Skip to main content

dig_store/
lib.rs

1//! # dig-store — the DIG Network DataLayer store manager
2//!
3//! A **store** is the composition of two planes:
4//!
5//! - an **on-chain anchor** — a CHIP-0035 DataLayer singleton (owned by
6//!   [`dig-merkle`](https://github.com/DIG-Network/dig-merkle)) whose metadata carries the `.dig`
7//!   merkle root plus its label / description / size bucket / program hash; and
8//! - an **off-chain data plane** — the `.dig` capsule format (owned by
9//!   [`dig-capsule`](https://github.com/DIG-Network/dig-capsule)).
10//!
11//! `dig-store` composes the two into ONE curated abstraction, with three concerns:
12//!
13//! 1. **Lifecycle** — a store is a coin that gets SPENT: [`create_store`], [`modify_store`],
14//!    [`melt_store`]. Each returns an UNSIGNED [`MerkleCoinSpend`]; the wallet-backend / node signs +
15//!    broadcasts. `dig-store` never holds a key, never signs, never dials the network.
16//! 2. **Size proof** — a store anchors its `.dig` SIZE on chain as a power-of-2 [`SizeBucket`]
17//!    (1 MB..1 GB, NC-8 minimal encoding). Before keeping a downloaded `.dig`, a client runs
18//!    [`SizeProof::verify`]: a real size that does not match the anchored bucket is
19//!    [`SizeVerdict::Discard`]ed — a dig-node MUST NOT store or serve a size-mismatched capsule.
20//! 3. **Getters** — a comprehensive read surface over both planes:
21//!    - **on-chain** (chain-proven, NC-9): [`get_store_did_owner`], [`get_store_singleton_tip`],
22//!      [`get_root_history`], [`get_latest_root`], [`get_latest_root_urn`], [`get_store_urn`], the
23//!      label / description / size / program-hash getters, and [`get_store_status`] — the aggregate
24//!      status snapshot from ONE consistent lineage walk;
25//!    - **off-chain** (from a compiled `.dig` module's bytes, wasmtime-free): [`get_capsule_identity`]
26//!      recovers a capsule's declared `(store_id, root_hash)`, and [`open_capsule`] additionally
27//!      cross-checks the declared `store_id` against a trusted anchor (fail-closed).
28//!
29//! The coin/identity types ([`Bytes32`], [`Coin`], [`CoinSpend`], [`DataStore`], [`DidRef`],
30//! [`DigDataStoreMetadata`], [`MerkleCoinSpend`]) and the owner type ([`StoreOwner`]) are re-exported
31//! VERBATIM from `dig-merkle`, and [`ChainSource`] from `dig-chainsource-interface`, so a consumer
32//! depends on ONE canonical shape across the whole DataLayer surface.
33//!
34//! ## Invariants
35//!
36//! - **INV-1 — No network.** `dig-store` performs no chain I/O itself; on-chain getters take a
37//!   [`ChainSource`] the caller supplies (the user's verified node or a trusted provider set, NC-9),
38//!   and lifecycle operations are pure transforms of their inputs.
39//! - **INV-2 — No keys, unsigned output.** Lifecycle operations return unsigned spends; signing is
40//!   always the caller's responsibility (inherited from `dig-merkle`).
41//! - **INV-3 — Minimal on-chain encoding (NC-8).** The store's on-chain footprint is delegated
42//!   wholesale to `dig-merkle`, which owns the minimal byte layout; the size is a single-byte bucket.
43//! - **INV-4 — On-chain proof always (NC-9).** Every getter that returns chain-anchored data proves
44//!   it against the chain; trust never comes from a self-declared field or an unverified peer.
45//! - **INV-5 — `.dig` back-compat (§5.1).** The capsule surface reads every older `.dig` format
46//!   identically (inherited from `dig-capsule`'s reader, which dispatches on the DIGS blob version); the
47//!   public API is extended additively, never broken.
48//!
49//! ## The `store_id` trust boundary (off-chain capsule getters)
50//!
51//! [`get_capsule_identity`] recovers a capsule's DECLARED `store_id` from module bytes. That id is the
52//! store's on-chain launcher id and is NOT self-verifiable from the bytes alone — treat it as a CLAIM
53//! until cross-checked against a trusted anchor. [`open_capsule`] does that cross-check against a
54//! caller-supplied anchor and fails closed on mismatch. The `root_hash` is always proven internally
55//! consistent by the reader (it recomputes the merkle root and rejects a forged one).
56
57// Public modules.
58pub mod capsule;
59pub mod chain;
60pub mod error;
61pub mod lifecycle;
62pub mod size;
63pub mod store;
64pub mod types;
65pub mod urn;
66
67// The curated public surface — consumers depend on these paths, not the module layout.
68pub use capsule::{get_capsule_identity, open_capsule};
69pub use chain::ChainSource;
70pub use error::{DigStoreError, DigStoreResult};
71pub use lifecycle::{create_store, melt_store, modify_store, CreateStoreParams, StoreOwner};
72pub use size::{SizeBucket, SizeProof, SizeVerdict};
73pub use store::{
74    get_latest_root, get_latest_root_urn, get_root_history, get_store_description,
75    get_store_did_owner, get_store_label, get_store_program_hash, get_store_singleton_tip,
76    get_store_size_bucket, get_store_status, get_store_urn, DEFAULT_CONFIRMATION_TARGET,
77};
78pub use types::{
79    Bytes32, CapsuleIdentity, Coin, CoinSpend, Confirmations, DataStore, DelegatedPuzzle, DidRef,
80    DigDataStoreMetadata, LineageProof, MerkleCoinSpend, Proof, RootHistory, StoreStatus,
81    StoreStatusKind,
82};
83
84/// Derives the [`LineageProof`] a child singleton spend must carry to be recreated from a hydrated
85/// store (the lineage-getter surface). Re-exported verbatim from `dig-merkle` (the byte-source-of-
86/// truth, INV-4) so a consumer builds the next spend against a store the walk returned without a
87/// separate `dig-merkle` dependency. `dig-merkle` 0.4.3 derives its `parent_inner_puzzle_hash` via
88/// the DataLayer updater path, so the resulting child spend is consensus-valid (no
89/// `AssertMyParentIdFailed`, #1332).
90pub use dig_merkle::child_lineage_proof;
91pub use urn::{capsule_urn, retrieval_key, store_urn, URN_PREFIX};