sgns::networkregistry¶
Classes¶
| Name | |
|---|---|
| class | sgns::networkregistry::NetworkMembershipPayload ISignedCRDTData payload type carrying a private network's membership record. Serialization is an explicit line-based field layout (see NetworkRegistry.cpp); every field is non-secret metadata (D-03) – the raw pnet credential is NEVER stored. |
| class | sgns::networkregistry::NetworkRegistry Per-privateNetworkId membership registry (D-06): a child trust domain of the global TrustedPeerRegistry. Delegates ALL signature/quorum logic to SecureCrdt/SecureCrdtRegistry. |
Types¶
| Name | |
|---|---|
| using std::function< bool(const libp2p::peer::PeerId &)> | MembershipFilter Predicate deciding whether a libp2p peer is an authorized member of the private network. Installed into PubSubBroadcasterExt (SetMembershipFilter) and consumed by the processing-path sender checks (15-13). |
Functions¶
| Name | |
|---|---|
| MembershipFilter | MakeNetworkMembershipFilter(std::weak_ptr< NetworkRegistry > registry) Builds a registry-backed, fail-closed MembershipFilter. |
| MembershipFilter | MakeBootstrapMembershipFilter(const std::vector< std::string > & bootstrap_peer_ids) Builds a config-backed, fail-closed MembershipFilter over the provisioned bootstrap membership (network_bootstrap_peers_). |
| bool | AuthorizeGossipSender(const MembershipFilter & filter, const libp2p::common::ByteArray & from_bytes) Authorizes a gossip message by its TRANSPORT sender field (Gossip::Message::from – a ByteArray carrying the serialized PeerId of the message creator). |
Types Documentation¶
using MembershipFilter¶
using sgns::networkregistry::MembershipFilter = typedef std::function<bool( const libp2p::peer::PeerId & )>;
Predicate deciding whether a libp2p peer is an authorized member of the private network. Installed into PubSubBroadcasterExt (SetMembershipFilter) and consumed by the processing-path sender checks (15-13).
Functions Documentation¶
function MakeNetworkMembershipFilter¶
Builds a registry-backed, fail-closed MembershipFilter.
Parameters:
- registry Weak reference to the NetworkRegistry consulted per message (kept weak so the filter never extends the registry's lifetime).
Return: The membership predicate (never null).
Semantics per invocation:
- registry weak_ptr expired -> DENY (the registry is gone; the
filter never fails open);
- GetCurrentPeers() empty -> DENY (15-05 fail-closed posture);
- otherwise -> allow iff the peer's base58 id is in the cached
membership snapshot copied under the call (the registry stays
lock-free on this path; membership sets are tens of peers, so
the per-message copy is acceptable).
function MakeBootstrapMembershipFilter¶
inline MembershipFilter MakeBootstrapMembershipFilter(
const std::vector< std::string > & bootstrap_peer_ids
)
Builds a config-backed, fail-closed MembershipFilter over the provisioned bootstrap membership (network_bootstrap_peers_).
Boot-window gate (CR-G02b / G-WR-03): on a private node the GlobalDB goes live and subscribes its topics from INITIALIZING_DATABASE, while the registry-backed filter installs only at NetworkRegistry construction in INITIALIZING_TRANSACTIONS – this predicate covers that startup window from the first live subscription. The argument strings are the SAME base58 PeerId strings the NetworkRegistry stores verbatim as its cached membership (cached_network_peers_ = initial_network_peers), and membership matching is base58 string comparison against PeerId::toBase58(), so the interim verdict matches the registry-backed verdict for the provisioned set; the registry filter later REPLACES this one via SetMembershipFilter.
Semantics per invocation:
- empty bootstrap set -> DENY everything (fail-closed: a private node with no bootstrap membership can never reach READY anyway per the 15-05 posture – empty membership NEVER fails open);
- otherwise -> allow iff the peer's base58 id is in the set. bootstrap_peer_idsProvisioned bootstrap member PeerId base58 strings (copied ONCE into a shared_ptr-held unordered_set for cheap per-message consultation).
The membership predicate (never null).
function AuthorizeGossipSender¶
inline bool AuthorizeGossipSender(
const MembershipFilter & filter,
const libp2p::common::ByteArray & from_bytes
)
Authorizes a gossip message by its TRANSPORT sender field (Gossip::Message::from – a ByteArray carrying the serialized PeerId of the message creator).
Parameters:
- filter Installed MembershipFilter (may be empty).
- from_bytes Transport
fromfield bytes (may be empty).
Return: true when the sender is authorized to participate.
Fail-closed decision table:
- no filter installed (empty std::function) -> ALLOW (public pass-through; public nodes keep byte-identical behavior);
- PeerId::fromBytes(from_bytes) failure -> DENY. This INCLUDES the empty-from_bytes case: fromBytes of an empty span fails, so under a set filter a message with no transport sender is DENIED, never skipped;
- otherwise -> the filter's verdict on the derived PeerId.
Consumed by the 15-13 processing-path handlers; kept dependency-light (libp2p peer types only).
Updated on 2026-10-06 at 13:34:20 +0000