codec_cbor/lib.rs
1// SPDX-FileCopyrightText: Copyright © 2026 ReallyMe LLC. All rights reserved
2//
3// SPDX-License-Identifier: Apache-2.0
4
5//! Deterministic DAG-CBOR codec for authoritative, cryptographically
6//! signed data.
7//!
8//! The decoder is strict by construction: it rejects non-canonical
9//! integers, indefinite-length items, floats, tags, out-of-order map keys,
10//! and trailing bytes, so a given value has exactly one accepted encoding.
11//! Decoding untrusted input is bounded in input size, memory, and stack
12//! depth — container length prefixes are checked against the remaining input
13//! before any allocation, and nesting is capped at [`MAX_NESTING_DEPTH`] — so
14//! neither a crafted length nor pathological nesting can drive an
15//! out-of-memory or stack-overflow abort.
16
17mod cid;
18mod decode_dag_cbor;
19mod decode_deterministic_cbor;
20mod deterministic;
21mod encode_dag_cbor;
22mod encode_deterministic_cbor;
23mod error;
24mod value;
25
26/// Maximum array/map nesting depth accepted by [`decode_dag_cbor`].
27///
28/// Authoritative documents in this system are shallow; this bound is far
29/// above any legitimate structure while still stopping a hostile input
30/// from recursing the decoder into a stack overflow.
31pub const MAX_NESTING_DEPTH: usize = 128;
32
33/// Maximum encoded DAG-CBOR byte length accepted at public decode/hash
34/// boundaries.
35///
36/// This is a defense-in-depth bound for authoritative signed documents. It is
37/// intentionally much larger than expected production payloads while keeping
38/// parser, hash, and allocation work predictable under hostile input.
39pub const MAX_DAG_CBOR_INPUT_LEN: usize = 1024 * 1024;
40
41pub use cid::{
42 compute_cid_dag_cbor, dag_cbor_multihash, is_valid_cid_string, sha2_256_content_hash,
43 try_parse_cid, verify_dag_cbor_cid, ContentHash, DagCborMultihash, DAG_CBOR_CODEC,
44};
45pub use decode_dag_cbor::decode_dag_cbor;
46pub use decode_deterministic_cbor::decode_deterministic_cbor;
47pub use deterministic::{
48 DeterministicCborError, DeterministicCborInteger, DeterministicCborMapEntry,
49 DeterministicCborMapKey, DeterministicCborNegativeInteger, DeterministicCborProfileError,
50 DeterministicCborValue, DETERMINISTIC_CBOR_NEGATIVE_MAX, DETERMINISTIC_CBOR_NEGATIVE_MIN,
51 MAX_DETERMINISTIC_CBOR_AGGREGATE_BYTE_STRING_BYTES,
52 MAX_DETERMINISTIC_CBOR_AGGREGATE_TEXT_BYTES, MAX_DETERMINISTIC_CBOR_CONTAINER_ENTRIES,
53 MAX_DETERMINISTIC_CBOR_INPUT_LEN, MAX_DETERMINISTIC_CBOR_NESTING_DEPTH,
54 MAX_DETERMINISTIC_CBOR_NODES, MAX_DETERMINISTIC_CBOR_OUTPUT_LEN,
55};
56pub use encode_dag_cbor::encode_dag_cbor;
57pub use encode_deterministic_cbor::encode_deterministic_cbor;
58pub use error::CborError;
59pub use value::CborValue;