Skip to main content

Crate chio_kernel_mobile

Crate chio_kernel_mobile 

Source
Expand description

Mobile FFI for the Chio kernel core.

This adapter wraps the portable chio_kernel_core surface in an ergonomic, JSON-in / JSON-out Rust API and projects it across the C ABI using UniFFI. The UDL file in src/chio_kernel_mobile.udl drives binding generation for Swift (iOS) and Kotlin (Android); see bindings/README.md for the bindgen workflow.

§Why JSON-in / JSON-out

Chio’s type graph (capability tokens, scopes, receipts, passport envelopes) is large and deeply nested. Projecting every field into UDL would double the FFI surface for zero additional safety: the app-side Chio SDK already knows how to serialize these types, and the kernel-core entry points accept the parsed Rust structs. We marshal once via serde at the boundary and keep the UDL interface small.

§Exposed entry points

§Offline guarantees

None of these entry points perform I/O. A mobile app can invoke the pure-verification entry points while offline – for example to gate a sensitive tool call with a cached capability and queue the resulting receipt for upload when connectivity returns.

§unsafe posture

The crate source itself contains no unsafe code. UniFFI’s build-script-generated scaffolding declares #[no_mangle] extern "C" symbols (required for the C ABI that Swift and Kotlin link against); that is trusted generated code, not crate-author code. We therefore do not apply #![deny(unsafe_code)] at the crate root because it would also reject the generated scaffolding. An equivalent hand-written lint applies to every module in this crate via #![forbid(unsafe_code)] on each module below except where the scaffolding is pulled in.

Structs§

MobileClock
Mobile-suitable Clock implementation that reads the device wall-clock via SystemTime::now().
MobileRng
Mobile-suitable Rng delegating to the getrandom crate.
PortablePassportMetadata
Verified portable-passport envelope metadata projected across the FFI.
VerifiedCapability
Verified capability snapshot projected across the FFI.

Enums§

ChioMobileError
Errors raised by the mobile FFI.

Functions§

attest_app_attest
Produce an App Attest challenge envelope bound to challenge_hex.
attest_play_integrity
Produce a Play Integrity challenge envelope bound to nonce_hex.
evaluate
Evaluate a tool-call request against a capability token.
sign_receipt
Sign a receipt body with the Ed25519 seed signing_seed_hex (PUBLIC WYSIWYS signer; fail-closed).
sign_receipt_relaying_trusted_body
Relay-sign an already-minted, upstream-trusted receipt body.
verify_app_attest_evidence
Verify App Attest platform evidence against the issued challenge.
verify_capability
Verify a capability token against a single trusted authority key.
verify_capability_with_context
Verify a capability token with the full portable JSON context.
verify_mobile_receipt
Shape-check a mobile receipt against App Attest or Play Integrity evidence.
verify_passport
Verify a portable passport envelope.
verify_play_integrity_evidence
Verify a Play Integrity JWS against an issuer nonce and JWKS.