Skip to main content

Module crypto

Module crypto 

Source
Expand description

Ed25519 message authentication for gossip broadcasts (design §6.3, FPT_ITT.1).

SWIM membership traffic (foca’s postcard-coded pings/acks) is left alone; this layer wraps only the GossipMessage custom broadcasts — the payloads that announce new signed artifacts and drive bundle propagation. Those are the messages that carry a trust decision (“epoch N exists for this scope”), so those are the ones that must be attributable to a known fleet member.

§Wire framing

A signed broadcast is [TAG][64-byte Ed25519 signature over payload][payload] where payload is the exact JSON GossipMessage bytes an unsigned node would emit. Legacy (unsigned) payloads are raw JSON and therefore always begin with { (0x7B); the SIGNED_TAG byte (0x01) can never collide with that, so a receiver can tell signed from unsigned without a version handshake. The signature travels with the message, so a relaying node re-broadcasts the original signer’s signature — every hop verifies the origin, not the last hop.

§Rollout policy

identity_key signs outbound messages. peer_identities binds each trusted key to its node name; a nonempty mapping requires authenticated broadcasts. An empty mapping retains unsigned rollout compatibility. Legacy peer_keys is rejected at startup because a key list cannot authorize node identities.

Structs§

GossipSigner
Signs outbound gossip broadcasts with this node’s identity key.
GossipVerifier
Verifies inbound gossip broadcasts against a set of trusted Ed25519 keys.

Enums§

GossipCryptoError
Error loading an Ed25519 gossip key.
VerifyOutcome
Result of checking an inbound broadcast frame.
VerifyPolicy
Inbound verification stance — see the module-level rollout policy.

Constants§

SIGNED_TAG
Wire tag for a signed broadcast frame. Chosen so it can never collide with a legacy raw-JSON payload, which always starts with { (0x7B).

Functions§

load_signing_key
Load an Ed25519 PKCS#8 private key. Accepts PEM (-----BEGIN PRIVATE KEY-----) or raw DER, chosen by sniffing for the PEM armor.
load_verifying_key
Load an Ed25519 SPKI public key. Accepts PEM (-----BEGIN PUBLIC KEY-----) or raw DER.
unwrap_frame
Strip a signed frame’s tag + signature without verifying it, returning the inner JSON payload; pass any unsigned/raw payload through unchanged.