#[non_exhaustive]pub struct VerificationReport {
pub body_hash_ok: bool,
pub signature_ok: bool,
pub schema_ok: bool,
pub data_ref_embedded: Vec<Result<usize, AcdpError>>,
pub data_ref_external: Vec<Option<Result<usize, AcdpError>>>,
pub ctx_id_ok: bool,
}Expand description
Structured diagnostic outcome from VerifiedContext::fetch_report.
Top-level booleans report the per-stage outcome of the verification
pipeline. Per-DataRef slots track outcomes for each entry in
body.data_refs, in declaration order:
data_ref_embedded[i]—Ok(decoded_size_bytes)when the embedded payload’scontent_hashmatched;Errwhen it didn’t (or the embedded was malformed). Refs without an embedded payload or without a declaredcontent_hashproduceOk(0).data_ref_external[i]—Nonewhen no external fetch was attempted (either nolocationor nofetcherwas provided);Some(Ok(bytes_len))when the fetch + hash succeeded;Some(Err(_))on any failure (SSRF rejection, hash mismatch, timeout, …).
AcdpError doesn’t implement Clone, so the report is move-only.
#[non_exhaustive]: this struct has already gained a field once as a
non-optional consequence of a security fix (the RFC-ACDP-0006 §4.1
context-identity binding), and it is output-only — constructed solely
inside this crate (verified.rs) — so downstream loses nothing by
being unable to construct it directly. Same rationale as SsrfReason
in crates/acdp-safe-http/src/lib.rs (“future spec revisions may add
ranges”): future fields stop being breaking changes for callers that
only read this report.
Fields (Non-exhaustive)§
This struct is marked as non-exhaustive
Struct { .. } syntax; cannot be matched against without a wildcard ..; and struct update syntax will not work.body_hash_ok: boolcontent_hash recomputed from the body matches the declared one.
signature_ok: boolThe producer signature verified against the resolved DID key.
schema_ok: boolvalidate_body passed (or was disabled by policy).
data_ref_embedded: Vec<Result<usize, AcdpError>>Per-DataRef embedded-hash outcome, in body.data_refs order.
data_ref_external: Vec<Option<Result<usize, AcdpError>>>Per-DataRef external-fetch outcome, in body.data_refs order.
None indicates “not attempted” (no fetcher provided or no
location to fetch from).
ctx_id_ok: boolThe served body’s ctx_id equals the one requested
(RFC-ACDP-0006 §4.1 step 7, NORMATIVE — “Bind the resolved
identity”). false means the registry served a different,
validly-signed body under the requested id (context
substitution); see VerifiedContext::verify_retrieved’s doc for
the full rationale. This flag gates whether
VerifiedContext::fetch_report_diagnose hands back a
Some(VerifiedContext) — appended last so any positional
construction fails loudly rather than silently binding the wrong
field.