Conversation
8ddb556 to
1b7eb4f
Compare
Automated code review (
|
e2fa3ed to
a8d2415
Compare
| type ShardPartyKey struct { | ||
| Shard types.ShardID | ||
| Party types.PartyID | ||
| // EntityType identifies the kind of node a public key belongs to. It is part of the verifier key |
There was a problem hiding this comment.
@DorKatzelnick is using similar data structure here: #1225
Lets put Role (=EntityType) and Entity (Role + party + shard) somewhere central, possibly i common/types?
a8d2415 to
09f20e1
Compare
| // so that entities which are not part of a shard (consenters and assemblers) can be told apart | ||
| // even though they share the reserved ShardIDConsensus value. | ||
| type EntityType uint8 | ||
|
|
||
| const ( | ||
| EntityUnknown EntityType = iota | ||
| EntityBatcher | ||
| EntityConsenter | ||
| EntityAssembler | ||
| ) | ||
|
|
||
| func (e EntityType) String() string { | ||
| switch e { | ||
| case EntityBatcher: | ||
| return "batcher" | ||
| case EntityConsenter: | ||
| return "consenter" | ||
| case EntityAssembler: | ||
| return "assembler" | ||
| default: | ||
| return fmt.Sprintf("unknown entity (%d)", uint8(e)) | ||
| } | ||
| } | ||
|
|
||
| type VerifierKey struct { | ||
| Entity EntityType | ||
| Shard types.ShardID | ||
| Party types.PartyID | ||
| } |
There was a problem hiding this comment.
Lets move all of this to somewhere common, and include the router as well.
…certs The verifier map was keyed by (shard, party), which cannot represent assemblers: unlike batchers they are not part of a shard, and unlike consenters they had no reserved key. Commit hyperledger#1216 pinned the assembler's signing certificate in the shared config, so the consenter can now hold the assembler public keys. Add an EntityType (batcher/consenter/assembler) to the verifier key so non-sharded entities can be told apart even when they share the reserved ShardIDConsensus value. VerifySignature and the key builders now take the entity explicitly; consenters and batchers keep their existing lookups. Plumb the assembler signing certs through: AssemblerInfo gains a public key, ConsenterNodeConfig gains the assemblers list, and the consenter's buildVerifier registers each assembler under EntityAssembler. This only registers the assembler keys and makes them addressable. The actual verification of assembler->consensus messages (the signing scheme deferred in hyperledger#1214) lands in a follow-up. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Hagar Meir <hagar.meir@ibm.com>
Signed-off-by: Hagar Meir <hagar.meir@ibm.com>
Signed-off-by: Hagar Meir <hagar.meir@ibm.com>
Replace the crypto-local EntityType and VerifierKey with the shared types.NodeRole and types.NodeIdentity so the verifier keys on the same node-identity abstraction used elsewhere. Consenters and assemblers are still keyed under ShardIDConsensus and disambiguated by role. Regenerate the batcher SigVerifier mock and update call sites in consensus, batcher, and test/utils accordingly. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Hagar Meir <hagar.meir@ibm.com>
09f20e1 to
d6bc22a
Compare
What
Adds an
EntityTypedimension to the crypto verifier and registers the assembler signing certificates (pinned in shared config by #1216) in the consenter's verifier, so a follow-up can verify assembler→consensus messages.This lays the verifier groundwork for the signature verification of
AssemblerDecisionReportthat was deliberately deferred in #1214 (the signing scheme was not yet defined there;verifyCEonly rejected unsigned reports).Why
The verifier map was keyed by
(shard, party), which cannot represent assemblers: unlike batchers they are not part of a shard, and unlike consenters they had no reserved key. AnEntityType(batcher/consenter/assembler) is added to the key so non-sharded entities can be told apart even when they share the reservedShardIDConsensusvalue —{EntityConsenter, ShardIDConsensus, party}and{EntityAssembler, ShardIDConsensus, party}are distinct.Changes
node/crypto/verifier.go— newEntityTypeuint8 enum (EntityBatcher/EntityConsenter/EntityAssembler) withString();ShardPartyKey→VerifierKeygains anEntityfield;VerifySignature,AddPublicKeyToVerifier, andParsePublicKeyFromPEMtake the typed entity (the oldentityType stringwas only used for logs).node/config:AssemblerInfo.PublicKeyandConsenterNodeConfig.Assemblers;config:ExtractAssemblerspopulatesPublicKeyfromAssemblerConfig.SignCert, andExtractConsenterConfigsetsAssemblers.node/consensus/consensus_builder.go—buildVerifiertakes the assemblers and registers them underEntityAssembleratShardIDConsensus.SigVerifier.VerifySignatureinnode/consensusandnode/batchertake the entity (consenter sig → Consenter; BAF/complaint/batch primary sig → Batcher); counterfeiter mock regenerated;test/utilsupdated.Deliberately deferred
Testing
TestVerifySignatureEntity(TDD): an assembler key verifies its signature, a wrong-entity lookup at the same shard/party does not collide.node/crypto,config,node/config,node/batcher(-race), and thenode/consensus/consensus_test.gosuite (-race).go build ./...,go vet ./...,goimports,gofumptclean.Refs #1214
🤖 Generated with Claude Code