Skip to main content

Crate dig_store

Crate dig_store 

Source
Expand description

§dig-store — the DIG Network DataLayer store manager

A store is the composition of two planes:

  • an on-chain anchor — a CHIP-0035 DataLayer singleton (owned by dig-merkle) whose metadata carries the .dig merkle root plus its label / description / size bucket / program hash; and
  • an off-chain data plane — the .dig capsule format (owned by dig-capsule).

dig-store composes the two into ONE curated abstraction, with three concerns:

  1. Lifecycle — a store is a coin that gets SPENT: create_store, modify_store, melt_store. Each returns an UNSIGNED MerkleCoinSpend; the wallet-backend / node signs + broadcasts. dig-store never holds a key, never signs, never dials the network.
  2. Size proof — a store anchors its .dig SIZE on chain as a power-of-2 SizeBucket (1 MB..1 GB, NC-8 minimal encoding). Before keeping a downloaded .dig, a client runs SizeProof::verify: a real size that does not match the anchored bucket is SizeVerdict::Discarded — a dig-node MUST NOT store or serve a size-mismatched capsule.
  3. Getters — a comprehensive read surface over both planes:

The coin/identity types (Bytes32, Coin, CoinSpend, DataStore, DidRef, DigDataStoreMetadata, MerkleCoinSpend) and the owner type (StoreOwner) are re-exported VERBATIM from dig-merkle, and ChainSource from dig-chainsource-interface, so a consumer depends on ONE canonical shape across the whole DataLayer surface.

§Invariants

  • INV-1 — No network. dig-store performs no chain I/O itself; on-chain getters take a ChainSource the caller supplies (the user’s verified node or a trusted provider set, NC-9), and lifecycle operations are pure transforms of their inputs.
  • INV-2 — No keys, unsigned output. Lifecycle operations return unsigned spends; signing is always the caller’s responsibility (inherited from dig-merkle).
  • INV-3 — Minimal on-chain encoding (NC-8). The store’s on-chain footprint is delegated wholesale to dig-merkle, which owns the minimal byte layout; the size is a single-byte bucket.
  • INV-4 — On-chain proof always (NC-9). Every getter that returns chain-anchored data proves it against the chain; trust never comes from a self-declared field or an unverified peer.
  • INV-5 — .dig back-compat (§5.1). The capsule surface reads every older .dig format identically (inherited from dig-capsule’s reader, which dispatches on the DIGS blob version); the public API is extended additively, never broken.

§The store_id trust boundary (off-chain capsule getters)

get_capsule_identity recovers a capsule’s DECLARED store_id from module bytes. That id is the store’s on-chain launcher id and is NOT self-verifiable from the bytes alone — treat it as a CLAIM until cross-checked against a trusted anchor. open_capsule does that cross-check against a caller-supplied anchor and fails closed on mismatch. The root_hash is always proven internally consistent by the reader (it recomputes the merkle root and rejects a forged one).

Re-exports§

pub use capsule::get_capsule_identity;
pub use capsule::open_capsule;
pub use error::DigStoreError;
pub use error::DigStoreResult;
pub use lifecycle::create_store;
pub use lifecycle::melt_store;
pub use lifecycle::modify_store;
pub use lifecycle::CreateStoreParams;
pub use size::SizeProof;
pub use size::SizeVerdict;
pub use store::get_latest_root;
pub use store::get_latest_root_urn;
pub use store::get_root_history;
pub use store::get_store_description;
pub use store::get_store_did_owner;
pub use store::get_store_label;
pub use store::get_store_program_hash;
pub use store::get_store_singleton_tip;
pub use store::get_store_size_bucket;
pub use store::get_store_urn;
pub use types::CapsuleIdentity;
pub use types::RootHistory;
pub use urn::capsule_urn;
pub use urn::retrieval_key;
pub use urn::store_urn;
pub use urn::URN_PREFIX;

Modules§

capsule
The OFF-CHAIN .dig capsule getters (SPEC §5/§11): recover a capsule’s declared identity from a compiled .dig module’s bytes, WITHOUT the on-chain suite and WITHOUT the full wasmtime serve runtime.
chain
The on-chain read boundary (SPEC §7, NC-9).
error
The dig-store error taxonomy (SPEC §6).
lifecycle
The store LIFECYCLE (SPEC §3): a store is a coin that gets SPENT.
size
The store SIZE and the SIZE PROOF (SPEC §4) — the download-gating core of this crate.
store
The comprehensive on-chain GETTER surface (SPEC §5/§7): every chain-anchored store property.
types
The shared identifier + value types of the store surface.
urn
Store + capsule URN formatting (SPEC §5).

Structs§

Coin
CoinSpend
DataStore
Everything that is required to spend a DataStore coin.
DidRef
A reference to a DID, identified by its immutable launcher_id (the DID’s on-chain identity).
DigDataStoreMetadata
The DIG DataLayer metadata: the SDK’s DataStoreMetadata shape with the exact byte count ("b") REPLACED by a power-of-2 size_bucket ("sz"), plus the additive program_hash ("p").
MerkleCoinSpend
The result of building a DataLayer-coin operation: the unsigned coin spends plus the recreated child DataStore.
SizeBucket
A .dig store size quantised to a power-of-2 bucket: exponent k ∈ 0..=102^k MiB (1 MB..1 GB). See the module docs for the full ladder and the canonical unit (1 MB = 1 MiB).

Enums§

StoreOwner
Who is authorized to spend a store coin — the p2 (“inner”) puzzle that guards it.

Traits§

ChainSource
A reads-only view of Chia chain state — the single canonical contract every provider implements and every consumer depends on.

Type Aliases§

Bytes32