pub fn verify_ranked_top_k_proof(
query: &DriveDocumentRankedQuery<'_>,
proof: &Proof,
mtd: &ResponseMetadata,
platform_version: &PlatformVersion,
provider: &dyn ContextProvider,
) -> Result<(RootHash, RankedPage), Error>Expand description
Verified ranked (GROUP BY … ORDER BY <aggregate> LIMIT n [OFFSET m]) result types. DocumentRankedEntries carries one entry
per returned group in ranking order, plus the starting_rank
that pins each entry to an absolute position;
verify_ranked_top_k_proof is the tenderdash-composition wrapper
that binds the proof’s reconstructed root hash to the signed app
hash and returns the whole verified drive::query::RankedPage.
Verify a grovedb indexed-axis top-k proof and the surrounding
tenderdash commit, returning the reconstructed root hash and the
RankedPage it commits to.
The page is returned whole rather than as a bare entry list because
RankedPage::skipped is verified evidence in its own right: it is
re-derived from the counted subtree commitments in the proof bytes,
so it pins each entry to an absolute rank, and on a page past the
end of the ranking it is the only payload — an attested total
population under an empty entry list.
Thin tenderdash-composition wrapper over
[DriveDocumentRankedQuery::verify_ranked_top_k_proof] in rs-drive
(which does the merk-level verification). Both sides derive the
proved subtree from the same
DriveDocumentRankedQuery::indexed_property_name_tree_path, so
prover and verifier cannot drift on which ranking is being
checked, and grovedb re-executes the proof against the
(axis, k, offset, descending) traversal rebuilt from the request —
a proof of one ranking does not cover another.
§The root hash is the whole point
The merk-level verifier returning Ok is not by itself
evidence of anything. Sweeping every bit of a real ranked envelope
shows why: most flips do error out, but roughly 9% of them (bytes
of sibling-subtree hashes inside the ancestor layer proofs) verify
cleanly and return the correct entries — under a different
reconstructed root hash. What rejects those is the
[verify_tenderdash_proof] call below, which checks the
reconstructed root against the quorum-signed app hash for the
response’s block. This function exists so that composition can
never be skipped by accident: there is no way to obtain the entries
from it without the binding having run.
The RootHash is returned as well, already bound, so callers can
log or cross-check it (e.g. against a root hash they verified for a
different query at the same height). Callers must not treat it as
something they still have to check.