Ported from validate_admin_leaf_coupling_for_staged_commit: enforces the
admin-policy resulting-epoch invariant (admin-policy-v1.md "Validation") —
every admin key in the resulting epoch's admin set MUST correspond to an
account with at least one member leaf in the resulting epoch.
resultingMemberAccounts is the set of hex account pubkeys that have at
least one member leaf in the RESULTING epoch (D-08: account-level, not
leaf-level — an account with two leaves survives if only one is removed).
Callers derive it from the post-apply state; this validator stays pure and
MLS-free.
When the resulting extensions carry no admin-policy bytes, this evaluates
the carried-forward (current-epoch) admin set instead of skipping the check
(Pitfall 3): a membership-only commit that de-leafs an admin without
touching admin-policy bytes must still be rejected.
An empty resolved admin set returns undefined (vacuously satisfied):
component bytes cannot encode an empty admin list, so an empty resolved set
means the epoch carries no admin-policy state at all — not a bypass, per
MDK's own documented rationale for the same early return.
Does NOT special-case SelfRemove (Pitfall 4): a non-admin's SelfRemove never
changes the admin set and passes trivially here; an admin's SelfRemove is
already refused earlier by createAdminCommitPolicyCallback
(src/engine/admin-policy.ts), so this validator never needs its own
carve-out for it.
Ported from
validate_admin_leaf_coupling_for_staged_commit: enforces the admin-policy resulting-epoch invariant (admin-policy-v1.md "Validation") — every admin key in the resulting epoch's admin set MUST correspond to an account with at least one member leaf in the resulting epoch.resultingMemberAccountsis the set of hex account pubkeys that have at least one member leaf in the RESULTING epoch (D-08: account-level, not leaf-level — an account with two leaves survives if only one is removed). Callers derive it from the post-apply state; this validator stays pure and MLS-free.When the resulting extensions carry no admin-policy bytes, this evaluates the carried-forward (current-epoch) admin set instead of skipping the check (Pitfall 3): a membership-only commit that de-leafs an admin without touching admin-policy bytes must still be rejected.
An empty resolved admin set returns
undefined(vacuously satisfied): component bytes cannot encode an empty admin list, so an empty resolved set means the epoch carries no admin-policy state at all — not a bypass, per MDK's own documented rationale for the same early return.Does NOT special-case SelfRemove (Pitfall 4): a non-admin's SelfRemove never changes the admin set and passes trivially here; an admin's SelfRemove is already refused earlier by
createAdminCommitPolicyCallback(src/engine/admin-policy.ts), so this validator never needs its own carve-out for it.