import type { ChainAdapter, OnChainPublishResult } from '@origintrail-official/dkg-chain'; import type { AsyncLiftChainProofLookup, AsyncLiftUpdateChainProofLookup, AsyncLiftChainProofResolution, AsyncLiftPublisherRecoveryResult, LiftJobHex } from '@origintrail-official/dkg-publisher'; /** * Can this publisher's chain adapter be asked whether a broadcast tx published? * * GH#2270 β€” EITHER lookup qualifies. `resolvePublishTransaction` is the surface * {@link createChainProofResolver} prefers, so an adapter offering only that one * must not silently lose chain recovery; an adapter offering only the legacy * `resolvePublishByTxHash` keeps the recovery it has always had. */ export declare function hasChainPublishLookup(chain: ChainAdapter): boolean; /** * GH#2270 PR-3 r22 (πŸ”΄ 3817363935) β€” can this adapter settle a job of THIS operation kind, on * every outcome the dispatcher can reach for it? The tri-state lookup is necessary and not * sufficient: it decides `confirmed` / `pending` / `reverted` / `not-found`, but each kind then * needs a different second capability to turn that into a disposition. * * - a CREATE's `not-found` becomes a release only through the finalized nonce/minted snapshot, so * without `readFinalizedChainProofSnapshot` every tick collapses to `inconclusive` and the job * is held forever behind a `retryable: true` that nothing can honour. * - an UPDATE's mined transaction is only recognized through `verifyKAUpdate` gated by * `isReceiptBlockFinalAndCanonical`, and its absence is deliberately inconclusive, so an adapter * missing either method can never settle one. * * Reporting the capability the adapter actually has is the whole point of the honesty contract: * a promise the wiring cannot keep is worse than an honest operator-clear. */ export declare function hasChainRecoveryCapabilityFor(chain: ChainAdapter, operationKind: 'create' | 'update' | undefined): boolean; /** * GH#2270 PR-3 r2 β€” wallet id to the chain adapter that signs for it. * * The recovery factories used to take the publisher map and reach through each `DKGPublisher` for * its `chain` with an `as unknown as { chain?: ChainAdapter }` cast β€” a private field, read through * an assertion the compiler cannot check, in six places. Rename that field and every cast keeps * compiling while silently answering `undefined`, which reads as "no chain recovery available" and * holds every job forever. * * The map is built once at the wiring site from `ConfiguredPublisherWallet[]`, where the adapter is * a real public field, and capability detection lives beside it. */ export type PublisherChainAdapters = ReadonlyMap; /** The walletβ†’adapter map for the recovery factories, from the wallets the runtime configured. */ export declare function chainAdaptersForWallets(wallets: readonly { readonly address: string; readonly chain: ChainAdapter; }[]): PublisherChainAdapters; /** * GH#2270 β€” the runner's implementation of the publisher's chain-proof contract. * * The VERDICT VOCABULARY is not defined here: `AsyncLiftChainProofResolution` belongs to the * publisher, which is what dispatches on it. This module's job is the one rule that union cannot * state β€” that an absence must be ESTABLISHED. Every unknown this side can produce collapses into * `inconclusive` and never into `not-found`: an RPC error, a wallet with no publisher, an adapter * with no publish lookup, a contract address that would not resolve, a chain result the lift mapper * rejected, and β€” deliberately β€” a `null` from an adapter offering only the two-state * {@link ChainAdapter.resolvePublishByTxHash}, which cannot tell a mempool transaction from an * unknown one. * * The publisher holds forever on `inconclusive`, so an unknown that leaked in here as `not-found` * would become a resend of a transaction that may be in flight. * * PR-3 r1 β€” and the adapter's own `not-found` is NOT one of those establishings. A transaction * lookup is point-in-time and backend-local: a broadcast whose response timed out can be sitting * in a mempool this endpoint cannot see, and be mined a minute later. `not-found` is therefore * EARNED here, from nonce consumption at finality, or it is downgraded. */ export declare function createChainProofResolver(adapters: PublisherChainAdapters): (lookup: AsyncLiftChainProofLookup, options?: { readonly signal?: AbortSignal; }) => Promise; /** * PR #2300 r1 (🟑 3809054830) β€” the canonically verified facts of ONE queued update, established * ONCE and shared by every consumer. * * The verdict resolver and the named-KA evidence resolver used to each call * {@link ChainAdapter.verifyKAUpdate} for the same transaction β€” genuine policy duplication with * drift risk: two call sites deciding "is this mined update OURS" can disagree about the binding * rules. This function is the one place that asks, and the one place that binds the answer: the * receipt fetched BY our recorded txHash carries an update event for exactly our pinned kaId, the * chain-verified new root equals the root our seal intended to install, and the root history at * the receipt block attributes it to our signing wallet (all established inside `verifyKAUpdate`; * nothing is taken from the job's say-so except which transaction and which root to ask about). * * PR #2300 r2 (πŸ”΄ 3809616675) β€” verified facts are FACTS only past finality: before anything is * returned, the receipt's block must be FINAL and CANONICAL, established through the SAME * {@link ChainAdapter.isReceiptBlockFinalAndCanonical} primitive the generic mined verdicts use * (shared, not duplicated). Every consumer inherits the gate here β€” the dispatcher's verdict AND * the LIVE interrupted lane, which reaches this without any verdict having run. A merely-mined * update answers `null`: a non-fact that keeps the job tx-bearing, because a reorg can land the * same signed transaction on a chain where it writes a different history. And because nothing * unfinalized ever becomes a fact, there is nothing to cache and no stale fact to survive β€” the * round-1 memo (and its shared-instance requirement and eviction policy) is deleted; the verdict * now CARRIES the evidence to the finalizer instead (see CanonicalUpdateEvidence). */ export interface CanonicalUpdateFacts { readonly kaId: bigint; readonly onChainRoot: LiftJobHex; readonly blockNumber: number; /** r5 β€” the verified position in the asset's update history; roots repeat, positions do not. */ /** * r13 (3813797045) β€” carried as the STRING it is persisted and compared as, so the value crosses * every boundary in one representation instead of being re-encoded at each hop. */ readonly merkleRootCount?: string; readonly blockHash?: string; readonly txIndex?: number; } export declare function verifyCanonicalUpdateFacts(lookup: AsyncLiftUpdateChainProofLookup, adapters: PublisherChainAdapters, options?: { readonly signal?: AbortSignal; }): Promise; /** Shared with the runner's canonical-receipt mapper; both narrow the same persisted hex shape. */ export declare function asLiftJobHex(value: string): LiftJobHex | null; export declare function asLiftJobBigInt(value: bigint | undefined): `${bigint}` | undefined; export declare function mapOnChainPublishResultToLiftRecovery(result: OnChainPublishResult, chainId: string, knowledgeAssetsContract: string): AsyncLiftPublisherRecoveryResult | null; //# sourceMappingURL=publisher-chain-proof.d.ts.map