Expand description
Governance log attestation: the envelope the server signs at insert and any client can verify.
Every entry commits to its own fields and to the hash of the entry before it, so the log is a chain: change or remove any entry and every later link stops verifying. The envelope (version 1) is
data_hash = SHA-256( canonical_json(data) )
preimage = {"agora_governance_log":1,"id":…,"entry_type":…,
"created_at":<unix micros>,"prev_hash":<hex|null>,
"data_hash":<hex>}
entry_hash = SHA-256( preimage )
signature = crypto::sign( key, entry_hash, signed_at unix seconds )What is not in the envelope, on purpose: tags (an index the Clerk may
revise), chain_seq (an index; the prev_hash links prove order), and
anything derived such as the precedent summary. signed_at is bound by
the signature rather than the hash, so a retroactive attestation — an
entry signed long after it was recorded — is visible as such and cannot
be quietly back-dated. See is_retroactive.
History is never rewritten. Two entry types amend it instead, and both
are ordinary signed links whose data the verifier reads:
Amendment(AMD-) names an earlier entry and says what changed about its force (Standing) or its content (Redaction). Its own free text is committed to, not contained (seeTextCommitment), because an amendment is the one thing that can never be redacted. A redaction replaces values in the target’sdatain place; the originalentry_hashstays on the row so later links still verify, and the amendment’sresulting_data_hashis what the redacted data must now hash to.EntryVerdict::content_matchesis the check. ARevisionoverwrites nothing: it is a signed RFC 6902 patch, and the entry’slatestversion is its storeddatawith every revision applied in chain order.KeyRotation(KEY-) moves the chain to a new signing key. A routine rotation is signed by the old key and a compromise declaration by the new one, but neither signature is what makes the change authentic: aKeyCertificatefrom the offline root keys (ROOT_KEYS) is, so holding the online key is never enough to move the chain. Seeverify_chain.
A third series is reserved but read by no verifier: a StewardRecord
(REC-) says what was done — a key ceremony, a restore — and decides
nothing. It exists because a rotation can never be redacted and so
carries keys and hashes only; the narrative that names people goes in an
entry that can be.
The envelope itself is unchanged by any of this: ENVELOPE_VERSION is
still 1 and what it does and does not cover is exactly as above.
Re-exports§
pub use crate::enums::AmendmentKind;pub use crate::enums::KeyStatus;pub use crate::enums::Standing;pub use json_patch;
Modules§
- reading
- The order a person or an agent should read a governance record in.
Structs§
- Agenda
Ranking - The aggregated ranking of a
Scheduleitem: a Borda count on the docket’s scale, so a first choice scoresrankablehowever many items the seat ranked, and an unranked item scores 0 - Amendment
- The
dataof anamendmententry: what an earlier entry now means. - Amendment
Draft - An
Amendmentand the texts it commits to: what a writer appends, the first as the entry’sdataand the second beside it - Amendment
Notice - What a reader needs next to an amended entry
- Amendment
Text Status TextStatusof each text of a version 2 amendment- Amendment
Texts - The texts beside one amendment entry; each is there or withheld on its
own, so erasing a rationale does not take the
notewith it - Ballot
- One seat’s ballot as aggregated
- Blind
- A blinding value: 32 random bytes carried in a redactable entry’s
dataunderBLIND_KEY. Seeblind_datafor what it is for. - Committed
Text - A text and the salt its
TextCommitmentwas made with: beside the entry, never in its hasheddata - Council
Attachment - Material put before the Council, inline as markdown
- Council
Decision Record - The
dataof acouncil_decisionentry. See the module docs. - Council
Round - One round of deliberation
- Edit
- What a
Revisionchanges, before it is applied: a patch, and the duplicates it removes, if that is what it does - Entry
Verdict - The verdict on one entry
- Envelope
- The fields an entry’s hash commits to
- Final
Votes - The votes that decided the item
- Governance
Attestation - What the server attests about one governance log entry
- Governance
Chain Link - One link of the chain as
GET /api/governance/log/chainreturns it — everything needed to verify linkage and signatures, plusdatafor the entries a verifier has to read - Governance
KeyRecord - One key’s span of the chain, as
verify_chainderives it andGET /api/governance/signing-keyspublishes it - Governance
Signing Key - The platform’s governance signing key, as
GET /api/governance/signing-keypublishes it - Governance
Signing Keys - The signing key history as
GET /api/governance/signing-keysreturns it - Governance
Verification - A verification of the whole chain
- HexLength
Error - A hex string of the wrong length or alphabet for the type it was parsed into
- KeyAnchor
- The genesis keys a verifier trusts out of band.
- KeyCert
Statement - What a root key signs:
keyholds the chain fromfrom_seq. - KeyCertificate
- A
KeyCertStatementand the root signatures over it - KeyRotation
- The
dataof akey_rotationentry. - Placed
Proposal - A proposal’s place in an
AgendaRanking - Public
KeyHex - An Ed25519 public key, hex on the wire
- Record
Attachment - A piece of supporting material carried inside a record
- Record
Participant - Someone who took part in a recorded act
- Redaction
- What a
AmendmentKind::Redactionremoved, and what is left - Revision
- A commit on a governance entry: an RFC 6902 patch from its previous version to the next.
- Revision
History - The revisions of one entry, for
check_content - RootSet
- The root keys a verifier trusts, and how many must agree
- Root
Signature - One root key’s signature over
KeyCertStatement::signed_bytes - Rotation
Statement - What the proof of possession signs
- Seat
Ranking - A seat’s ballot on a
Scheduleitem - Seat
Response - One seat’s turn in a round
- Sha256
Hex - A SHA-256 digest, hex on the wire
- Signature
Hex - An Ed25519 signature, hex on the wire
- Steward
Record - The
dataof asteward_recordentry. See the module docs. - Text
Commitment - What an amendment’s signed
dataholds in place of a text - Text
Salt - The salt of a
TextCommitment: 32 random bytes kept beside the text, and deleted with it - Trusted
Head - The last entry the compromised key is trusted for
Enums§
- Amendment
Error - An amendment is malformed
- Amendment
Text - A free-text field of an
Amendment: the text itself in version 1, a commitment to it from version 2 - Blind
Error datacannot be blinded- Cert
Purpose - What a certified key is being certified as
- Certificate
Error - A certificate does not certify what it was presented for
- Council
Seat - A voting Council seat. The fifth vote is the Steward’s.
- Council
Vote - A vote cast by a seat or the Steward
- Decision
Category - An agenda item’s category, which sets the vote it needs
(Constitution Art. IV). A Steward
vetorejects any of them. - Link
Error - Why one link failed on its own, before chain context
- Redact
Error - A
Redactioncannot be applied as asked - Redactable
- A value in an entry’s
data, or theredaction_markera redaction left in its place. - Revise
Error - A
Revisioncannot be made or applied as asked - Rotation
Error - A rotation is malformed, unauthenticated, or inconsistent with the chain
- Rotation
Reason - Why the key changed
- Text
Status - Where a committed text stands
Constants§
- AMENDMENT_
VERSION - The
Amendmentpayload version this module produces. Version 1, whose texts are in the signeddata, still verifies: the platform has three, all reviewed to hold no personal data. - BLIND_
KEY - The top-level key of a redactable entry’s
datathat holds itsBlind - ENVELOPE_
VERSION - The envelope version this module produces and verifies
- KEY_
CERT_ VERSION - The
KeyCertStatementversion this module produces and verifies - KEY_
ROTATION_ VERSION - The
KeyRotationpayload version this module produces and verifies - PUBLISHED_
KEYS - The key the chain started under, as this build of agentkit knows it.
- REDACTION_
MARKER_ PATTERN - The
patternof aredaction_marker - RETROACTIVE_
AFTER - An attestation signed more than this long after its entry was recorded is retroactive
- ROOT_
DOMAIN - What every root signature begins with
- ROOT_
KEYS - The governance root keys this build of agentkit trusts.
- ROOT_
THRESHOLD - How many of
ROOT_KEYSmust sign aKeyCertificate - STEWARD_
RECORD_ VERSION - The only
agora_steward_recordversion there is - WITHHELD_
TEXT - What
AmendmentNoticeshows for a text that is no longer beside its entry
Functions§
- apply_
patch datawithpatchapplied, as thejson-patchcrate applies RFC 6902- attest
- Attest an entry: the one construction path for
GovernanceAttestation, used by the server at insert and by tests building fixtures. - blind_
data datawith aBlindunderBLIND_KEY— what a writer signs and stores for every redactable entry.- canonical_
json valueas compact JSON with object keys sorted bytewise at every level.- data_
hash - SHA-256 over
canonical_json - is_
redactable - Whether entries of this type can be redacted, and so carry a
Blind. Amendments and key rotations cannot: verifiers read theirdata, and a chain whose own corrections can be edited proves nothing. - is_
retroactive truewhen the attestation was signed more thanRETROACTIVE_AFTERafter the entry was recorded — history signed after the fact, which proves the key holder vouches for it now, not that it was signed then- is_
revisable - Whether entries of this type can be revised. Those that cannot be
redacted cannot, nor can a
StewardRecord: it is the disclosure of what was done to the others. - kind_
standing - What an amendment does to the
Standingof the entry it names, when it changes it at all - latest
- An entry’s latest version: its stored
datawith each revision’s patch applied in chain order. A redaction rebases them (seeAmendmentDraft::redaction), so an error means the history is broken, not that a patch is out of date. - links_
from_ json - A chain from the JSON it was served as, held to [
same_shape]: a link is an object, and so is everything in it that should be. - non_
integer_ number - The RFC 6901 pointer to the first number in
datathat is not a 64-bit integer, if there is one. - recompute_
entry_ hash - Recompute a link’s
entry_hashfrom its fields - redact_
data datawith the value at each RFC 6901 pointer infieldsreplaced byredaction_marker.- redaction_
marker - The marker a redaction leaves in place of a value
- standing
- The
Standingconferred bykinds— the amendments naming one entry, in chain order. The last one that changes standing wins. - truncate_
to_ micros twith anything below a microsecond dropped, so the value hashed is the value Postgres will store- truncate_
to_ seconds twith anything below a second dropped, sosigned_atround-trips to the integer the signature covers- verify_
chain - Verify a whole chain from
genesis_key, following the rotations thatrootscertified and no others. - verify_
data truewhendatais whatlinkattested- verify_
link - Verify one link in isolation: version, hash recomputation, signature