Skip to main content

drive/verify/composite_document/verify_composite_documents_proof/
mod.rs

1mod v0;
2mod v1;
3
4use crate::error::drive::DriveError;
5use crate::error::Error;
6use crate::query::{CompositeDocumentsResult, DriveDocumentQuery};
7use crate::verify::RootHash;
8use dpp::version::PlatformVersion;
9
10impl DriveDocumentQuery<'_> {
11    /// Verifies a composite query's single merged proof — this query as
12    /// the page plus its [`sub_queries`](DriveDocumentQuery::sub_queries)
13    /// — and returns `(root_hash, result)`.
14    ///
15    /// The verifier trusts nothing about the derivation, and needs
16    /// nothing beyond the proof itself: a BOOTSTRAP subset pass runs the
17    /// page query (and every sub-query that feeds a later binding) alone
18    /// against the merged proof to extract candidate values; every
19    /// sub-query is derived from those exactly as the prover derived it
20    /// from its materialization, the merged query is rebuilt, and the
21    /// AUTHORITATIVE full pass verifies the whole composition — grovedb
22    /// enforces every component's per-instance limit and range
23    /// completeness. The proven results are then routed back to their
24    /// components: an entry no derivation asked for is an invalid proof,
25    /// so is a by-id join off a `permanentDocument` property missing a
26    /// referenced document (such a reference cannot dangle; off a
27    /// `deletableDocument` property the proven-absent document is left
28    /// out instead), and so is any
29    /// divergence between the values the proven page derives and the
30    /// candidates the query was built from. A proof covering only the
31    /// page (an old node serving the plain query) fails the full pass
32    /// whenever a sub-query derived anything.
33    ///
34    /// One proof means one root by construction; the caller combines the
35    /// returned root hash with the surrounding tenderdash signature — see
36    /// `rs-drive-proof-verifier` for the canonical composition.
37    ///
38    /// # Parameters
39    ///
40    /// * `proof`: The merged proof, as `query_composite_documents_with_proof` produced it.
41    /// * `platform_version`: The platform version.
42    ///
43    /// # Returns
44    ///
45    /// * `Ok((RootHash, CompositeDocumentsResult))` with the proof's root hash, the proven page,
46    ///   one proven result per sub-query, and the ids each by-id join proved absent.
47    /// * `Err(Error)` when the method version is unknown, the query is not a valid composite
48    ///   query, or the proof is invalid: it fails verification, carries an entry no derivation
49    ///   asked for, lacks a referenced document that cannot be deleted, or its page derives
50    ///   values other than those the query was built from.
51    pub fn verify_composite_documents_proof(
52        &self,
53        proof: &[u8],
54        platform_version: &PlatformVersion,
55    ) -> Result<(RootHash, CompositeDocumentsResult), Error> {
56        match platform_version
57            .drive
58            .methods
59            .verify
60            .composite_document
61            .verify_composite_documents_proof
62        {
63            0 => self.verify_composite_documents_proof_v0(proof, platform_version),
64            1 => self.verify_composite_documents_proof_v1(proof, platform_version),
65            version => Err(Error::Drive(DriveError::UnknownVersionMismatch {
66                method: "DriveDocumentQuery::verify_composite_documents_proof".to_string(),
67                known_versions: vec![0, 1],
68                received: version,
69            })),
70        }
71    }
72}