Marmot-TS
    Preparing search index...

    Function validateAdminLeafCoupling

    • Ported from validate_admin_leaf_coupling_for_staged_commit: enforces the admin-policy resulting-epoch invariant (admin-policy-v1.md "Validation") — every admin key in the resulting epoch's admin set MUST correspond to an account with at least one member leaf in the resulting epoch.

      resultingMemberAccounts is the set of hex account pubkeys that have at least one member leaf in the RESULTING epoch (D-08: account-level, not leaf-level — an account with two leaves survives if only one is removed). Callers derive it from the post-apply state; this validator stays pure and MLS-free.

      When the resulting extensions carry no admin-policy bytes, this evaluates the carried-forward (current-epoch) admin set instead of skipping the check (Pitfall 3): a membership-only commit that de-leafs an admin without touching admin-policy bytes must still be rejected.

      An empty resolved admin set returns undefined (vacuously satisfied): component bytes cannot encode an empty admin list, so an empty resolved set means the epoch carries no admin-policy state at all — not a bypass, per MDK's own documented rationale for the same early return.

      Does NOT special-case SelfRemove (Pitfall 4): a non-admin's SelfRemove never changes the admin set and passes trivially here; an admin's SelfRemove is already refused earlier by createAdminCommitPolicyCallback (src/engine/admin-policy.ts), so this validator never needs its own carve-out for it.

      Parameters

      • args: {
            currentExtensions: GroupContextExtension[];
            resultingExtensions: GroupContextExtension[];
            resultingMemberAccounts: readonly string[];
        }

      Returns CommitIntegrityViolation | undefined

      • refs/mdk/crates/cgka-engine/src/app_components.rs validate_admin_leaf_coupling_for_staged_commit, reject_admins_without_member_accounts
      • Marmot v2 spec: app-components/admin-policy-v1.md "Validation"