Skip to main content

TimelineOriginEndorsement

Struct TimelineOriginEndorsement 

Source
pub struct TimelineOriginEndorsement {
    pub deployment_public_key: Vec<u8>,
    pub spool_id: String,
    pub thread_id: Vec<u8>,
    pub run_id: String,
    pub principal_id: String,
    pub credential_class: i32,
    pub effective_pop_key_sha256: Vec<u8>,
    pub credential_identity: Option<TimelineOriginCredentialIdentity>,
    pub uploader_device_public_key: Vec<u8>,
    pub signature: Vec<u8>,
}
Expand description

The active origin credential signs this exact transcript with Ed25519: UTF8(“heddle-timeline-run-origin-v3”) || 0x00, then, in field order below, each byte/string field as u32be(byte_length) || its exact bytes; class is one unsigned byte (1 or 2). Credential identity is one tag byte followed by counted IDs: 0x01 || counted(credential_id) for server_issued, or 0x02 || counted(issued_ancestor_credential_id) || counted(terminal_revocation_id) || counted(derivation_path_sha256) for offline_derived. UUIDs are 36 lowercase ASCII bytes in canonical hyphenated form. The signature itself is excluded. No protobuf serialization, client timestamp or hash of a reconstructed RunRecord is a signing input. For offline_derived, Weft verifies the COMPLETE chain from the exact named Weft-issued ancestor authority block through the terminal block, with at least one attenuation block. Every Biscuit block, including the authority, MUST use signature-v1. Each attenuation signature covers the preceding block signature. Reject any chain containing a signature-v0 block. Verify the complete chain, attenuation and lineage against the issued ancestor, then derive revocation IDs from every block in order, including the authority and terminal blocks. Each is the 64 raw signature bytes from Biscuit::revocation_identifiers(). Compute derivation_path_sha256 as SHA-256(UTF8(“heddle-timeline-derivation-path-v1”) || 0x00 || u32be(N) || ID[0] || … || ID[N-1]), where N >= 2 and IDs are exactly 64 bytes. Each signature-v1 attenuation block binds to its predecessor, and the complete ordered signature list commits to the entire path. Require the computed path digest and terminal ID to equal the signed identity; match SHA-256(final effective PoP public key) to the signed key digest, then verify the endorsement with that effective public key. The ancestor ID alone never authenticates the agent. Reject a wrong root, path, terminal ID or key. An exact pre-expiry registration may supply the stored VERIFIED chain binding and original effective public key when the chain is absent from an upload. Otherwise the complete chain is required, including with fresh acceptance or a receipt retry. Fresh acceptance may override original expiry or revocation only for ADMISSION; it never skips lineage, path/key recomputation, signature verification, or original public-key resolution. A live-chain admission requires the chain to be live, unexpired and unrevoked. Registration stores the full revocation set; later revocation invalidates its admission basis.

Fields§

§deployment_public_key: Vec<u8>

Weft deployment public identity, exactly 32 bytes; not a replica key.

§spool_id: String

Canonical Spool UUID; must match thread.spool and run.spool.

§thread_id: Vec<u8>

Exact ThreadId.value, 32 bytes.

§run_id: String

ASCII [A-Za-z0-9_-]{1,128}.

§principal_id: String

Server-verified run-principal canonical account UUID.

§credential_class: i32§effective_pop_key_sha256: Vec<u8>

SHA-256 of the final effective PoP public key, exactly 32 bytes.

§credential_identity: Option<TimelineOriginCredentialIdentity>§uploader_device_public_key: Vec<u8>

Exact enrolled or paired uploader device proof key, 32 bytes.

§signature: Vec<u8>

Ed25519 signature by the verified origin credential, exactly 64 bytes.

Implementations§

Source§

impl TimelineOriginEndorsement

Source

pub fn credential_class(&self) -> TimelineOriginCredentialClass

Returns the enum value of credential_class, or the default if the field is set to an invalid enum value.

Source

pub fn set_credential_class(&mut self, value: TimelineOriginCredentialClass)

Sets credential_class to the provided enum value.

Trait Implementations§

Source§

impl Clone for TimelineOriginEndorsement

Source§

fn clone(&self) -> TimelineOriginEndorsement

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for TimelineOriginEndorsement

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result<(), Error>

Formats the value using the given formatter. Read more
Source§

impl Default for TimelineOriginEndorsement

Source§

fn default() -> TimelineOriginEndorsement

Returns the “default value” for a type. Read more
Source§

impl Eq for TimelineOriginEndorsement

Source§

impl Hash for TimelineOriginEndorsement

Source§

fn hash<__H>(&self, state: &mut __H)
where __H: Hasher,

Feeds this value into the given Hasher. Read more
1.3.0 · Source§

fn hash_slice<H>(data: &[Self], state: &mut H)
where H: Hasher, Self: Sized,

Feeds a slice of this type into the given Hasher. Read more
Source§

impl Message for TimelineOriginEndorsement

Source§

fn encoded_len(&self) -> usize

Returns the encoded length of the message without a length delimiter.
Source§

fn clear(&mut self)

Clears the message, resetting all fields to their default.
Source§

fn encode(&self, buf: &mut impl BufMut) -> Result<(), EncodeError>
where Self: Sized,

Encodes the message to a buffer. Read more
Source§

fn encode_to_vec(&self) -> Vec<u8> ⓘ
where Self: Sized,

Encodes the message to a newly allocated buffer.
Source§

fn encode_length_delimited( &self, buf: &mut impl BufMut, ) -> Result<(), EncodeError>
where Self: Sized,

Encodes the message with a length-delimiter to a buffer. Read more
Source§

fn encode_length_delimited_to_vec(&self) -> Vec<u8> ⓘ
where Self: Sized,

Encodes the message with a length-delimiter to a newly allocated buffer.
Source§

fn decode(buf: impl Buf) -> Result<Self, DecodeError>
where Self: Default,

Decodes an instance of the message from a buffer. Read more
Source§

fn decode_length_delimited(buf: impl Buf) -> Result<Self, DecodeError>
where Self: Default,

Decodes a length-delimited instance of the message from the buffer.
Source§

fn merge(&mut self, buf: impl Buf) -> Result<(), DecodeError>
where Self: Sized,

Decodes an instance of the message from a buffer, and merges it into self. Read more
Source§

fn merge_length_delimited(&mut self, buf: impl Buf) -> Result<(), DecodeError>
where Self: Sized,

Decodes a length-delimited instance of the message from buffer, and merges it into self.
Source§

impl PartialEq for TimelineOriginEndorsement

Source§

fn eq(&self, other: &TimelineOriginEndorsement) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for TimelineOriginEndorsement

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more