Skip to content

docs(proofs): align hinted registration references - #2045

Merged
roethke merged 2 commits into
roethke/hinted-tee-registrationfrom
leopoldjoy/hinted-registration-reference-docs
Oct 1, 2026
Merged

roethke merged 2 commits into
roethke/hinted-tee-registrationfrom
leopoldjoy/hinted-registration-reference-docs

Conversation

@leopoldjoy

@leopoldjoy leopoldjoy commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

What changed? Why?

Stacked on #2044 to bring the surrounding proof references into agreement with the hinted Registrar specification.

  • Replace the obsolete ZK attestation flow in Proof Contracts with the current NitroValidator / CertManager / P384Verifier graph, registration API, validation boundaries, and administrative roles.
  • Keep the NitroEnclaveVerifier anchor as a short pre-Cobalt note linking to the migration, rather than documenting its interfaces as current.
  • Correct enclave_signerAttestation(user_data, nonces) to document one nonce byte array per enclave, consistent ordering, optional arguments, 512-byte limits, and invalid-parameter behavior.
  • Regenerate the LLM indexes for the updated Proof Contracts description.

Notes to reviewers

  • Base branch: roethke/hinted-tee-registration (docs(proofs): specify hinted TEE registration in the Registrar spec #2044), not master. The Registrar page and Cobalt overview are unchanged in this PR.

  • Cross-checked against freshly fetched base/base main at fade4e5ed4592894e05b323d95e650c2d8755f0a and base/contracts main at 5c6c0f6c38b2898820fde81dce712ae5a12133d8, including its pinned base/nitro-validator dependency at 0ea0d12366b4fa44f9e07e4755f2ad36561cb674.

  • Certificate revocation and expiry gate new registrations; previously registered signers require separate deregistration. Only the CertManager owner can revoke the root, while the revoker handles non-root identities.

  • CI note: The screenshot tag triggered Chromatic Publish, whose existing Storybook build fails with WebpackInvocationError: Cannot read properties of undefined (reading 'tap'). The identical failure occurred on #1956's screenshot-tag run on September 24. This PR changes neither Storybook nor its workflow; that separate CI issue is left out of scope.

How has it been tested?

  • MDX lint on both changed pages: zero errors; three advisory code-highlighting warnings on existing code blocks.
  • node scripts/validate-docs-structure.js: passes.
  • npm test: 85 tests pass.
  • node scripts/llms.js and git diff --check: pass.
  • The implementation review for this stack also passed 65 Rust registrar tests, 47 registry tests, 44 hinted-verifier tests (including enabled FFI checks), and two targeted revocation/expiry tests using a real signed attestation.
  • Rendered both pages in local Mintlify/Chromium and checked that the updated API code blocks and nonce table fit at 1280 px.

Screenshots

Proof Contracts: graph, registration, and hinted validators

Updated proof-contract graph

Hinted signer registration

NitroValidator reference

Certificate cache, revocation scope, and P384Verifier

TEE Prover: per-enclave nonce API

Per-enclave attestation nonce API

Generated with Toshi

@leopoldjoy
leopoldjoy marked this pull request as ready for review October 1, 2026 00:13
@roethke
roethke merged commit b822374 into roethke/hinted-tee-registration Oct 1, 2026
16 of 17 checks passed
@roethke
roethke deleted the leopoldjoy/hinted-registration-reference-docs branch October 1, 2026 16:08
roethke added a commit that referenced this pull request Oct 1, 2026
…2044)

* docs(proofs): specify hinted TEE registration in the Registrar spec

Bring over Leopold's changes from #1956 (merged into the #1953 branch,
never landed on master): replace the ZK/Boundless registrar description
with the hinted P-384 flow shipped in Cobalt, and add the Hinted TEE
Registration page. Past tense where the migration has now shipped, and
link the new page from the Cobalt overview.

Co-authored-by: Leopold Joy <leo@leopoldjoy.com>
Generated with Claude Code

Co-Authored-By: Claude <noreply@anthropic.com>

* docs(proofs): fold Hinted TEE Registration into the Registrar page

Per Leopold: the hinted flow is the Registrar's architecture going
forward, and only the migration itself is upgrade-specific. Drop the
standalone page, replace Upgrade Compatibility with a Hinted
Registration Migration section (previous flow, why, what was preserved),
and link that anchor from the Cobalt overview.

Generated with Claude Code

Co-Authored-By: Claude <noreply@anthropic.com>

* docs(proofs): apply Leopold's Registrar review suggestions

- Condense Responsibilities into a high-level summary
- State that revocation/expiry does not invalidate registered signers
- Drop the repeated no-fallback safety bullet

Co-authored-by: Leopold Joy <leo@leopoldjoy.com>
Generated with Claude Code

Co-Authored-By: Claude <noreply@anthropic.com>

* docs(proofs): align hinted registration references (#2045)

* docs(proofs): align hinted registration references

* docs(proofs): keep hinted API references readable

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Leopold Joy <leo@leopoldjoy.com>
Co-authored-by: Youssef <youcefea99@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants