Sigil documentation
ReferenceRust referencesigil-state

sigil-state · dao_validators::snapshot

Source declarations, signatures and documentation for dao_validators::snapshot.

Source: sigil/node/sigil-state/src/dao_validators/snapshot.rs. SHA-256: f07f7133cc4c0fde8c6627d082b812d13ce243acf2a9f28fe08f3e2bc8ece41a.

This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.

Module condition:

#[cfg(any(feature = "dao-validators", test))]

dao_validators::snapshot::IssuerTrust

Outcome of running the GAL trust path on a single subject DID. This captures the resolver-level result without leaking the async resolver machinery into validator code.

#[cfg(any(feature = "dao-validators", test))]
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
#[serde(tag = "kind", rename_all = "snake_case")]
pub enum IssuerTrust {
    /// The full GAL trust path (Rules 1-7) accepts this issuer:
    ///
    /// - revocation-first: not revoked
    /// - root anchor present, status `"active"`, anchored in the past
    /// - non-root issuers presented a valid `AgentLineageProof2025`
    /// - if the GAL has an `OrgLineageRoot` for the creator, the
    ///   inclusion proof verified
    Verified {
        /// The terminal root anchor that grounds this issuer.
        anchor: GalRootAnchor,
        /// The on-chain `OrgLineageRoot` for this issuer when it is an
        /// MHR / ENR org. `None` for HMRs and for orgs that haven't
        /// published a Merkle commitment yet.
        org_root: Option<GalOrgLineageRoot>,
    },
    /// The GAL has no terminal root anchor for this DID (or any
    /// ancestor). The trust path cannot ground the issuer.
    MissingRoot,
    /// The DID, or one of its ancestors, is revoked on Sigil. Cascade
    /// revocation rejects.
    Revoked {
        /// The specific revoked DID (issuer itself or an ancestor).
        revoked_did: String,
    },
    /// A non-root issuer presented a `derivation_proof` that did not
    /// verify against the parent's declared `verificationMethod`, OR
    /// the proof was missing entirely.
    ParentSignatureInvalid {
        /// The DID whose proof failed.
        did: String,
        /// Free-form detail.
        reason: String,
    },
    /// The GAL has an `OrgLineageRoot` for the creator, but the entity
    /// presented no inclusion proof.
    OrgInclusionMissing {
        /// The DID with the missing proof.
        did: String,
    },
    /// An `org_inclusion_proof` was present but did not verify against
    /// the on-chain Merkle root.
    OrgInclusionInvalid {
        /// The DID whose proof failed.
        did: String,
        /// Free-form detail.
        reason: String,
    },
    /// The GAL backend was unreachable. Validators MUST treat this as a
    /// hard rejection.
    Unreachable {
        /// Free-form transport detail.
        reason: String,
    },
}

Source line: 32.

dao_validators::snapshot::IssuerTrust::is_verified

True iff the issuer is fully GAL-verified for the recorded block height.

#[cfg(any(feature = "dao-validators", test))]
pub fn is_verified(&self) -> bool;

Source line: 91.

dao_validators::snapshot::IssuerTrust::to_error

Promote this trust verdict into a typed validator error. Used by validators when they encounter a non-Verified outcome.

#[cfg(any(feature = "dao-validators", test))]
pub fn to_error(&self, fallback_did: &str) -> DaoValidatorError;

Source line: 97.

dao_validators::snapshot::GalSnapshot

Canonical, sync, replay-safe GAL view consumed by validators.

The snapshot is keyed by DID. Validators look up the issuer DID, the actor DID, and any ancestor DIDs from this single in-memory map. Building the snapshot is async (it talks to the GAL); validation is sync.

#[cfg(any(feature = "dao-validators", test))]
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct GalSnapshot {
/// Block height at which the snapshot was taken. Validators MUST

/// use this rather than wall-clock time, so replay is deterministic.

pub snapshot_block: u64,
/// Per-DID trust verdicts. `BTreeMap` for deterministic iteration.

pub issuer_trust: BTreeMap<String, IssuerTrust>,
/// Per-DID revocation status (raw GAL data). Used by cascade-revoke

/// validators that need to walk lineage chains independently of the

/// `IssuerTrust::Verified` outcome.

pub revocations: BTreeMap<String, GalRevocationStatus>
}

Source line: 140.

dao_validators::snapshot::GalSnapshot::require_trust

Look up an issuer's trust verdict, or return DaoValidatorError::Internal when the snapshot did not include the DID. (This is a programmer-error surface — validators must always pre-populate every DID they will reference.)

#[cfg(any(feature = "dao-validators", test))]
pub fn require_trust(&self, did: &str) -> Result<&IssuerTrust, DaoValidatorError>;

Source line: 157.

dao_validators::snapshot::GalSnapshot::require_revocation

Look up the raw revocation status for a DID. Returns Internal when missing.

#[cfg(any(feature = "dao-validators", test))]
pub fn require_revocation(&self, did: &str) -> Result<&GalRevocationStatus, DaoValidatorError>;

Source line: 167.

dao_validators::snapshot::IssuerVerifier

Async trait that produces a single-issuer trust verdict by consuming the live GAL trust path. Production wires this to a thin wrapper over oas_resolve::SigilGuardedResolver; tests wire it to a MemoryGalSource-backed implementation.

The trait is async because the underlying GAL queries are async; the snapshot itself is sync.

#[cfg(any(feature = "dao-validators", test))]
#[async_trait]
pub trait IssuerVerifier: Send + Sync {
    /// Resolve the GAL trust verdict for `did`. Implementations MUST:
    ///
    /// - run revocation-first
    /// - reject anchors whose status is not `"active"` or whose
    ///   `anchored_at_block` is in the future
    /// - exercise parent-signature verification on non-root issuers
    /// - exercise org Merkle inclusion when the GAL has a root for the
    ///   creator
    ///
    /// Failures from the GAL trust path become `IssuerTrust` failure
    /// variants; the result is `Err` only for `IssuerVerifier`-level
    /// programming errors (which validators surface as
    /// [`DaoValidatorError::Internal`]).
    async fn verify_issuer(&self, did: &str) -> Result<IssuerTrust, DaoValidatorError>;
}

Source line: 184.

dao_validators::snapshot::build_snapshot

Build a GalSnapshot covering every DID a validator will reference.

subject_dids is the union of (issuer, actor, every ancestor in the human_root_chain). The builder issues:

  • one IssuerVerifier::verify_issuer per DID — the live GAL trust path, recorded as the snapshot's issuer_trust entry.
  • one SigilGalSource::check_revocation per DID — captured in revocations for cascade-revoke validators that walk lineage.

Failures from the GAL itself surface as IssuerTrust::Unreachable inside the verdict; transport errors during the raw check_revocation calls bubble up as [DaoValidatorError::GalUnreachable].

#[cfg(any(feature = "dao-validators", test))]
pub async fn build_snapshot<V, G>(
    verifier: &V,
    gal: &G,
    snapshot_block: u64,
    subject_dids: &[String],
) -> Result<GalSnapshot, DaoValidatorError>
where
    V: IssuerVerifier + ?Sized,
    G: SigilGalSource + ?Sized,;

Source line: 215.

On this page