mtpublisher

package
v0.20260928.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: MPL-2.0 Imports: 22 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func New

func New(dbMap *db.WrappedMap, interval time.Duration, logID issuancelog.ID, mtcaPublicKey *mldsa.PublicKey, mirror Mirror, log blog.Logger) (*mtpublisher, error)

New returns a publisher for the issuance log logID. It reconstructs each checkpoint's signed note from the stored MTCA signature, verified against mtcaPublicKey, and obtains each cosignature from mirror, which verifies it before returning it.

Types

type Mirror added in v0.20260908.0

type Mirror interface {
	// ID returns the mirror's cosigner ID.
	ID() string
	// Cosign submits the log's signed note for cp and returns the mirror's raw
	// cosignature, verified against the mirror's key.
	Cosign(ctx context.Context, cp *checkpoint.Checkpoint, signedNote []byte) ([]byte, error)
}

Mirror cosigns checkpoints, requiring the entries they commit to before signing.

https://c2sp.org/tlog-cosignature

type MirrorClient added in v0.20260908.0

type MirrorClient struct {
	// contains filtered or unexported fields
}

MirrorClient is a Mirror that uses the c2sp.org/tlog-mirror submission protocol, submitting the checkpoint to add-checkpoint and uploading the log's entries to add-entries until the mirror cosigns.

func NewMirrorClient added in v0.20260908.0

func NewMirrorClient(baseURL string, src *Source, mirrorID string, mirrorPublicKey *mldsa.PublicKey, timeout time.Duration) (*MirrorClient, error)

NewMirrorClient returns a MirrorClient that submits to the mirror's endpoints under baseURL, giving each request timeout to complete.

func (*MirrorClient) Cosign added in v0.20260908.0

func (m *MirrorClient) Cosign(ctx context.Context, cp *checkpoint.Checkpoint, signedNoteForMirror []byte) ([]byte, error)

Cosign runs the c2sp.org/tlog-mirror submission protocol for the checkpoint and returns the mirror's raw signature over the whole tree from sign-subtree, verified against the mirror's key. A mirror that is already up to date, whether from an earlier submission whose cosignature was never stored or from another submitter, still gets the full exchange, since that is the only way to obtain its cosignature.

func (*MirrorClient) ID added in v0.20260908.0

func (m *MirrorClient) ID() string

ID returns the mirror's cosigner ID.

type Source added in v0.20260908.0

type Source struct {
	// contains filtered or unexported fields
}

Source builds consistency proofs and entry packages from the log's tile storage. In the future, when we want to support multiple mirrors, we may want to improve Source to memoize the tiles, consistency proofs, and entry packages built for the latest tree, purging the memo when the tree changes.

func NewSource added in v0.20260908.0

func NewSource(s3c simpleS3, tilePrefix string) *Source

NewSource returns a Source over the tiles stored in s3c under tilePrefix.

Directories

Path Synopsis
Package mtpublishertest provides an in-process cosigner for unit tests of the mtca and the mtpublisher.
Package mtpublishertest provides an in-process cosigner for unit tests of the mtca and the mtpublisher.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL