Files
arbiter/protobufs/operator/vault/rekey.proto
CleverWild 8c0855b16e feat(proto)!: Shamir re-key, governance and bootstrapping vault state
Split out of feat-shamir so the wire contract can be reviewed on its own.
Rebased onto main: main's UNSEAL_RESULT_LOCKED_OUT keeps tag 4, so
UNSEAL_RESULT_AWAITING_CONTRIBUTIONS moved to 5.

BREAKING CHANGE: `shared.VaultState` renumbers SEALED/UNSEALED/ERROR to
make room for VAULT_STATE_BOOSTRAPPING = 2. Old and new peers disagree on
every vault state value.

- operator: new `governance` branch in OperatorRequest/Response (field 5)
- vault: new `rekey` branch in vault Request/Response (field 4)
- bootstrap/unseal: passphrase and recovery-passphrase contribution payloads
2026-08-24 14:59:42 +02:00

31 lines
649 B
Protocol Buffer

syntax = "proto3";
package arbiter.operator.vault.rekey;
message ContributePassphrase {
bytes passphrase = 1;
}
message ContributeRecoveryPassphrase {
int32 recovery_operator_id = 1;
bytes passphrase = 2;
}
enum RekeyResult {
REKEY_RESULT_UNSPECIFIED = 0;
REKEY_RESULT_SUCCESS = 1;
REKEY_RESULT_AWAITING_CONTRIBUTIONS = 2;
REKEY_RESULT_NOT_IN_PROGRESS = 3;
}
message Request {
oneof payload {
ContributePassphrase contribute_passphrase = 1;
ContributeRecoveryPassphrase contribute_recovery_passphrase = 2;
}
}
message Response {
RekeyResult result = 1;
}