Expand description
Native source downloads retain original Thread identities and causal proofs. Pack chunks are staging bytes: install only after the verified Complete frame.
Structs§
- Download
- Limits
- Owned
Device Binding - Current endpoint possession under independently retained account authority. Retain the original credential privately; it never joins source proof packs.
- Provider
Candidate - An unsigned offer bound to the authenticated issuer, client, and exact selected source. It grants no provider read until final ticket admission.
- Provider
Download - An authenticated Fetch exchange whose request half remains open for exact consent and the final verified result. Dropping it aborts both halves.
- Provider
Plan Session - Only an issued plan matching the signed candidate can reach this stage.
- Staged
Source - Verified source artifacts and their original proofs. Dropping this value removes its temporary files. Native callers can install it on a disk worker.
- Validated
Source Artifacts - Structurally verified original source and actual artifact closure. This is not an author, audience, executor, or sharing-policy admission decision.
Enums§
- Error
- Item
- Each item has passed its frame, scope and cryptographic checks. An operation can still have missing causal parents; the durable replica decides admission.
- Provider
Fetch - The issuer may explicitly select ordinary direct source delivery when a preferred provider transfer cannot be offered. Only the admitted Ready decides the branch; an arbitrary stream error never triggers a retry.
Traits§
- Provider
Consent Signer - Implemented by the same credential that signed the Fetch opening. The server verifies this identity against its authenticated Biscuit subject and requires the signature key to equal the credential’s terminal cnf key.