Skip to main content

verify_ranked_top_k_proof

Function verify_ranked_top_k_proof 

Source
pub fn verify_ranked_top_k_proof(
    query: &DriveDocumentRankedQuery<'_>,
    proof: &Proof,
    mtd: &ResponseMetadata,
    platform_version: &PlatformVersion,
    provider: &dyn ContextProvider,
) -> Result<(RootHash, RankedPage), Error>
Expand description

Verified ranked (GROUP BY … ORDER BY <aggregate> LIMIT n [OFFSET m]) result types. DocumentRankedEntries carries one entry per returned group in ranking order, plus the starting_rank that pins each entry to an absolute position; verify_ranked_top_k_proof is the tenderdash-composition wrapper that binds the proof’s reconstructed root hash to the signed app hash and returns the whole verified drive::query::RankedPage. Verify a grovedb indexed-axis top-k proof and the surrounding tenderdash commit, returning the reconstructed root hash and the RankedPage it commits to.

The page is returned whole rather than as a bare entry list because RankedPage::skipped is verified evidence in its own right: it is re-derived from the counted subtree commitments in the proof bytes, so it pins each entry to an absolute rank, and on a page past the end of the ranking it is the only payload — an attested total population under an empty entry list.

Thin tenderdash-composition wrapper over [DriveDocumentRankedQuery::verify_ranked_top_k_proof] in rs-drive (which does the merk-level verification). Both sides derive the proved subtree from the same DriveDocumentRankedQuery::indexed_property_name_tree_path, so prover and verifier cannot drift on which ranking is being checked, and grovedb re-executes the proof against the (axis, k, offset, descending) traversal rebuilt from the request — a proof of one ranking does not cover another.

§The root hash is the whole point

The merk-level verifier returning Ok is not by itself evidence of anything. Sweeping every bit of a real ranked envelope shows why: most flips do error out, but roughly 9% of them (bytes of sibling-subtree hashes inside the ancestor layer proofs) verify cleanly and return the correct entries — under a different reconstructed root hash. What rejects those is the [verify_tenderdash_proof] call below, which checks the reconstructed root against the quorum-signed app hash for the response’s block. This function exists so that composition can never be skipped by accident: there is no way to obtain the entries from it without the binding having run.

The RootHash is returned as well, already bound, so callers can log or cross-check it (e.g. against a root hash they verified for a different query at the same height). Callers must not treat it as something they still have to check.