Skip to main content

DurableKeyMaterial

Struct DurableKeyMaterial 

Source
pub struct DurableKeyMaterial {
    pub cipher: Option<Arc<dyn PayloadCipher>>,
    pub hmac_key: Option<[u8; 32]>,
    pub hwm_key: Option<(u32, [u8; 32])>,
    pub previous_hmac_key: Option<[u8; 32]>,
    pub previous_hwm_key: Option<(u32, [u8; 32])>,
    pub integrity_sealed: bool,
    pub integrity_grandfather: HashSet<ExecutionId>,
}
Expand description

Key material and integrity-seal state shared by every durable-backend construction call site: open_durable_backend, the P1/P2 AgentBuilder::with_durable_* methods (builder.rs), and their reassembly points in Agent::ensure_session_durable_ctx and plan.rs’s ensure_durable_backend (#6458).

hmac_key is None for a single-user local, non-shared database (INV-8) — the documented stance where control entries carry no HMAC. hwm_key (issue #6360) is meant to be attached unconditionally (FR-009): None only when ZEPH_DURABLE_KEY itself is unavailable — unlike hmac_key, single-user local deployments still get high-water-mark deletion detection. previous_hmac_key is Some only while a zeph durable rotate-key rotation window is open (#6451). previous_hwm_key is the HWM-side counterpart, Some under the same condition (addendum to #6451): unlike previous_hmac_key, its epoch reuses the AEAD cipher’s key_id lifecycle rather than being epoch-less try-both (see HwmKeySlot/with_previous_hwm_key in zeph-durable). integrity_sealed/integrity_grandfather (issue #6449) are resolved from the vault by crate::commands::durable::load_integrity_seal in the zeph binary crate.

A mis-wired key field here — wrong key, wrong slot, or an unintended None — never results in a silent accept: every control-entry and high-water-mark verification this key material feeds fails closed, surfacing as ControlIntegrity or HighWaterMarkIntegrity rather than a silently accepted read.

Deliberately does not derive Debug: every key field holds raw key-material bytes that must never be logged or printed (see project pitfall: secret-bearing Debug derives).

§Examples

use zeph_core::DurableKeyMaterial;

// A non-durable / disabled-encryption configuration: every key slot empty.
let key_material = DurableKeyMaterial {
    cipher: None,
    hmac_key: None,
    hwm_key: None,
    previous_hmac_key: None,
    previous_hwm_key: None,
    integrity_sealed: false,
    integrity_grandfather: Default::default(),
};
assert!(key_material.hmac_key.is_none());

Fields§

§cipher: Option<Arc<dyn PayloadCipher>>

AEAD payload cipher; None when config.encrypt_payload = false (development mode only).

§hmac_key: Option<[u8; 32]>

Current control-entry HMAC key.

§hwm_key: Option<(u32, [u8; 32])>

Current high-water-mark key as (epoch, key).

§previous_hmac_key: Option<[u8; 32]>

Previous control-entry HMAC key, valid only during an open rotation window.

§previous_hwm_key: Option<(u32, [u8; 32])>

Previous high-water-mark key as (epoch, key), valid only during an open rotation window.

§integrity_sealed: bool

Whether the durable integrity seal is set.

§integrity_grandfather: HashSet<ExecutionId>

Executions grandfathered in before the integrity seal was set, exempt from verification.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> IntoRequest<T> for T

Source§

fn into_request(self) -> Request<T>

Wrap the input message T in a tonic::Request
Source§

impl<L> LayerExt<L> for L

Source§

fn named_layer<S>(&self, service: S) -> Layered<<L as Layer<S>>::Service, S>
where L: Layer<S>,

Applies the layer to a service and wraps it in Layered.
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more