Expand description
Offline device enrollment, trust bundles, and generation-bound proof.
Discovery remains deliberately untrusted. LAN, BLE, QR, and USB adapters
may report candidates, but only these signed facts can authorize an offline
device. The normal Client peer-session actor remains the sole owner of
dialing, transport generations, and application-route readiness.
Structs§
- Durable
Offline Trust State - Native, restart-safe trust journal. The bundle journal is written before a separate high-water anchor so a crash can advance but never silently roll back accepted trust. Hosts facing malicious whole-disk rollback should put the anchor path on platform anti-rollback storage.
- Offline
Admission - Offline
Admission Handoff - Opaque proof verdict consumed by the existing Rust admission owner.
- Offline
Candidate Handoff - Trust-validated local reachability input. It is not a dial command and it is not an admission verdict. Only the existing Rust peer actor may turn it into a transport attempt.
- Offline
Client - Offline
Connection Proof - Offline
Device Credential - Offline
Device Credential Body - Offline
Enrollment Body - Offline
Enrollment Options - Offline
Enrollment Request - Offline
Proof Transcript - Offline
Replay Cache - Bounded replay owner. One instance belongs to the Rust admission owner.
- Offline
Runtime Config - Native-only runtime inputs retained by the Rust owner while offline LAN discovery and admission are enabled.
- Offline
Transport Binding - Exact local physical generation to which a fresh offline proof is bound.
- Offline
Trust Bundle - Offline
Trust Bundle Body - Offline
Trust High Water - Offline
Trust State - Persist this value atomically after
OfflineTrustState::applysucceeds. - Software
Offline Signer - Software profile for Rust-native devices without a hardware signer.
Enums§
- Offline
Assurance - Truthful strength of the target-owned proof key.
Constants§
- MAX_
OFFLINE_ CREDENTIALS - MAX_
OFFLINE_ REPLAY_ ENTRIES - MAX_
OFFLINE_ REVOKED_ SERIALS - MAX_
OFFLINE_ ROLES - MAX_
OFFLINE_ SWARM_ DEGREE - MAX_
OFFLINE_ SWARM_ MEMBERS - MAX_
OFFLINE_ TRUST_ HISTORY - OFFLINE_
DEVICE_ PROTOCOL - OFFLINE_
PROOF_ PROTOCOL - OFFLINE_
TRUST_ BUNDLE_ PROTOCOL
Traits§
- Offline
Signer - Sign-only boundary used by app-private or hardware-backed storage.
Functions§
- bounded_
swarm_ neighbors - Deterministic bounded-neighbor intent for a signed offline member set.