codec_cbor/lib.rs
1// SPDX-FileCopyrightText: Copyright © 2026 ReallyMe LLC. All rights reserved
2//
3// SPDX-License-Identifier: Apache-2.0
4
5//! Deterministic DAG-CBOR codec for authoritative, cryptographically
6//! signed data.
7//!
8//! The decoder is strict by construction: it rejects non-canonical
9//! integers, indefinite-length items, floats, tags, out-of-order map keys,
10//! and trailing bytes, so a given value has exactly one accepted encoding.
11//! Decoding untrusted input is bounded in input size, memory, and stack
12//! depth — container length prefixes are checked against the remaining input
13//! before any allocation, and nesting is capped at [`MAX_NESTING_DEPTH`] — so
14//! neither a crafted length nor pathological nesting can drive an
15//! out-of-memory or stack-overflow abort.
16
17mod cid;
18mod decode_dag_cbor;
19mod encode_dag_cbor;
20mod error;
21mod value;
22
23/// Maximum array/map nesting depth accepted by [`decode_dag_cbor`].
24///
25/// Authoritative documents in this system are shallow; this bound is far
26/// above any legitimate structure while still stopping a hostile input
27/// from recursing the decoder into a stack overflow.
28pub const MAX_NESTING_DEPTH: usize = 128;
29
30/// Maximum encoded DAG-CBOR byte length accepted at public decode/hash
31/// boundaries.
32///
33/// This is a defense-in-depth bound for authoritative signed documents. It is
34/// intentionally much larger than expected production payloads while keeping
35/// parser, hash, and allocation work predictable under hostile input.
36pub const MAX_DAG_CBOR_INPUT_LEN: usize = 1024 * 1024;
37
38pub use cid::{
39 compute_cid_dag_cbor, dag_cbor_multihash, is_valid_cid_string, sha2_256_content_hash,
40 try_parse_cid, verify_dag_cbor_cid, ContentHash, DagCborMultihash, DAG_CBOR_CODEC,
41};
42pub use decode_dag_cbor::decode_dag_cbor;
43pub use encode_dag_cbor::encode_dag_cbor;
44pub use error::CborError;
45pub use value::CborValue;