Weave documentation
Weft

Publish

Prepare a real producer signature before storing or advertising a manifest.

LocalWeftStore::in_memory() keeps state in-process. LocalWeftStore::open(path) uses local files. WeftDhtStore delegates to a configured DhtKv backend. All publish_bytes APIs take bytes, ChunkConfig, a pre-signed ManifestProducer, ArtifactMetadata and PeerId; they do not obtain a signing key for you.

Prepare descriptors and an unsigned in-memory manifest, sign it, validate the final manifest, then pass its producer/artifact fields with the exact same bytes and chunk configuration to the store. The unsigned draft below is never published:

use ed25519_dalek::{Signer, SigningKey};
use weave_weft::{
    chunk::{chunk_bytes, ChunkConfig},
    manifest::{ArtifactMetadata, ManifestProducer, WeftManifest,
        WEFT_MANIFEST_SCHEMA, WEFT_MANIFEST_VERSION},
    tree::MerkleTree,
};

fn signed_manifest(
    bytes: &[u8],
    config: ChunkConfig,
    producer_did: String,
    artifact: ArtifactMetadata,
    key: &SigningKey,
) -> weave_weft::Result<WeftManifest> {
    let chunks = chunk_bytes(bytes, config)?;
    let root = MerkleTree::from_leaves(chunks.iter().map(|c| c.id).collect())?.root();
    let mut manifest = WeftManifest {
        schema: WEFT_MANIFEST_SCHEMA.to_string(),
        version: WEFT_MANIFEST_VERSION,
        root,
        chunk_size: config.chunk_size() as u64,
        chunk_count: chunks.len() as u64,
        total_len: bytes.len() as u64,
        chunks,
        parity: None,
        producer: ManifestProducer {
            did: producer_did,
            signing_key_id: None,
            signature: Vec::new(),
        },
        artifact,
    };
    manifest.producer.signature = key.sign(&manifest.signing_payload()?).to_bytes().to_vec();
    manifest.validate()?;
    Ok(manifest)
}

This function uses caller-owned signing material and is checked against source declarations; it was not compiled or executed in this documentation pass. Before publication, the caller is responsible for authorizing the DID/key relationship. Verify that the store-returned manifest matches the signed draft before distributing it.

publish_reader accepts synchronous std::io::Read on the local store. It avoids requiring one contiguous input buffer, but the local store still retains chunk bytes in memory; this is not a constant-memory ingestion guarantee. A non-seekable one-pass reader cannot magically supply a signature over its not-yet-known final manifest: use a two-pass source or stage the payload first.

Default chunk size is 4 MiB; valid explicit sizes are 1 byte through 64 MiB. Stores and DHT backends can impose stricter record limits. Storage writes are not a multi-record transaction, so a publication error can leave partial chunks/records; verify the final record and fetched payload.

Source declarations · Source declarations