pub struct DriveDocumentQuery<'a> {
pub contract: &'a DataContract,
pub document_type: DocumentTypeRef<'a>,
pub internal_clauses: InternalClauses,
pub offset: Option<u16>,
pub limit: Option<u16>,
pub order_by: IndexMap<String, OrderClause>,
pub start_at: Option<[u8; 32]>,
pub start_at_included: bool,
pub block_time_ms: Option<u64>,
pub resolved_time_ranges: Vec<ResolvedTimeRange>,
pub sub_queries: Vec<DriveSubQuery<'a>>,
}Expand description
Drive query struct
Fields§
§contract: &'a DataContractDataContract
document_type: DocumentTypeRef<'a>Document type
internal_clauses: InternalClausesInternal clauses
offset: Option<u16>Offset
limit: Option<u16>Limit
order_by: IndexMap<String, OrderClause>Order by
start_at: Option<[u8; 32]>Start at document id
start_at_included: boolStart at included
block_time_ms: Option<u64>Block time
resolved_time_ranges: Vec<ResolvedTimeRange>The fields whose equality clause in internal_clauses was produced by
IN_TIME_RANGE resolution — i.e. by
resolve_time_range_bucket_clause, on the server from committed
block time and in the verifier from the quorum-signed response metadata
time.
Never parsed from the wire: every from_cbor / from_value /
from_typed_clauses entry point leaves this empty, so a client cannot
claim resolution it did not go through. It is what
Self::find_best_index uses to pin index selection to the index that
buckets the field (see index_admissible_for_resolved_time_range),
which is required because the resolved clause is an ordinary equality
and cannot be told apart from a raw-timestamp lookup once built.
Empty for every raw query.
sub_queries: Vec<DriveSubQuery<'a>>The composite sub-queries: queries whose IN clauses are derived
from this query’s proven results (by-id joins, indexed lookups,
counts — see the composite_document_query module docs), listed
in binding order (a sub-query may only bind an earlier one) and
answered together with this query as ONE merged grovedb proof.
Empty for an ordinary documents query, which is what every plain
entry point requires: a query carrying sub-queries is served by
Drive::query_composite_documents /
query_composite_documents_with_proof and verified by
verify_composite_documents_proof, and the plain
query/proof/verify surfaces refuse it rather than silently prove
the page alone.
Never parsed from the wire: every from_cbor / from_value /
from_typed_clauses entry point leaves this empty; composite
requests are built programmatically (see
Self::with_sub_queries).
Implementations§
Source§impl<'a> DriveDocumentQuery<'a>
impl<'a> DriveDocumentQuery<'a>
Sourcepub fn validate_chained(
&self,
platform_version: &PlatformVersion,
) -> Result<(), Error>
pub fn validate_chained( &self, platform_version: &PlatformVersion, ) -> Result<(), Error>
Validates the chained shape: this query as the inner indexOnly
half plus the single by-id join its
sub_queries carry (see
Self::chained_join). Called by the server before executing and
by the verifier before verifying, so an invalid spec fails
identically on both sides.
Sourcepub fn chained_join_values(
&self,
inner_documents: &[Document],
) -> Result<Vec<Identifier>, Error>
pub fn chained_join_values( &self, inner_documents: &[Document], ) -> Result<Vec<Identifier>, Error>
Extracts the join values from the inner documents in their proof order, deduplicated to first appearance. ONE extraction both the server and the verifier run — the single-builder rule that keeps the derived outer query identical on both sides.
Sourcepub fn derive_chained_outer_query(
&self,
join_values: &[Identifier],
) -> Result<DriveDocumentQuery<'a>, Error>
pub fn derive_chained_outer_query( &self, join_values: &[Identifier], ) -> Result<DriveDocumentQuery<'a>, Error>
The derived outer query: a pure by-ids fetch of the join values
from the outer type’s primary storage. No clauses, no limit, no
cursor — completeness is set-equality against join_values,
checked by the verifier.
Sourcepub fn assemble_chained_outer_documents(
&self,
join_values: &[Identifier],
outer_documents: Vec<Document>,
) -> Result<Vec<Document>, Error>
pub fn assemble_chained_outer_documents( &self, join_values: &[Identifier], outer_documents: Vec<Document>, ) -> Result<Vec<Document>, Error>
Reorders the outer documents (returned in key order by the by-ids query) into first-appearance join order, and enforces EXACT set equality between the proven outer ids and the derived join values — both directions. Shared by the server (where a mismatch is corrupted state: permanentDocument references cannot dangle) and the verifier (where it is an invalid proof).
Sourcepub fn chained_proof_path_queries(
&self,
join_values: &[Identifier],
platform_version: &PlatformVersion,
) -> Result<Vec<PathQuery>, Error>
pub fn chained_proof_path_queries( &self, join_values: &[Identifier], platform_version: &PlatformVersion, ) -> Result<Vec<PathQuery>, Error>
The component path queries the chained proof covers: the inner
query’s own path query, plus — for a non-empty join — the outer
by-ids path query derived from join_values. ONE builder both
the prover (prove_query_many merges these) and the verifier
(PathQuery::merge on the same inputs at the same grove
version) call, so the merged query is byte-identical on both
sides. Grovedb’s merge lifts the inner query’s global
SizedQuery::limit into its branch’s per-instance
Query::limit, which is exact here: the branch instance
executes once.
Source§impl<'a> DriveDocumentQuery<'a>
impl<'a> DriveDocumentQuery<'a>
Sourcepub fn validate_composite(
&self,
platform_version: &PlatformVersion,
) -> Result<(), Error>
pub fn validate_composite( &self, platform_version: &PlatformVersion, ) -> Result<(), Error>
Validates the composite shape: this query as the page plus its
sub_queries. Called by the server before
executing and by the verifier before verifying, so an invalid
request fails identically on both sides.
Construction contract: every sub-query’s document_type MUST be a
document type of its own contract. This validates everything
derivable from the shapes themselves.
Sourcepub fn page_path_query(
&self,
platform_version: &PlatformVersion,
) -> Result<PathQuery, Error>
pub fn page_path_query( &self, platform_version: &PlatformVersion, ) -> Result<PathQuery, Error>
The page as a component of the proof, its limit carried as its
root query’s per-instance cap (see Self::budget_as_instance_cap).
A by-ids page is built WITHOUT its limit: its ids already bound
it, and grovedb refuses a budget on a query that lands at the
merged root (which a by-ids page shares with a join on the same
type).
Sourcepub fn derive_values(
&self,
binding: &SubQueryBinding,
source_documents: &[Document],
) -> Result<Vec<Identifier>, Error>
pub fn derive_values( &self, binding: &SubQueryBinding, source_documents: &[Document], ) -> Result<Vec<Identifier>, Error>
Extracts a binding’s values from its source documents in their order, deduplicated to first appearance. ONE extraction both the server and the verifier run — the single-builder rule that keeps every derived sub-query identical on both sides.
Sourcepub fn sub_query_document_query(
&self,
sub_query: &DriveSubQuery<'a>,
values: &[Identifier],
platform_version: &PlatformVersion,
) -> Result<DriveDocumentQuery<'a>, Error>
pub fn sub_query_document_query( &self, sub_query: &DriveSubQuery<'a>, values: &[Identifier], platform_version: &PlatformVersion, ) -> Result<DriveDocumentQuery<'a>, Error>
The concrete documents query of a sub-query for values: the
fixed clauses plus the derived IN, or a pure by-ids fetch for
a join. A sibling ignores values.
Sourcepub fn sub_query_count_query<'b>(
&'b self,
sub_query: &'b DriveSubQuery<'a>,
values: &[Identifier],
_platform_version: &PlatformVersion,
) -> Result<DriveDocumentCountQuery<'b>, Error>
pub fn sub_query_count_query<'b>( &'b self, sub_query: &'b DriveSubQuery<'a>, values: &[Identifier], _platform_version: &PlatformVersion, ) -> Result<DriveDocumentCountQuery<'b>, Error>
The concrete count query of a bound count sub-query for values.
Borrows the covering index through sub_query, so the count query
lives as long as that reference.
Sourcepub fn sub_query_path_query(
&self,
sub_query: &DriveSubQuery<'a>,
values: &[Identifier],
platform_version: &PlatformVersion,
) -> Result<PathQuery, Error>
pub fn sub_query_path_query( &self, sub_query: &DriveSubQuery<'a>, values: &[Identifier], platform_version: &PlatformVersion, ) -> Result<PathQuery, Error>
The path query of one sub-query for values.
Sourcepub fn proof_path_queries(
&self,
derived: &[Vec<Identifier>],
platform_version: &PlatformVersion,
) -> Result<(PathQuery, Vec<Option<PathQuery>>), Error>
pub fn proof_path_queries( &self, derived: &[Vec<Identifier>], platform_version: &PlatformVersion, ) -> Result<(PathQuery, Vec<Option<PathQuery>>), Error>
The component path queries the merged proof covers, in component
order: the page, then one entry per sub-query — None for a
bound sub-query whose binding derived nothing (it has no branch).
Every sub-query walks in the page’s direction: documents must
already agree, while counts and by-id joins may be aligned without
changing their selected sets. ONE builder both the prover and the
verifier feed into Self::merged_path_query, so the merged
query is byte-identical on both sides.
Sourcepub fn merged_path_query(
page: &PathQuery,
sub_path_queries: &[Option<PathQuery>],
platform_version: &PlatformVersion,
) -> Result<PathQuery, Error>
pub fn merged_path_query( page: &PathQuery, sub_path_queries: &[Option<PathQuery>], platform_version: &PlatformVersion, ) -> Result<PathQuery, Error>
Merges the component path queries into the one query the proof
covers. Components carry their budgets as per-instance caps (see
Self::budget_as_instance_cap), which the merge carries along
on their branches, so a page alone is proven in the very form it
would have inside a merge.
Sourcepub fn derive_all<'d>(
&self,
page_documents: &[Document],
sub_documents: impl Fn(usize) -> Option<&'d [Document]>,
) -> Result<Vec<Vec<Identifier>>, Error>
pub fn derive_all<'d>( &self, page_documents: &[Document], sub_documents: impl Fn(usize) -> Option<&'d [Document]>, ) -> Result<Vec<Vec<Identifier>>, Error>
Derives every sub-query’s values, in request order — see
Self::derive_for.
Source§impl<'a> DriveDocumentQuery<'a>
impl<'a> DriveDocumentQuery<'a>
Sourcepub fn new_primary_key_single_item_query(
contract: &'a DataContract,
document_type: DocumentTypeRef<'a>,
id: Identifier,
) -> Self
pub fn new_primary_key_single_item_query( contract: &'a DataContract, document_type: DocumentTypeRef<'a>, id: Identifier, ) -> Self
Gets a document by their primary key
Sourcepub fn any_item_query(
contract: &'a DataContract,
document_type: DocumentTypeRef<'a>,
) -> Self
pub fn any_item_query( contract: &'a DataContract, document_type: DocumentTypeRef<'a>, ) -> Self
Returns any item
Sourcepub fn all_items_query(
contract: &'a DataContract,
document_type: DocumentTypeRef<'a>,
limit: Option<u16>,
) -> Self
pub fn all_items_query( contract: &'a DataContract, document_type: DocumentTypeRef<'a>, limit: Option<u16>, ) -> Self
Returns all items
Sourcepub fn with_sub_queries(self, sub_queries: Vec<DriveSubQuery<'a>>) -> Self
pub fn with_sub_queries(self, sub_queries: Vec<DriveSubQuery<'a>>) -> Self
Extends this query into a composite one: self becomes the page
and sub_queries are derived from its proven results — see
Self::sub_queries and the composite_document_query module
docs.
Sourcepub fn with_by_id_join(
self,
source_property: impl Into<String>,
document_type: DocumentTypeRef<'a>,
) -> Self
pub fn with_by_id_join( self, source_property: impl Into<String>, document_type: DocumentTypeRef<'a>, ) -> Self
Appends a by-id join sub-query: source_property’s values, read
off this query’s proven documents, become the $ids of
document_type documents fetched from the same contract. The
property must carry a refersTo: permanentDocument declaration
targeting document_type, so every derived id resolves.
This is the one shape the chained surface
(Drive::query_chained_documents,
verify_chained_documents_proof) requires exactly one of, and one
of the composite sub-query shapes. A cross-contract by-id join
(composite only) is built by pushing a DriveSubQuery with the
target contract instead.
Sourcepub fn is_for_primary_key(&self) -> bool
pub fn is_for_primary_key(&self) -> bool
Returns true if the query clause if for primary keys.
Sourcepub fn from_cbor(
query_cbor: &[u8],
contract: &'a DataContract,
document_type: DocumentTypeRef<'a>,
config: &DriveConfig,
platform_version: &PlatformVersion,
) -> Result<Self, Error>
pub fn from_cbor( query_cbor: &[u8], contract: &'a DataContract, document_type: DocumentTypeRef<'a>, config: &DriveConfig, platform_version: &PlatformVersion, ) -> Result<Self, Error>
Converts a query CBOR to a DriveQuery.
Sourcepub fn from_value(
query_value: Value,
contract: &'a DataContract,
document_type: DocumentTypeRef<'a>,
config: &DriveConfig,
platform_version: &PlatformVersion,
) -> Result<Self, Error>
pub fn from_value( query_value: Value, contract: &'a DataContract, document_type: DocumentTypeRef<'a>, config: &DriveConfig, platform_version: &PlatformVersion, ) -> Result<Self, Error>
Converts a query Value to a DriveQuery.
Sourcepub fn from_btree_map_value(
query_document: BTreeMap<String, Value>,
contract: &'a DataContract,
document_type: DocumentTypeRef<'a>,
config: &DriveConfig,
platform_version: &PlatformVersion,
) -> Result<Self, Error>
pub fn from_btree_map_value( query_document: BTreeMap<String, Value>, contract: &'a DataContract, document_type: DocumentTypeRef<'a>, config: &DriveConfig, platform_version: &PlatformVersion, ) -> Result<Self, Error>
Converts a query Value to a DriveQuery.
Sourcepub fn from_decomposed_values(
where_clause: Value,
order_by: Option<Value>,
maybe_limit: Option<u16>,
start_at: Option<[u8; 32]>,
start_at_included: bool,
block_time_ms: Option<u64>,
contract: &'a DataContract,
document_type: DocumentTypeRef<'a>,
config: &DriveConfig,
platform_version: &PlatformVersion,
) -> Result<Self, Error>
pub fn from_decomposed_values( where_clause: Value, order_by: Option<Value>, maybe_limit: Option<u16>, start_at: Option<[u8; 32]>, start_at_included: bool, block_time_ms: Option<u64>, contract: &'a DataContract, document_type: DocumentTypeRef<'a>, config: &DriveConfig, platform_version: &PlatformVersion, ) -> Result<Self, Error>
Converts a query Value to a DriveQuery.
Sourcepub fn from_typed_clauses(
where_clauses: Vec<WhereClause>,
order_by_clauses: Vec<OrderClause>,
maybe_limit: Option<u16>,
start_at: Option<[u8; 32]>,
start_at_included: bool,
block_time_ms: Option<u64>,
contract: &'a DataContract,
document_type: DocumentTypeRef<'a>,
config: &DriveConfig,
platform_version: &PlatformVersion,
) -> Result<Self, Error>
pub fn from_typed_clauses( where_clauses: Vec<WhereClause>, order_by_clauses: Vec<OrderClause>, maybe_limit: Option<u16>, start_at: Option<[u8; 32]>, start_at_included: bool, block_time_ms: Option<u64>, contract: &'a DataContract, document_type: DocumentTypeRef<'a>, config: &DriveConfig, platform_version: &PlatformVersion, ) -> Result<Self, Error>
Build a DriveDocumentQuery from already-structured where /
order_by clauses. This is the typed-input twin of
Self::from_decomposed_values — same downstream shape, just
without the Value::Array(...) parse step.
Used by the v1 getDocuments ABCI handler whose wire format
carries repeated WhereClause / repeated OrderClause
natively (no CBOR envelope). The v0 path keeps using
from_decomposed_values so its CBOR-decoded inputs flow
through the existing WhereClause::from_components parser
for shape validation; the typed path expects that validation
(or the equivalent proto→drive conversion) to have run
upstream.
Limit semantics mirror from_decomposed_values:
maybe_limit = None or Some(0) falls back to
config.default_query_limit; Some(N) with N > config.default_query_limit is rejected as
QuerySyntaxError::InvalidLimit.
Sourcepub fn from_sql_expr(
sql_string: &str,
contract: &'a DataContract,
config: Option<&DriveConfig>,
platform_version: &PlatformVersion,
) -> Result<Self, Error>
pub fn from_sql_expr( sql_string: &str, contract: &'a DataContract, config: Option<&DriveConfig>, platform_version: &PlatformVersion, ) -> Result<Self, Error>
Converts a SQL expression to a DriveQuery.
Sourcepub fn to_cbor(&self) -> Result<Vec<u8>, Error>
pub fn to_cbor(&self) -> Result<Vec<u8>, Error>
Serialize drive query to CBOR format.
FIXME: The data contract is only referred as ID, and document type as its name. This can change in the future to include full data contract and document type.
Sourcepub fn start_at_document_path_and_key(
&self,
starts_at: &[u8; 32],
) -> (Vec<Vec<u8>>, Vec<u8>)
pub fn start_at_document_path_and_key( &self, starts_at: &[u8; 32], ) -> (Vec<Vec<u8>>, Vec<u8>)
Operations to construct a path query.
Sourcepub fn validate_in_clause_shape(
&self,
platform_version: &PlatformVersion,
) -> Result<(), Error>
pub fn validate_in_clause_shape( &self, platform_version: &PlatformVersion, ) -> Result<(), Error>
Versioned preflight over the non-primary-key In clause shape.
Runs before any cursor storage lookup or proof processing so the
rejection precedence matches each protocol version’s contract: v0
rejects more than one In clause with MultipleInClauses before a
startAt/startAfter document is ever fetched (matching the
pre-protocol-version-14 parse-time rejection), and v1 rejects the
unsupported multi-In + cursor combination with Unsupported
before spending state or proof work on the cursor. The lowering
keeps equivalent guards for callers that reach it directly.
Sourcepub fn construct_path_query_operations(
&self,
drive: &Drive,
include_start_at_for_proof: bool,
transaction: TransactionArg<'_, '_>,
drive_operations: &mut Vec<LowLevelDriveOperation>,
platform_version: &PlatformVersion,
) -> Result<PathQuery, Error>
pub fn construct_path_query_operations( &self, drive: &Drive, include_start_at_for_proof: bool, transaction: TransactionArg<'_, '_>, drive_operations: &mut Vec<LowLevelDriveOperation>, platform_version: &PlatformVersion, ) -> Result<PathQuery, Error>
Operations to construct a path query.
Sourcepub fn construct_path_query(
&self,
starts_at_document: Option<Document>,
platform_version: &PlatformVersion,
) -> Result<PathQuery, Error>
pub fn construct_path_query( &self, starts_at_document: Option<Document>, platform_version: &PlatformVersion, ) -> Result<PathQuery, Error>
Operations to construct a path query.
Sourcepub fn pads_cursor_page(&self, platform_version: &PlatformVersion) -> bool
pub fn pads_cursor_page(&self, platform_version: &PlatformVersion) -> bool
Whether a startAfter cursor on this query is lowered as startAt
with one extra result slot, the cursor document then being dropped
from the page by Self::strip_cursor_from_page.
GroveDB charges a result slot for every visited subtree whose subquery yields nothing, and the prover accounts the same way. A lowering that visits the cursor’s branch or index key looking for rows after the cursor therefore pays that slot whenever nothing follows, which is nearly every page on unique-valued data: pages came back one row short, and a limit of one came back empty while later rows remained. Keeping the cursor document in the walk keeps every subtree on its path non-empty, and documents sharing its index key continue by document id. The primary-key path has no subtrees to charge and is left alone, as is the released (protocol version 13) lowering.
Sourcepub fn get_primary_key_path_query(
&self,
document_type_path: Vec<Vec<u8>>,
starts_at_document: Option<(Document, bool)>,
platform_version: &PlatformVersion,
) -> Result<PathQuery, Error>
pub fn get_primary_key_path_query( &self, document_type_path: Vec<Vec<u8>>, starts_at_document: Option<(Document, bool)>, platform_version: &PlatformVersion, ) -> Result<PathQuery, Error>
Returns a path query given a document type path and starting document.
Sourcepub fn find_best_index(
&self,
platform_version: &PlatformVersion,
) -> Result<&Index, Error>
pub fn find_best_index( &self, platform_version: &PlatformVersion, ) -> Result<&Index, Error>
Finds the best index for the query.
Queries with more than one In clause use their own selection
(Self::find_best_index_for_multiple_in_clauses); they only
reach it through the v1 (protocol version 14+) path-query
lowering, since the v0 lowering rejects them first.
Selection is restricted to the indexes admissible for this query’s
Self::resolved_time_ranges: a query carrying an
IN_TIME_RANGE-resolved equality may only be served by the index that
buckets that field, and a raw query may never be served by a bucketed
index. See index_admissible_for_resolved_time_range for why either
mismatch would produce a validly-proven wrong answer. The rule applies
on both routes, including the multiple-In selection.
Sourcepub fn query_item_for_starts_at_key(
starts_at_key: Vec<u8>,
left_to_right: bool,
) -> QueryItem
pub fn query_item_for_starts_at_key( starts_at_key: Vec<u8>, left_to_right: bool, ) -> QueryItem
Returns a QueryItem given a start key and query direction.
Sourcepub fn get_non_primary_key_path_query(
&self,
document_type_path: Vec<Vec<u8>>,
starts_at_document: Option<(Document, bool)>,
platform_version: &PlatformVersion,
) -> Result<PathQuery, Error>
pub fn get_non_primary_key_path_query( &self, document_type_path: Vec<Vec<u8>>, starts_at_document: Option<(Document, bool)>, platform_version: &PlatformVersion, ) -> Result<PathQuery, Error>
Returns a path query for non-primary keys given a document type path and starting document.
Versioned because the set of accepted query shapes is part of the
consensus query contract: v0 rejects more than one In clause per
query, v1 (protocol version 14) lowers multiple In clauses on
consecutive index properties to a multi-level key-set path query.
Sourcepub fn execute_with_proof(
self,
drive: &Drive,
block_info: Option<BlockInfo>,
transaction: TransactionArg<'_, '_>,
platform_version: &PlatformVersion,
) -> Result<(Vec<u8>, u64), Error>
pub fn execute_with_proof( self, drive: &Drive, block_info: Option<BlockInfo>, transaction: TransactionArg<'_, '_>, platform_version: &PlatformVersion, ) -> Result<(Vec<u8>, u64), Error>
Executes a query with proof and returns the items and fee.
Source§impl DriveDocumentQuery<'_>
impl DriveDocumentQuery<'_>
Sourcepub fn verify_chained_documents_proof(
&self,
proof: &[u8],
platform_version: &PlatformVersion,
) -> Result<(RootHash, ChainedDocumentsResult), Error>
pub fn verify_chained_documents_proof( &self, proof: &[u8], platform_version: &PlatformVersion, ) -> Result<(RootHash, ChainedDocumentsResult), Error>
Verifies a chained query’s single merged proof — this query as the
inner half plus the single by-id join its
sub_queries carry — and
returns (root_hash, result).
The verifier trusts nothing about the join, and needs nothing
beyond the proof itself: a BOOTSTRAP subset pass runs the inner
query alone against the merged proof and extracts candidate
join values from its proven positions; the outer by-ids
component is derived from those (exactly as the prover derived
it from its materialization), the merged query is rebuilt, and
the AUTHORITATIVE full pass verifies the whole composition —
grovedb enforces the inner page’s lifted per-instance limit and
range completeness — with the proven outer documents required
to match the proven inner join values exactly. A missing
referenced document is an invalid proof (refersTo: permanentDocument targets cannot dangle), and so is an extra
one; a proof covering only the inner half (an old node serving
the plain query) fails the full pass whenever the inner page is
non-empty.
One proof means one root by construction; the caller combines
the returned root hash with the surrounding tenderdash
signature — see rs-drive-proof-verifier for the canonical
composition.
Source§impl DriveDocumentQuery<'_>
impl DriveDocumentQuery<'_>
Sourcepub fn verify_composite_documents_proof(
&self,
proof: &[u8],
platform_version: &PlatformVersion,
) -> Result<(RootHash, CompositeDocumentsResult), Error>
pub fn verify_composite_documents_proof( &self, proof: &[u8], platform_version: &PlatformVersion, ) -> Result<(RootHash, CompositeDocumentsResult), Error>
Verifies a composite query’s single merged proof — this query as
the page plus its sub_queries
— and returns (root_hash, result).
The verifier trusts nothing about the derivation, and needs
nothing beyond the proof itself: a BOOTSTRAP subset pass runs the
page query (and every sub-query that feeds a later binding) alone
against the merged proof to extract candidate values; every
sub-query is derived from those exactly as the prover derived it
from its materialization, the merged query is rebuilt, and the
AUTHORITATIVE full pass verifies the whole composition — grovedb
enforces every component’s per-instance limit and range
completeness. The proven results are then routed back to their
components: an entry no derivation asked for is an invalid proof,
so is a by-id join missing a referenced document (a
permanentDocument reference cannot dangle), and so is any
divergence between the values the proven page derives and the
candidates the query was built from. A proof covering only the
page (an old node serving the plain query) fails the full pass
whenever a sub-query derived anything.
One proof means one root by construction; the caller combines the
returned root hash with the surrounding tenderdash signature — see
rs-drive-proof-verifier for the canonical composition.
Source§impl DriveDocumentQuery<'_>
impl DriveDocumentQuery<'_>
Sourcepub fn verify_proof(
&self,
proof: &[u8],
platform_version: &PlatformVersion,
) -> Result<(RootHash, Vec<Document>), Error>
pub fn verify_proof( &self, proof: &[u8], platform_version: &PlatformVersion, ) -> Result<(RootHash, Vec<Document>), Error>
Verifies a proof for a collection of documents.
This function takes a byte slice representing the serialized proof, verifies it, and returns a tuple consisting of the root hash and a vector of deserialized documents.
§Arguments
proof- A byte slice representing the proof to be verified.platform_version- The platform version against which to verify the proof.
§Returns
A Result containing:
- A tuple with the root hash and a vector of deserialized
Documents if the proof is valid. - An
Errorvariant, in case the proof verification fails or a deserialization error occurs.
§Errors
This function will return an Error variant if:
- The proof verification fails.
- A deserialization error occurs when parsing the serialized document(s).
Source§impl DriveDocumentQuery<'_>
impl DriveDocumentQuery<'_>
Sourcepub fn verify_proof_keep_serialized(
&self,
proof: &[u8],
platform_version: &PlatformVersion,
) -> Result<(RootHash, Vec<Vec<u8>>), Error>
pub fn verify_proof_keep_serialized( &self, proof: &[u8], platform_version: &PlatformVersion, ) -> Result<(RootHash, Vec<Vec<u8>>), Error>
Verifies the given proof and returns the root hash of the GroveDB tree and a vector of serialized documents if the verification is successful.
§Arguments
proof- A byte slice representing the proof to be verified.platform_version- The platform version against which to verify the proof.
§Returns
- On success, returns a tuple containing the root hash of the GroveDB tree and a vector of serialized documents.
- On failure, returns an Error.
§Errors
This function will return an Error if:
- The start at document is not present in proof and it is expected to be.
- The path query fails to verify against the given proof.
- Converting the element into bytes fails.
Source§impl DriveDocumentQuery<'_>
impl DriveDocumentQuery<'_>
Sourcepub fn verify_start_at_document_in_proof(
&self,
proof: &[u8],
is_proof_subset: bool,
document_id: [u8; 32],
platform_version: &PlatformVersion,
) -> Result<(RootHash, Option<Document>), Error>
pub fn verify_start_at_document_in_proof( &self, proof: &[u8], is_proof_subset: bool, document_id: [u8; 32], platform_version: &PlatformVersion, ) -> Result<(RootHash, Option<Document>), Error>
Verifies if a document exists at the beginning of a proof, and returns the root hash and the optionally found document.
§Arguments
proof- A byte slice containing the proof data.is_proof_subset- A boolean indicating whether the proof is a subset query or not.document_id- A byte_32 array, representing the ID of the document to start at.platform_version- The platform version against which to verify the proof.
§Returns
A Result with a tuple containing:
- The root hash of the verified proof.
- An
Option<Document>containing the found document if available.
§Errors
This function returns an Error in the following cases:
- If the proof is corrupted (wrong path, wrong key, etc.).
- If the provided proof has an incorrect number of elements.
Trait Implementations§
Source§impl<'a> Clone for DriveDocumentQuery<'a>
impl<'a> Clone for DriveDocumentQuery<'a>
Source§fn clone(&self) -> DriveDocumentQuery<'a>
fn clone(&self) -> DriveDocumentQuery<'a>
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl<'a> Debug for DriveDocumentQuery<'a>
impl<'a> Debug for DriveDocumentQuery<'a>
Source§impl<'a> From<&DriveDocumentQuery<'a>> for BTreeMap<String, Value>
Convert DriveQuery to a BTreeMap of values
impl<'a> From<&DriveDocumentQuery<'a>> for BTreeMap<String, Value>
Convert DriveQuery to a BTreeMap of values
Source§fn from(query: &DriveDocumentQuery<'a>) -> Self
fn from(query: &DriveDocumentQuery<'a>) -> Self
Source§impl<'a> PartialEq for DriveDocumentQuery<'a>
impl<'a> PartialEq for DriveDocumentQuery<'a>
Source§fn eq(&self, other: &DriveDocumentQuery<'a>) -> bool
fn eq(&self, other: &DriveDocumentQuery<'a>) -> bool
self and other values to be equal, and is used by ==.impl<'a> StructuralPartialEq for DriveDocumentQuery<'a>
Auto Trait Implementations§
impl<'a> Freeze for DriveDocumentQuery<'a>
impl<'a> RefUnwindSafe for DriveDocumentQuery<'a>
impl<'a> Send for DriveDocumentQuery<'a>
impl<'a> Sync for DriveDocumentQuery<'a>
impl<'a> Unpin for DriveDocumentQuery<'a>
impl<'a> UnsafeUnpin for DriveDocumentQuery<'a>
impl<'a> UnwindSafe for DriveDocumentQuery<'a>
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<T> Conv for T
impl<T> Conv for T
§impl<T> CostsExt for T
impl<T> CostsExt for T
§fn wrap_with_cost(self, cost: OperationCost) -> CostContext<Self>where
Self: Sized,
fn wrap_with_cost(self, cost: OperationCost) -> CostContext<Self>where
Self: Sized,
CostContext object with provided costs.§fn wrap_fn_cost(
self,
f: impl FnOnce(&Self) -> OperationCost,
) -> CostContext<Self>where
Self: Sized,
fn wrap_fn_cost(
self,
f: impl FnOnce(&Self) -> OperationCost,
) -> CostContext<Self>where
Self: Sized,
CostContext object with costs computed using the
value getting wrapped.§impl<T> FmtForward for T
impl<T> FmtForward for T
§fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
self to use its Binary implementation when Debug-formatted.§fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
self to use its Display implementation when
Debug-formatted.§fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
self to use its LowerExp implementation when
Debug-formatted.§fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
self to use its LowerHex implementation when
Debug-formatted.§fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
self to use its Octal implementation when Debug-formatted.§fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
self to use its Pointer implementation when
Debug-formatted.§fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
self to use its UpperExp implementation when
Debug-formatted.§fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
self to use its UpperHex implementation when
Debug-formatted.§fn fmt_list(self) -> FmtList<Self>where
&'a Self: for<'a> IntoIterator,
fn fmt_list(self) -> FmtList<Self>where
&'a Self: for<'a> IntoIterator,
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more§impl<T, U> IntoOnNetwork<U> for Twhere
U: FromOnNetwork<T>,
impl<T, U> IntoOnNetwork<U> for Twhere
U: FromOnNetwork<T>,
§fn into_on_network(self, network: Network) -> U
fn into_on_network(self, network: Network) -> U
Calls U::from_on_network(self).
§impl<T, U> IntoPlatformVersioned<U> for Twhere
U: FromPlatformVersioned<T>,
impl<T, U> IntoPlatformVersioned<U> for Twhere
U: FromPlatformVersioned<T>,
§fn into_platform_versioned(self, platform_version: &PlatformVersion) -> U
fn into_platform_versioned(self, platform_version: &PlatformVersion) -> U
§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read more§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read more§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
self, then passes self.as_ref() into the pipe function.§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
self, then passes self.as_mut() into the pipe
function.§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
self, then passes self.deref() into the pipe function.§impl<T> Pointable for T
impl<T> Pointable for T
impl<T> Read<Exclusive, BecauseExclusive> for Twhere
T: ?Sized,
§impl<T> Tap for T
impl<T> Tap for T
§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Borrow<B> of a value. Read more§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
BorrowMut<B> of a value. Read more§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
AsRef<R> view of a value. Read more§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
AsMut<R> view of a value. Read more§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Deref::Target of a value. Read more§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Deref::Target of a value. Read more§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
.tap() only in debug builds, and is erased in release builds.§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
.tap_mut() only in debug builds, and is erased in release
builds.§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
.tap_borrow() only in debug builds, and is erased in release
builds.§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
.tap_borrow_mut() only in debug builds, and is erased in release
builds.§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
.tap_ref() only in debug builds, and is erased in release
builds.§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
.tap_ref_mut() only in debug builds, and is erased in release
builds.§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
.tap_deref() only in debug builds, and is erased in release
builds.