Weave documentation
Weft

Manifest

Manifest structure, canonical signing bytes and separate identity verification.

The schema is weave.weft.manifest.v1, version 1. WeftManifest contains the root, chunk size/count/total length, ordered chunk descriptors, reserved parity field, producer and artifact metadata. ManifestProducer carries a DID, optional signing-key ID and signature bytes; ArtifactMetadata carries media type/schema plus optional external asset/commitment references.

validate() checks schema/version, chunk bounds and contiguous descriptors, total size/root consistency, required producer/artifact fields and a nonempty signature field. It rejects parity because erasure coding is not implemented. It does not cryptographically verify the signature or resolve its producer DID. A nonempty dummy signature can pass that particular structural check and must never be treated as authenticated publication.

to_canonical_bytes() serializes with the struct’s deterministic JSON field order. signing_payload() clones the manifest, clears producer.signature and serializes the clone; it does not run validation on that unsigned clone. Sign exactly those bytes, then put the real signature into the original manifest. from_canonical_bytes() parses and structurally validates; it does not perform identity verification or require incoming whitespace/key order to match the serializer byte-for-byte.

use ed25519_dalek::{Signature, Verifier, VerifyingKey};
use weave_weft::manifest::WeftManifest;

fn verify_producer(
    manifest: &WeftManifest,
    trusted_key: &VerifyingKey,
) -> Result<(), Box<dyn std::error::Error>> {
    manifest.validate()?;
    let signature = Signature::from_slice(&manifest.producer.signature)?;
    trusted_key.verify(&manifest.signing_payload()?, &signature)?;
    Ok(())
}

The caller must obtain trusted_key through its identity authority and check it is allowed to speak for the producer. This source-checked example does not implement DID resolution. A manifest root commits ordered chunk IDs; it is not a commitment to every metadata field or producer claim. Signatures cover those additional fields.

Source declarations