Repository navigation
Conversation
leopoldjoy
marked this pull request as ready for review
October 1, 2026 00:13
roethke
merged commit Oct 1, 2026
b822374
into
roethke/hinted-tee-registration
16 of 17 checks passed
roethke
added a commit
that referenced
this pull request
Oct 1, 2026
…2044) * docs(proofs): specify hinted TEE registration in the Registrar spec Bring over Leopold's changes from #1956 (merged into the #1953 branch, never landed on master): replace the ZK/Boundless registrar description with the hinted P-384 flow shipped in Cobalt, and add the Hinted TEE Registration page. Past tense where the migration has now shipped, and link the new page from the Cobalt overview. Co-authored-by: Leopold Joy <leo@leopoldjoy.com> Generated with Claude Code Co-Authored-By: Claude <noreply@anthropic.com> * docs(proofs): fold Hinted TEE Registration into the Registrar page Per Leopold: the hinted flow is the Registrar's architecture going forward, and only the migration itself is upgrade-specific. Drop the standalone page, replace Upgrade Compatibility with a Hinted Registration Migration section (previous flow, why, what was preserved), and link that anchor from the Cobalt overview. Generated with Claude Code Co-Authored-By: Claude <noreply@anthropic.com> * docs(proofs): apply Leopold's Registrar review suggestions - Condense Responsibilities into a high-level summary - State that revocation/expiry does not invalidate registered signers - Drop the repeated no-fallback safety bullet Co-authored-by: Leopold Joy <leo@leopoldjoy.com> Generated with Claude Code Co-Authored-By: Claude <noreply@anthropic.com> * docs(proofs): align hinted registration references (#2045) * docs(proofs): align hinted registration references * docs(proofs): keep hinted API references readable --------- Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Leopold Joy <leo@leopoldjoy.com> Co-authored-by: Youssef <youcefea99@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed? Why?
Stacked on #2044 to bring the surrounding proof references into agreement with the hinted Registrar specification.
NitroValidator/CertManager/P384Verifiergraph, registration API, validation boundaries, and administrative roles.NitroEnclaveVerifieranchor as a short pre-Cobalt note linking to the migration, rather than documenting its interfaces as current.enclave_signerAttestation(user_data, nonces)to document one nonce byte array per enclave, consistent ordering, optional arguments, 512-byte limits, and invalid-parameter behavior.Notes to reviewers
Base branch:
roethke/hinted-tee-registration(docs(proofs): specify hinted TEE registration in the Registrar spec #2044), notmaster. The Registrar page and Cobalt overview are unchanged in this PR.Cross-checked against freshly fetched
base/basemain atfade4e5ed4592894e05b323d95e650c2d8755f0aandbase/contractsmain at5c6c0f6c38b2898820fde81dce712ae5a12133d8, including its pinnedbase/nitro-validatordependency at0ea0d12366b4fa44f9e07e4755f2ad36561cb674.Certificate revocation and expiry gate new registrations; previously registered signers require separate deregistration. Only the
CertManagerowner can revoke the root, while the revoker handles non-root identities.CI note: The screenshot tag triggered Chromatic Publish, whose existing Storybook build fails with
WebpackInvocationError: Cannot read properties of undefined (reading 'tap'). The identical failure occurred on #1956's screenshot-tag run on September 24. This PR changes neither Storybook nor its workflow; that separate CI issue is left out of scope.How has it been tested?
node scripts/validate-docs-structure.js: passes.npm test: 85 tests pass.node scripts/llms.jsandgit diff --check: pass.Screenshots
Proof Contracts: graph, registration, and hinted validators
TEE Prover: per-enclave nonce API
Generated with Toshi