ReadonlyciphersuiteReadonlyhistoryOptional ReadonlyingestOptional ReadonlylifecycleOptional ReadonlyrewindReadonlystoreThe full-fork history tree (every observed state, canonical + forks).
Whether this group's canonical GroupContext still classifies as the
current account identity proof profile (D-11). Orthogonal to lifecycle:
an unsupported group can still be Stable — it stays listable and
destroy()-able, but every outbound send and every inbound envelope is
refused. Delegates to the engine, which recomputes this on every access.
Synchronous terminal authority after lifecycle hydration has completed.
Establishes the durable application-observation boundary for an effect.
Returns the hydrated durable disband request, if one exists.
Returns authoritative terminal evidence, failing closed on corrupt bytes.
Releases engine resources (the settle-check timer); call on teardown (B5).
Runs one retained-input scheduler edge through the normal reconciliation seam.
Builds the atomic active+required lifecycle enablement commit.
Waits until both durable lifecycle namespaces have been decoded.
Optionaloptions: { maxRetries?: number }Builds the self-remove proposal effects for leaving the group.
Per RFC 9420 §12.4 a member cannot commit a Remove targeting their own
leaf, so this emits self-remove proposal(s) for the next committer (e.g.
an admin) to apply. Modelled as a send-intent — the darkmatter engine
exposes the same operation as do_send_leave rather than letting callers
hand-build the proposals.
The leaving member's Nostr public key (hex string).
Publishable proposal effects (one per owned leaf node).
Durably records public notification delivery before application callbacks run.
Transport events received but not yet decrypted/processed into the history tree — the engine's ingestion pool (undecryptable-so-far events held for retry as the tree grows).
Commits selected terminal evidence before repeatable cleanup. The first durable write is authoritative even if any later store operation fails.
Re-scores the persisted fork history against the current tip and switches to
the canonical branch if a competing fork now wins (convergence.md), then
persists a resulting switch. Sources candidates from the history tree, so a
client that diverged onto a losing fork converges from disk without waiting
for the network to re-deliver the winning branch. Called on load.
Returns the pass's results in the same shape ingest yields, so the
caller can route them through the identical handler — in particular the
stateInvalidated withdrawal that clears the removed-inactive marker
(CONV-03, D-12). This layer used to swallow them (CR-06).
Persists irreversible terminal intent before returning publish work.
The retained canonical states within the rollback horizon, newest epoch first — the candidate epochs for cross-epoch encrypted-media decryption (see MarmotGroupEngine.retainedStates).
The derived convergence status (
group-state.md§Convergence status, B5).