pub struct TimelineAdmissionAcceptance {
pub origin_sha256: Vec<u8>,
pub uploader_device_public_key: Vec<u8>,
pub deployment_public_key: Vec<u8>,
pub request_sha256: Vec<u8>,
pub first_position: u64,
pub event_count: u32,
pub signature: Vec<u8>,
pub authority: Option<Authority>,
}Expand description
A current direct-human run-principal authority or a current format-3
OwnerAuthorizationBundle (owner_records.proto) with an
ACCEPT_TIMELINE_ORIGIN grant signs this exact acceptance:
UTF8(“heddle-timeline-run-acceptance-v1”) || 0x00 followed by fields 1..6
below, then one authority byte (1 for principal credential, 2 for owner
capability) and counted(exact authority bytes). Byte fields use
u32be(length)||bytes, uint64 fields use u64be, and event_count uses u32be.
The signature and transport PoP are excluded. The original digest is
SHA-256 of the origin transcript plus
its 64-byte signature. The request digest is SHA-256 of:
UTF8(“heddle-timeline-upload-v1”) || 0x00 || counted(client_operation_id)
|| counted(spool UUID) || counted(ThreadId.value) || counted(run ID)
|| u32be(canonicalization_version) || u64be(run_revision)
|| one byte snapshot presence || [u32be(state)||counted(harness) if present]
|| u32be(event count), then for each event in wire order:
u64be(position)||u32be(kind)||i64be(recorded_at.seconds)
||u32be(recorded_at.nanos)||one byte tool presence
|| [u32be(tool) if present]
|| counted(origin SHA-256) || u64be(first_position).
counted means u32be(byte_length)||exact bytes; presence is 0 or 1. The
acceptance, its authority selector and transport PoP are excluded. Unknown
fields are invalid. This layout is independent of protobuf serialization.
An acceptance is valid only for this exact digest and position range.
For principal_credential_id, Weft resolves the exact ID in its current
credential registry, verifies a live independent root or server-issued
direct-human session/pairing chain, and uses that chain’s final effective
Ed25519 PoP key for this signature. Its account MUST be the origin’s verified
principal. Agent labels, account claims and uploader credentials do not
confer acceptance permission.
For owner_derived_capability, the bytes are a protobuf wire encoding of
OwnerAuthorizationBundle, at most 4096 bytes. Decode the complete bundle,
rejecting unknown fields and trailing bytes. Verify its owner root and
transition history against the independently pinned CURRENT owner state of
the run-principal account; OwnerRoot.account_uuid MUST equal the verified
principal UUID (never accept a state supplied only by this bundle). Then
verify the single format-3 capability and subject Biscuit. The grant’s exact
Spool selector, Thread ID, original principal UUID, credential class,
original credential identity variant and values, effective key digest and
signed origin SHA-256 MUST equal the verified origin. The leaf
CapabilityPrincipal.key is the effective
Ed25519 signing key for this acceptance. SignedOwnerCapability.signature
signer_key_id instead resolves to the owner issuer key through the accepted
owner transition at issuer_state_hash and its live rotation/recovery signing
window; reject an obsolete, vetoed or uncommitted issuer state. The subject
signs this acceptance transcript with its effective key, not the
owner key or the uploader key. Recheck capability validity interval,
direct-only/single-block attenuation restriction, active owner
transitions/recovery windows, every credential and capability revocation,
and the subject proof at the admission transaction.
No v1 PURGE grant, generic grant envelope, passkey certificate alone, or
owner/admin status authorizes acceptance. The acceptance bytes do not replace
the uploader’s independent Tier-1 transport proof.
Fields§
§origin_sha256: Vec<u8>Exactly 32 bytes.
uploader_device_public_key: Vec<u8>Exactly 32 bytes.
deployment_public_key: Vec<u8>Exactly 32 bytes.
request_sha256: Vec<u8>Exactly 32 bytes.
first_position: u640..2^63-1.
event_count: u320..64.
signature: Vec<u8>Ed25519, exactly 64 bytes.
Exactly one current authority route; credential IDs are 1..128 bytes and owner-derived capability bundles are at most 4096 bytes.
Trait Implementations§
Source§impl Clone for TimelineAdmissionAcceptance
impl Clone for TimelineAdmissionAcceptance
Source§fn clone(&self) -> TimelineAdmissionAcceptance
fn clone(&self) -> TimelineAdmissionAcceptance
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for TimelineAdmissionAcceptance
impl Debug for TimelineAdmissionAcceptance
Source§impl Default for TimelineAdmissionAcceptance
impl Default for TimelineAdmissionAcceptance
Source§fn default() -> TimelineAdmissionAcceptance
fn default() -> TimelineAdmissionAcceptance
impl Eq for TimelineAdmissionAcceptance
Source§impl Hash for TimelineAdmissionAcceptance
impl Hash for TimelineAdmissionAcceptance
Source§impl Message for TimelineAdmissionAcceptance
impl Message for TimelineAdmissionAcceptance
Source§fn encoded_len(&self) -> usize
fn encoded_len(&self) -> usize
Source§fn encode(&self, buf: &mut impl BufMut) -> Result<(), EncodeError>where
Self: Sized,
fn encode(&self, buf: &mut impl BufMut) -> Result<(), EncodeError>where
Self: Sized,
Source§fn encode_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
fn encode_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
Source§fn encode_length_delimited(
&self,
buf: &mut impl BufMut,
) -> Result<(), EncodeError>where
Self: Sized,
fn encode_length_delimited(
&self,
buf: &mut impl BufMut,
) -> Result<(), EncodeError>where
Self: Sized,
Source§fn encode_length_delimited_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
fn encode_length_delimited_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
Source§fn decode(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
fn decode(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
Source§fn decode_length_delimited(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
fn decode_length_delimited(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
Source§fn merge(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
fn merge(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
self. Read moreSource§fn merge_length_delimited(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
fn merge_length_delimited(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
self.impl StructuralPartialEq for TimelineAdmissionAcceptance
Auto Trait Implementations§
impl Freeze for TimelineAdmissionAcceptance
impl RefUnwindSafe for TimelineAdmissionAcceptance
impl Send for TimelineAdmissionAcceptance
impl Sync for TimelineAdmissionAcceptance
impl Unpin for TimelineAdmissionAcceptance
impl UnsafeUnpin for TimelineAdmissionAcceptance
impl UnwindSafe for TimelineAdmissionAcceptance
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more