pub struct GovernanceVerification {
pub public_key: PublicKeyHex,
pub ok: bool,
pub head: Option<GovernanceLogId>,
pub entries: Vec<EntryVerdict>,
pub keys: Vec<GovernanceKeyRecord>,
pub unanchored_keys: Vec<PublicKeyHex>,
pub repudiated: Vec<GovernanceLogId>,
}Expand description
A verification of the whole chain
Fields§
§public_key: PublicKeyHexThe key in force for the next entry — the active end of keys
ok: boolEvery entry’s signature and link verified under the key in force,
no entry’s content is known to differ from what was attested, and
every amendment and rotation is well-formed. Repudiated entries do
not clear this by themselves: repudiation is a declared state, not
a defect, and repudiated is where to look for it.
head: Option<GovernanceLogId>The last entry in the chain
entries: Vec<EntryVerdict>In chain order
keys: Vec<GovernanceKeyRecord>The signing key history the chain itself declares, oldest first
unanchored_keys: Vec<PublicKeyHex>The genesis key, when neither this verifier’s KeyAnchor nor a
CertPurpose::Genesis certificate in the chain vouches for it.
Not a failure, but a reference client says so loudly. Never a later
key: those are certified or they do not hold the chain at all.
repudiated: Vec<GovernanceLogId>Entries inside a compromise window that no reattestation restored
Implementations§
Source§impl GovernanceVerification
impl GovernanceVerification
Sourcepub fn check_content(
&mut self,
link: &GovernanceChainLink,
data: &Value,
) -> bool
pub fn check_content( &mut self, link: &GovernanceChainLink, data: &Value, ) -> bool
Record whether data is the content link attested — or what a
redaction of it left behind, or its latest version. Folding its
revisions over the stored content checks them too.
The chain endpoint carries data only for amendments and
rotations, so this is how a caller that read an entry in full folds
that read into the report. false (and a false
content_matches, which clears
ok on the next settle) when the
entry is not in this report at all.