sigil-node · compute_state
Source declarations, signatures and documentation for compute_state.
Source: sigil/node/sigil-node/src/compute_state.rs. SHA-256: 4d3972f1807f71d929091f0a1bb937a72d80d993b28821996f64b4250188d5c0.
This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.
Module condition:
#[cfg(feature = "compute")]compute_state::receipt_settlement_tuple_key
#[cfg(feature = "compute")]
pub fn receipt_settlement_tuple_key(
receipt_id: &str,
job_id: &str,
task_id: Option<&str>,
) -> String;Source line: 17.
compute_state::ProviderTier
Provider stake tier — copy of arise-bridge's ProviderTier on-chain.
#[cfg(feature = "compute")]
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum ProviderTier {
Consumer,
Professional,
Enterprise,
Cluster,
}Source line: 32.
compute_state::ProviderTier::min_stake
#[cfg(feature = "compute")]
pub fn min_stake(self) -> u64;Source line: 40.
compute_state::ProviderTier::from_stake
#[cfg(feature = "compute")]
pub fn from_stake(stake: u64) -> Self;Source line: 49.
compute_state::ProviderStatus
Operational status of a registered provider.
#[cfg(feature = "compute")]
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum ProviderStatus {
Active,
Suspended,
Exiting,
Exited,
}Source line: 65.
compute_state::ComputeProvider
On-chain compute provider record.
#[cfg(feature = "compute")]
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct ComputeProvider {
pub provider_did: String,
pub human_root_did: Option<String>,
pub tier: ProviderTier,
pub stake: u64,
pub pricing: ComputePricing,
pub supported_models: Vec<String>,
pub capabilities: Option<serde_json::Value>,
pub endpoint_url: Option<String>,
pub verification_tiers: Vec<ComputeVerificationTier>,
pub hardware_attestation: Option<serde_json::Value>,
pub provider_pubkey: Option<Vec<u8>>,
#[serde(default)]
pub relayer_dids: Vec<String>,
pub status: ProviderStatus,
pub registered_epoch: u64,
pub last_updated_epoch: u64,
pub unbonding_until_epoch: Option<u64>,
pub active_jobs: u64,
pub unresolved_challenges: u64,
/// Aggregate reputation score (signed). Updated by reputation signals.
pub reputation: i64
}Source line: 74.
compute_state::ComputeEscrow
#[cfg(feature = "compute")]
#[derive(Debug, Clone, PartialEq, Eq, Default, Serialize, Deserialize)]
pub struct ComputeEscrow {
pub owner_did: String,
pub available_balance: u64,
pub reserved_balance: u64,
pub mandate_id: Option<String>,
pub budget_limit: Option<u64>,
pub last_updated_epoch: u64
}Source line: 103.
compute_state::ComputeEscrow::total
#[cfg(feature = "compute")]
pub fn total(&self) -> u64;Source line: 113.
compute_state::JobStatus
#[cfg(feature = "compute")]
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum JobStatus {
Pending,
Dispatched,
Running,
Completed,
Failed,
Challenged,
Refunded,
}Source line: 124.
compute_state::JobStatus::is_terminal
#[cfg(feature = "compute")]
pub fn is_terminal(self) -> bool;Source line: 135.
compute_state::JobStatus::is_active
#[cfg(feature = "compute")]
pub fn is_active(self) -> bool;Source line: 138.
compute_state::JobStatus::allows_receipt_settlement
#[cfg(feature = "compute")]
pub fn allows_receipt_settlement(self) -> bool;Source line: 142.
compute_state::ComputeJob
#[cfg(feature = "compute")]
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct ComputeJob {
pub job_id: String,
pub consumer_did: String,
pub provider_did: String,
pub model_id: String,
pub input_hash: SigilHash,
pub max_cost: u64,
pub reserved_amount: u64,
pub verification_tier: ComputeVerificationTier,
pub status: JobStatus,
pub created_epoch: u64,
pub dispatched_epoch: Option<u64>,
pub completed_epoch: Option<u64>,
pub agent_did: Option<String>,
pub dao_did: Option<String>,
pub mandate_id: Option<String>,
pub treasury_did: Option<String>,
pub authority_context: Option<serde_json::Value>,
pub receipt_id: Option<String>
}Source line: 148.
compute_state::ComputeReceiptRecord
#[cfg(feature = "compute")]
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct ComputeReceiptRecord {
pub receipt: ComputeReceipt,
pub settled_epoch: u64,
pub challenge_window_until_epoch: u64,
pub challenged: bool
}Source line: 174.
compute_state::ChallengeState
#[cfg(feature = "compute")]
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum ChallengeState {
Open,
Resolving,
Resolved,
}Source line: 187.
compute_state::ComputeChallenge
#[cfg(feature = "compute")]
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct ComputeChallenge {
pub challenge_id: String,
pub receipt_id: String,
pub challenger_did: String,
pub deposit: u64,
pub evidence: serde_json::Value,
pub opened_at_epoch: u64,
pub state: ChallengeState,
pub resolution: Option<ChallengeResolution>,
pub resolved_at_epoch: Option<u64>
}Source line: 194.
compute_state::AuditAggregate
#[cfg(feature = "compute")]
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum AuditAggregate {
Provider,
Escrow,
Job,
Receipt,
Challenge,
Maca,
}Source line: 212.
compute_state::ComputeAuditEvent
#[cfg(feature = "compute")]
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct ComputeAuditEvent {
pub aggregate: AuditAggregate,
pub seq: u64,
pub epoch: u64,
pub block_height: u64,
pub kind: String,
pub payload: serde_json::Value
}Source line: 222.
compute_state::ReputationSignalKind
#[cfg(feature = "compute")]
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum ReputationSignalKind {
JobCompleted,
LatencyAccurate,
Available,
ChallengeSurvived,
ChallengeLost,
InvalidReceipt,
InvalidProofCommitment,
RedundantOutlier,
ValidatorAgreement,
TeeAttestationFresh,
JobFailed,
StorageChallengeFailed,
}Source line: 237.
compute_state::ComputeReputationSignal
#[cfg(feature = "compute")]
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct ComputeReputationSignal {
pub provider_did: String,
pub kind: ReputationSignalKind,
pub weight: i32,
pub at_epoch: u64,
pub evidence_seq: Option<u64>
}Source line: 253.
compute_state::MacaWorkClaim
#[cfg(feature = "compute")]
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct MacaWorkClaim {
pub work_id: SigilHash,
pub receipt_id: String,
pub worker_did: String,
pub consumer_did: String,
pub agent_did: Option<String>,
pub dao_did: Option<String>,
pub mandate_id: Option<String>,
pub verification_tier: ComputeVerificationTier,
pub commitments: ComputeEvidenceCommitment,
pub authority_context: Option<serde_json::Value>,
pub worker_signature: Vec<u8>,
pub worker_pubkey: Vec<u8>,
pub epoch_settled: u64,
pub challenge_window_until_epoch: u64,
pub tee_attestation: Option<TeeAttestation>,
pub lumen_attestation: Option<sigil_core::transaction::LumenAttestation>
}Source line: 266.
compute_state::MacaWorkClaim::derive_work_id
Canonical work id derivation: BLAKE3(receipt_id || worker_did || epoch_le).
#[cfg(feature = "compute")]
pub fn derive_work_id(receipt_id: &str, worker_did: &str, epoch: u64) -> SigilHash;Source line: 287.
compute_state::MacaValidationRecord
#[cfg(feature = "compute")]
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct MacaValidationRecord {
pub attestation: AgentVerificationAttestation,
pub recorded_at_epoch: u64,
pub recorded_at_block: u64,
/// Phase 12: epoch this attestation was submitted under (when the
/// validator submitted via the on-chain `MacaSubmitAttestation` tx).
/// `None` for records persisted directly by the executor before
/// Phase 12 wiring.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub maca_epoch_id: Option<u64>
}Source line: 294.
compute_state::ValidatorAgentRecord
On-chain validator agent record. Tracks the role and signing key the agent claimed at registration time. Authority gates (proposer/beacon allowlists) are still policy-driven; this record exists so attestations can be cross-checked against the registered pubkey + role.
#[cfg(feature = "compute")]
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct ValidatorAgentRecord {
pub agent_did: String,
pub role: ValidatorRole,
pub human_root_did: Option<String>,
pub agent_pubkey: Vec<u8>,
pub capabilities: Option<serde_json::Value>,
pub registered_epoch: u64,
pub last_updated_epoch: u64
}Source line: 315.
compute_state::BeaconRecord
On-chain beacon publication for a single epoch.
#[cfg(feature = "compute")]
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct BeaconRecord {
pub epoch_id: u64,
pub beacon_did: String,
pub beacon_value: SigilHash,
pub beacon_signature: Vec<u8>,
pub published_at_epoch: u64,
pub published_at_block: u64
}Source line: 327.
compute_state::MacaEpoch
On-chain MACA epoch record. Aggregates open work claims and (after
finalization) the per-work MacaQuorumProofs.
#[cfg(feature = "compute")]
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct MacaEpoch {
pub epoch_id: u64,
/// `BLAKE3(epoch_id LE || proposer_did || beacon_value || start_block_height
/// LE || end_block_height LE || sorted_included_work_ids)`.
/// Replay-safe: identical inputs always yield the same hash.
pub epoch_hash: SigilHash,
pub proposer_did: String,
pub beacon_value: SigilHash,
pub start_block_height: u64,
pub end_block_height: u64,
/// Sorted ascending so the canonical hash is order-independent.
pub included_work_ids: Vec<SigilHash>,
pub state: MacaEpochState,
pub proposed_at_epoch: u64,
pub proposed_at_block: u64,
pub finalized_at_epoch: Option<u64>,
pub proposer_signature: Vec<u8>
}Source line: 339.
compute_state::MacaEpoch::canonical_hash
Canonical replay-safe hash. Used by tests and the executor to
deduplicate and to check that a re-proposal of the same epoch
(with the same content) produces the same epoch_hash.
#[cfg(feature = "compute")]
pub fn canonical_hash(
epoch_id: u64,
proposer_did: &str,
beacon_value: &SigilHash,
start_block_height: u64,
end_block_height: u64,
sorted_work_ids: &[SigilHash],
) -> SigilHash;Source line: 362.
compute_state::MacaQuorumProof
Per-work-claim aggregate of validator attestations. Created when an epoch is finalized.
#[cfg(feature = "compute")]
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct MacaQuorumProof {
/// `BLAKE3(epoch_id LE || work_id || sorted_validator_dids || sorted_signatures)`
/// — replay-safe.
pub proof_id: SigilHash,
pub epoch_id: u64,
pub work_id: SigilHash,
pub outcome: QuorumOutcome,
/// Sorted ascending.
pub agreeing_validators: Vec<String>,
/// Sorted ascending.
pub dissenting_validators: Vec<String>,
/// Validators that submitted Indeterminate or whose attestation could
/// not be classified (e.g. missing output_hash).
pub indeterminate_validators: Vec<String>,
/// `(validator_did, validator_signature)` pairs sorted by `validator_did`.
pub validator_signatures: Vec<(String, Vec<u8>)>,
pub quorum_threshold: u32,
pub finalized_at_epoch: u64,
pub finalized_at_block: u64
}Source line: 389.
compute_state::MacaQuorumProof::canonical_hash
Canonical replay-safe hash over (epoch_id, work_id, sorted validator dids, sorted signatures).
#[cfg(feature = "compute")]
pub fn canonical_hash(
epoch_id: u64,
work_id: &SigilHash,
sorted_validators: &[(String, Vec<u8>)],
) -> SigilHash;Source line: 413.
compute_state::EpochQuery
#[cfg(feature = "compute")]
#[derive(Debug, Clone, Default, Serialize, Deserialize)]
pub struct EpochQuery {
pub state: Option<MacaEpochState>,
pub limit: Option<u32>
}Source line: 431.
compute_state::JobIndexFilter
#[cfg(feature = "compute")]
#[derive(Debug, Clone, Default, Serialize, Deserialize)]
pub struct JobIndexFilter {
pub by_provider: Option<String>,
pub by_consumer: Option<String>,
pub status: Option<JobStatus>
}Source line: 441.
compute_state::AuditQuery
#[cfg(feature = "compute")]
#[derive(Debug, Clone, Default, Serialize, Deserialize)]
pub struct AuditQuery {
pub aggregate: Option<AuditAggregate>,
pub after_seq: Option<u64>,
pub limit: Option<u32>
}Source line: 448.
compute_state::ComputePolicy
Snapshot of the chain config the compute executor consults at every
transaction. Loaded from genesis::ComputeParams by the production
state backend; the trait default in ExecutionState::compute_policy
returns fail_closed() so a backend that forgets to wire genesis
rejects all challenge-resolves and T3 settlements.
#[cfg(feature = "compute")]
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct ComputePolicy {
/// Allowlist of DIDs that may resolve compute challenges. The executor
/// MUST fail closed when the sender is not in this list. An empty list
/// disables challenge resolution entirely.
pub challenge_resolver_dids: Vec<String>,
/// When `true`, T3 (TEE) receipts may settle. When `false`, the
/// executor refuses T3 settlement.
pub tee_verifier_enabled: bool,
/// Provider exit cooldown in epochs.
pub unbonding_epochs: u64,
/// Default challenger deposit (micro-MINT) when the tx omits one.
pub default_challenge_deposit: u64,
/// Default challenge window in epochs (used when the receipt does not
/// pin one).
pub default_challenge_window_epochs: u32,
/// Default reward shares applied when `ChallengeResolveData.reward_shares`
/// is `None`. `(challenger, arbitrators, treasury)`. Must sum to 1.0.
pub default_reward_shares: (f64, f64, f64),
/// Treasury DID (paid arbitrator + treasury shares).
pub treasury_did: String,
/// Phase 12 — DIDs authorised to submit `MacaProposeEpoch` and
/// `MacaFinalizeEpoch` transactions. Empty list disables MACA epoch
/// proposal entirely (fail-closed).
#[serde(default)]
pub proposer_dids: Vec<String>,
/// Phase 12 — DIDs authorised to submit `MacaPublishBeacon`. Empty
/// list disables beacon publication.
#[serde(default)]
pub beacon_dids: Vec<String>,
/// Phase 12 — minimum number of agreeing validators required for a
/// `MacaQuorumProof` to be `Confirmed`. Below this, the outcome is
/// `Inconclusive` (no clear majority) or `Rejected` (majority
/// disagreement).
#[serde(default = "default_validator_quorum_threshold")]
pub validator_quorum_threshold: u32,
/// Protocol escape hatch for receipts that are not bound to a stored job.
/// Mainnet and canary keep this off; tests and explicitly named ad-hoc
/// networks may enable it while they migrate dispatch to durable jobs.
#[serde(default)]
pub allow_ad_hoc_receipts: bool,
/// Phase 14a — AMD SEV-SNP trust anchors. When `None`, the SEV-SNP
/// verifier remains the Phase 13 fail-closed stub. When set, the
/// verifier accepts an attestation iff (a) its 1184-byte report
/// signature verifies against one of the allowlisted VCEK pubkeys,
/// (b) the report's MEASUREMENT field is on the measurement
/// allowlist. Cert-chain validation (VCEK → ASK → ARK) and
/// REPORT_DATA / freshness binding are deferred to Phase 14a-2.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub sev_snp_trust_anchors: Option<SevSnpTrustAnchors>,
/// Phase 14b — Intel SGX DCAP trust anchor material. When `Some`
/// and the `tee-verify-sgx-dcap` feature is compiled in, the verifier
/// validates DCAP Quote v3 against the configured Intel root /
/// MRENCLAVE / MRSIGNER allowlists, REPORT_DATA binding, freshness
/// window, and TCB minimum.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub sgx_dcap_trust_anchors: Option<SgxDcapTrustAnchors>,
/// Phase 14c — Intel TDX trust anchor material. When `Some` and
/// the `tee-verify-tdx` feature is compiled in, the verifier
/// validates DCAP Quote v4 (TDX) against the configured Intel
/// root, MRTD / MRSIGNER_SEAM / RTMR allowlists, REPORT_DATA
/// binding, collateral, and TCB minima.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub tdx_trust_anchors: Option<TdxTrustAnchors>,
/// Phase 14d — Arm CCA (Confidential Compute Architecture) trust
/// anchor material. When `Some` and the `tee-verify-arm-cca`
/// feature is compiled in, the verifier validates a CCA realm
/// token (COSE_Sign1 + CBOR EAT-style claims) against the pinned
/// IAK pubkey, RIM allowlist, challenge binding, and freshness
/// window.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub arm_cca_trust_anchors: Option<ArmCcaTrustAnchors>
}Source line: 464.
compute_state::SevSnpTrustAnchors
Phase 14a / 14a-2 — AMD SEV-SNP trust anchor material.
acceptable_vcek_pubkeys: SEC1-encoded uncompressed P-384 public
keys (97 bytes each: 0x04 || x || y). Operators may pre-pin one
entry per CPU they accept attestations from. When
pinned_ark_fingerprint_sha256 is set, the verifier instead extracts
the VCEK pubkey from the cert chain in the attestation envelope after
validating VCEK → ASK → ARK against the pinned root, and the
pre-pinned key list becomes optional (kept for operators that want
belt-and-braces).
measurement_allowlist: 48-byte SHA-384 launch / image measurements
the chain accepts. The verifier compares the report's MEASUREMENT
field against this list and rejects if not present.
Phase 14a-2 fields:
pinned_ark_fingerprint_sha256: SHA-256 of the AMD ARK certificate
(DER form). When set, every attestation must carry a cert chain whose
terminal cert hashes to this value; intermediate ASK is verified
against ARK; VCEK is verified against ASK. When None, the verifier
falls back to direct VCEK pubkey pinning (Phase 14a posture).
pinned_ask_fingerprint_sha256: optional SHA-256 fingerprint of the
AMD ASK / product signing certificate (DER form). When set, the
verifier rejects any SEV-SNP chain whose ASK cert does not match this
product anchor. This prevents a broad ARK pin from accidentally
accepting the wrong AMD product line.
vcek_allowlist: optional explicit CPU allowlist. Each entry binds
a chip ID to the exact reported TCB version accepted for that VCEK
issuance, with an optional VCEK certificate fingerprint. When the
list is non-empty, every accepted report must match one entry.
max_attestation_age_epochs: when set, the verifier requires
att.generated_at_epoch to be within this many epochs of the
executor's now_epoch. When None, freshness is not enforced
(Phase 14a posture).
min_tcb: minimum SEV-SNP TCB version the chain accepts. Each report
carries a REPORTED_TCB field at offset 0x180; the verifier rejects
reports where any pinned component is below the corresponding minimum.
When None, TCB is not enforced (Phase 14a posture).
require_receipt_binding: when true, the verifier requires the
SEV-SNP report's REPORT_DATA field at offset 0x50..0x90 to match
the canonical 64-byte receipt-binding derivation. The settle path
computes the expected binding from the receipt being settled and
passes it to the verifier. Enabled independently of the other
fields so operators can dial in production posture incrementally.
#[cfg(feature = "compute")]
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct SevSnpTrustAnchors {
/// SEC1 uncompressed P-384 pubkeys (`0x04 || x || y`, 97 bytes each).
/// May be empty if `pinned_ark_fingerprint_sha256` is set.
#[serde(default)]
pub acceptable_vcek_pubkeys: Vec<Vec<u8>>,
/// 48-byte SHA-384 measurements.
pub measurement_allowlist: Vec<Vec<u8>>,
/// Phase 14a-2 — SHA-256 of the AMD ARK certificate (DER).
#[serde(default, skip_serializing_if = "Option::is_none")]
pub pinned_ark_fingerprint_sha256: Option<[u8; 32]>,
/// Phase 14a-2 — SHA-256 of the AMD ASK / product signing
/// certificate (DER).
#[serde(default, skip_serializing_if = "Option::is_none")]
pub pinned_ask_fingerprint_sha256: Option<[u8; 32]>,
/// Phase 14a-2 — optional exact VCEK allowlist by chip ID and TCB.
#[serde(default)]
pub vcek_allowlist: Vec<SevSnpVcekAllowlistEntry>,
/// Phase 14a-2 — maximum attestation age (in chain epochs).
#[serde(default, skip_serializing_if = "Option::is_none")]
pub max_attestation_age_epochs: Option<u64>,
/// Phase 14a-2 — minimum SEV-SNP TCB version.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub min_tcb: Option<SevSnpTcb>,
/// Phase 14a-2 — require REPORT_DATA receipt-binding.
#[serde(default)]
pub require_receipt_binding: bool
}Source line: 592.
compute_state::SevSnpVcekAllowlistEntry
One accepted AMD SEV-SNP VCEK issuance.
#[cfg(feature = "compute")]
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct SevSnpVcekAllowlistEntry {
/// AMD KDS product name (`Milan`, `Genoa`, `Turin`, ...). The current
/// verifier treats this as operator/audit metadata because the report
/// carries chip ID and TCB, not a product string.
pub product: String,
/// 64-byte chip ID (`CHIP_ID`) from the SEV-SNP report / VCEK HWID.
pub chip_id: Vec<u8>,
/// Exact reported TCB tuple accepted for this VCEK issuance.
pub tcb: SevSnpTcb,
/// Optional SHA-256 fingerprint of the VCEK certificate DER.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub vcek_fingerprint_sha256: Option<[u8; 32]>
}Source line: 622.
compute_state::SevSnpTcb
SEV-SNP TCB version. Each component is a u8 packed into the
REPORTED_TCB u64 in the report:
- byte 0: bootloader
- byte 1: tee
- byte 6: snp firmware
- byte 7: microcode
Bytes 2..6 are AMD-reserved.
#[cfg(feature = "compute")]
#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize, Default)]
pub struct SevSnpTcb {
pub bootloader: u8,
pub tee: u8,
pub snp: u8,
pub microcode: u8
}Source line: 645.
compute_state::SevSnpTcb::from_le_bytes
Decode from the 8-byte little-endian REPORTED_TCB field.
#[cfg(feature = "compute")]
pub fn from_le_bytes(bytes: [u8; 8]) -> Self;Source line: 654.
compute_state::SevSnpTcb::meets
True when every component on self is >= other.
#[cfg(feature = "compute")]
pub fn meets(&self, minimum: &SevSnpTcb) -> bool;Source line: 664.
compute_state::ComputePolicy::fail_closed
Maximum-restriction policy: no resolver may resolve, T3 disabled.
Used as the default for backends that don't override
ExecutionState::compute_policy.
#[cfg(feature = "compute")]
pub fn fail_closed() -> Self;Source line: 676.
compute_state::ComputePolicy::is_authorised_proposer
Returns true when did is on the proposer allowlist.
#[cfg(feature = "compute")]
pub fn is_authorised_proposer(&self, did: &str) -> bool;Source line: 697.
compute_state::ComputePolicy::is_authorised_beacon
Returns true when did is on the beacon allowlist.
#[cfg(feature = "compute")]
pub fn is_authorised_beacon(&self, did: &str) -> bool;Source line: 702.
compute_state::ComputePolicy::is_authorised_resolver
Returns true when did is on the resolver allowlist.
#[cfg(feature = "compute")]
pub fn is_authorised_resolver(&self, did: &str) -> bool;Source line: 707.
compute_state::ArmCcaTrustAnchors
Phase 14d — Arm CCA (Confidential Compute Architecture) trust anchor material.
pinned_iak_pubkeys_sec1: SEC1-uncompressed P-384 public keys
(0x04 || x || y, 97 bytes each) for the Initial Attestation Keys
(IAKs) accepted by the chain. The verifier verifies the realm
token's COSE_Sign1 ECDSA-P-384/SHA-384 signature against any of
these pubkeys; first match accepts.
rim_allowlist: realm initial measurements (RIM) the chain
accepts. Each entry is the raw measurement bytes (length depends
on the CCA hash algo claim — 32 / 48 / 64 bytes).
max_attestation_age_epochs / require_receipt_binding:
same shape as the other vendors. Receipt-binding compares
att.binding_nonce against the realm token's
cca-realm-challenge claim (canonical CBOR label 44233).
Mainnet caveats
Arm CCA's verifier ecosystem is still maturing. This slice implements the structural checks (COSE_Sign1 envelope, CBOR claim parsing, ECDSA P-384 signature verification, RIM allowlist, challenge binding, freshness) and explicitly defers the platform-token / realm-token cross-binding, the full Arm IAK certificate chain (Arm has not published a stable production root yet), TCB lifecycle claim semantics, and per-claim policy enforcement. Until those land, mainnet operators should keep T3 Arm CCA off or pin a known-good IAK pubkey + RIM allowlist as an interim measure.
#[cfg(feature = "compute")]
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize, Default)]
pub struct ArmCcaTrustAnchors {
/// SEC1-uncompressed P-384 IAK pubkeys (97 bytes each).
#[serde(default)]
pub pinned_iak_pubkeys_sec1: Vec<Vec<u8>>,
/// Realm initial measurement allowlist (raw measurement bytes).
#[serde(default)]
pub rim_allowlist: Vec<Vec<u8>>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub max_attestation_age_epochs: Option<u64>,
#[serde(default)]
pub require_receipt_binding: bool
}Source line: 749.
compute_state::TdxTrustAnchors
Phase 14c — Intel TDX trust anchor material.
Reuses the Intel root pinning + collateral pattern established by SGX DCAP. TDX-specific fields:
mrtd_allowlist: 48-byte SHA-384 measurements of accepted TD
images. Equivalent to MRENCLAVE on SGX but always 48 bytes.
mrsigner_seam_allowlist: 48-byte SHA-384 measurements of
accepted SEAM-module signers. Equivalent to MRSIGNER on SGX.
rtmr_allowlist[0..4]: optional 48-byte allowlists for RTMR0..3
(Runtime Measurement Registers). When None for a slot, the
corresponding RTMR is not enforced; when Some, the report's
RTMR<i> must match one of the listed values. Operators that pin
boot-time RTMRs (e.g. UEFI/firmware via RTMR0) configure these.
Collateral fields (intel_tcb_signing_cert_der, tcb_info_json,
qe_identity_json, pck_crl_der, root_ca_crl_der,
allowed_tcb_statuses) follow the same shape as SGX DCAP. The
QE Identity for TDX has id == "TD_QE" and the TCB Info contains
both SGX and TDX TCB component arrays — the verifier walks
both against the quote's CPUSVN+TEE_TCB_SVN and takes the lower
status.
#[cfg(feature = "compute")]
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize, Default)]
pub struct TdxTrustAnchors {
#[serde(default, skip_serializing_if = "Option::is_none")]
pub pinned_intel_root_fingerprint_sha256: Option<[u8; 32]>,
/// 48-byte MRTD values the chain accepts.
#[serde(default)]
pub mrtd_allowlist: Vec<Vec<u8>>,
/// 48-byte MRSIGNER_SEAM values the chain accepts.
#[serde(default)]
pub mrsigner_seam_allowlist: Vec<Vec<u8>>,
/// Per-RTMR allowlists. Index 0 = RTMR0, 1 = RTMR1, etc.
/// `None` disables enforcement for that register.
#[serde(default)]
pub rtmr0_allowlist: Vec<Vec<u8>>,
#[serde(default)]
pub rtmr1_allowlist: Vec<Vec<u8>>,
#[serde(default)]
pub rtmr2_allowlist: Vec<Vec<u8>>,
#[serde(default)]
pub rtmr3_allowlist: Vec<Vec<u8>>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub max_attestation_age_epochs: Option<u64>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub min_pce_svn: Option<u16>,
#[serde(default)]
pub require_receipt_binding: bool,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub intel_tcb_signing_cert_der: Option<Vec<u8>>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub tcb_info_json: Option<String>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub qe_identity_json: Option<String>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub pck_crl_der: Option<Vec<u8>>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub root_ca_crl_der: Option<Vec<u8>>,
#[serde(default)]
pub allowed_tcb_statuses: Vec<String>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub collateral_max_age_epochs: Option<u64>
}Source line: 787.
compute_state::SgxDcapTrustAnchors
Phase 14b — Intel SGX DCAP trust anchor material.
pinned_intel_root_fingerprint_sha256: SHA-256 of the Intel SGX
Root CA certificate (DER form). When set, the verifier walks the
PCK certificate chain inside the quote (PCK leaf → PCK Platform CA →
Intel SGX Root CA), validates the SHA-256 fingerprint of the root
against the operator anchor, verifies every link's
ECDSA-P-256/SHA-256 signature, and uses the PCK leaf pubkey to
verify the QE report signature inside the quote.
mrenclave_allowlist: 32-byte SHA-256 enclave-image measurements
(MRENCLAVE) the chain accepts.
mrsigner_allowlist: 32-byte SHA-256 enclave-signer measurements
(MRSIGNER) the chain accepts. Either the report's MRENCLAVE
must match the MRENCLAVE allowlist, or the report's MRSIGNER
must match the MRSIGNER allowlist (both can be configured for
belt-and-braces; at least one must be non-empty for the verifier to
have something to compare against).
max_attestation_age_epochs: when set, enforces a freshness window
against att.generated_at_epoch (operator-supplied, since DCAP
quotes carry collateral timestamps but we keep parity with the
SEV-SNP gate for now).
min_isv_svn: minimum ISVSVN value the chain accepts on the ISV
enclave report. min_pce_svn plays the same role for the
platform-config-enclave SVN advertised in the quote header.
require_receipt_binding: when true, the verifier requires the
ISV report's REPORT_DATA field at offset 0x140 (first 64 bytes) to
match att.binding_nonce decoded as 64 bytes of hex.
#[cfg(feature = "compute")]
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize, Default)]
pub struct SgxDcapTrustAnchors {
/// SHA-256 of Intel SGX Root CA DER. When `None`, every well-formed
/// quote falls into `FixtureMaterialRequired` (Phase 13 posture).
#[serde(default, skip_serializing_if = "Option::is_none")]
pub pinned_intel_root_fingerprint_sha256: Option<[u8; 32]>,
/// 32-byte MRENCLAVE values the chain accepts.
#[serde(default)]
pub mrenclave_allowlist: Vec<Vec<u8>>,
/// 32-byte MRSIGNER values the chain accepts.
#[serde(default)]
pub mrsigner_allowlist: Vec<Vec<u8>>,
/// Freshness window in chain epochs.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub max_attestation_age_epochs: Option<u64>,
/// Minimum ISV enclave SVN.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub min_isv_svn: Option<u16>,
/// Minimum PCE SVN (from quote header).
#[serde(default, skip_serializing_if = "Option::is_none")]
pub min_pce_svn: Option<u16>,
/// Require REPORT_DATA receipt-binding on every quote.
#[serde(default)]
pub require_receipt_binding: bool,
// ----- Phase 14b-2 collateral hardening -----
/// Intel TCB Signing Cert (DER). The cert that signs Intel TCB
/// Info and QE Identity JSON. Must be signed by Intel SGX Root
/// CA (the verifier validates this against the pinned root at
/// quote time). When `None`, every quote is rejected with
/// `FixtureMaterialRequired` once collateral fields are present —
/// a partial collateral configuration is itself a misconfiguration.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub intel_tcb_signing_cert_der: Option<Vec<u8>>,
/// Intel TCB Info JSON document. Operator-supplied; the verifier
/// checks the signature on the inner `tcbInfo` value with the TCB
/// Signing Cert pubkey, walks `tcbLevels` against the quote's
/// CPUSVN / PCESVN, and rejects when the resolved status is not
/// in `allowed_tcb_statuses`.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub tcb_info_json: Option<String>,
/// Intel QE Identity JSON document. Operator-supplied; the
/// verifier checks the signature on `enclaveIdentity`, matches
/// fields against the quote's QE report (mrsigner / isvprodid /
/// miscselect / attributes), and walks `tcbLevels` against the
/// QE ISVSVN.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub qe_identity_json: Option<String>,
/// PCK Platform CA CRL (DER). Required when collateral is on. The
/// verifier rejects when the PCK leaf serial appears in the
/// revoked list or when the CRL is expired.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub pck_crl_der: Option<Vec<u8>>,
/// Intel SGX Root CA CRL (DER). Optional. When set, the verifier
/// also rejects when the PCK Platform CA serial appears in this
/// CRL.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub root_ca_crl_der: Option<Vec<u8>>,
/// Allowed Intel TCB statuses. The verifier interprets the
/// **empty** Vec as the strict default `["UpToDate"]` —
/// `OutOfDate`, `Revoked`, `ConfigurationNeeded`,
/// `ConfigurationAndSWHardeningNeeded`, `SWHardeningNeeded`, etc.
/// all reject unless explicitly listed here.
#[serde(default)]
pub allowed_tcb_statuses: Vec<String>,
/// Maximum collateral age in chain epochs. When set, the verifier
/// requires the TCB Info / QE Identity to be no older than this
/// many epochs relative to the chain `now_epoch` (uses the
/// collateral's `issueDate` field).
#[serde(default, skip_serializing_if = "Option::is_none")]
pub collateral_max_age_epochs: Option<u64>
}Source line: 860.
compute_state::ComputeSnapshot
JSON-serialisable snapshot of the compute marketplace state.
Used by MemoryExecutionState::compute_snapshot
MemoryExecutionState::compute_restore to provide restart/reload
semantics until a disk-backed state store lands across the rest of the
chain. Every field round-trips through serde so the snapshot can be
written to disk, sent over the wire, or replayed in tests.
SigilHash-keyed maps are stored as Vec<(SigilHash, ...)> because
JSON requires string keys at the protocol level. The structures are
rebuilt into HashMaps by compute_restore.
#[cfg(feature = "compute")]
#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct ComputeSnapshot {
pub policy: ComputePolicy,
pub clock: (u64, u64),
pub providers: std::collections::HashMap<String, ComputeProvider>,
pub escrows: std::collections::HashMap<String, ComputeEscrow>,
pub jobs: std::collections::HashMap<String, ComputeJob>,
pub receipts: std::collections::HashMap<String, ComputeReceiptRecord>,
pub settled: std::collections::HashSet<String>,
pub challenges: std::collections::HashMap<String, ComputeChallenge>,
pub audit: Vec<ComputeAuditEvent>,
pub audit_seq: u64,
pub reputation: std::collections::HashMap<String, Vec<ComputeReputationSignal>>,
/// `(work_id, claim)` pairs — JSON cannot key maps by `SigilHash`.
pub maca_claims: Vec<(sigil_core::hash::SigilHash, MacaWorkClaim)>,
/// `(work_id, [(validator_did, record), ...])` — same reason.
pub maca_validations: Vec<(
sigil_core::hash::SigilHash,
Vec<(String, MacaValidationRecord)>,
)>,
pub balances: std::collections::HashMap<String, u64>,
/// Phase 12 — `MacaEpoch` state.
#[serde(default)]
pub maca_epochs: std::collections::HashMap<u64, MacaEpoch>,
/// Phase 12 — `(epoch_id, work_id) → MacaQuorumProof`.
#[serde(default)]
pub maca_quorum_proofs: Vec<((u64, sigil_core::hash::SigilHash), MacaQuorumProof)>,
/// Phase 12 — `(epoch_id) → BeaconRecord`.
#[serde(default)]
pub maca_beacons: std::collections::HashMap<u64, BeaconRecord>,
/// Phase 12 — registered MACA validator agents.
#[serde(default)]
pub validator_agents: std::collections::HashMap<String, ValidatorAgentRecord>
}Source line: 944.