Files
arbiter/protobufs/operator/vault/bootstrap.proto
CleverWild 8c0855b16e feat(proto)!: Shamir re-key, governance and bootstrapping vault state
Split out of feat-shamir so the wire contract can be reviewed on its own.
Rebased onto main: main's UNSEAL_RESULT_LOCKED_OUT keeps tag 4, so
UNSEAL_RESULT_AWAITING_CONTRIBUTIONS moved to 5.

BREAKING CHANGE: `shared.VaultState` renumbers SEALED/UNSEALED/ERROR to
make room for VAULT_STATE_BOOSTRAPPING = 2. Old and new peers disagree on
every vault state value.

- operator: new `governance` branch in OperatorRequest/Response (field 5)
- vault: new `rekey` branch in vault Request/Response (field 4)
- bootstrap/unseal: passphrase and recovery-passphrase contribution payloads
2026-08-24 14:59:42 +02:00

45 lines
1.0 KiB
Protocol Buffer

syntax = "proto3";
package arbiter.operator.vault.bootstrap;
message BootstrapEncryptedKey {
bytes nonce = 1;
bytes ciphertext = 2;
bytes associated_data = 3;
}
message DeclareCommittee {
uint32 count = 1;
uint32 recovery_count = 2;
}
message ContributePassphrase {
bytes passphrase = 1;
}
message ContributeRecoveryPassphrase {
int32 recovery_operator_id = 1;
bytes passphrase = 2;
}
enum BootstrapResult {
BOOTSTRAP_RESULT_UNSPECIFIED = 0;
BOOTSTRAP_RESULT_SUCCESS = 1;
BOOTSTRAP_RESULT_ALREADY_BOOTSTRAPPED = 2;
BOOTSTRAP_RESULT_INVALID_KEY = 3;
BOOTSTRAP_RESULT_AWAITING_CONTRIBUTIONS = 4;
}
message Request {
oneof payload {
BootstrapEncryptedKey encrypted_key = 2;
DeclareCommittee declare_committee = 3;
ContributePassphrase contribute_passphrase = 4;
ContributeRecoveryPassphrase contribute_recovery_passphrase = 5;
}
}
message Response {
BootstrapResult result = 1;
}