Skip to main content

Crate vgi_core

Crate vgi_core 

Source
Expand description

Shared primitives for Verifiable Git Infrastructure (VGI).

Pure, dependency-light building blocks that both the signer (did-git-sign) and the CI verifier (verify-trust) rely on, kept in one crate so their wire formats cannot drift:

Nothing here touches the network, a keyring, or a VTA — that is what lets the CI verifier stay a small, fast dependency.

Re-exports§

pub use resource::ResourceError;
pub use resource::ResourceErrorKind;
pub use resource::normalize_resource;
pub use resource::normalize_resource_with_depth;
pub use resource::resource_contains;

Modules§

resource
Forge-qualified trust-tuple resources.

Constants§

ED25519_MULTICODEC_PREFIX
Multicodec prefix for an Ed25519 public key in publicKeyMultibase.
GIT_SSHSIG_NAMESPACE
The sshsig namespace git uses for commit and tag signatures.

Functions§

assemble_ssh_signature
Armor a signature made elsewhere — by a VTA that holds the key — as an SSHSIG signature over message.
committer_did
The signer DID a commit claims: its committer identity when that is a DID, reduced to the bare DID.
committer_identity
The committer identity: the <…> field of the committer header.
conflicting_signer_dids
Return both explicit identity claims when the final Signed-by-DID: trailer and legacy DID committer identity disagree.
create_ssh_signature
Create an armored SSH signature following the PROTOCOL.sshsig format, signing locally with signing_key: sshsig_signed_data over the SHA-512 of message, wrapped as [armor_ssh_signature] describes.
ed25519_signing_keys_from_doc
Extract the Ed25519 public keys a DID document authorizes for signing: the methods its assertionMethod relationship lists (publicKeyMultibase, multicodec 0xED01).
messaging_mediator
The mediator a DID document is reached through: the DID endpoint of its TSPTransport service, else of its DIDCommMessaging service. None when neither names a DID (an https DIDComm endpoint is the subject itself, not a mediator).
normalize_sshsig_armor
Re-wrap an sshsig armor’s base64 body at 70 columns.
registry_referral
The registry DID a DID document refers to: a service whose type is (or includes) TrustRegistry and whose endpoint uri is a DID. An https endpoint is a registry serving TRQP, not a referral, and is not taken.
signer_did
The signer DID a commit claims, checking the Signed-by-DID: trailer first, then falling back to the committer email for legacy commits.
split_signed_commit
Split a raw commit object into (payload-as-signed, armored signature).
sshsig_message_hash
H(message) for an SSHSIG signature: SHA-512, the hash git and ssh-keygen -Y sign use.
sshsig_signed_data
The bytes an SSHSIG signature is made over, for a SHA-512 message_hash (PROTOCOL.sshsig §4):