Expand description
Mobile FFI for the Chio kernel core.
This adapter wraps the portable chio_kernel_core
surface in an ergonomic, JSON-in / JSON-out Rust API and projects it
across the C ABI using UniFFI. The UDL file in
src/chio_kernel_mobile.udl drives binding generation for Swift
(iOS) and Kotlin (Android); see bindings/README.md for the bindgen
workflow.
§Why JSON-in / JSON-out
Chio’s type graph (capability tokens, scopes, receipts, passport envelopes) is large and deeply nested. Projecting every field into UDL would double the FFI surface for zero additional safety: the app-side Chio SDK already knows how to serialize these types, and the kernel-core entry points accept the parsed Rust structs. We marshal once via serde at the boundary and keep the UDL interface small.
§Exposed entry points
evaluate– evaluate a tool-call request against a capability.sign_receipt– sign anChioReceiptBodywith a 32-byte seed.verify_capability– offline capability verification.verify_passport– offline portable-passport envelope verification.attest_app_attest– App Attest challenge entry point.verify_app_attest_evidence– App Attest evidence verifier.attest_play_integrity– Play Integrity challenge entry point.verify_play_integrity_evidence– Play Integrity JWS verifier.verify_mobile_receipt– mobile attestation receipt verifier.
§Offline guarantees
None of these entry points perform I/O. A mobile app can invoke the pure-verification entry points while offline – for example to gate a sensitive tool call with a cached capability and queue the resulting receipt for upload when connectivity returns.
§unsafe posture
The crate source itself contains no unsafe code. UniFFI’s
build-script-generated scaffolding declares #[no_mangle]
extern "C" symbols (required for the C ABI that Swift and Kotlin
link against); that is trusted generated code, not crate-author
code. We therefore do not apply #![deny(unsafe_code)] at the
crate root because it would also reject the generated scaffolding.
An equivalent hand-written lint applies to every module in this
crate via #![forbid(unsafe_code)] on each module below except
where the scaffolding is pulled in.
Structs§
- Mobile
Clock - Mobile-suitable
Clockimplementation that reads the device wall-clock viaSystemTime::now(). - Mobile
Rng - Mobile-suitable
Rngdelegating to thegetrandomcrate. - Portable
Passport Metadata - Verified portable-passport envelope metadata projected across the FFI.
- Verified
Capability - Verified capability snapshot projected across the FFI.
Enums§
- Chio
Mobile Error - Errors raised by the mobile FFI.
Functions§
- attest_
app_ attest - Produce an App Attest challenge envelope bound to
challenge_hex. - attest_
play_ integrity - Produce a Play Integrity challenge envelope bound to
nonce_hex. - evaluate
- Evaluate a tool-call request against a capability token.
- sign_
receipt - Sign a receipt body with the Ed25519 seed
signing_seed_hex(PUBLIC WYSIWYS signer; fail-closed). - sign_
receipt_ relaying_ trusted_ body - Relay-sign an already-minted, upstream-trusted receipt body.
- verify_
app_ attest_ evidence - Verify App Attest platform evidence against the issued challenge.
- verify_
capability - Verify a capability token against a single trusted authority key.
- verify_
capability_ with_ context - Verify a capability token with the full portable JSON context.
- verify_
mobile_ receipt - Shape-check a mobile receipt against App Attest or Play Integrity evidence.
- verify_
passport - Verify a portable passport envelope.
- verify_
play_ integrity_ evidence - Verify a Play Integrity JWS against an issuer nonce and JWKS.