size_t signer_set_size
)

function ValidateBurnQuorumThreshold

inline outcome::result< void > ValidateBurnQuorumThreshold(
    uint64_t threshold,
    size_t signer_set_size
)

function StrictMajorityQuorumFloor

inline uint64_t StrictMajorityQuorumFloor(
    size_t signer_set_size
)

Strict-majority safety floor, ceil(0.51 * signer_set_size): the minimum threshold that can never be met by a signer set alone without cooperation of more than half of its members. Returns 0 for an empty signer set (an empty set can never authorize anything – ValidateThresholdAtFloor rejects it).

function ValidateQuorumThreshold

inline outcome::result< void > ValidateQuorumThreshold(
    uint64_t threshold,
    size_t signer_set_size
)

Validates threshold against the strict-majority floor ceil(0.51 * signer_set_size). Used by registries whose bootstrap authority is an external peer set (e.g. NetworkRegistry's TrustedPeerRegistry-majority bootstrap, D-06): the bootstrap record must carry signatures from strictly more than half of the authorizing set.

Parameters:

  • threshold Configured required-signature count.
  • signer_set_size Size of the authorizing signer set.

Return: success, or SecureCrdt::Error::QUORUM_THRESHOLD_BELOW_FLOOR when the set is empty, the threshold is 0/above the set size, or below the strict-majority floor.


Updated on 2026-10-06 at 13:34:20 +0000