Sigil documentation
ReferenceRust referencesigil-core

sigil-core · gal

Source declarations, signatures and documentation for gal.

Source: sigil/node/sigil-core/src/gal.rs. SHA-256: b6adee272791a48c7fd1a18126c5620936bdf457ff76ca61277c3cce7dfd11dd.

This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.

gal::RootStatus

Lifecycle of a root anchor on the GAL.

#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum RootStatus {
    /// The root is currently authoritative and may be used to verify lineage.
    Active,
    /// A key rotation is in progress; new signatures must use the new key, but
    /// the previous key is still recognized for a grace window.
    Rotating,
    /// The root has been revoked; resolution MUST reject any DID rooted here.
    Revoked,
}

Source line: 35.

gal::AffinityKind

How a subject was assigned to its shard.

#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum AffinityKind {
    /// Co-located with the rest of the issuing organization.
    Organization,
    /// Co-located by DID namespace prefix.
    Namespace,
    /// Random / load-balanced.
    Random,
}

Source line: 48.

gal::RevocationKind

Shape of a revocation: targets a single DID, cascades from a root, or cascades through an org tree.

#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum RevocationKind {
    /// Revokes a single DID only.
    Single,
    /// Revokes an HMR / MHR / ENR root and cascades to every descendant.
    CascadeRoot,
    /// Revokes through an org-tree subset (e.g., a single department).
    CascadeOrg,
}

Source line: 61.

gal::ShardOp

Topology change kind.

#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum ShardOp {
    Add,
    Remove,
    Split,
    Merge,
    Migrate,
}

Source line: 73.

gal::HmrAnchor

Human Root (HMR) anchor.

A single human's controlling root identity.

#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct HmrAnchor {
/// `did:oas:sigil:hmr:<id>`.

pub hmr_did: String,
/// Multibase-encoded ed25519 controller public key.

pub controller_pubkey: String,
/// Multibase-encoded ed25519 recovery public keys.

pub recovery_pubkeys: Vec<String>,
/// BLAKE3 commitment to the off-chain DID document / bio / charter.

pub metadata_commitment: String,
/// Shard the anchor lives on.

pub shard_id: String,
/// Lifecycle status.

pub status: RootStatus,
/// Monotonic per-subject sequence number across updates.

pub sequence: u64,
/// Block height at which this version was anchored.

pub anchored_at_block: u64
}

Source line: 89.

gal::MhrAnchor

Machine / Multi-Human Root (MHR) anchor.

A multi-party root controlled by a threshold of HMRs (or other roots).

#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct MhrAnchor {
/// `did:oas:sigil:mhr:<id>`.

pub mhr_did: String,
/// Threshold policy over member HMR DIDs.

pub controller_policy: ThresholdPolicy,
/// Member HMR DIDs explicitly enumerated for explorer / cascade purposes.

pub member_hmrs: Vec<String>,
/// Profit share assignments (sum to 10_000 basis points; enforced

/// downstream by the `DistributionPolicy::is_complete` invariant).

pub profit_shares: Vec<ProfitShare>,
/// Recovery policy for compromise / rotation events.

pub recovery_policy: ControlPolicy,
/// BLAKE3 commitment to off-chain metadata.

pub metadata_commitment: String,
pub shard_id: String,
pub status: RootStatus,
pub sequence: u64,
pub anchored_at_block: u64
}

Source line: 112.

gal::EnrAnchor

Enterprise / Entity Root (ENR) anchor.

#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct EnrAnchor {
/// `did:oas:sigil:enr:<id>`.

pub enr_did: String,
/// Authority policy over enterprise actions.

pub controller_policy: ControlPolicy,
/// Anchoring commitment to off-chain governance documents.

pub governance_root: String,
/// Authorized signers (officers / employees) that can sign ENR-issued

/// child anchors.

pub authorized_signers: Vec<String>,
pub metadata_commitment: String,
pub shard_id: String,
pub status: RootStatus,
pub sequence: u64,
pub anchored_at_block: u64
}

Source line: 134.

gal::OrgLineageRoot

Org-tree Merkle root.

Updated atomically when child membership changes. Resolvers verify a Merkle inclusion proof against this root before trusting any sub-org or agent claim of org membership.

#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct OrgLineageRoot {
/// Controlling org DID — typically an MHR or ENR.

pub org_did: String,
/// BLAKE3 Merkle root over canonical leaf hashes.

pub merkle_root: String,
/// Number of leaves the root covers.

pub leaf_count: u64,
pub sequence: u64,
pub anchored_at_block: u64,
pub status: RootStatus
}

Source line: 157.

gal::ShardAssignment

Shard assignment for a single DID.

#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct ShardAssignment {
pub subject_did: String,
pub shard_id: String,
pub affinity_kind: AffinityKind,
pub assigned_at_block: u64,
pub sequence: u64
}

Source line: 171.

gal::RevocationRecord

Revocation record. The chain serves these via gal_check_revocation, which MUST be called first by every resolver.

#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct RevocationRecord {
pub subject_did: String,
pub revocation_kind: RevocationKind,
/// BLAKE3 commitment to the off-chain reason document.

pub reason_commitment: String,
pub revoked_at_block: u64,
pub revoked_by_did: String,
/// Set when `revocation_kind != Single` so cascade chains are

/// deterministically reconstructible from on-chain state.

pub parent_root_did: Option<String>
}

Source line: 182.

gal::ShardTopologyEntry

Shard topology change entry.

#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct ShardTopologyEntry {
pub shard_id: String,
pub operation: ShardOp,
pub affected_dids: Vec<String>,
pub parent_shard_id: Option<String>,
pub new_shard_id: Option<String>,
pub applied_at_block: u64,
pub sequence: u64
}

Source line: 196.

gal::RevocationStatus

Status returned by gal_check_revocation.

#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct RevocationStatus {
/// True if the subject is revoked.

pub revoked: bool,
/// The matching record when `revoked == true`. None otherwise.

pub record: Option<RevocationRecord>
}

Source line: 212.

gal::GalValidationError

Errors produced when validating GAL records.

#[derive(Debug, Clone, PartialEq, Eq, Error)]
pub enum GalValidationError {
    #[error("did mismatch: expected {expected}, found {found}")]
    DidMismatch { expected: String, found: String },
    #[error("status is not active")]
    StatusNotActive,
    #[error("anchor block is in the future")]
    AnchorInFuture,
    #[error("sequence is not monotonic (have {have}, got {got})")]
    NonMonotonicSequence { have: u64, got: u64 },
    #[error("metadata commitment mismatch")]
    MetadataCommitmentMismatch,
    #[error("subject is revoked")]
    Revoked,
}

Source line: 221.

gal::RootAnchor

Common interface for typed root anchors.

Implemented by [HmrAnchor], [MhrAnchor], [EnrAnchor].

pub trait RootAnchor {
    /// The subject DID this anchor binds.
    fn subject_did(&self) -> &str;
    /// Current lifecycle status.
    fn status(&self) -> RootStatus;
    /// Block height the anchor was first / last published at.
    fn anchored_at_block(&self) -> u64;
    /// Monotonic sequence for the subject.
    fn sequence(&self) -> u64;
    /// BLAKE3 commitment to the off-chain DID document.
    fn metadata_commitment(&self) -> &str;
}

Source line: 239.

gal::validate_root_anchor

Validate a candidate root anchor against the chain state.

current_block is the latest finalized block height; prior_sequence is the most recent on-chain sequence for this subject (or zero if none). expected_did is the subject DID the caller already resolved.

pub fn validate_root_anchor<A: RootAnchor>(
    anchor: &A,
    expected_did: &str,
    current_block: u64,
    prior_sequence: u64,
) -> Result<(), GalValidationError>;

Source line: 311.

gal::verify_metadata_commitment

Verify the off-chain DID document matches an anchor's commitment.

document_blake3 is the BLAKE3 hex digest of the canonical JSON form of the resolved DID document; equality is the one-and-only check.

pub fn verify_metadata_commitment<A: RootAnchor>(
    anchor: &A,
    document_blake3: &str,
) -> Result<(), GalValidationError>;

Source line: 342.

gal::is_revoked

Returns true when the supplied [RevocationStatus] indicates the subject is currently revoked. Sugar so callers can lead with this check.

pub fn is_revoked(status: &RevocationStatus) -> bool;

Source line: 355.

On this page