Skip to main content

Module platform_verifier

Module platform_verifier 

Source
Expand description

Deploying a launch Platform Verifier: which contract serves which platform, what it initializes with, and the rules its initialize enforces — checked here, off chain, before a transaction is built.

PlatformVerifierBase.__PlatformVerifierBase_init refuses three things a deployer would otherwise rediscover at the proxy’s constructor revert: a Notary Service that does not match what the profile notarizes (a TLSNotary profile must hold one, Google must hold none), a code hash that is zero, keccak256("") or not the hash of the code at the Honk verifier’s address, and a zero owner or root list. The validity window is not among them: each verifier reads its profile’s from CeremonyProfile, so a deployment supplies none. Initializer::call reads the code hash off the chain, checks the rest, and builds the exact initialize call; deploy_platform_verifier puts the implementation behind a fresh ERC1967 proxy with it.

The Honk verifier a Platform Verifier pins is vendored here too (circuits): bb-generated in libid-circuits from the circuit’s verification key, deployed by deploy_honk_verifier. Which circuit a platform proves under is PlatformVerifier::circuit; the contract pins whichever address governance names, by address AND by code hash.

Structs§

GoogleRoots
What the Google Platform Verifier initializes with. No Notary Service: the profile notarizes nothing, and the base refuses one.
TlsNotaryRoots
What a TLSNotary Platform Verifier (x/v1, github/v1) initializes with: its owner and trust roots.

Enums§

InitializeCall
A built initialize call, typed by shape. Feed abi_encode to an ERC1967 proxy as its init data — through deploy_platform_verifier, deploy_proxy, or as part of the creation code a factory deploy takes.
Initializer
What one Platform Verifier is initialized with.
PlatformVerifier
One of the three launch Platform Verifiers.

Functions§

codehash_at
The code hash of the account at address, as EXTCODEHASH reports it for an account with code: keccak256 of its runtime bytecode. An account without code is an error rather than keccak256("") or zero, because setTrustRoots refuses both and a caller comparing against the hash of nothing has nothing to pin.
deploy_platform_verifier
Deploy the verifier’s implementation from artifacts and put it behind a fresh ERC1967 proxy initialized with init — the code hash read off the chain, the rules checked first. Returns the proxy address, which is the Platform Verifier a Proof Verifier registers with setVerifier.