pub struct TimelineOriginEndorsement {
pub deployment_public_key: Vec<u8>,
pub spool_id: String,
pub thread_id: Vec<u8>,
pub run_id: String,
pub principal_id: String,
pub credential_class: i32,
pub effective_pop_key_sha256: Vec<u8>,
pub credential_identity: Option<TimelineOriginCredentialIdentity>,
pub uploader_device_public_key: Vec<u8>,
pub signature: Vec<u8>,
}Expand description
The active origin credential signs this exact transcript with Ed25519: UTF8(“heddle-timeline-run-origin-v3”) || 0x00, then, in field order below, each byte/string field as u32be(byte_length) || its exact bytes; class is one unsigned byte (1 or 2). Credential identity is one tag byte followed by counted IDs: 0x01 || counted(credential_id) for server_issued, or 0x02 || counted(issued_ancestor_credential_id) || counted(terminal_revocation_id) || counted(derivation_path_sha256) for offline_derived. UUIDs are 36 lowercase ASCII bytes in canonical hyphenated form. The signature itself is excluded. No protobuf serialization, client timestamp or hash of a reconstructed RunRecord is a signing input. For offline_derived, Weft verifies the COMPLETE chain from the exact named Weft-issued ancestor authority block through the terminal block, with at least one attenuation block. Every Biscuit block, including the authority, MUST use signature-v1. Each attenuation signature covers the preceding block signature. Reject any chain containing a signature-v0 block. Verify the complete chain, attenuation and lineage against the issued ancestor, then derive revocation IDs from every block in order, including the authority and terminal blocks. Each is the 64 raw signature bytes from Biscuit::revocation_identifiers(). Compute derivation_path_sha256 as SHA-256(UTF8(“heddle-timeline-derivation-path-v1”) || 0x00 || u32be(N) || ID[0] || … || ID[N-1]), where N >= 2 and IDs are exactly 64 bytes. Each signature-v1 attenuation block binds to its predecessor, and the complete ordered signature list commits to the entire path. Require the computed path digest and terminal ID to equal the signed identity; match SHA-256(final effective PoP public key) to the signed key digest, then verify the endorsement with that effective public key. The ancestor ID alone never authenticates the agent. Reject a wrong root, path, terminal ID or key. An exact pre-expiry registration may supply the stored VERIFIED chain binding and original effective public key when the chain is absent from an upload. Otherwise the complete chain is required, including with fresh acceptance or a receipt retry. Fresh acceptance may override original expiry or revocation only for ADMISSION; it never skips lineage, path/key recomputation, signature verification, or original public-key resolution. A live-chain admission requires the chain to be live, unexpired and unrevoked. Registration stores the full revocation set; later revocation invalidates its admission basis.
Fields§
§deployment_public_key: Vec<u8>Weft deployment public identity, exactly 32 bytes; not a replica key.
spool_id: StringCanonical Spool UUID; must match thread.spool and run.spool.
thread_id: Vec<u8>Exact ThreadId.value, 32 bytes.
run_id: StringASCII [A-Za-z0-9_-]{1,128}.
principal_id: StringServer-verified run-principal canonical account UUID.
credential_class: i32§effective_pop_key_sha256: Vec<u8>SHA-256 of the final effective PoP public key, exactly 32 bytes.
credential_identity: Option<TimelineOriginCredentialIdentity>§uploader_device_public_key: Vec<u8>Exact enrolled or paired uploader device proof key, 32 bytes.
signature: Vec<u8>Ed25519 signature by the verified origin credential, exactly 64 bytes.
Implementations§
Source§impl TimelineOriginEndorsement
impl TimelineOriginEndorsement
Sourcepub fn credential_class(&self) -> TimelineOriginCredentialClass
pub fn credential_class(&self) -> TimelineOriginCredentialClass
Returns the enum value of credential_class, or the default if the field is set to an invalid enum value.
Sourcepub fn set_credential_class(&mut self, value: TimelineOriginCredentialClass)
pub fn set_credential_class(&mut self, value: TimelineOriginCredentialClass)
Sets credential_class to the provided enum value.
Trait Implementations§
Source§impl Clone for TimelineOriginEndorsement
impl Clone for TimelineOriginEndorsement
Source§fn clone(&self) -> TimelineOriginEndorsement
fn clone(&self) -> TimelineOriginEndorsement
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for TimelineOriginEndorsement
impl Debug for TimelineOriginEndorsement
Source§impl Default for TimelineOriginEndorsement
impl Default for TimelineOriginEndorsement
Source§fn default() -> TimelineOriginEndorsement
fn default() -> TimelineOriginEndorsement
impl Eq for TimelineOriginEndorsement
Source§impl Hash for TimelineOriginEndorsement
impl Hash for TimelineOriginEndorsement
Source§impl Message for TimelineOriginEndorsement
impl Message for TimelineOriginEndorsement
Source§fn encoded_len(&self) -> usize
fn encoded_len(&self) -> usize
Source§fn encode(&self, buf: &mut impl BufMut) -> Result<(), EncodeError>where
Self: Sized,
fn encode(&self, buf: &mut impl BufMut) -> Result<(), EncodeError>where
Self: Sized,
Source§fn encode_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
fn encode_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
Source§fn encode_length_delimited(
&self,
buf: &mut impl BufMut,
) -> Result<(), EncodeError>where
Self: Sized,
fn encode_length_delimited(
&self,
buf: &mut impl BufMut,
) -> Result<(), EncodeError>where
Self: Sized,
Source§fn encode_length_delimited_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
fn encode_length_delimited_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
Source§fn decode(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
fn decode(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
Source§fn decode_length_delimited(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
fn decode_length_delimited(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
Source§fn merge(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
fn merge(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
self. Read moreSource§fn merge_length_delimited(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
fn merge_length_delimited(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
self.impl StructuralPartialEq for TimelineOriginEndorsement
Auto Trait Implementations§
impl Freeze for TimelineOriginEndorsement
impl RefUnwindSafe for TimelineOriginEndorsement
impl Send for TimelineOriginEndorsement
impl Sync for TimelineOriginEndorsement
impl Unpin for TimelineOriginEndorsement
impl UnsafeUnpin for TimelineOriginEndorsement
impl UnwindSafe for TimelineOriginEndorsement
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more