Skip to content

Commit e2f82a3

Browse files
feat(sdk)!: reshape dash-platform-cxx into a thin shell over dash-sdk
packages/rs-platform-cxx rebuilt on v4.2-dev with dash-sdk (default-features off: dpns-contract, dashpay-contract, core_key_wallet) and platform-encryption as its only Platform dependencies; the direct dpp/drive/platform-version/context-provider/dash-platform-queries dependencies, the #4632 builders and the decode/st/queries modules are gone. Bridge (namespace platform_ffi): Config{network, tenderdash_chain_id, platform_llmq_type, proxy}; nine-kind Status; one Verified* struct per read with typed ProvenAbsent (also under an unsupported protocol version, which meta then shows; the default value could not tell absence apart); one page per bridge call with a StartAfter cursor, has_more computed against the query's own limit (at PV13 Drive answers a names_of_identity continuation with an empty page); typed BroadcastResult; builders returning Built{bytes, hash, object_id}; pure DPNS/DIP-15 helpers. Every entry, including new_platform_client and Drop, runs under catch_unwind, and the crate refuses panic=abort at compile time as well as in build.rs. provider.rs is the push-model ContextProvider: LLMQ-type gate, quorum-hash normalization from Core's internal uint256 order, refusal of every proof until a local ChainLock height is pushed, a 288-block ChainLock-lag floor with no ceiling, and the compiled-in DPNS/DashPay contracts cached per protocol version with negative entries. Provider errors map to Status by variant, also when raised inside proof verification. client.rs builds the SDK lazily from the https endpoint set the embedder pushes (any other scheme is refused: the address list would dial http in the clear; the host must be an IP address, or an onion name when a proxy is set, so nothing is resolved locally). Config.proxy{kind, address, isolate} is the embedder's SOCKS5 proxy (none, a numeric TCP address or a Unix socket; isolate = fresh random credentials per connection, one Tor circuit each), fixed for the client's lifetime and passed to every SDK it builds through SdkBuilder::with_proxy, with a 15 s connect budget instead of 5 s; a proxy the shell cannot use fails new_platform_client, so there is never a direct fallback. A proxy failure is Unavailable (the SDK neither retries nor bans for it), not Rejected. The DAPI client keeps a pooled channel, and so an open connection, per evonode it has talked to, and removing an address from the list does not touch the pool, which is private to the client: an empty set therefore drops the SDK (no Platform socket stays open while the embedder has disabled networking), a set that removes endpoints rebuilds the SDK over the same, updated AddressList (retained entries keep their ban state), and a set that only adds updates the list in place. The provider, the height watermark and the verified protocol version belong to the client and survive every rebuild; a rebuilt SDK is seeded at the verified version. Proved reads are not dispatched before a ChainLock anchor is pushed or after shutdown. The SDK watermark is off; ops.rs checks the chain id, keeps a tolerance-3 Platform-height watermark keyed after it, records the protocol version of every accepted response, and signals UnsupportedProtocolVersion while still returning the value. Builders and contested_vote_fund_credits take that verified version (transition rules and the contested prefund changed across versions), so they fail before the first accepted read, except on a devnet whose floor is the latest version, and once a version this build does not know was seen. Document queries load the compiled-in contracts at this build's latest version, since a network SDK seeded at the PV13 floor could not decode a DashPay v2 profile. A node's definitive (non-retryable) gRPC refusal of a read or a broadcast, including tonic's answer to a response above the 4 MiB decoding bound, is Rejected; no answer is Unavailable. search_names refuses an empty or over-long prefix before dispatch, which Drive would refuse anyway. runtime.rs owns the tokio runtime and aborts the in-flight task on shutdown. signer.rs: BytesSigner hands the full signable preimage to WalletSigner::SignForKey; AssetLockSigner is the single digest path and recovers the public key from the compact signature (compressed-key header only, as Core funds P2PKH of the compressed key), so PublicKeyForKey is gone. The adapters take a SignerCallbacks trait whose Send + Sync impls sit on the extern type under the any-thread contract signer.h states. builders.rs: identity create through dpp try_from_identity_with_signers, DPNS preorder/domain and the profile create assembled inline until rs-sdk exports them, each create given the document id put_to_platform derives from its entropy and nonce at the verified version (dpp derives it itself only from PV14; up to PV13 it sends the document's id as is, and a zero id is refused by Drive with InvalidDocumentTransitionIdError), a property the network's contract does not have yet refused before signing, contact requests through Sdk::create_contact_request with client-side ECDH under the verified version. build_profile replaces the Profile a get_profile read at its revision + 1 and carries the fields the embedder does not edit (avatar, DashPay v2 payment addresses) into the replacement, since a replace transition carries the whole document and would otherwise erase what another wallet set. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
1 parent 324dbc9 commit e2f82a3

19 files changed

Lines changed: 4982 additions & 15 deletions

File tree

‎.github/package-filters/rs-packages-direct.yml‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -131,6 +131,9 @@ dash-platform-queries:
131131
dash-sdk:
132132
- packages/rs-sdk/**
133133

134+
dash-platform-cxx:
135+
- packages/rs-platform-cxx/**
136+
134137
rs-sdk-ffi:
135138
- packages/rs-sdk-ffi/**
136139

‎.github/package-filters/rs-packages-no-workflows.yml‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -153,6 +153,11 @@ dash-sdk: &sdk
153153
- *dapi_client
154154
- *drive
155155

156+
dash-platform-cxx:
157+
- packages/rs-platform-cxx/**
158+
- *sdk
159+
- *platform_encryption
160+
156161
rs-sdk-ffi: &sdk_ffi
157162
- packages/rs-sdk-ffi/**
158163
- *simple-signer

‎.github/package-filters/rs-packages.yml‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -181,6 +181,12 @@ dash-sdk: &sdk
181181
- *dapi_client
182182
- *drive
183183

184+
dash-platform-cxx:
185+
- .github/workflows/tests*
186+
- packages/rs-platform-cxx/**
187+
- *sdk
188+
- *platform_encryption
189+
184190
rs-sdk-ffi: &sdk_ffi
185191
- .github/workflows/tests*
186192
- packages/rs-sdk-ffi/**

‎Cargo.lock‎

Lines changed: 133 additions & 15 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎Cargo.toml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -40,6 +40,7 @@ members = [
4040
"packages/app-connect-contract",
4141
"packages/moderation-charters-contract",
4242
"packages/rs-sdk-ffi",
43+
"packages/rs-platform-cxx",
4344
"packages/wasm-drive-verify",
4445
"packages/dash-platform-balance-checker",
4546
"packages/rs-dapi",
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
[package]
2+
name = "dash-platform-cxx"
3+
version.workspace = true
4+
authors = ["Dash Core Group <dev@dash.org>"]
5+
edition = "2021"
6+
rust-version.workspace = true
7+
license = "MIT"
8+
description = "CXX shell over dash-sdk for C++ embedders that supply their own trust context and signing keys"
9+
10+
[lib]
11+
name = "dash_platform_cxx"
12+
crate-type = ["staticlib", "rlib"]
13+
14+
[features]
15+
default = []
16+
# dash-sdk's mock transport, for tests that replay recorded proved responses
17+
# through the same client code an embedder runs. Never enabled by embedders.
18+
mocks = ["dash-sdk/mocks"]
19+
20+
[dependencies]
21+
cxx = "1.0"
22+
dash-sdk = { path = "../rs-sdk", default-features = false, features = [
23+
"dpns-contract",
24+
"dashpay-contract",
25+
"core_key_wallet",
26+
] }
27+
platform-encryption = { path = "../rs-platform-encryption" }
28+
tokio = { version = "1.40", features = ["rt-multi-thread", "net", "time"] }
29+
futures = "0.3"
30+
async-trait = "0.1"
31+
zeroize = "1.8"
32+
hex = "0.4"
33+
34+
[build-dependencies]
35+
cxx-build = "1.0"

0 commit comments

Comments
 (0)