drive/verify/composite_document/verify_composite_documents_proof/mod.rs
1mod v0;
2mod v1;
3
4use crate::error::drive::DriveError;
5use crate::error::Error;
6use crate::query::{CompositeDocumentsResult, DriveDocumentQuery};
7use crate::verify::RootHash;
8use dpp::version::PlatformVersion;
9
10impl DriveDocumentQuery<'_> {
11 /// Verifies a composite query's single merged proof — this query as
12 /// the page plus its [`sub_queries`](DriveDocumentQuery::sub_queries)
13 /// — and returns `(root_hash, result)`.
14 ///
15 /// The verifier trusts nothing about the derivation, and needs
16 /// nothing beyond the proof itself: a BOOTSTRAP subset pass runs the
17 /// page query (and every sub-query that feeds a later binding) alone
18 /// against the merged proof to extract candidate values; every
19 /// sub-query is derived from those exactly as the prover derived it
20 /// from its materialization, the merged query is rebuilt, and the
21 /// AUTHORITATIVE full pass verifies the whole composition — grovedb
22 /// enforces every component's per-instance limit and range
23 /// completeness. The proven results are then routed back to their
24 /// components: an entry no derivation asked for is an invalid proof,
25 /// so is a by-id join off a `permanentDocument` property missing a
26 /// referenced document (such a reference cannot dangle; off a
27 /// `deletableDocument` property the proven-absent document is left
28 /// out instead), and so is any
29 /// divergence between the values the proven page derives and the
30 /// candidates the query was built from. A proof covering only the
31 /// page (an old node serving the plain query) fails the full pass
32 /// whenever a sub-query derived anything.
33 ///
34 /// One proof means one root by construction; the caller combines the
35 /// returned root hash with the surrounding tenderdash signature — see
36 /// `rs-drive-proof-verifier` for the canonical composition.
37 ///
38 /// # Parameters
39 ///
40 /// * `proof`: The merged proof, as `query_composite_documents_with_proof` produced it.
41 /// * `platform_version`: The platform version.
42 ///
43 /// # Returns
44 ///
45 /// * `Ok((RootHash, CompositeDocumentsResult))` with the proof's root hash, the proven page,
46 /// one proven result per sub-query, and the ids each by-id join proved absent.
47 /// * `Err(Error)` when the method version is unknown, the query is not a valid composite
48 /// query, or the proof is invalid: it fails verification, carries an entry no derivation
49 /// asked for, lacks a referenced document that cannot be deleted, or its page derives
50 /// values other than those the query was built from.
51 pub fn verify_composite_documents_proof(
52 &self,
53 proof: &[u8],
54 platform_version: &PlatformVersion,
55 ) -> Result<(RootHash, CompositeDocumentsResult), Error> {
56 match platform_version
57 .drive
58 .methods
59 .verify
60 .composite_document
61 .verify_composite_documents_proof
62 {
63 0 => self.verify_composite_documents_proof_v0(proof, platform_version),
64 1 => self.verify_composite_documents_proof_v1(proof, platform_version),
65 version => Err(Error::Drive(DriveError::UnknownVersionMismatch {
66 method: "DriveDocumentQuery::verify_composite_documents_proof".to_string(),
67 known_versions: vec![0, 1],
68 received: version,
69 })),
70 }
71 }
72}