pub trait NotificationIsCertificateBacked:
NotificationImpliesPersistedChange
+ BlockOutputsArePersisted
+ InboxHoldsOnlySentBundles { }Expand description
Lemma (A notification is backed by a certificate the validator can serve — except for a new
round). For every notification a correct validator emits other than Reason::NewRound, that
validator holds a quorum-signed certificate establishing what the notification reports, and
will hand it to anyone who asks. A recipient can therefore not merely learn that something
happened but verify it, and carry the evidence to other validators.
Proof. Site by site, for the reasons a validator emits.
Reason::NewBlockandReason::NewEventsare reachable only throughChainWorkerState::process_confirmed_block, which verifies theConfirmedBlockCertificatewithcertificate.checkand writes it withwrite_blobs_and_certificatebefore dispatching to the path that emits them (BlockOutputsArePersisted). The certificate is in storage before the notification exists.Reason::NewIncomingBundleis emitted onceprocess_cross_chain_updatereportsCrossChainUpdateResult::Updated. ByInboxHoldsOnlySentBundlesthat bundle reached the inbox from another worker of the same validator, built from its persisted outbox for a block that validator had processed — so the sending block’s certificate is in this validator’s storage too. Note it certifies a block of the sending chain, not of the chain the notification names.
Serving them is the ordinary node surface: download_certificate, download_certificates and
download_certificates_by_heights. A node that receives one of these notifications can fetch
the certificate, verify it against the committee for its epoch, and push it onward —
send_confirmed_certificate
is exactly that path. ∎
This is the precise sense in which a notification is worth acting on despite carrying no evidence itself. The message is unsigned and, at best, authenticated only to its recipient by the transport; what it points at is quorum-signed and transferable to anyone. The hint is non-transferable, the thing it hints at is not.
Reason::NewRound has no such backing, and cannot. ChainManager::update_current_round
takes a maximum over four inputs, and only two are certificates: a TimeoutCertificate, or a
locking block, which is a ValidatedBlockCertificate. The other two are proposed and
signed_proposal — one owner’s signature, not a quorum’s. A round raised by a proposal in a
higher multi-leader round therefore has nothing portable behind it, which is
MultiLeaderRoundsAreLocal seen from the notification side: a recipient that wants to reach
that round must be sent the proposal itself, because no compact proof of it exists to send.
Reason::BlockExecuted is out of scope here. It is emitted by linera_core::client, not by
a validator, so it is a client telling itself something rather than a claim one node makes to
another.