loom-encrypt · metadata
Source declarations, signatures and documentation for metadata.
Source: sigil/weave/tools/loom-encrypt/src/metadata.rs. SHA-256: d49fb474b0c4aef6fedc9f17bbe74f14855a5c05a2984b1ee137a5ef6fedfcbc.
This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.
metadata::METADATA_FORMAT_VERSION
Private-metadata envelope format version.
pub const METADATA_FORMAT_VERSION: u8;Source line: 21.
metadata::MetadataEncryptError
Errors raised while sealing private metadata.
#[derive(Debug, Error)]
pub enum MetadataEncryptError {
/// The caller exceeded the bounded private-metadata payload size.
#[error("metadata plaintext is {len} bytes; maximum is {max}")]
TooLarge {
/// Supplied plaintext length.
len: usize,
/// Maximum admitted plaintext length.
max: usize,
},
/// The platform RNG could not provide a nonce.
#[error("metadata nonce generation failed")]
Random,
/// Authenticated encryption failed.
#[error("metadata AEAD seal failed")]
Aead,
}Source line: 38.
metadata::MetadataDecryptError
Errors raised while opening private metadata.
#[derive(Debug, Error, PartialEq, Eq)]
pub enum MetadataDecryptError {
/// Ciphertext is shorter than the version, nonce, and authentication tag.
#[error("metadata ciphertext is too short")]
TooShort,
/// The envelope version is unsupported.
#[error("unsupported metadata format version 0x{0:02x}")]
UnknownVersion(u8),
/// The envelope exceeds the largest plaintext plus bounded padding.
#[error("metadata ciphertext is {len} bytes; maximum is {max}")]
TooLarge {
/// Supplied ciphertext length.
len: usize,
/// Maximum admitted ciphertext length.
max: usize,
},
/// Authenticated decryption failed.
#[error("metadata authentication failed")]
Auth,
/// The authenticated plaintext carried an invalid embedded length.
#[error("metadata plaintext length is invalid")]
InvalidLength,
/// The authenticated padding was not canonical zero padding.
#[error("metadata padding is not canonical")]
InvalidPadding,
}Source line: 57.
metadata::seal_metadata
Seal a private metadata payload.
context is a stable, non-secret type label such as commit or
access-manifest. It is authenticated as associated data and separates
otherwise identical payload classes.
pub fn seal_metadata(
mek: &MasterKey,
context: &str,
plaintext: &[u8],
) -> Result<Vec<u8>, MetadataEncryptError>;Source line: 88.
metadata::open_metadata
Open a private metadata payload sealed by [seal_metadata].
pub fn open_metadata(
mek: &MasterKey,
context: &str,
ciphertext: &[u8],
) -> Result<Vec<u8>, MetadataDecryptError>;Source line: 136.
metadata::opaque_id
Derive a keyed, domain-separated identifier for a private metadata value.
The result is suitable for replicated object names and cannot be confirmed from a guessed plaintext value without possession of the repository key.
pub fn opaque_id(mek: &MasterKey, kind: &str, clear_identifier: &[u8]) -> String;Source line: 194.
metadata::replication_access_proof
Derive the anonymous, one-time proof sent before private peers disclose their DIDs. The proof is bound to the current repository key epoch, the exact Noise channel, requested discovery key, and live/non-live mode.
pub fn replication_access_proof(
mek: &MasterKey,
channel_binding: &[u8; 32],
discovery_key: &[u8; 32],
live: bool,
) -> [u8; 32];Source line: 207.
metadata::verify_replication_access_proof
Constant-time verification of a private replication access proof.
pub fn verify_replication_access_proof(
mek: &MasterKey,
channel_binding: &[u8; 32],
discovery_key: &[u8; 32],
live: bool,
proof: &[u8; 32],
) -> bool;Source line: 222.