Skip to main content

ConsensusMessage

Enum ConsensusMessage 

Source
pub enum ConsensusMessage {
    Proposal {
        block: Box<Block>,
        proposer: String,
        round: u64,
        high_qc_view: u64,
        timeout_certificate: Option<Vec<u8>>,
        no_endorsement_certificate: Option<Vec<u8>>,
    },
    Vote {
        block_hash: Hash,
        voter: String,
        vote_type: VoteType,
        round: u64,
        height: u64,
        high_qc_view: u64,
        signature: Vec<u8>,
        public_key: Vec<u8>,
        bls_signature: Vec<u8>,
    },
    Commit {
        block_hash: Hash,
        signatures: Vec<Vec<u8>>,
    },
    Timeout {
        format_version: u8,
        view: u64,
        high_qc_view: u64,
        finalized_height: u64,
        voter: Address,
        signature: Vec<u8>,
        public_key: Vec<u8>,
    },
    NoEndorsement {
        format_version: u8,
        view: u64,
        voter: Address,
        signature: Vec<u8>,
        public_key: Vec<u8>,
    },
}
Expand description

Consensus message types.

Uses serde’s default externally-tagged enum representation. See MessagePayload above for the rationale — #[serde(tag = "...")] is internally-tagged and incompatible with bincode 1.x.

Variants§

§

Proposal

Block proposal.

timeout_certificate is Some(_) only when the leader is recovering from a view timeout — it carries the bincode-serialized tenzro_consensus::timeout::TimeoutCertificate (2f+1 timeout signatures from the previous view) so peers can verify the new view was legitimately abandoned (Jolteon safe_to_extend, DiemBFT v4 §3.5).

high_qc_view is the proposer’s local highest-Prepare-QC view at the moment of proposing (#171, Aptos SyncInfo pattern). Receivers adopt it if higher than their own to fast-forward the lagging-replica case. Must satisfy high_qc_view < block.header.view.

Fields

§block: Box<Block>
§proposer: String
§round: u64
§high_qc_view: u64
§timeout_certificate: Option<Vec<u8>>

bincode-serialized tenzro_consensus::timeout::TimeoutCertificate, or None for the steady-state happy path.

§no_endorsement_certificate: Option<Vec<u8>>

bincode-serialized tenzro_consensus::timeout::NoEndorsementCertificate. Carries f+1 no-endorsement signatures attesting that no Prepare-QC formed at the timed-out view (MonadBFT, arXiv:2502.20692). Some(_) is required when the leader is proposing a fresh block after a TC — receivers reject an unaccompanied fresh block. None for the steady-state happy path AND when the leader is reproposing the existing high-tip block (the parent-hash match suffices).

§

Vote

Vote on a proposal

Carries a hybrid (Ed25519 + ML-DSA-65) signature and the voter’s composite public key so peers can verify both legs without an out-of-band registry lookup. The two opaque blobs are bincode- serialized CompositeSignature / CompositePublicKey from tenzro_crypto::composite.

high_qc_view is the voter’s local highest-Prepare-QC view at the moment of voting (#171, Aptos SyncInfo). Bound into the vote’s signing payload — must match the bound on the inner Vote or signature verification fails.

Fields

§block_hash: Hash
§voter: String
§vote_type: VoteType
§round: u64
§height: u64
§high_qc_view: u64
§signature: Vec<u8>

bincode-serialized tenzro_crypto::composite::CompositeSignature

§public_key: Vec<u8>

bincode-serialized tenzro_crypto::composite::CompositePublicKey

§bls_signature: Vec<u8>

Raw 96-byte BLS12-381 G2 signature over the canonical QC payload (TENZRO_QC_BLS: || vote_format_version || view || height || block_hash || vote_type). Aggregated by VoteCollectorinto the QC'sbls_aggregate`.

§

Commit

Commit message

Fields

§block_hash: Hash
§signatures: Vec<Vec<u8>>
§

Timeout

Pacemaker timeout broadcast (DiemBFT v4 §3.5).

Sent on local view-timer expiry. Receivers at a strictly lower view adopt view after verifying the sender’s hybrid signature — the signature is the cryptographic gate (DiemBFT v4 §3.5 process_remote_timeout); no numeric jump cap is applied, since stuck replicas may legitimately need to sync forward by many thousands of views. This is the backward-sync channel that prevents two honest replicas from drifting apart under partial synchrony.

The two opaque blobs are bincode-serialized CompositeSignature / CompositePublicKey from tenzro_crypto::composite, mirroring the Vote variant. Format version is pinned by tenzro_consensus::TIMEOUT_MSG_FORMAT_VERSION.

Fields

§format_version: u8
§view: u64
§high_qc_view: u64

Highest Prepare-QC view this voter has observed (≤ view - 1). Aggregated by the receiver into the TC’s max_high_qc_view() so the next leader can compute the Jolteon safe_to_extend predicate.

§finalized_height: u64

The sender’s highest finalized block height. Part of the signed payload. Receivers behind this height engage block-sync — the heal path for single-block finalization skew (one replica finalized via a Commit QC the others never received).

§voter: Address
§signature: Vec<u8>

bincode-serialized tenzro_crypto::composite::CompositeSignature

§public_key: Vec<u8>

bincode-serialized tenzro_crypto::composite::CompositePublicKey

§

NoEndorsement

MonadBFT no-endorsement attestation broadcast (arXiv:2502.20692).

Sent on local view-timer expiry alongside the Timeout broadcast. Aggregated by the receiver into a NoEndorsementCertificate (f+1 signatures) which the next leader attaches to a fresh block proposal after the timed-out view. The f+1 threshold is the smallest set that guarantees at least one honest signer — and any honest signer would refuse to sign if it had observed a Prepare-QC at the timed-out view, so the NEC is unforgeable evidence that no QC formed.

The two opaque blobs mirror the Vote / Timeout variants — bincode- serialized CompositeSignature / CompositePublicKey. Format version is pinned by tenzro_consensus::NO_ENDORSEMENT_MSG_FORMAT_VERSION.

Fields

§format_version: u8
§view: u64
§voter: Address
§signature: Vec<u8>

bincode-serialized tenzro_crypto::composite::CompositeSignature

§public_key: Vec<u8>

bincode-serialized tenzro_crypto::composite::CompositePublicKey

Trait Implementations§

Source§

impl Clone for ConsensusMessage

Source§

fn clone(&self) -> ConsensusMessage

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for ConsensusMessage

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for ConsensusMessage

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Serialize for ConsensusMessage

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

Source§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

Source§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

Source§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more