Class GroupFounding
java.lang.Object
ai.badmonkey.agentspaces.peering.node.GroupFounding
Founds self-certifying groups and verifies their founding advertisements
(spec §4.4, §5.1). A GroupID is the hash of the group's founding document,
so possession of the document proves the name and, just as importantly, no
one can publish a different policy under the same name: a receiver
that re-derives the id from the document it was handed detects any
substitution.
The founding document is defined precisely as follows.
- The founding fields are the advertisement's immutable
fields, in this order:
name,founder(the issuer PeerID),issued,ttl,membershipPolicy,defaultStrategy,gossip— the recordGroupFounding.FoundingFields, encoded as canonical CBOR byCborCodec.defaultCodec(). - The founder signs those canonical bytes with its Ed25519 identity key (RFC 8032; deterministic, so the same founder founding the same fields always derives the same id).
- The founding document is the record
GroupFounding.FoundingDocument(the fields plus that signature), again as canonical CBOR, andGroupId = GroupId.fromFounding(canonical CBOR of the founding document). - The advertisement's
idis"aspace://" + groupId.
verify(SignedGroupAdvertisement) accepts a SignedGroupAdvertisement only when the
carried key hashes to the advertisement's issuer, the signature verifies
under that key over the founding fields, the derived id equals the
advertisement's group, and the id URI matches. Any group
advertisement that arrives from the network MUST pass this check before a
node acts on it; locally configured literal-id groups (the older
PeerNode.joinGroup(GroupAdvertisement, ...)) are exempt only because
their advertisement is local configuration the network cannot swap.
-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionstatic final recordThe founding document whose canonical CBOR hashes to the GroupID: the founding fields and the founder's signature over their canonical bytes.static final recordThe immutable founding fields of a group: everything a member relies on that no later party may change. -
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final StringThe URI scheme prefix a founding advertisement'sidcarries. -
Method Summary
Modifier and TypeMethodDescriptionstatic GroupIdderive(GroupFounding.FoundingFields fields, byte[] signature) Derives the self-certifying GroupID of a founding document.static GroupFounding.FoundingFieldsExtracts the founding fields of an advertisement, in canonical order.static SignedGroupAdvertisementfound(PeerIdentity founder, String name, GroupAdvertisement.MembershipPolicy membershipPolicy, ConflictStrategyType defaultStrategy, GroupAdvertisement.GossipParameters gossip, Instant issued, Duration ttl) Founds a group: signs the founding fields, derives the self-certifying GroupID, and returns the signed founding advertisement to join with and to serve to newcomers.static booleanverify(SignedGroupAdvertisement signed) Verifies that a signed group advertisement is the genuine founding document of the group it names: the founder key hashes to the issuer, the signature verifies over the founding fields, the derived id equalsadvertisement().group(), and theidURI names that group.
-
Field Details
-
URI_PREFIX
The URI scheme prefix a founding advertisement'sidcarries.- See Also:
-
-
Method Details
-
found
public static SignedGroupAdvertisement found(PeerIdentity founder, String name, GroupAdvertisement.MembershipPolicy membershipPolicy, ConflictStrategyType defaultStrategy, GroupAdvertisement.GossipParameters gossip, Instant issued, Duration ttl) Founds a group: signs the founding fields, derives the self-certifying GroupID, and returns the signed founding advertisement to join with and to serve to newcomers.- Parameters:
founder- the founding identity (becomes the issuer)name- the group namemembershipPolicy- who may joindefaultStrategy- the default conflict strategy of the group's spacesgossip- the gossip parametersissued- the founding instantttl- the advertisement's cache time-to-live- Returns:
- the signed, self-certifying founding advertisement
-
derive
Derives the self-certifying GroupID of a founding document.- Parameters:
fields- the founding fieldssignature- the founder's signature over the fields' canonical bytes- Returns:
- the GroupID
-
fieldsOf
Extracts the founding fields of an advertisement, in canonical order.- Parameters:
ad- the advertisement- Returns:
- its founding fields
-
verify
Verifies that a signed group advertisement is the genuine founding document of the group it names: the founder key hashes to the issuer, the signature verifies over the founding fields, the derived id equalsadvertisement().group(), and theidURI names that group.- Parameters:
signed- the signed advertisement- Returns:
trueonly when every check passes
-