Expand description
Ed25519 message authentication for gossip broadcasts (design §6.3, FPT_ITT.1).
SWIM membership traffic (foca’s postcard-coded pings/acks) is left alone; this
layer wraps only the GossipMessage custom broadcasts — the payloads that
announce new signed artifacts and drive bundle propagation. Those are the
messages that carry a trust decision (“epoch N exists for this scope”), so
those are the ones that must be attributable to a known fleet member.
§Wire framing
A signed broadcast is [TAG][64-byte Ed25519 signature over payload][payload]
where payload is the exact JSON GossipMessage bytes an unsigned node would
emit. Legacy (unsigned) payloads are raw JSON and therefore always begin with
{ (0x7B); the SIGNED_TAG byte (0x01) can never collide with that, so a
receiver can tell signed from unsigned without a version handshake. The
signature travels with the message, so a relaying node re-broadcasts the
original signer’s signature — every hop verifies the origin, not the last
hop.
§Rollout policy
identity_key signs outbound messages. peer_identities binds each trusted
key to its node name; a nonempty mapping requires authenticated broadcasts.
An empty mapping retains unsigned rollout compatibility. Legacy peer_keys
is rejected at startup because a key list cannot authorize node identities.
Structs§
- Gossip
Signer - Signs outbound gossip broadcasts with this node’s identity key.
- Gossip
Verifier - Verifies inbound gossip broadcasts against a set of trusted Ed25519 keys.
Enums§
- Gossip
Crypto Error - Error loading an Ed25519 gossip key.
- Verify
Outcome - Result of checking an inbound broadcast frame.
- Verify
Policy - Inbound verification stance — see the module-level rollout policy.
Constants§
- SIGNED_
TAG - Wire tag for a signed broadcast frame. Chosen so it can never collide with a
legacy raw-JSON payload, which always starts with
{(0x7B).
Functions§
- load_
signing_ key - Load an Ed25519 PKCS#8 private key. Accepts PEM (
-----BEGIN PRIVATE KEY-----) or raw DER, chosen by sniffing for the PEM armor. - load_
verifying_ key - Load an Ed25519 SPKI public key. Accepts PEM (
-----BEGIN PUBLIC KEY-----) or raw DER. - unwrap_
frame - Strip a signed frame’s tag + signature without verifying it, returning the inner JSON payload; pass any unsigned/raw payload through unchanged.