#if OCTAGON
#import <Foundation/Foundation.h>
#import "keychain/ckks/CKKS.h"
#import "keychain/ckks/CKKSItem.h"
#import "keychain/ckks/CKKSKey.h"
#import "keychain/ckks/CKKSPeer.h"
#import <SecurityFoundation/SFEncryptionOperation.h>
#import <SecurityFoundation/SFKey.h>
NS_ASSUME_NONNULL_BEGIN
typedef NS_ENUM(NSUInteger, SecCKKSTLKShareVersion) {
SecCKKSTLKShareVersion0 = 0, };
#define SecCKKSTLKShareCurrentVersion SecCKKSTLKShareVersion0
@interface CKKSTLKShare : CKKSCKRecordHolder
@property SFEllipticCurve curve;
@property SecCKKSTLKShareVersion version;
@property NSString* tlkUUID;
@property id<CKKSPeer> receiver;
@property NSString* senderPeerID;
@property NSInteger epoch;
@property NSInteger poisoned;
@property (nullable) NSData* wrappedTLK;
@property (nullable) NSData* signature;
- (instancetype)init NS_UNAVAILABLE;
- (CKKSKey* _Nullable)recoverTLK:(id<CKKSSelfPeer>)recoverer trustedPeers:(NSSet<id<CKKSPeer>>*)peers error:(NSError**)error;
+ (CKKSTLKShare* _Nullable)share:(CKKSKey*)key
as:(id<CKKSSelfPeer>)sender
to:(id<CKKSPeer>)receiver
epoch:(NSInteger)epoch
poisoned:(NSInteger)poisoned
error:(NSError**)error;
- (bool)signatureVerifiesWithPeerSet:(NSSet<id<CKKSPeer>>*)peerSet error:(NSError**)error;
+ (instancetype _Nullable)fromDatabase:(NSString*)uuid
receiverPeerID:(NSString*)receiverPeerID
senderPeerID:(NSString*)senderPeerID
zoneID:(CKRecordZoneID*)zoneID
error:(NSError* __autoreleasing*)error;
+ (instancetype _Nullable)tryFromDatabase:(NSString*)uuid
receiverPeerID:(NSString*)receiverPeerID
senderPeerID:(NSString*)senderPeerID
zoneID:(CKRecordZoneID*)zoneID
error:(NSError**)error;
+ (NSArray<CKKSTLKShare*>*)allFor:(NSString*)receiverPeerID
keyUUID:(NSString*)uuid
zoneID:(CKRecordZoneID*)zoneID
error:(NSError* __autoreleasing*)error;
+ (NSArray<CKKSTLKShare*>*)allForUUID:(NSString*)uuid zoneID:(CKRecordZoneID*)zoneID error:(NSError**)error;
+ (NSArray<CKKSTLKShare*>*)allInZone:(CKRecordZoneID*)zoneID error:(NSError**)error;
+ (instancetype _Nullable)tryFromDatabaseFromCKRecordID:(CKRecordID*)recordID error:(NSError**)error;
+ (NSString*)ckrecordPrefix;
- (CKKSKey* _Nullable)unwrapUsing:(id<CKKSSelfPeer>)localPeer error:(NSError**)error;
- (NSData* _Nullable)signRecord:(SFECKeyPair*)signingKey error:(NSError**)error;
- (bool)verifySignature:(NSData*)signature verifyingPeer:(id<CKKSPeer>)peer error:(NSError**)error;
- (NSData*)dataForSigning;
@end
NS_ASSUME_NONNULL_END
#endif // OCTAGON