Layer 6 · The blind host model
Canonical reference: hub
services/retrieval/src/bin/bootstrap.rs(blind read/write),services/resolver(the resolver),services/api(the/v1control plane). DIG's hub is a provider-blind host plus three trust planes.
The blind invariant
The hub holds only ciphertext keyed by retrieval_key — no URN, no decryption key. It relays the capsule's serve_blind output verbatim (a real hit OR the capsule's own indistinguishable decoy) and cannot tell hit from miss. The trusted root comes only from the chain, never from the serving origin.
Plane A — blind read/write at rpc.dig.net
serve_blind (framing-only decode)
serve_via_runtime (bootstrap.rs:1489-1633): fetch the .dig for (store, root) from the modules bucket (staging fallback for the read-before-promote window), check magic \0asm + size ≤ 256 MiB, then run the module's serve for the 32-byte key inside HostRuntime under §18.2 ExecutionLimits (fuel/epoch/384-MiB). The host decodes the ContentResponse framing only — NOT decryption; ciphertext stays sealed. It does not verify the proof and does not judge presence.
A None is returned only for a genuine infra failure (no host seed / module absent / trap / undecodable) → a uniform -32004; the hub never fabricates a miss.