Class GroupFounding

java.lang.Object
ai.badmonkey.agentspaces.peering.node.GroupFounding

public final class GroupFounding extends Object
Founds self-certifying groups and verifies their founding advertisements (spec §4.4, §5.1). A GroupID is the hash of the group's founding document, so possession of the document proves the name and, just as importantly, no one can publish a different policy under the same name: a receiver that re-derives the id from the document it was handed detects any substitution.

The founding document is defined precisely as follows.

  1. The founding fields are the advertisement's immutable fields, in this order: name, founder (the issuer PeerID), issued, ttl, membershipPolicy, defaultStrategy, gossip — the record GroupFounding.FoundingFields, encoded as canonical CBOR by CborCodec.defaultCodec().
  2. The founder signs those canonical bytes with its Ed25519 identity key (RFC 8032; deterministic, so the same founder founding the same fields always derives the same id).
  3. The founding document is the record GroupFounding.FoundingDocument (the fields plus that signature), again as canonical CBOR, and GroupId = GroupId.fromFounding(canonical CBOR of the founding document).
  4. The advertisement's id is "aspace://" + groupId.

verify(SignedGroupAdvertisement) accepts a SignedGroupAdvertisement only when the carried key hashes to the advertisement's issuer, the signature verifies under that key over the founding fields, the derived id equals the advertisement's group, and the id URI matches. Any group advertisement that arrives from the network MUST pass this check before a node acts on it; locally configured literal-id groups (the older PeerNode.joinGroup(GroupAdvertisement, ...)) are exempt only because their advertisement is local configuration the network cannot swap.

  • Field Details

    • URI_PREFIX

      public static final String URI_PREFIX
      The URI scheme prefix a founding advertisement's id carries.
      See Also:
  • Method Details

    • found

      public static SignedGroupAdvertisement found(PeerIdentity founder, String name, GroupAdvertisement.MembershipPolicy membershipPolicy, ConflictStrategyType defaultStrategy, GroupAdvertisement.GossipParameters gossip, Instant issued, Duration ttl)
      Founds a group: signs the founding fields, derives the self-certifying GroupID, and returns the signed founding advertisement to join with and to serve to newcomers.
      Parameters:
      founder - the founding identity (becomes the issuer)
      name - the group name
      membershipPolicy - who may join
      defaultStrategy - the default conflict strategy of the group's spaces
      gossip - the gossip parameters
      issued - the founding instant
      ttl - the advertisement's cache time-to-live
      Returns:
      the signed, self-certifying founding advertisement
    • derive

      public static GroupId derive(GroupFounding.FoundingFields fields, byte[] signature)
      Derives the self-certifying GroupID of a founding document.
      Parameters:
      fields - the founding fields
      signature - the founder's signature over the fields' canonical bytes
      Returns:
      the GroupID
    • fieldsOf

      public static GroupFounding.FoundingFields fieldsOf(GroupAdvertisement ad)
      Extracts the founding fields of an advertisement, in canonical order.
      Parameters:
      ad - the advertisement
      Returns:
      its founding fields
    • verify

      public static boolean verify(SignedGroupAdvertisement signed)
      Verifies that a signed group advertisement is the genuine founding document of the group it names: the founder key hashes to the issuer, the signature verifies over the founding fields, the derived id equals advertisement().group(), and the id URI names that group.
      Parameters:
      signed - the signed advertisement
      Returns:
      true only when every check passes