//! Generated by `trust-tasks-codegen` — do not edit by hand.
//!
//! Spec slug: `audit/verify`. Version: `0.1`.
#[allow(unused_imports)]
use serde::{Deserialize, Serialize};
/// Error types.
pub mod error {
/// Error from a `TryFrom` or `FromStr` implementation.
pub struct ConversionError(::std::borrow::Cow<'static, str>);
impl ::std::error::Error for ConversionError {}
impl ::std::fmt::Display for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Display::fmt(&self.0, f)
}
}
impl ::std::fmt::Debug for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Debug::fmt(&self.0, f)
}
}
impl From<&'static str> for ConversionError {
fn from(value: &'static str) -> Self {
Self(value.into())
}
}
impl From<String> for ConversionError {
fn from(value: String) -> Self {
Self(value.into())
}
}
}
///Locates the first envelope at which chain verification failed.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "ChainBreak",
/// "description": "Locates the first envelope at which chain verification failed.",
/// "type": "object",
/// "required": [
/// "index",
/// "kind"
/// ],
/// "properties": {
/// "eventId": {
/// "description": "Identifier of the offending envelope, when it has one (an unparseable envelope may not).",
/// "type": "string"
/// },
/// "index": {
/// "description": "Zero-based position in chronological order of the offending envelope.",
/// "type": "integer",
/// "minimum": 0.0
/// },
/// "kind": {
/// "description": "`tamperedEntry`: the envelope's content changed after writing, so its `entryHash` no longer re-derives. `brokenLink`: the envelope's `prevHash` does not point at its predecessor's `entryHash` — a reorder, drop, insertion, or duplication.",
/// "type": "string",
/// "enum": [
/// "tamperedEntry",
/// "brokenLink"
/// ]
/// }
/// },
/// "additionalProperties": false,
/// "$anchor": "chainBreak"
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
pub struct ChainBreak {
///Identifier of the offending envelope, when it has one (an unparseable envelope may not).
#[serde(
rename = "eventId",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub event_id: ::std::option::Option<::std::string::String>,
///Zero-based position in chronological order of the offending envelope.
pub index: u64,
///`tamperedEntry`: the envelope's content changed after writing, so its `entryHash` no longer re-derives. `brokenLink`: the envelope's `prevHash` does not point at its predecessor's `entryHash` — a reorder, drop, insertion, or duplication.
pub kind: ChainBreakKind,
}
///`tamperedEntry`: the envelope's content changed after writing, so its `entryHash` no longer re-derives. `brokenLink`: the envelope's `prevHash` does not point at its predecessor's `entryHash` — a reorder, drop, insertion, or duplication.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "`tamperedEntry`: the envelope's content changed after writing, so its `entryHash` no longer re-derives. `brokenLink`: the envelope's `prevHash` does not point at its predecessor's `entryHash` — a reorder, drop, insertion, or duplication.",
/// "type": "string",
/// "enum": [
/// "tamperedEntry",
/// "brokenLink"
/// ]
///}
/// ```
/// </details>
#[derive(
::serde::Deserialize,
::serde::Serialize,
Clone,
Copy,
Debug,
Eq,
Hash,
Ord,
PartialEq,
PartialOrd,
)]
pub enum ChainBreakKind {
#[serde(rename = "tamperedEntry")]
TamperedEntry,
#[serde(rename = "brokenLink")]
BrokenLink,
}
impl ::std::fmt::Display for ChainBreakKind {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
match *self {
Self::TamperedEntry => f.write_str("tamperedEntry"),
Self::BrokenLink => f.write_str("brokenLink"),
}
}
}
impl ::std::str::FromStr for ChainBreakKind {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
match value {
"tamperedEntry" => Ok(Self::TamperedEntry),
"brokenLink" => Ok(Self::BrokenLink),
_ => Err("invalid value".into()),
}
}
}
impl ::std::convert::TryFrom<&str> for ChainBreakKind {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ChainBreakKind {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ChainBreakKind {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
///Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Ext",
/// "description": "Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.",
/// "type": "object",
/// "minProperties": 1,
/// "additionalProperties": true,
/// "propertyNames": {
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
/// }
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(transparent)]
pub struct Ext(pub ::std::collections::HashMap<ExtKey, ::serde_json::Value>);
impl ::std::ops::Deref for Ext {
type Target = ::std::collections::HashMap<ExtKey, ::serde_json::Value>;
fn deref(&self) -> &::std::collections::HashMap<ExtKey, ::serde_json::Value> {
&self.0
}
}
impl ::std::convert::From<Ext> for ::std::collections::HashMap<ExtKey, ::serde_json::Value> {
fn from(value: Ext) -> Self {
value.0
}
}
impl ::std::convert::From<::std::collections::HashMap<ExtKey, ::serde_json::Value>> for Ext {
fn from(value: ::std::collections::HashMap<ExtKey, ::serde_json::Value>) -> Self {
Self(value)
}
}
///`ExtKey`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ExtKey(::std::string::String);
impl ::std::ops::Deref for ExtKey {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ExtKey> for ::std::string::String {
fn from(value: ExtKey) -> Self {
value.0
}
}
impl ::std::str::FromStr for ExtKey {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new("^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$").unwrap()
});
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ExtKey {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///Request to verify the integrity of a maintainer's append-only audit hash chain. The request carries no parameters — verification is store-wide.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "$id": "https://trusttasks.org/spec/audit/verify/0.1",
/// "title": "Payload",
/// "description": "Request to verify the integrity of a maintainer's append-only audit hash chain. The request carries no parameters — verification is store-wide.",
/// "type": "object",
/// "properties": {
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
pub struct Payload {
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
}
impl ::std::default::Default for Payload {
fn default() -> Self {
Self {
ext: Default::default(),
}
}
}
///The outcome of walking the audit log in chronological order and checking each envelope's hash links. `verified` is true only when every chainable envelope re-derived its own `entryHash` and pointed at its predecessor's. When false, `chainBreak` locates the first failure.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Response",
/// "description": "The outcome of walking the audit log in chronological order and checking each envelope's hash links. `verified` is true only when every chainable envelope re-derived its own `entryHash` and pointed at its predecessor's. When false, `chainBreak` locates the first failure.",
/// "type": "object",
/// "required": [
/// "entriesExamined",
/// "entriesVerified",
/// "legacySkipped",
/// "unparseableSkipped",
/// "verified"
/// ],
/// "properties": {
/// "chainBreak": {
/// "description": "Present iff `verified` is false — the first inconsistency found. Absent when verified.",
/// "$ref": "#/definitions/ChainBreak"
/// },
/// "entriesExamined": {
/// "description": "Total envelopes walked, including those skipped.",
/// "type": "integer",
/// "minimum": 0.0
/// },
/// "entriesVerified": {
/// "description": "Envelopes whose links were actually checked (examined minus skipped).",
/// "type": "integer",
/// "minimum": 0.0
/// },
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// },
/// "head": {
/// "description": "Hex `entryHash` of the newest envelope reached. Absent when the log is empty.",
/// "type": "string"
/// },
/// "legacySkipped": {
/// "description": "Envelopes stepped over because they predate the hash-chain format. A value > 0 on a store that should hold none is itself a finding — skipped envelopes are an insertion point, not a verified prefix.",
/// "type": "integer",
/// "minimum": 0.0
/// },
/// "unparseableSkipped": {
/// "description": "Envelopes that could not be deserialized and so could not be checked. Reported at the same prominence as a break, not swallowed.",
/// "type": "integer",
/// "minimum": 0.0
/// },
/// "verified": {
/// "description": "True iff the chain is internally consistent end-to-end: every examined envelope re-derived its `entryHash` and its `prevHash` matched its predecessor. See Security & Privacy — this proves consistency, NOT authenticity.",
/// "type": "boolean"
/// }
/// },
/// "additionalProperties": false,
/// "$anchor": "response"
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
pub struct Response {
///Present iff `verified` is false — the first inconsistency found. Absent when verified.
#[serde(
rename = "chainBreak",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub chain_break: ::std::option::Option<ChainBreak>,
///Total envelopes walked, including those skipped.
#[serde(rename = "entriesExamined")]
pub entries_examined: u64,
///Envelopes whose links were actually checked (examined minus skipped).
#[serde(rename = "entriesVerified")]
pub entries_verified: u64,
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
///Hex `entryHash` of the newest envelope reached. Absent when the log is empty.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub head: ::std::option::Option<::std::string::String>,
///Envelopes stepped over because they predate the hash-chain format. A value > 0 on a store that should hold none is itself a finding — skipped envelopes are an insertion point, not a verified prefix.
#[serde(rename = "legacySkipped")]
pub legacy_skipped: u64,
///Envelopes that could not be deserialized and so could not be checked. Reported at the same prominence as a break, not swallowed.
#[serde(rename = "unparseableSkipped")]
pub unparseable_skipped: u64,
///True iff the chain is internally consistent end-to-end: every examined envelope re-derived its `entryHash` and its `prevHash` matched its predecessor. See Security & Privacy — this proves consistency, NOT authenticity.
pub verified: bool,
}
impl crate::Payload for Payload {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/audit/verify/0.1";
const IS_RECIPIENT_REQUIRED: bool = true;
}
impl crate::Payload for Response {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/audit/verify/0.1#response";
const IS_RECIPIENT_REQUIRED: bool = true;
}
#[cfg(feature = "validate")]
impl crate::validate::ValidatedPayload for Payload {
const SCHEMA_JSON: &'static str = "{\n \"$defs\": {\n \"ChainBreak\": {\n \"$anchor\": \"chainBreak\",\n \"additionalProperties\": false,\n \"description\": \"Locates the first envelope at which chain verification failed.\",\n \"properties\": {\n \"eventId\": {\n \"description\": \"Identifier of the offending envelope, when it has one (an unparseable envelope may not).\",\n \"type\": \"string\"\n },\n \"index\": {\n \"description\": \"Zero-based position in chronological order of the offending envelope.\",\n \"minimum\": 0,\n \"type\": \"integer\"\n },\n \"kind\": {\n \"description\": \"`tamperedEntry`: the envelope's content changed after writing, so its `entryHash` no longer re-derives. `brokenLink`: the envelope's `prevHash` does not point at its predecessor's `entryHash` — a reorder, drop, insertion, or duplication.\",\n \"enum\": [\n \"tamperedEntry\",\n \"brokenLink\"\n ],\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"kind\",\n \"index\"\n ],\n \"title\": \"ChainBreak\",\n \"type\": \"object\"\n },\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"description\": \"The outcome of walking the audit log in chronological order and checking each envelope's hash links. `verified` is true only when every chainable envelope re-derived its own `entryHash` and pointed at its predecessor's. When false, `chainBreak` locates the first failure.\",\n \"properties\": {\n \"chainBreak\": {\n \"$ref\": \"#/$defs/ChainBreak\",\n \"description\": \"Present iff `verified` is false — the first inconsistency found. Absent when verified.\"\n },\n \"entriesExamined\": {\n \"description\": \"Total envelopes walked, including those skipped.\",\n \"minimum\": 0,\n \"type\": \"integer\"\n },\n \"entriesVerified\": {\n \"description\": \"Envelopes whose links were actually checked (examined minus skipped).\",\n \"minimum\": 0,\n \"type\": \"integer\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"head\": {\n \"description\": \"Hex `entryHash` of the newest envelope reached. Absent when the log is empty.\",\n \"type\": \"string\"\n },\n \"legacySkipped\": {\n \"description\": \"Envelopes stepped over because they predate the hash-chain format. A value > 0 on a store that should hold none is itself a finding — skipped envelopes are an insertion point, not a verified prefix.\",\n \"minimum\": 0,\n \"type\": \"integer\"\n },\n \"unparseableSkipped\": {\n \"description\": \"Envelopes that could not be deserialized and so could not be checked. Reported at the same prominence as a break, not swallowed.\",\n \"minimum\": 0,\n \"type\": \"integer\"\n },\n \"verified\": {\n \"description\": \"True iff the chain is internally consistent end-to-end: every examined envelope re-derived its `entryHash` and its `prevHash` matched its predecessor. See Security & Privacy — this proves consistency, NOT authenticity.\",\n \"type\": \"boolean\"\n }\n },\n \"required\": [\n \"verified\",\n \"entriesExamined\",\n \"entriesVerified\",\n \"legacySkipped\",\n \"unparseableSkipped\"\n ],\n \"title\": \"Audit Verify — response payload\",\n \"type\": \"object\"\n }\n },\n \"$id\": \"https://trusttasks.org/spec/audit/verify/0.1\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\",\n \"additionalProperties\": false,\n \"description\": \"Request to verify the integrity of a maintainer's append-only audit hash chain. The request carries no parameters — verification is store-wide.\",\n \"properties\": {\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n }\n },\n \"title\": \"Audit Verify — payload\",\n \"type\": \"object\"\n}\n";
}
#[cfg(test)]
mod conformance {
//! Round-trip tests harvested from the spec's `spec.md`,
//! plus a `rejects_invalid_examples` test for any fixtures
//! in `payload.invalid-examples.json` (validate feature).
/// Each fixture in `payload.invalid-examples.json` MUST be
/// rejected by at least one of: serde deserialization, or
/// JSON-Schema validation under the `validate` feature. The
/// fixture file documents the producer-side bug class that
/// each payload exemplifies; this generated test pins it.
#[cfg(feature = "validate")]
#[test]
fn rejects_invalid_examples() {
use crate::validate::ValidatedPayload;
let fixtures: &[(&str, &str)] = &[
(
"Unknown top-level member is rejected (additionalProperties: false).",
"{\n \"__notARealMember__\": true\n}",
),
(
"The request takes no verification parameters; a stray `contextId` is rejected.",
"{\n \"contextId\": \"ctx_1\"\n}",
),
];
for (i, (note, raw)) in fixtures.iter().enumerate() {
let value: serde_json::Value = match serde_json::from_str(raw) {
Ok(v) => v,
Err(_) => continue,
};
let serde_ok = serde_json::from_value::<super::Payload>(value.clone()).is_ok();
let schema_ok = super::Payload::validate_value(&value).is_ok();
assert!(
!(serde_ok && schema_ok),
"invalid-example #{} ({:?}) was accepted by both serde and JSON Schema; \
the fixture's stated failure class is no longer caught:\n{}",
i + 1,
note,
raw
);
}
}
}