Skip to main content

dig_store/
lib.rs

1//! # dig-store — the DIG Network DataLayer store manager
2//!
3//! A **store** is the composition of two planes:
4//!
5//! - an **on-chain anchor** — a CHIP-0035 DataLayer singleton (owned by
6//!   [`dig-merkle`](https://github.com/DIG-Network/dig-merkle)) whose metadata carries the `.dig`
7//!   merkle root plus its label / description / size bucket / program hash; and
8//! - an **off-chain data plane** — the `.dig` capsule format (owned by
9//!   [`dig-capsule`](https://github.com/DIG-Network/dig-capsule)).
10//!
11//! `dig-store` composes the two into ONE curated abstraction, with three concerns:
12//!
13//! 1. **Lifecycle** — a store is a coin that gets SPENT: [`create_store`], [`modify_store`],
14//!    [`melt_store`]. Each returns an UNSIGNED [`MerkleCoinSpend`]; the wallet-backend / node signs +
15//!    broadcasts. `dig-store` never holds a key, never signs, never dials the network.
16//! 2. **Size proof** — a store anchors its `.dig` SIZE on chain as a power-of-2 [`SizeBucket`]
17//!    (1 MB..1 GB, NC-8 minimal encoding). Before keeping a downloaded `.dig`, a client runs
18//!    [`SizeProof::verify`]: a real size that does not match the anchored bucket is
19//!    [`SizeVerdict::Discard`]ed — a dig-node MUST NOT store or serve a size-mismatched capsule.
20//! 3. **Getters** — a comprehensive read surface over both planes:
21//!    - **on-chain** (chain-proven, NC-9): [`get_store_did_owner`], [`get_store_singleton_tip`],
22//!      [`get_root_history`], [`get_latest_root`], [`get_latest_root_urn`], [`get_store_urn`], and the
23//!      label / description / size / program-hash getters;
24//!    - **off-chain** (from a compiled `.dig` module's bytes, wasmtime-free): [`get_capsule_identity`]
25//!      recovers a capsule's declared `(store_id, root_hash)`, and [`open_capsule`] additionally
26//!      cross-checks the declared `store_id` against a trusted anchor (fail-closed).
27//!
28//! The coin/identity types ([`Bytes32`], [`Coin`], [`CoinSpend`], [`DataStore`], [`DidRef`],
29//! [`DigDataStoreMetadata`], [`MerkleCoinSpend`]) and the owner type ([`StoreOwner`]) are re-exported
30//! VERBATIM from `dig-merkle`, and [`ChainSource`] from `dig-chainsource-interface`, so a consumer
31//! depends on ONE canonical shape across the whole DataLayer surface.
32//!
33//! ## Invariants
34//!
35//! - **INV-1 — No network.** `dig-store` performs no chain I/O itself; on-chain getters take a
36//!   [`ChainSource`] the caller supplies (the user's verified node or a trusted provider set, NC-9),
37//!   and lifecycle operations are pure transforms of their inputs.
38//! - **INV-2 — No keys, unsigned output.** Lifecycle operations return unsigned spends; signing is
39//!   always the caller's responsibility (inherited from `dig-merkle`).
40//! - **INV-3 — Minimal on-chain encoding (NC-8).** The store's on-chain footprint is delegated
41//!   wholesale to `dig-merkle`, which owns the minimal byte layout; the size is a single-byte bucket.
42//! - **INV-4 — On-chain proof always (NC-9).** Every getter that returns chain-anchored data proves
43//!   it against the chain; trust never comes from a self-declared field or an unverified peer.
44//! - **INV-5 — `.dig` back-compat (§5.1).** The capsule surface reads every older `.dig` format
45//!   identically (inherited from `dig-capsule`'s reader, which dispatches on the DIGS blob version); the
46//!   public API is extended additively, never broken.
47//!
48//! ## The `store_id` trust boundary (off-chain capsule getters)
49//!
50//! [`get_capsule_identity`] recovers a capsule's DECLARED `store_id` from module bytes. That id is the
51//! store's on-chain launcher id and is NOT self-verifiable from the bytes alone — treat it as a CLAIM
52//! until cross-checked against a trusted anchor. [`open_capsule`] does that cross-check against a
53//! caller-supplied anchor and fails closed on mismatch. The `root_hash` is always proven internally
54//! consistent by the reader (it recomputes the merkle root and rejects a forged one).
55
56// Public modules.
57pub mod capsule;
58pub mod chain;
59pub mod error;
60pub mod lifecycle;
61pub mod size;
62pub mod store;
63pub mod types;
64pub mod urn;
65
66// The curated public surface — consumers depend on these paths, not the module layout.
67pub use capsule::{get_capsule_identity, open_capsule};
68pub use chain::ChainSource;
69pub use error::{DigStoreError, DigStoreResult};
70pub use lifecycle::{create_store, melt_store, modify_store, CreateStoreParams, StoreOwner};
71pub use size::{SizeBucket, SizeProof, SizeVerdict};
72pub use store::{
73    get_latest_root, get_latest_root_urn, get_root_history, get_store_description,
74    get_store_did_owner, get_store_label, get_store_program_hash, get_store_singleton_tip,
75    get_store_size_bucket, get_store_urn,
76};
77pub use types::{
78    Bytes32, CapsuleIdentity, Coin, CoinSpend, DataStore, DidRef, DigDataStoreMetadata,
79    MerkleCoinSpend, RootHistory,
80};
81pub use urn::{capsule_urn, retrieval_key, store_urn, URN_PREFIX};