Skip to main content

TimelineAdmissionAcceptance

Struct TimelineAdmissionAcceptance 

Source
pub struct TimelineAdmissionAcceptance {
    pub origin_sha256: Vec<u8>,
    pub uploader_device_public_key: Vec<u8>,
    pub deployment_public_key: Vec<u8>,
    pub request_sha256: Vec<u8>,
    pub first_position: u64,
    pub event_count: u32,
    pub signature: Vec<u8>,
    pub authority: Option<Authority>,
}
Expand description

A current direct-human run-principal authority or a current format-3 OwnerAuthorizationBundle (owner_records.proto) with an ACCEPT_TIMELINE_ORIGIN grant signs this exact acceptance: UTF8(“heddle-timeline-run-acceptance-v1”) || 0x00 followed by fields 1..6 below, then one authority byte (1 for principal credential, 2 for owner capability) and counted(exact authority bytes). Byte fields use u32be(length)||bytes, uint64 fields use u64be, and event_count uses u32be. The signature and transport PoP are excluded. The original digest is SHA-256 of the origin transcript plus its 64-byte signature. The request digest is SHA-256 of: UTF8(“heddle-timeline-upload-v1”) || 0x00 || counted(client_operation_id) || counted(spool UUID) || counted(ThreadId.value) || counted(run ID) || u32be(canonicalization_version) || u64be(run_revision) || one byte snapshot presence || [u32be(state)||counted(harness) if present] || u32be(event count), then for each event in wire order: u64be(position)||u32be(kind)||i64be(recorded_at.seconds) ||u32be(recorded_at.nanos)||one byte tool presence || [u32be(tool) if present] || counted(origin SHA-256) || u64be(first_position). counted means u32be(byte_length)||exact bytes; presence is 0 or 1. The acceptance, its authority selector and transport PoP are excluded. Unknown fields are invalid. This layout is independent of protobuf serialization. An acceptance is valid only for this exact digest and position range. For principal_credential_id, Weft resolves the exact ID in its current credential registry, verifies a live independent root or server-issued direct-human session/pairing chain, and uses that chain’s final effective Ed25519 PoP key for this signature. Its account MUST be the origin’s verified principal. Agent labels, account claims and uploader credentials do not confer acceptance permission. For owner_derived_capability, the bytes are a protobuf wire encoding of OwnerAuthorizationBundle, at most 4096 bytes. Decode the complete bundle, rejecting unknown fields and trailing bytes. Verify its owner root and transition history against the independently pinned CURRENT owner state of the run-principal account; OwnerRoot.account_uuid MUST equal the verified principal UUID (never accept a state supplied only by this bundle). Then verify the single format-3 capability and subject Biscuit. The grant’s exact Spool selector, Thread ID, original principal UUID, credential class, original credential identity variant and values, effective key digest and signed origin SHA-256 MUST equal the verified origin. The leaf CapabilityPrincipal.key is the effective Ed25519 signing key for this acceptance. SignedOwnerCapability.signature signer_key_id instead resolves to the owner issuer key through the accepted owner transition at issuer_state_hash and its live rotation/recovery signing window; reject an obsolete, vetoed or uncommitted issuer state. The subject signs this acceptance transcript with its effective key, not the owner key or the uploader key. Recheck capability validity interval, direct-only/single-block attenuation restriction, active owner transitions/recovery windows, every credential and capability revocation, and the subject proof at the admission transaction. No v1 PURGE grant, generic grant envelope, passkey certificate alone, or owner/admin status authorizes acceptance. The acceptance bytes do not replace the uploader’s independent Tier-1 transport proof.

Fields§

§origin_sha256: Vec<u8>

Exactly 32 bytes.

§uploader_device_public_key: Vec<u8>

Exactly 32 bytes.

§deployment_public_key: Vec<u8>

Exactly 32 bytes.

§request_sha256: Vec<u8>

Exactly 32 bytes.

§first_position: u64

0..2^63-1.

§event_count: u32

0..64.

§signature: Vec<u8>

Ed25519, exactly 64 bytes.

§authority: Option<Authority>

Exactly one current authority route; credential IDs are 1..128 bytes and owner-derived capability bundles are at most 4096 bytes.

Trait Implementations§

Source§

impl Clone for TimelineAdmissionAcceptance

Source§

fn clone(&self) -> TimelineAdmissionAcceptance

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for TimelineAdmissionAcceptance

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result<(), Error>

Formats the value using the given formatter. Read more
Source§

impl Default for TimelineAdmissionAcceptance

Source§

fn default() -> TimelineAdmissionAcceptance

Returns the “default value” for a type. Read more
Source§

impl Eq for TimelineAdmissionAcceptance

Source§

impl Hash for TimelineAdmissionAcceptance

Source§

fn hash<__H>(&self, state: &mut __H)
where __H: Hasher,

Feeds this value into the given Hasher. Read more
1.3.0 · Source§

fn hash_slice<H>(data: &[Self], state: &mut H)
where H: Hasher, Self: Sized,

Feeds a slice of this type into the given Hasher. Read more
Source§

impl Message for TimelineAdmissionAcceptance

Source§

fn encoded_len(&self) -> usize

Returns the encoded length of the message without a length delimiter.
Source§

fn clear(&mut self)

Clears the message, resetting all fields to their default.
Source§

fn encode(&self, buf: &mut impl BufMut) -> Result<(), EncodeError>
where Self: Sized,

Encodes the message to a buffer. Read more
Source§

fn encode_to_vec(&self) -> Vec<u8> ⓘ
where Self: Sized,

Encodes the message to a newly allocated buffer.
Source§

fn encode_length_delimited( &self, buf: &mut impl BufMut, ) -> Result<(), EncodeError>
where Self: Sized,

Encodes the message with a length-delimiter to a buffer. Read more
Source§

fn encode_length_delimited_to_vec(&self) -> Vec<u8> ⓘ
where Self: Sized,

Encodes the message with a length-delimiter to a newly allocated buffer.
Source§

fn decode(buf: impl Buf) -> Result<Self, DecodeError>
where Self: Default,

Decodes an instance of the message from a buffer. Read more
Source§

fn decode_length_delimited(buf: impl Buf) -> Result<Self, DecodeError>
where Self: Default,

Decodes a length-delimited instance of the message from the buffer.
Source§

fn merge(&mut self, buf: impl Buf) -> Result<(), DecodeError>
where Self: Sized,

Decodes an instance of the message from a buffer, and merges it into self. Read more
Source§

fn merge_length_delimited(&mut self, buf: impl Buf) -> Result<(), DecodeError>
where Self: Sized,

Decodes a length-delimited instance of the message from buffer, and merges it into self.
Source§

impl PartialEq for TimelineAdmissionAcceptance

Source§

fn eq(&self, other: &TimelineAdmissionAcceptance) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for TimelineAdmissionAcceptance

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more