pub struct Amendment {
pub agora_governance_amendment: u32,
pub target: GovernanceLogId,
pub target_entry_hash: Sha256Hex,
pub kind: AmendmentKind,
pub authority: Option<GovernanceLogId>,
pub basis: String,
pub note: String,
pub rationale: Option<String>,
pub redaction: Option<Redaction>,
}Expand description
The data of an amendment entry: what an earlier entry now means.
The target is never edited — except its data under a Redaction —
so the amendment is the whole record of the change, and both are
signed links of the same chain.
Fields§
§agora_governance_amendment: u32Always AMENDMENT_VERSION
target: GovernanceLogId§target_entry_hash: Sha256HexThe target’s entry_hash — binds this to one exact entry
kind: AmendmentKindThe governance entry that authorizes this, when one does
(e.g. GOV-2026-0005). None for a lawful-deletion redaction.
basis: StringSection or legal basis, human-readable: "§1 (Red Team Cases Recharacterized)", "GDPR Art. 17(1)(a)". Never personal data.
note: StringThe label readers and prompts show next to the target
rationale: Option<String>Why, at length — note is the label, this is the reasoning, and it
is part of the signed record. Never personal data.
redaction: Option<Redaction>Present iff kind is AmendmentKind::Redaction
Implementations§
Source§impl Amendment
impl Amendment
Sourcepub fn new(
target: GovernanceLogId,
target_entry_hash: Sha256Hex,
kind: AmendmentKind,
basis: impl Into<String>,
note: impl Into<String>,
) -> Result<Self, AmendmentError>
pub fn new( target: GovernanceLogId, target_entry_hash: Sha256Hex, kind: AmendmentKind, basis: impl Into<String>, note: impl Into<String>, ) -> Result<Self, AmendmentError>
The amendment with the governance entry that authorizes it
Sourcepub fn with_rationale(self, rationale: impl Into<String>) -> Self
pub fn with_rationale(self, rationale: impl Into<String>) -> Self
The amendment with its rationale
Sourcepub fn redaction(
amendment_id: &GovernanceLogId,
target: GovernanceLogId,
target_entry_hash: Sha256Hex,
basis: impl Into<String>,
note: impl Into<String>,
fields: Vec<String>,
data: &Value,
blind: Blind,
) -> Result<(Self, Value), RedactError>
pub fn redaction( amendment_id: &GovernanceLogId, target: GovernanceLogId, target_entry_hash: Sha256Hex, basis: impl Into<String>, note: impl Into<String>, fields: Vec<String>, data: &Value, blind: Blind, ) -> Result<(Self, Value), RedactError>
A redaction of fields from the target’s data, with the redacted
data it commits to.
amendment_id is the id this amendment will be appended under: the
marker left behind names it, so the redaction says who ordered it.
Append both together or neither — the returned data is what the
target’s row must hold for verify_chain to accept it. blind
is the target’s new Blind: random, so a
rehearsal’s resulting_data_hash is not the real one’s.
Sourcepub fn validate(&self) -> Result<(), AmendmentError>
pub fn validate(&self) -> Result<(), AmendmentError>
Version and the redaction-shape invariant — everything checkable without the rest of the chain