pub struct GetRewardDistributorResult {Show 16 fields
pub launcher_id: HexId,
pub store_id: HexId,
pub root: HexId,
pub epoch_seconds: u64,
pub first_epoch_start: u64,
pub payout_threshold: u64,
pub fee_bps: u16,
pub withdrawal_share_bps: u16,
pub reserve_base_units: u64,
pub entry_count: u64,
pub current_distributor_epoch: u64,
pub last_entry_write_at: Option<u64>,
pub entry_set_stale: bool,
pub observed_at: u64,
pub chain_peak_height: u64,
pub chain_peak_timestamp: u64,
}Expand description
Result for
dig.getRewardDistributor —
SPEC §2.6, third method: chain-derived distributor state only, never the
local prover loop’s own state (see RewardProverStatus for that).
§entry_set_stale lives HERE, never on RewardProverStatus
This is the one boolean in the reward-distributor surface, and it belongs
here specifically: per SPEC §12.4 it is computed by the responder from the
distributor singleton’s on-chain spend history at read time, not
self-reported by a possibly-wedged writer. Copying it onto
RewardProverStatus would reintroduce exactly the self-reported-health
failure that type’s doc comment forbids — see that type for the full
argument.
§The chain-view anchor (chain_peak_height / chain_peak_timestamp) — SPEC §4.5
observed_at dates when THIS REPLY was assembled — a wall clock, and
nothing else. entry_set_stale above is computed on a different clock
entirely: the distributor singleton’s on-chain peak. A stalled chain
source freezes that peak while the wall clock keeps advancing, which
freezes entry_set_stale at false under a freshly stamped
observed_at — the optimistic-staleness defect this field pair exists to
close (dig_ecosystem#3262). chain_peak_height and chain_peak_timestamp
expose the clock entry_set_stale was actually computed against, so a
reader can check the two are self-consistent:
entry_set_stale == (reserve_base_units > 0
&& chain_peak_timestamp - last_entry_write_at.unwrap_or(0) >= 172_800)What this check is, and is not. Every value on the right-hand side —
chain_peak_timestamp included — comes from the SAME response and the
SAME responder as entry_set_stale itself. Re-deriving the formula from
the responder’s own numbers catches an INTERNALLY INCONSISTENT responder
only; it is not evidence against a lying, wedged, or compromised one,
which can report any self-consistent triple it likes and pass this check
every time. What the anchor genuinely fixes is narrower, and real: an
HONEST but chain-stalled responder can no longer freeze entry_set_stale
at false under a freshly stamped observed_at, because its own stalled
chain clock now travels on the wire beside it — the defect
dig_ecosystem#3262 was filed for, and it is closed. Real protection
against a dishonest responder requires comparing chain_peak_height
against a chain view the consumer obtained INDEPENDENTLY of this
response — see Self::chain_peak_height. SPEC §4.5.
Both fields are required, never Option, never 0. A responder that
cannot obtain the chain peak (dig-rewards-coin’s read_distributor
refuses without one) MUST answer a JSON-RPC error, not a result with a
missing or zeroed anchor — there is no result arm for “I could not look”.
Fields§
§launcher_id: HexIdThe distributor singleton’s launcher id (64-hex).
store_id: HexIdThe backing store’s launcher id (64-hex).
root: HexIdThe store’s current generation root (64-hex).
epoch_seconds: u64The payout epoch length, in seconds.
first_epoch_start: u64Unix seconds the first epoch started.
payout_threshold: u64The reserve threshold, in base units, that triggers a payout.
fee_bps: u16The distributor’s fee, in basis points.
The share of a clawed-back commitment the committer recovers, in basis
points — SPEC §7.5. withdrawal_share_bps = 9000 means a clawback
returns 90% of the committed value; the remaining 10% is forfeited to
the reserve as a deterrent against the funder (SPEC §7.5 clause 1: it
is priced correctly and is not compensation to induced mirrors).
Curried at launch and immutable, same as Self::fee_bps beside it.
reserve_base_units: u64The current reserve, in base units.
entry_count: u64The current entry-set size.
current_distributor_epoch: u64The current epoch index (0-based from first_epoch_start).
last_entry_write_at: Option<u64>Unix seconds of the most recent entry-set write on chain, if any.
None together with a non-zero reserve_base_units implies
stale: an entry set that has never been written is maximally
stale, not unknown, and a consumer MUST NOT render it as blank or
“unknown” (SPEC §2.4 cl. 1 — silence is not an acceptable
representation of “not distributing”).
entry_set_stale: booltrue when the entry set has not changed in
STALE_ENTRY_SET_SECONDS = 172_800 (48 h) while the reserve is
non-zero — SPEC §12.4. A drained distributor with a frozen entry set
is not stale, it is Unfunded;
the non-zero-reserve conjunct exists to keep the two states distinct.
The responder computes this at read time from the singleton’s own
on-chain spend history — it is not self-reported, so a wedged prover
cannot fake it. See the type doc for why this boolean is safe here and
forbidden on RewardProverStatus.
observed_at: u64Unix seconds this result was assembled — a WALL clock. Says nothing
about chain freshness; read chain_peak_timestamp for that (see the
type doc’s “chain-view anchor” section).
chain_peak_height: u64The distributor singleton’s chain peak height at read time
(ChainObservation::peak_height, widened losslessly from u32).
Required — a responder with no chain peak in hand errors instead of
answering. This is the field that carries REAL protection against a
dishonest responder: compare it against a chain view the consumer
obtained independently, not against anything else in this response.
See the type doc’s trust-boundary section. SPEC §4.5.
chain_peak_timestamp: u64block_timestamp(chain_peak_height) — the CHAIN clock, never the wall
clock, and the exact clock Self::entry_set_stale is computed
against. Required, never 0: a responder with no chain peak errors
instead of answering. Self-consistency against entry_set_stale only
catches an internally inconsistent responder — see the type doc’s
trust-boundary section. SPEC §4.5.