//! Generated by `trust-tasks-codegen` — do not edit by hand.
//!
//! Spec slug: `rooms/keys/chain`. Version: `0.1`.
#[allow(unused_imports)]
use serde::{Deserialize, Serialize};
/// Error types.
pub mod error {
/// Error from a `TryFrom` or `FromStr` implementation.
pub struct ConversionError(::std::borrow::Cow<'static, str>);
impl ::std::error::Error for ConversionError {}
impl ::std::fmt::Display for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Display::fmt(&self.0, f)
}
}
impl ::std::fmt::Debug for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Debug::fmt(&self.0, f)
}
}
impl From<&'static str> for ConversionError {
fn from(value: &'static str) -> Self {
Self(value.into())
}
}
impl From<String> for ConversionError {
fn from(value: String) -> Self {
Self(value.into())
}
}
}
///One rung of a room's epoch key chain: the storage key of epoch `epoch - 1`, sealed under the storage key of `epoch`. A group key schedule offers no way to derive an earlier epoch's key from a later one — that property is what makes removing a member mean something — so without a chain the first membership change makes every record already in the room unopenable by everyone, including whoever wrote it. The chain is the one-way street run deliberately the other way: a member holding the current key walks it backwards to any retained epoch, and a member holding an earlier key still derives nothing later. Removal stays forward-only; reading stays possible. What a chain costs is stated where it is chosen, in the room's retention policy.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "EpochLink",
/// "description": "One rung of a room's epoch key chain: the storage key of epoch `epoch - 1`, sealed under the storage key of `epoch`. A group key schedule offers no way to derive an earlier epoch's key from a later one — that property is what makes removing a member mean something — so without a chain the first membership change makes every record already in the room unopenable by everyone, including whoever wrote it. The chain is the one-way street run deliberately the other way: a member holding the current key walks it backwards to any retained epoch, and a member holding an earlier key still derives nothing later. Removal stays forward-only; reading stays possible. What a chain costs is stated where it is chosen, in the room's retention policy.",
/// "type": "object",
/// "required": [
/// "epoch",
/// "nonce",
/// "wrapped"
/// ],
/// "properties": {
/// "epoch": {
/// "description": "The epoch whose storage key opens this link; it wraps the storage key of `epoch - 1`. Never 1: a room's first epoch has no predecessor, so a link claiming one wraps something that is not an earlier epoch's key.",
/// "type": "integer",
/// "minimum": 2.0
/// },
/// "nonce": {
/// "description": "AEAD nonce, base64url.",
/// "type": "string"
/// },
/// "wrapped": {
/// "description": "The wrapped predecessor key, base64url. Bound by AEAD associated data to `roomId` and to this link's own position in the chain, so a link lifted to another rung, or served under another room, fails to open rather than yielding a key that is wrong. The binding is load-bearing rather than decorative: every rung is a fixed-length key sealed under a fixed-length key, so nothing about the ciphertext itself says where it belongs.",
/// "type": "string"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct EpochLink {
///The epoch whose storage key opens this link; it wraps the storage key of `epoch - 1`. Never 1: a room's first epoch has no predecessor, so a link claiming one wraps something that is not an earlier epoch's key.
pub epoch: i64,
///AEAD nonce, base64url.
pub nonce: ::std::string::String,
///The wrapped predecessor key, base64url. Bound by AEAD associated data to `roomId` and to this link's own position in the chain, so a link lifted to another rung, or served under another room, fails to open rather than yielding a key that is wrong. The binding is load-bearing rather than decorative: every rung is a fixed-length key sealed under a fixed-length key, so nothing about the ciphertext itself says where it belongs.
pub wrapped: ::std::string::String,
}
impl EpochLink {
pub fn builder() -> builder::EpochLink {
Default::default()
}
}
///Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Ext",
/// "description": "Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.",
/// "type": "object",
/// "minProperties": 1,
/// "additionalProperties": true,
/// "propertyNames": {
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
/// }
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(transparent)]
pub struct Ext(pub ::std::collections::HashMap<ExtKey, ::serde_json::Value>);
impl ::std::ops::Deref for Ext {
type Target = ::std::collections::HashMap<ExtKey, ::serde_json::Value>;
fn deref(&self) -> &::std::collections::HashMap<ExtKey, ::serde_json::Value> {
&self.0
}
}
impl ::std::convert::From<Ext> for ::std::collections::HashMap<ExtKey, ::serde_json::Value> {
fn from(value: Ext) -> Self {
value.0
}
}
impl ::std::convert::From<::std::collections::HashMap<ExtKey, ::serde_json::Value>> for Ext {
fn from(value: ::std::collections::HashMap<ExtKey, ::serde_json::Value>) -> Self {
Self(value)
}
}
///`ExtKey`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ExtKey(::std::string::String);
impl ::std::ops::Deref for ExtKey {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ExtKey> for ::std::string::String {
fn from(value: ExtKey) -> Self {
value.0
}
}
impl ::std::str::FromStr for ExtKey {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new("^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$").unwrap()
});
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ExtKey {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///`Payload`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "$id": "https://trusttasks.org/spec/rooms/keys/chain/0.1",
/// "title": "Payload",
/// "type": "object",
/// "required": [
/// "links",
/// "roomId"
/// ],
/// "properties": {
/// "ext": {
/// "description": "Ecosystem-defined extension members per SPEC.md §4.5.1.",
/// "$ref": "#/definitions/Ext"
/// },
/// "links": {
/// "description": "The rungs, in any order. A recipient stores them and reports how far back it can now reach — see the response's `earliestReadableEpoch`.",
/// "type": "array",
/// "items": {
/// "$ref": "#/definitions/EpochLink"
/// },
/// "minItems": 1
/// },
/// "roomId": {
/// "description": "The room whose chain these rungs belong to. The recipient MUST hold group state for it, and MUST NOT create any on the strength of this request: rungs are inert without an epoch key, so accepting them for a room one is not in would retain key material for nothing.",
/// "type": "string"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Payload {
///Ecosystem-defined extension members per SPEC.md §4.5.1.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
///The rungs, in any order. A recipient stores them and reports how far back it can now reach — see the response's `earliestReadableEpoch`.
pub links: ::std::vec::Vec<EpochLink>,
///The room whose chain these rungs belong to. The recipient MUST hold group state for it, and MUST NOT create any on the strength of this request: rungs are inert without an epoch key, so accepting them for a room one is not in would retain key material for nothing.
#[serde(rename = "roomId")]
pub room_id: ::std::string::String,
}
impl Payload {
pub fn builder() -> builder::Payload {
Default::default()
}
}
///Success response to rooms/keys/chain. Type https://trusttasks.org/spec/rooms/keys/chain/0.1#response.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Response",
/// "description": "Success response to rooms/keys/chain. Type https://trusttasks.org/spec/rooms/keys/chain/0.1#response.",
/// "type": "object",
/// "required": [
/// "earliestReadableEpoch",
/// "roomId"
/// ],
/// "properties": {
/// "earliestReadableEpoch": {
/// "description": "The earliest epoch the recipient can now derive a key for, having walked the chain it holds. **This is the answer worth having**, and it is not a restatement of what was sent: a rung only extends reach if every rung above it is present too, so a caller that supplied a set with a gap in it learns that here rather than at the first record that will not open. `1` means the room's whole history is reachable.",
/// "type": "integer",
/// "minimum": 1.0
/// },
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// },
/// "roomId": {
/// "type": "string"
/// },
/// "stored": {
/// "description": "How many rungs the recipient did not already hold. Zero is a success, not a no-op: it means the caller's chain was already delivered, which is what a retry looks like.",
/// "type": "integer",
/// "minimum": 0.0
/// }
/// },
/// "additionalProperties": false,
/// "$anchor": "response"
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Response {
///The earliest epoch the recipient can now derive a key for, having walked the chain it holds. **This is the answer worth having**, and it is not a restatement of what was sent: a rung only extends reach if every rung above it is present too, so a caller that supplied a set with a gap in it learns that here rather than at the first record that will not open. `1` means the room's whole history is reachable.
#[serde(rename = "earliestReadableEpoch")]
pub earliest_readable_epoch: ::std::num::NonZeroU64,
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
#[serde(rename = "roomId")]
pub room_id: ::std::string::String,
///How many rungs the recipient did not already hold. Zero is a success, not a no-op: it means the caller's chain was already delivered, which is what a retry looks like.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub stored: ::std::option::Option<u64>,
}
impl Response {
pub fn builder() -> builder::Response {
Default::default()
}
}
/// Types for composing complex structures.
pub mod builder {
#[derive(Clone, Debug)]
pub struct EpochLink {
epoch: ::std::result::Result<i64, ::std::string::String>,
nonce: ::std::result::Result<::std::string::String, ::std::string::String>,
wrapped: ::std::result::Result<::std::string::String, ::std::string::String>,
}
impl ::std::default::Default for EpochLink {
fn default() -> Self {
Self {
epoch: Err("no value supplied for epoch".to_string()),
nonce: Err("no value supplied for nonce".to_string()),
wrapped: Err("no value supplied for wrapped".to_string()),
}
}
}
impl EpochLink {
pub fn epoch<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<i64>,
T::Error: ::std::fmt::Display,
{
self.epoch = value
.try_into()
.map_err(|e| format!("error converting supplied value for epoch: {e}"));
self
}
pub fn nonce<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::string::String>,
T::Error: ::std::fmt::Display,
{
self.nonce = value
.try_into()
.map_err(|e| format!("error converting supplied value for nonce: {e}"));
self
}
pub fn wrapped<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::string::String>,
T::Error: ::std::fmt::Display,
{
self.wrapped = value
.try_into()
.map_err(|e| format!("error converting supplied value for wrapped: {e}"));
self
}
}
impl ::std::convert::TryFrom<EpochLink> for super::EpochLink {
type Error = super::error::ConversionError;
fn try_from(
value: EpochLink,
) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
epoch: value.epoch?,
nonce: value.nonce?,
wrapped: value.wrapped?,
})
}
}
impl ::std::convert::From<super::EpochLink> for EpochLink {
fn from(value: super::EpochLink) -> Self {
Self {
epoch: Ok(value.epoch),
nonce: Ok(value.nonce),
wrapped: Ok(value.wrapped),
}
}
}
#[derive(Clone, Debug)]
pub struct Payload {
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
links: ::std::result::Result<::std::vec::Vec<super::EpochLink>, ::std::string::String>,
room_id: ::std::result::Result<::std::string::String, ::std::string::String>,
}
impl ::std::default::Default for Payload {
fn default() -> Self {
Self {
ext: Ok(Default::default()),
links: Err("no value supplied for links".to_string()),
room_id: Err("no value supplied for room_id".to_string()),
}
}
}
impl Payload {
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn links<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::vec::Vec<super::EpochLink>>,
T::Error: ::std::fmt::Display,
{
self.links = value
.try_into()
.map_err(|e| format!("error converting supplied value for links: {e}"));
self
}
pub fn room_id<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::string::String>,
T::Error: ::std::fmt::Display,
{
self.room_id = value
.try_into()
.map_err(|e| format!("error converting supplied value for room_id: {e}"));
self
}
}
impl ::std::convert::TryFrom<Payload> for super::Payload {
type Error = super::error::ConversionError;
fn try_from(value: Payload) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
ext: value.ext?,
links: value.links?,
room_id: value.room_id?,
})
}
}
impl ::std::convert::From<super::Payload> for Payload {
fn from(value: super::Payload) -> Self {
Self {
ext: Ok(value.ext),
links: Ok(value.links),
room_id: Ok(value.room_id),
}
}
}
#[derive(Clone, Debug)]
pub struct Response {
earliest_readable_epoch:
::std::result::Result<::std::num::NonZeroU64, ::std::string::String>,
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
room_id: ::std::result::Result<::std::string::String, ::std::string::String>,
stored: ::std::result::Result<::std::option::Option<u64>, ::std::string::String>,
}
impl ::std::default::Default for Response {
fn default() -> Self {
Self {
earliest_readable_epoch: Err(
"no value supplied for earliest_readable_epoch".to_string()
),
ext: Ok(Default::default()),
room_id: Err("no value supplied for room_id".to_string()),
stored: Ok(Default::default()),
}
}
}
impl Response {
pub fn earliest_readable_epoch<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::num::NonZeroU64>,
T::Error: ::std::fmt::Display,
{
self.earliest_readable_epoch = value.try_into().map_err(|e| {
format!("error converting supplied value for earliest_readable_epoch: {e}")
});
self
}
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn room_id<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::string::String>,
T::Error: ::std::fmt::Display,
{
self.room_id = value
.try_into()
.map_err(|e| format!("error converting supplied value for room_id: {e}"));
self
}
pub fn stored<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<u64>>,
T::Error: ::std::fmt::Display,
{
self.stored = value
.try_into()
.map_err(|e| format!("error converting supplied value for stored: {e}"));
self
}
}
impl ::std::convert::TryFrom<Response> for super::Response {
type Error = super::error::ConversionError;
fn try_from(value: Response) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
earliest_readable_epoch: value.earliest_readable_epoch?,
ext: value.ext?,
room_id: value.room_id?,
stored: value.stored?,
})
}
}
impl ::std::convert::From<super::Response> for Response {
fn from(value: super::Response) -> Self {
Self {
earliest_readable_epoch: Ok(value.earliest_readable_epoch),
ext: Ok(value.ext),
room_id: Ok(value.room_id),
stored: Ok(value.stored),
}
}
}
}
impl crate::Payload for Payload {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/rooms/keys/chain/0.1";
const IS_PROOF_REQUIRED: bool = true;
const IS_ISSUED_AT_REQUIRED: bool = true;
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"EpochLink\": {\n \"additionalProperties\": false,\n \"description\": \"One rung of a room's epoch key chain: the storage key of epoch `epoch - 1`, sealed under the storage key of `epoch`. A group key schedule offers no way to derive an earlier epoch's key from a later one — that property is what makes removing a member mean something — so without a chain the first membership change makes every record already in the room unopenable by everyone, including whoever wrote it. The chain is the one-way street run deliberately the other way: a member holding the current key walks it backwards to any retained epoch, and a member holding an earlier key still derives nothing later. Removal stays forward-only; reading stays possible. What a chain costs is stated where it is chosen, in the room's retention policy.\",\n \"properties\": {\n \"epoch\": {\n \"description\": \"The epoch whose storage key opens this link; it wraps the storage key of `epoch - 1`. Never 1: a room's first epoch has no predecessor, so a link claiming one wraps something that is not an earlier epoch's key.\",\n \"minimum\": 2,\n \"type\": \"integer\"\n },\n \"nonce\": {\n \"description\": \"AEAD nonce, base64url.\",\n \"type\": \"string\"\n },\n \"wrapped\": {\n \"description\": \"The wrapped predecessor key, base64url. Bound by AEAD associated data to `roomId` and to this link's own position in the chain, so a link lifted to another rung, or served under another room, fails to open rather than yielding a key that is wrong. The binding is load-bearing rather than decorative: every rung is a fixed-length key sealed under a fixed-length key, so nothing about the ciphertext itself says where it belongs.\",\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"epoch\",\n \"wrapped\",\n \"nonce\"\n ],\n \"title\": \"EpochLink\",\n \"type\": \"object\"\n },\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"description\": \"Success response to rooms/keys/chain. Type https://trusttasks.org/spec/rooms/keys/chain/0.1#response.\",\n \"properties\": {\n \"earliestReadableEpoch\": {\n \"description\": \"The earliest epoch the recipient can now derive a key for, having walked the chain it holds. **This is the answer worth having**, and it is not a restatement of what was sent: a rung only extends reach if every rung above it is present too, so a caller that supplied a set with a gap in it learns that here rather than at the first record that will not open. `1` means the room's whole history is reachable.\",\n \"minimum\": 1,\n \"type\": \"integer\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"roomId\": {\n \"type\": \"string\"\n },\n \"stored\": {\n \"description\": \"How many rungs the recipient did not already hold. Zero is a success, not a no-op: it means the caller's chain was already delivered, which is what a retry looks like.\",\n \"minimum\": 0,\n \"type\": \"integer\"\n }\n },\n \"required\": [\n \"roomId\",\n \"earliestReadableEpoch\"\n ],\n \"title\": \"Rooms Keys Chain — response payload\",\n \"type\": \"object\"\n }\n },\n \"$id\": \"https://trusttasks.org/spec/rooms/keys/chain/0.1\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\",\n \"additionalProperties\": false,\n \"properties\": {\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\",\n \"description\": \"Ecosystem-defined extension members per SPEC.md §4.5.1.\"\n },\n \"links\": {\n \"description\": \"The rungs, in any order. A recipient stores them and reports how far back it can now reach — see the response's `earliestReadableEpoch`.\",\n \"items\": {\n \"$ref\": \"#/$defs/EpochLink\"\n },\n \"minItems\": 1,\n \"type\": \"array\"\n },\n \"roomId\": {\n \"description\": \"The room whose chain these rungs belong to. The recipient MUST hold group state for it, and MUST NOT create any on the strength of this request: rungs are inert without an epoch key, so accepting them for a room one is not in would retain key material for nothing.\",\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"roomId\",\n \"links\"\n ],\n \"title\": \"Rooms Keys Chain — payload\",\n \"type\": \"object\"\n}\n",
);
}
impl crate::Payload for Response {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/rooms/keys/chain/0.1#response";
const IS_PROOF_REQUIRED: bool = true;
const IS_ISSUED_AT_REQUIRED: bool = true;
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"EpochLink\": {\n \"additionalProperties\": false,\n \"description\": \"One rung of a room's epoch key chain: the storage key of epoch `epoch - 1`, sealed under the storage key of `epoch`. A group key schedule offers no way to derive an earlier epoch's key from a later one — that property is what makes removing a member mean something — so without a chain the first membership change makes every record already in the room unopenable by everyone, including whoever wrote it. The chain is the one-way street run deliberately the other way: a member holding the current key walks it backwards to any retained epoch, and a member holding an earlier key still derives nothing later. Removal stays forward-only; reading stays possible. What a chain costs is stated where it is chosen, in the room's retention policy.\",\n \"properties\": {\n \"epoch\": {\n \"description\": \"The epoch whose storage key opens this link; it wraps the storage key of `epoch - 1`. Never 1: a room's first epoch has no predecessor, so a link claiming one wraps something that is not an earlier epoch's key.\",\n \"minimum\": 2,\n \"type\": \"integer\"\n },\n \"nonce\": {\n \"description\": \"AEAD nonce, base64url.\",\n \"type\": \"string\"\n },\n \"wrapped\": {\n \"description\": \"The wrapped predecessor key, base64url. Bound by AEAD associated data to `roomId` and to this link's own position in the chain, so a link lifted to another rung, or served under another room, fails to open rather than yielding a key that is wrong. The binding is load-bearing rather than decorative: every rung is a fixed-length key sealed under a fixed-length key, so nothing about the ciphertext itself says where it belongs.\",\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"epoch\",\n \"wrapped\",\n \"nonce\"\n ],\n \"title\": \"EpochLink\",\n \"type\": \"object\"\n },\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"description\": \"Success response to rooms/keys/chain. Type https://trusttasks.org/spec/rooms/keys/chain/0.1#response.\",\n \"properties\": {\n \"earliestReadableEpoch\": {\n \"description\": \"The earliest epoch the recipient can now derive a key for, having walked the chain it holds. **This is the answer worth having**, and it is not a restatement of what was sent: a rung only extends reach if every rung above it is present too, so a caller that supplied a set with a gap in it learns that here rather than at the first record that will not open. `1` means the room's whole history is reachable.\",\n \"minimum\": 1,\n \"type\": \"integer\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"roomId\": {\n \"type\": \"string\"\n },\n \"stored\": {\n \"description\": \"How many rungs the recipient did not already hold. Zero is a success, not a no-op: it means the caller's chain was already delivered, which is what a retry looks like.\",\n \"minimum\": 0,\n \"type\": \"integer\"\n }\n },\n \"required\": [\n \"roomId\",\n \"earliestReadableEpoch\"\n ],\n \"title\": \"Rooms Keys Chain — response payload\",\n \"type\": \"object\"\n }\n },\n \"$ref\": \"#/$defs/Response\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\"\n}\n",
);
}
impl crate::RequestPayload for Payload {
type Response = Response;
}
/// The extended error codes this specification declares (SPEC §7.3 item 9,
/// §8.5), in declaration order. Empty when it declares none.
pub const ERROR_CODES: &[crate::DeclaredErrorCode] = &[error_codes::NOT_A_MEMBER];
/// One constant per extended error code this specification declares
/// (SPEC §7.3 item 9), named for its local part.
///
/// Emit these rather than a string literal: the code is read from the
/// specification, so it cannot name a code the specification never
/// declared.
pub mod error_codes {
/// `rooms/keys/chain:notAMember`
///
/// The recipient holds no group state for this room, so there is nothing for the rungs to extend.
///
/// Declared `retryable: false`.
pub const NOT_A_MEMBER: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "rooms/keys/chain:notAMember",
retryable: false,
};
}
#[cfg(test)]
mod conformance {
//! Round-trip tests harvested from the spec's `spec.md`,
//! plus a `rejects_invalid_examples` test for any fixtures
//! in `payload.invalid-examples.json` (validate feature).
#[test]
fn request_example_1() {
const JSON: &str = "{\n \"id\": \"urn:uuid:00000000-0000-4000-8000-000000000001\",\n \"type\": \"https://trusttasks.org/spec/rooms/keys/chain/0.1#request\",\n \"issuer\": \"did:example:member\",\n \"recipient\": \"did:example:keyholder\",\n \"issuedAt\": \"2026-01-01T00:00:00Z\",\n \"threadId\": \"urn:uuid:00000000-0000-4000-8000-0000000000ff\",\n \"payload\": {\n \"roomId\": \"did:webvh:example.com:rooms:northwind\",\n \"links\": [\n { \"epoch\": 4, \"wrapped\": \"Lp3wXc9TgYw2mQnR4vBk8Q\", \"nonce\": \"c1Au9Rn3Zr2tWwS1\" },\n { \"epoch\": 3, \"wrapped\": \"Tf6yNb2VhZx5pRoS7wCl9Q\", \"nonce\": \"d2Bv0So4As3uXxT2\" },\n { \"epoch\": 2, \"wrapped\": \"Wq8zMd4XjBy7rTqU9yEn1Q\", \"nonce\": \"e3Cw1Tp5Bt4vYyU3\" }\n ]\n }\n}\n";
let doc: crate::TrustTask<super::Payload> =
serde_json::from_str(JSON).expect("deserialize request example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "request example failed round-trip");
}
#[test]
fn response_example_1() {
const JSON: &str = "{\n \"id\": \"urn:uuid:00000000-0000-4000-8000-000000000002\",\n \"type\": \"https://trusttasks.org/spec/rooms/keys/chain/0.1#response\",\n \"issuer\": \"did:example:keyholder\",\n \"recipient\": \"did:example:member\",\n \"issuedAt\": \"2026-01-01T00:00:01Z\",\n \"threadId\": \"urn:uuid:00000000-0000-4000-8000-0000000000ff\",\n \"payload\": {\n \"roomId\": \"did:webvh:example.com:rooms:northwind\",\n \"earliestReadableEpoch\": 1,\n \"stored\": 3\n }\n}\n";
let doc: crate::TrustTask<super::Response> =
serde_json::from_str(JSON).expect("deserialize response example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "response example failed round-trip");
}
/// Each fixture in `payload.invalid-examples.json` MUST be
/// rejected by at least one of: serde deserialization, or
/// JSON-Schema validation under the `validate` feature. The
/// fixture file documents the producer-side bug class that
/// each payload exemplifies; this generated test pins it.
#[cfg(feature = "validate")]
#[test]
fn rejects_invalid_examples() {
use crate::validate::ValidatedPayload;
let fixtures: &[(&str, &str)] = &[
(
"An empty links array. A delivery that carries no rungs asks the recipient to retain nothing and report on nothing; `minItems: 1` makes the caller say what they meant rather than receive a success that changed no state.",
"{\n \"links\": [],\n \"roomId\": \"did:webvh:example.com:rooms:northwind\"\n}",
),
(
"No links member at all. The rungs are the entire payload — a request without them is a request to do nothing, and there is no defaulting that would be honest.",
"{\n \"roomId\": \"did:webvh:example.com:rooms:northwind\"\n}",
),
(
"A rung claiming epoch 1. A room's first epoch has no predecessor, so rung 1 wraps something that is not an earlier epoch's key; EpochLink's floor of 2 refuses it before it can be stored as a rung that silently ends the walk.",
"{\n \"links\": [\n {\n \"epoch\": 1,\n \"nonce\": \"b0Zt8Qm2Yq1sVvR0\",\n \"wrapped\": \"9jK2_QhV1sVvR0m5xAqZ7A\"\n }\n ],\n \"roomId\": \"did:webvh:example.com:rooms:northwind\"\n}",
),
(
"A rung with no wrapped key. The nonce alone is not a rung; storing one would extend the chain's length without extending its reach, which is the shape of a gap that looks like a delivery.",
"{\n \"links\": [\n {\n \"epoch\": 3,\n \"nonce\": \"b0Zt8Qm2Yq1sVvR0\"\n }\n ],\n \"roomId\": \"did:webvh:example.com:rooms:northwind\"\n}",
),
(
"An unknown member inside a rung — additionalProperties: false on EpochLink. A rung carries wrapped key material and nothing descriptive; an extra member is the obvious place to leak what the sealing exists to hide.",
"{\n \"links\": [\n {\n \"epoch\": 3,\n \"joinedAt\": \"2026-01-01T00:00:00Z\",\n \"nonce\": \"b0Zt8Qm2Yq1sVvR0\",\n \"wrapped\": \"9jK2_QhV1sVvR0m5xAqZ7A\"\n }\n ],\n \"roomId\": \"did:webvh:example.com:rooms:northwind\"\n}",
),
(
"Bare/unnamespaced ext key — SPEC §4.5.1 requires every immediate child of ext to be reverse-DNS namespaced.",
"{\n \"ext\": {\n \"bare-key\": {\n \"anything\": \"here\"\n }\n },\n \"links\": [\n {\n \"epoch\": 2,\n \"nonce\": \"b0Zt8Qm2Yq1sVvR0\",\n \"wrapped\": \"9jK2_QhV1sVvR0m5xAqZ7A\"\n }\n ],\n \"roomId\": \"did:webvh:example.com:rooms:northwind\"\n}",
),
];
for (i, (note, raw)) in fixtures.iter().enumerate() {
let value: serde_json::Value = match serde_json::from_str(raw) {
Ok(v) => v,
Err(_) => continue,
};
let serde_ok = serde_json::from_value::<super::Payload>(value.clone()).is_ok();
let schema_ok = super::Payload::validate_value(&value).is_ok();
assert!(
!(serde_ok && schema_ok),
"invalid-example #{} ({:?}) was accepted by both serde and JSON Schema; \
the fixture's stated failure class is no longer caught:\n{}",
i + 1,
note,
raw
);
}
}
}