Expand description
Deploying a launch Platform Verifier: which contract serves which
platform, what it initializes with, and the rules its initialize
enforces — checked here, off chain, before a transaction is built.
PlatformVerifierBase.__PlatformVerifierBase_init refuses three things a
deployer would otherwise rediscover at the proxy’s constructor revert:
a Notary Service that does not match what the profile notarizes (a
TLSNotary profile must hold one, Google must hold none), a code hash
that is zero, keccak256("") or not the hash of the code at the Honk
verifier’s address, and a zero owner or root list. The validity window is
not among them: each verifier reads its profile’s from CeremonyProfile,
so a deployment supplies none. Initializer::call reads the code hash off the chain, checks
the rest, and builds the exact initialize call;
deploy_platform_verifier puts the implementation behind a fresh
ERC1967 proxy with it.
The Honk verifier a Platform Verifier pins is vendored here too
(circuits): bb-generated in libid-circuits from
the circuit’s verification key, deployed by
deploy_honk_verifier. Which
circuit a platform proves under is PlatformVerifier::circuit; the
contract pins whichever address governance names, by address AND by
code hash.
Structs§
- Google
Roots - What the Google Platform Verifier initializes with. No Notary Service: the profile notarizes nothing, and the base refuses one.
- TlsNotary
Roots - What a TLSNotary Platform Verifier (
x/v1,github/v1) initializes with: its owner and trust roots.
Enums§
- Initialize
Call - A built
initializecall, typed by shape. Feedabi_encodeto an ERC1967 proxy as its init data — throughdeploy_platform_verifier,deploy_proxy, or as part of the creation code a factory deploy takes. - Initializer
- What one Platform Verifier is initialized with.
- Platform
Verifier - One of the three launch Platform Verifiers.
Functions§
- codehash_
at - The code hash of the account at
address, asEXTCODEHASHreports it for an account with code:keccak256of its runtime bytecode. An account without code is an error rather thankeccak256("")or zero, becausesetTrustRootsrefuses both and a caller comparing against the hash of nothing has nothing to pin. - deploy_
platform_ verifier - Deploy the verifier’s implementation from
artifactsand put it behind a fresh ERC1967 proxy initialized withinit— the code hash read off the chain, the rules checked first. Returns the proxy address, which is the Platform Verifier a Proof Verifier registers withsetVerifier.