sigil-state · dao_validators::snapshot
Source declarations, signatures and documentation for dao_validators::snapshot.
Source: sigil/node/sigil-state/src/dao_validators/snapshot.rs. SHA-256: f07f7133cc4c0fde8c6627d082b812d13ce243acf2a9f28fe08f3e2bc8ece41a.
This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.
Module condition:
#[cfg(any(feature = "dao-validators", test))]dao_validators::snapshot::IssuerTrust
Outcome of running the GAL trust path on a single subject DID. This captures the resolver-level result without leaking the async resolver machinery into validator code.
#[cfg(any(feature = "dao-validators", test))]
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
#[serde(tag = "kind", rename_all = "snake_case")]
pub enum IssuerTrust {
/// The full GAL trust path (Rules 1-7) accepts this issuer:
///
/// - revocation-first: not revoked
/// - root anchor present, status `"active"`, anchored in the past
/// - non-root issuers presented a valid `AgentLineageProof2025`
/// - if the GAL has an `OrgLineageRoot` for the creator, the
/// inclusion proof verified
Verified {
/// The terminal root anchor that grounds this issuer.
anchor: GalRootAnchor,
/// The on-chain `OrgLineageRoot` for this issuer when it is an
/// MHR / ENR org. `None` for HMRs and for orgs that haven't
/// published a Merkle commitment yet.
org_root: Option<GalOrgLineageRoot>,
},
/// The GAL has no terminal root anchor for this DID (or any
/// ancestor). The trust path cannot ground the issuer.
MissingRoot,
/// The DID, or one of its ancestors, is revoked on Sigil. Cascade
/// revocation rejects.
Revoked {
/// The specific revoked DID (issuer itself or an ancestor).
revoked_did: String,
},
/// A non-root issuer presented a `derivation_proof` that did not
/// verify against the parent's declared `verificationMethod`, OR
/// the proof was missing entirely.
ParentSignatureInvalid {
/// The DID whose proof failed.
did: String,
/// Free-form detail.
reason: String,
},
/// The GAL has an `OrgLineageRoot` for the creator, but the entity
/// presented no inclusion proof.
OrgInclusionMissing {
/// The DID with the missing proof.
did: String,
},
/// An `org_inclusion_proof` was present but did not verify against
/// the on-chain Merkle root.
OrgInclusionInvalid {
/// The DID whose proof failed.
did: String,
/// Free-form detail.
reason: String,
},
/// The GAL backend was unreachable. Validators MUST treat this as a
/// hard rejection.
Unreachable {
/// Free-form transport detail.
reason: String,
},
}Source line: 32.
dao_validators::snapshot::IssuerTrust::is_verified
True iff the issuer is fully GAL-verified for the recorded block height.
#[cfg(any(feature = "dao-validators", test))]
pub fn is_verified(&self) -> bool;Source line: 91.
dao_validators::snapshot::IssuerTrust::to_error
Promote this trust verdict into a typed validator error. Used by
validators when they encounter a non-Verified outcome.
#[cfg(any(feature = "dao-validators", test))]
pub fn to_error(&self, fallback_did: &str) -> DaoValidatorError;Source line: 97.
dao_validators::snapshot::GalSnapshot
Canonical, sync, replay-safe GAL view consumed by validators.
The snapshot is keyed by DID. Validators look up the issuer DID, the actor DID, and any ancestor DIDs from this single in-memory map. Building the snapshot is async (it talks to the GAL); validation is sync.
#[cfg(any(feature = "dao-validators", test))]
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct GalSnapshot {
/// Block height at which the snapshot was taken. Validators MUST
/// use this rather than wall-clock time, so replay is deterministic.
pub snapshot_block: u64,
/// Per-DID trust verdicts. `BTreeMap` for deterministic iteration.
pub issuer_trust: BTreeMap<String, IssuerTrust>,
/// Per-DID revocation status (raw GAL data). Used by cascade-revoke
/// validators that need to walk lineage chains independently of the
/// `IssuerTrust::Verified` outcome.
pub revocations: BTreeMap<String, GalRevocationStatus>
}Source line: 140.
dao_validators::snapshot::GalSnapshot::require_trust
Look up an issuer's trust verdict, or return
DaoValidatorError::Internal when the snapshot did not include
the DID. (This is a programmer-error surface — validators must
always pre-populate every DID they will reference.)
#[cfg(any(feature = "dao-validators", test))]
pub fn require_trust(&self, did: &str) -> Result<&IssuerTrust, DaoValidatorError>;Source line: 157.
dao_validators::snapshot::GalSnapshot::require_revocation
Look up the raw revocation status for a DID. Returns
Internal when missing.
#[cfg(any(feature = "dao-validators", test))]
pub fn require_revocation(&self, did: &str) -> Result<&GalRevocationStatus, DaoValidatorError>;Source line: 167.
dao_validators::snapshot::IssuerVerifier
Async trait that produces a single-issuer trust verdict by consuming
the live GAL trust path. Production wires this to a thin wrapper
over oas_resolve::SigilGuardedResolver; tests wire it to a
MemoryGalSource-backed implementation.
The trait is async because the underlying GAL queries are async; the snapshot itself is sync.
#[cfg(any(feature = "dao-validators", test))]
#[async_trait]
pub trait IssuerVerifier: Send + Sync {
/// Resolve the GAL trust verdict for `did`. Implementations MUST:
///
/// - run revocation-first
/// - reject anchors whose status is not `"active"` or whose
/// `anchored_at_block` is in the future
/// - exercise parent-signature verification on non-root issuers
/// - exercise org Merkle inclusion when the GAL has a root for the
/// creator
///
/// Failures from the GAL trust path become `IssuerTrust` failure
/// variants; the result is `Err` only for `IssuerVerifier`-level
/// programming errors (which validators surface as
/// [`DaoValidatorError::Internal`]).
async fn verify_issuer(&self, did: &str) -> Result<IssuerTrust, DaoValidatorError>;
}Source line: 184.
dao_validators::snapshot::build_snapshot
Build a GalSnapshot covering every DID a validator will reference.
subject_dids is the union of (issuer, actor, every ancestor in the
human_root_chain). The builder issues:
- one
IssuerVerifier::verify_issuerper DID — the live GAL trust path, recorded as the snapshot'sissuer_trustentry. - one
SigilGalSource::check_revocationper DID — captured inrevocationsfor cascade-revoke validators that walk lineage.
Failures from the GAL itself surface as IssuerTrust::Unreachable
inside the verdict; transport errors during the raw
check_revocation calls bubble up as
[DaoValidatorError::GalUnreachable].
#[cfg(any(feature = "dao-validators", test))]
pub async fn build_snapshot<V, G>(
verifier: &V,
gal: &G,
snapshot_block: u64,
subject_dids: &[String],
) -> Result<GalSnapshot, DaoValidatorError>
where
V: IssuerVerifier + ?Sized,
G: SigilGalSource + ?Sized,;Source line: 215.