loom-pr · approval
Source declarations, signatures and documentation for approval.
Source: sigil/weave/tools/loom-pr/src/approval.rs. SHA-256: 7b3bd2dbbc497a6d712701dee4b4a38691be2c7b93278fbd0afad9dd44765c7d.
This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.
approval::ApprovalPayload
The bytes that get Ed25519-signed. Order matters; serde_json serializes fields in declaration order.
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct ApprovalPayload {
/// Schema version.
pub version: u32,
/// PR being approved.
pub pr_id: PrId,
/// Approver DID.
pub approver_did: String,
/// The exact head-commit sequence number the approver is endorsing.
/// Approvals only count toward threshold when the PR's
/// `head_commit_seq` matches this field.
pub approved_head_seq: u64,
/// UNIX millis the approval was signed.
pub signed_at_ms: u64
}Source line: 18.
approval::ApprovalPayload::canonical_bytes
Canonical JSON bytes used for signing/verification. Stable across serde versions because field order is fixed by the struct declaration and serde_json preserves that order for structs.
pub fn canonical_bytes(&self) -> Result<Vec<u8>, serde_json::Error>;Source line: 37.
approval::Approval
A persisted approval — payload plus signature plus the verifying key needed to check it without DID resolution.
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct Approval {
/// The signed payload.
pub payload: ApprovalPayload,
/// Hex-encoded 64-byte Ed25519 signature.
pub signature_hex: String,
/// Hex-encoded 32-byte Ed25519 public key of the approver. Embedded
/// here so verifiers don't need to chase the approver's DID document
/// before checking — speeds up the common path while still being
/// auditable (the DID's pubkey is the source of truth).
pub approver_pubkey_hex: String
}Source line: 45.
approval::ApprovalError
Errors raised by approval verification.
#[derive(Debug, Error)]
pub enum ApprovalError {
/// Signature does not validate against the embedded public key.
#[error("signature invalid")]
SignatureInvalid,
/// Payload re-encoding failed (corrupt JSON).
#[error("payload encoding: {0}")]
Encoding(#[from] serde_json::Error),
/// Public-key bytes were not 32 hex-bytes.
#[error("invalid public key encoding: {0}")]
BadKey(String),
/// Signature bytes were not 64 hex-bytes.
#[error("invalid signature encoding: {0}")]
BadSig(String),
}Source line: 59.
approval::verify_approval
Verify an approval's signature. Returns Ok(()) when the signature
is valid for the embedded payload + pubkey. Does not check
authorization; the merge policy layer enforces that separately.
pub fn verify_approval(approval: &Approval) -> Result<(), ApprovalError>;Source line: 77.