loom-mandate · mandate
Source declarations, signatures and documentation for mandate.
Source: sigil/weave/tools/loom-mandate/src/mandate.rs. SHA-256: 9858bfadcd29410c974bd62dd03e8b23f330b263d49f7af75b90ca4be7ce750e.
This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.
mandate::Permission
Granted action.
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum Permission {
/// Read repo contents (clone, fetch, log, diff).
Read,
/// Write commits / push / append to refs.
Write,
/// Approve PRs (signature counts toward `MergePolicy::min_approvals`).
Approve,
/// Issue / revoke / update other mandates on this repo.
Admin,
/// Mint merge commits — last gate before commits land on the base
/// branch. Reserved for v2 multi-writer-coordinator role.
Mint,
}Source line: 16.
mandate::ApprovalPolicy
N-of-M threshold over a set of subject DIDs. Mirrors Sigil's
ApprovalPolicy so the policy can be lifted onto a chain Mandate
verbatim. min_approvals is the threshold; block_self_approval
guards against the issuer satisfying their own threshold.
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct ApprovalPolicy {
/// Minimum distinct DIDs that must contribute a valid signature.
pub min_approvals: u32,
/// Optional list of allowed approver DIDs. Empty = "anyone".
#[serde(default)]
pub allowed_approvers: Vec<String>,
/// Reject approvals from the same DID as the issuer.
#[serde(default = "default_block_self_approval")]
pub block_self_approval: bool
}Source line: 35.
mandate::DelegationPolicy
Limits on re-delegation. Mirrors Sigil's DelegationPolicy.
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize, Default)]
pub struct DelegationPolicy {
/// Maximum chain length: 0 = leaf (cannot delegate further),
/// 1 = grantee can delegate once, etc. Defaults to 0 (no
/// re-delegation).
pub max_depth: u32,
/// Permissions the grantee is permitted to delegate. Subset of the
/// permissions in `grant`. Empty = no delegation allowed.
#[serde(default)]
pub allowed_actions: Vec<Permission>
}Source line: 52.
mandate::IssuePayload
Canonical signed payload for IssueMandate. Field order is the
declaration order; serde_json preserves that for structs, so this
serializes deterministically.
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct IssuePayload {
/// Schema version.
pub version: u32,
/// Issuer DID.
pub issuer: String,
/// Subject DID (recipient of the grant).
pub subject: String,
/// Repo id binding (matches `RepoConfig::repo_id`).
pub repo_id: String,
/// What's being granted.
pub grant: Permission,
/// Required for `Permission::Approve` / `Permission::Mint`. None
/// otherwise.
pub policy: Option<ApprovalPolicy>,
/// Re-delegation limits.
pub delegation: DelegationPolicy,
/// UNIX millis after which the mandate is automatically inert.
/// `None` = never expires (don't use this for live repos).
pub expires_at_ms: Option<u64>,
/// UNIX millis when the mandate was issued.
pub issued_at_ms: u64
}Source line: 67.
mandate::IssuePayload::canonical_bytes
Canonical JSON bytes for signing/hashing.
pub fn canonical_bytes(&self) -> Result<Vec<u8>, serde_json::Error>;Source line: 92.
mandate::IssuePayload::id
16-hex content-addressed id (BLAKE3 prefix of canonical bytes).
pub fn id(&self) -> Result<String, serde_json::Error>;Source line: 97.
mandate::Mandate
A persisted mandate — payload + signature + issuer pubkey.
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct Mandate {
/// Content-addressed id (BLAKE3 prefix of `IssuePayload`).
pub id: String,
/// The signed payload.
pub payload: IssuePayload,
/// Hex-encoded 64-byte Ed25519 signature.
pub signature_hex: String,
/// Hex-encoded 32-byte issuer pubkey.
pub issuer_pubkey_hex: String
}Source line: 106.
mandate::RevocationEntry
A revocation entry, signed by the original issuer (or by an Admin over the same repo). Cancels a mandate by id.
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct RevocationEntry {
/// Mandate id being revoked.
pub mandate_id: String,
/// Repo id (binds the revocation to one repo, just like the
/// mandate).
pub repo_id: String,
/// Revoker DID (issuer or admin).
pub revoker: String,
/// UNIX millis.
pub revoked_at_ms: u64,
/// Hex-encoded 64-byte Ed25519 signature over `(mandate_id ||
/// repo_id || revoker || revoked_at_ms)`.
pub signature_hex: String,
/// Hex-encoded revoker pubkey.
pub revoker_pubkey_hex: String
}Source line: 120.
mandate::MandateError
Errors raised during issue/verify.
#[derive(Debug, Error)]
pub enum MandateError {
/// Signature failed verification.
#[error("mandate signature invalid")]
SignatureInvalid,
/// Encoded pubkey was malformed.
#[error("invalid issuer pubkey: {0}")]
BadKey(String),
/// Encoded signature was malformed.
#[error("invalid signature: {0}")]
BadSig(String),
/// JSON encode/decode error.
#[error("json: {0}")]
Json(#[from] serde_json::Error),
}Source line: 139.
mandate::sign_issue
Sign a fresh IssuePayload with a signing key, producing a complete
Mandate. The id is derived from the payload at signing time.
pub fn sign_issue(payload: IssuePayload, signer: &SigningKey) -> Result<Mandate, MandateError>;Source line: 156.
mandate::verify_issue
Verify a mandate's signature against its embedded pubkey.
pub fn verify_issue(mandate: &Mandate) -> Result<(), MandateError>;Source line: 170.