Expand description
Canonical-tree witnesses for sparse checkout (SPEC-SPARSE-CHECKOUT v2).
A witness carries complete metadata for one tree. The verifier binds it to an independently trusted object ID and derives the selected entries locally. Directory entries authenticate child IDs; recursive consumers must verify a witness for every selected child before declaring the traversal complete.
Structs§
- Sparse
Manifest - Sparse
Proof - Sparse
Response - Verified
Sparse Tree - Locally derived selection after witness and requested-context verification.
Enums§
Constants§
- MAX_
FILTER_ BYTES - MAX_
FILTER_ PATHS - MAX_
LEAVES - SPARSE_
CACHE_ DIR - SPARSE_
CACHE_ MAGIC - SPARSE_
CACHE_ VERSION - SPARSE_
WIRE_ MAGIC - SPARSE_
WIRE_ MAX_ BYTES - SPARSE_
WIRE_ VERSION
Functions§
- build_
sparse - decode_
sparse_ cache - decode_
sparse_ response - encode_
sparse_ cache - encode_
sparse_ response - The wire contains only the root, filter commitment and full tree witness.
Delivered entries are derived from that witness by
verify_sparseconsumers. - hash_
filter - tree_
hash - validate_
filter - Filters are UTF-8 repository-relative literal path prefixes.
.selects everything; an empty list selects nothing. Negation and globbing require the authenticated full-metadata fallback, never an approximate sparse filter. - verify_
sparse - Authenticate the witness against the requested root and filter, then derive the complete selection locally. No server-selected list is accepted.
- verify_
sparse_ hierarchy - Verify an entire selected hierarchy. Missing selected child witnesses fail; ancestors are followed using only IDs authenticated by their parent tree. Limits bound aggregate witness bytes, traversal count and path depth.