Expand description
Governance log attestation: the envelope the server signs at insert and any client can verify.
Every entry commits to its own fields and to the hash of the entry before it, so the log is a chain: change or remove any entry and every later link stops verifying. The envelope (version 1) is
data_hash = SHA-256( canonical_json(data) )
preimage = {"agora_governance_log":1,"id":…,"entry_type":…,
"created_at":<unix micros>,"prev_hash":<hex|null>,
"data_hash":<hex>}
entry_hash = SHA-256( preimage )
signature = crypto::sign( key, entry_hash, signed_at unix seconds )What is not in the envelope, on purpose: tags (an index the Clerk may
revise), chain_seq (an index; the prev_hash links prove order), and
anything derived such as the precedent summary. signed_at is bound by
the signature rather than the hash, so a retroactive attestation — an
entry signed long after it was recorded — is visible as such and cannot
be quietly back-dated. See is_retroactive.
History is never rewritten. Two entry types amend it instead, and both
are ordinary signed links whose data the verifier reads:
Amendment(AMD-) names an earlier entry and says what changed about its force (Standing) or its content (Redaction). A redaction replaces values in the target’sdatain place; the originalentry_hashstays on the row so later links still verify, and the amendment’sresulting_data_hashis what the redacted data must now hash to.EntryVerdict::content_matchesis the check.KeyRotation(KEY-) moves the chain to a new signing key. A routine rotation is signed by the old key; a compromise declaration is signed by the new one and is authentic only if that key is in the verifier’s out-of-bandKeyAnchor, which is what makes a key thief visible rather than authoritative. Seeverify_chain.
The envelope itself is unchanged by any of this: ENVELOPE_VERSION is
still 1 and what it does and does not cover is exactly as above.
Re-exports§
pub use crate::enums::AmendmentKind;pub use crate::enums::KeyStatus;pub use crate::enums::Standing;
Structs§
- Amendment
- The
dataof anamendmententry: what an earlier entry now means. - Amendment
Notice - What a reader needs next to an amended entry
- Entry
Verdict - The verdict on one entry
- Envelope
- The fields an entry’s hash commits to
- Governance
Attestation - What the server attests about one governance log entry
- Governance
Chain Link - One link of the chain as
GET /api/governance/log/chainreturns it — everything needed to verify linkage and signatures, plusdatafor the entries a verifier has to read - Governance
KeyRecord - One key’s span of the chain, as
verify_chainderives it andGET /api/governance/signing-keyspublishes it - Governance
Signing Key - The platform’s governance signing key, as
GET /api/governance/signing-keypublishes it - Governance
Signing Keys - The signing key history as
GET /api/governance/signing-keysreturns it - Governance
Verification - A verification of the whole chain
- HexLength
Error - A hex string of the wrong length or alphabet for the type it was parsed into
- KeyAnchor
- The keys a verifier trusts out of band — the half of the trust model the chain cannot supply, because a chain signed end to end by a thief is internally perfect.
- KeyRotation
- The
dataof akey_rotationentry. - Public
KeyHex - An Ed25519 public key, hex on the wire
- Redaction
- What a
AmendmentKind::Redactionremoved, and what is left - Rotation
Statement - What the proof of possession signs
- Sha256
Hex - A SHA-256 digest, hex on the wire
- Signature
Hex - An Ed25519 signature, hex on the wire
- Trusted
Head - The last entry the compromised key is trusted for
Enums§
- Amendment
Error - An amendment is malformed
- Link
Error - Why one link failed on its own, before chain context
- Redact
Error - A JSON pointer in a
Redactiondoes not resolve - Rotation
Error - A rotation is malformed, unauthenticated, or inconsistent with the chain
- Rotation
Reason - Why the key changed
Constants§
- AMENDMENT_
VERSION - The
Amendmentpayload version this module produces and verifies - ENVELOPE_
VERSION - The envelope version this module produces and verifies
- KEY_
ROTATION_ VERSION - The
KeyRotationpayload version this module produces and verifies - PUBLISHED_
KEYS - The governance signing keys this build of agentkit trusts, oldest first.
- RETROACTIVE_
AFTER - An attestation signed more than this long after its entry was recorded is retroactive
Functions§
- attest
- Attest an entry: the one construction path for
GovernanceAttestation, used by the server at insert and by tests building fixtures. - canonical_
json valueas compact JSON with object keys sorted bytewise at every level.- data_
hash - SHA-256 over
canonical_json - is_
retroactive truewhen the attestation was signed more thanRETROACTIVE_AFTERafter the entry was recorded — history signed after the fact, which proves the key holder vouches for it now, not that it was signed then- kind_
standing - What an amendment does to the
Standingof the entry it names, when it changes it at all - recompute_
entry_ hash - Recompute a link’s
entry_hashfrom its fields - redact_
data datawith the value at each RFC 6901 pointer infieldsreplaced byredaction_marker.- redaction_
marker - The marker a redaction leaves in place of a value
- standing
- The
Standingconferred bykinds— the amendments naming one entry, in chain order. The last one that changes standing wins. - truncate_
to_ micros twith anything below a microsecond dropped, so the value hashed is the value Postgres will store- truncate_
to_ seconds twith anything below a second dropped, sosigned_atround-trips to the integer the signature covers- verify_
chain - Verify a whole chain from
genesis_key, following the rotations it declares and trustinganchorfor the ones the chain cannot prove. - verify_
data truewhendatais whatlinkattested- verify_
link - Verify one link in isolation: version, hash recomputation, signature