zer0-secret-stream · protocol
Source declarations, signatures and documentation for protocol.
Source: sigil/weave/network/zer0-secret-stream/src/protocol.rs. SHA-256: c54c2015b3c6d8659eaa5f2c92c4b1e2d3bcf3b5519425df890dd650d1de4a1b.
This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.
protocol::ALLOCATED_FEATURE_MASK
Protocol 1.0 currently allocates feature bits 0 through 9.
pub const ALLOCATED_FEATURE_MASK: u64;Source line: 13.
protocol::INNER_BINDING_FEATURE
Mandatory inner zer0-secret-stream binding feature bit.
pub const INNER_BINDING_FEATURE: u64;Source line: 15.
protocol::MAX_BOOTSTRAP_BYTES
Maximum accepted deterministic-CBOR bootstrap size.
pub const MAX_BOOTSTRAP_BYTES: usize;Source line: 17.
protocol::MAX_TRANSPORT_PEER_ID_BYTES
Exact canonical inline-Ed25519 transport PeerId byte length.
pub const MAX_TRANSPORT_PEER_ID_BYTES: usize;Source line: 19.
protocol::MAX_CAPABILITY_BYTES
Maximum opaque requested-capability byte length.
pub const MAX_CAPABILITY_BYTES: usize;Source line: 21.
protocol::MAX_APPLICATION_IDENTITY_BYTES
Maximum opaque application-identity byte length.
pub const MAX_APPLICATION_IDENTITY_BYTES: usize;Source line: 23.
protocol::MAX_BOOTSTRAP_LIFETIME_MS
Maximum Protocol 1.0 bootstrap lifetime.
pub const MAX_BOOTSTRAP_LIFETIME_MS: u64;Source line: 25.
protocol::MAX_APPLICATION_AUTH_LIFETIME_MS
Maximum Protocol 1.0 application authorization lifetime.
pub const MAX_APPLICATION_AUTH_LIFETIME_MS: u64;Source line: 27.
protocol::ProtocolError
Fail-closed transcript and binding errors.
#[derive(Debug, Error)]
pub enum ProtocolError {
#[error("unsupported or malformed protocol identifier")]
InvalidProtocolId,
#[error("invalid endpoint profile {0}")]
InvalidEndpointProfile(u64),
#[error("service-role bitmap contains unallocated bits: {0:#06x}")]
InvalidServiceRoles(u16),
#[error("feature bitmap contains unallocated bits: {0:#018x}")]
UnsupportedCriticalFeature(u64),
#[error("selected features are not the exact supported-feature intersection")]
InvalidSelectedFeatures,
#[error("required features are not covered by the selected features")]
MissingRequiredFeature,
#[error("transport PeerId must be the canonical inline-Ed25519 libp2p encoding")]
InvalidTransportPeerId,
#[error("a pinned route must use a null digest and generation zero")]
InvalidPinnedRoute,
#[error("initiator and responder challenges must be independent")]
ReusedChallenge,
#[error("invalid bootstrap validity interval")]
InvalidBootstrapLifetime,
#[error("bootstrap was issued in the future")]
BootstrapNotYetValid,
#[error("bootstrap has expired")]
BootstrapExpired,
#[error("invalid application-authorization validity interval")]
InvalidApplicationAuthLifetime,
#[error("application protocol version must be ASCII semantic version without build metadata")]
InvalidApplicationProtocolVersion,
#[error("opaque requested capability exceeds 256 bytes")]
CapabilityTooLarge,
#[error("opaque application identity exceeds 4096 bytes")]
ApplicationIdentityTooLarge,
#[error("deterministic CBOR is malformed or non-canonical: {0}")]
NonCanonicalCbor(&'static str),
#[error("deterministic CBOR exceeds the Protocol 1.0 size limit")]
CborTooLarge,
#[error("received transcript does not exactly match the locally reconstructed transcript")]
TranscriptMismatch,
#[error("migration generation overflow")]
MigrationGenerationOverflow,
#[error("a replacement plan has already been issued for this session")]
ReplacementAlreadyPlanned,
}Source line: 35.
protocol::ProtocolId
Exact negotiated Protocol 1.0 identifier.
#[derive(Clone, Debug, PartialEq, Eq)]
pub struct ProtocolId(String);Source line: 82.
protocol::ProtocolId::parse
Parse a frozen network identifier or an application identifier.
pub fn parse(value: impl Into<String>) -> Result<Self, ProtocolError>;Source line: 86.
protocol::ProtocolId::as_str
pub fn as_str(&self) -> &str;Source line: 119.
protocol::ProtocolId::wire_version
Exact semantic-version suffix carried by the negotiated identifier.
pub fn wire_version(&self) -> &str;Source line: 124.
protocol::EndpointProfile
Frozen endpoint profile values admitted in Protocol 1.0.
#[derive(Clone, Copy, Debug, PartialEq, Eq)]
#[repr(u8)]
pub enum EndpointProfile {
NativeFull = 0,
NativeRestricted = 1,
PortableMacosAlpha = 2,
OfflineLan = 3,
}Source line: 134.
protocol::ServiceRoles
Protocol 1.0 service-role bitmap. Only bits 0 through 3 are allocated.
#[derive(Clone, Copy, Debug, PartialEq, Eq)]
pub struct ServiceRoles(u16);Source line: 157.
protocol::ServiceRoles::new
pub fn new(bits: u16) -> Result<Self, ProtocolError>;Source line: 160.
protocol::ServiceRoles::bits
pub fn bits(self) -> u16;Source line: 167.
protocol::FeatureSet
A validated Protocol 1.0 feature bitmap.
#[derive(Clone, Copy, Debug, PartialEq, Eq)]
pub struct FeatureSet(u64);Source line: 174.
protocol::FeatureSet::new
pub fn new(bits: u64) -> Result<Self, ProtocolError>;Source line: 177.
protocol::FeatureSet::bits
pub fn bits(self) -> u64;Source line: 184.
protocol::TransportPeerId
Canonical, role-specific transport PeerId bytes supplied by the outer transport.
#[derive(Clone, Debug, PartialEq, Eq)]
pub struct TransportPeerId(Vec<u8>);Source line: 191.
protocol::TransportPeerId::new
pub fn new(bytes: impl Into<Vec<u8>>) -> Result<Self, ProtocolError>;Source line: 194.
protocol::TransportPeerId::as_bytes
pub fn as_bytes(&self) -> &[u8];Source line: 205.
protocol::RouteBinding
Route state bound into a session for one role.
#[derive(Clone, Debug, PartialEq, Eq)]
pub struct RouteBinding {
pub route_set_digest: Option<[u8; 32]>,
pub generation: u64
}Source line: 212.
protocol::RouteBinding::pinned
pub fn pinned() -> Self;Source line: 218.
protocol::RouteBinding::routed
pub fn routed(digest: [u8; 32], generation: u64) -> Self;Source line: 225.
protocol::SessionBootstrapContext
Static, role-ordered inputs used to construct SessionBootstrapV1.
T-A must supply canonical initiator/responder transport PeerIds in Noise-role order. This type never sorts identities lexicographically.
#[derive(Clone, Debug, PartialEq, Eq)]
pub struct SessionBootstrapContext {
pub selected_protocol_id: ProtocolId,
pub initiator_endpoint_profile: EndpointProfile,
pub responder_endpoint_profile: EndpointProfile,
pub initiator_service_roles: ServiceRoles,
pub responder_service_roles: ServiceRoles,
pub initiator_transport_peer_id: TransportPeerId,
pub responder_transport_peer_id: TransportPeerId,
pub initiator_route: RouteBinding,
pub responder_route: RouteBinding,
pub initiator_supported_features: FeatureSet,
pub initiator_required_features: FeatureSet,
pub responder_supported_features: FeatureSet,
pub responder_required_features: FeatureSet,
pub selected_features: FeatureSet,
pub proposed_migration_generation: u64,
pub issued_at_ms: u64,
pub expires_at_ms: u64
}Source line: 246.
protocol::SessionBootstrapContext::validate
pub fn validate(&self) -> Result<(), ProtocolError>;Source line: 267.
protocol::SessionBootstrapContext::validate_at
Validate freshness against an injected clock and the smaller of the configured handshake deadline or the Protocol 1.0 60-second ceiling.
pub fn validate_at(
&self,
now_ms: u64,
handshake_lifetime_ms: u64,
) -> Result<(), ProtocolError>;Source line: 287.
protocol::SessionBootstrapContext::with_challenges
pub fn with_challenges(
self,
initiator_challenge: [u8; 32],
responder_challenge: [u8; 32],
) -> Result<SessionBootstrapV1, ProtocolError>;Source line: 301.
protocol::SessionBootstrapV1
Exact frozen Protocol 1.0 secure-session bootstrap transcript.
#[derive(Clone, Debug, PartialEq, Eq)]
pub struct SessionBootstrapV1 {
pub version: u64,
pub selected_protocol_id: ProtocolId,
pub initiator_endpoint_profile: EndpointProfile,
pub responder_endpoint_profile: EndpointProfile,
pub initiator_service_roles: ServiceRoles,
pub responder_service_roles: ServiceRoles,
pub initiator_transport_peer_id: TransportPeerId,
pub responder_transport_peer_id: TransportPeerId,
pub initiator_challenge: [u8; 32],
pub responder_challenge: [u8; 32],
pub initiator_route: RouteBinding,
pub responder_route: RouteBinding,
pub initiator_supported_features: FeatureSet,
pub initiator_required_features: FeatureSet,
pub responder_supported_features: FeatureSet,
pub responder_required_features: FeatureSet,
pub selected_features: FeatureSet,
pub proposed_migration_generation: u64,
pub issued_at_ms: u64,
pub expires_at_ms: u64
}Source line: 335.
protocol::SessionBootstrapV1::validate
pub fn validate(&self) -> Result<(), ProtocolError>;Source line: 387.
protocol::SessionBootstrapV1::validate_at
pub fn validate_at(
&self,
now_ms: u64,
handshake_lifetime_ms: u64,
) -> Result<(), ProtocolError>;Source line: 413.
protocol::SessionBootstrapV1::to_deterministic_cbor
Encode the exact 22-entry, integer-keyed deterministic-CBOR map.
pub fn to_deterministic_cbor(&self) -> Result<Vec<u8>, ProtocolError>;Source line: 428.
protocol::SessionBootstrapV1::from_deterministic_cbor
Strictly decode the exact map, rejecting non-canonical integers, extra or missing keys, indefinite values, tags, floats, and trailing bytes.
pub fn from_deterministic_cbor(input: &[u8]) -> Result<Self, ProtocolError>;Source line: 485.
protocol::ChannelBinding
Binding derived from the Noise handshake hash and exact confirmed bootstrap bytes.
This value is intentionally non-serializable and zeroized when dropped.
#[derive(PartialEq, Eq, Zeroize, ZeroizeOnDrop)]
pub struct ChannelBinding([u8; 32]);Source line: 579.
protocol::ChannelBinding::derive
pub fn derive(
inner_handshake_hash: &[u8; 32],
confirmed_bootstrap_cbor: &[u8],
) -> Result<Self, ProtocolError>;Source line: 582.
protocol::ChannelBinding::as_bytes
pub fn as_bytes(&self) -> &[u8; 32];Source line: 598.
protocol::ChannelBinding::digest
pub fn digest(&self) -> [u8; 32];Source line: 602.
protocol::OpaqueApplicationAuthInputs
Opaque, unverified application-controlled fields supplied by T-F.
Constructing this value is not an authorization decision. T-F must separately verify the application proof, capability, scope, policy generation, and expiry.
#[derive(Clone, Debug, PartialEq, Eq)]
pub struct OpaqueApplicationAuthInputs {
pub opaque_scope_digest: [u8; 32],
pub requested_capability: Vec<u8>,
pub proving_application_identity: Vec<u8>,
pub verifying_application_identity: Vec<u8>,
pub issued_at_ms: u64,
pub expires_at_ms: u64,
pub policy_generation: u64
}Source line: 621.
protocol::ApplicationAuthTranscriptV1
Exact frozen 29-entry application-authorization transcript.
All session-duplicated fields are copied from SessionBootstrapV1; callers
cannot independently override them.
#[derive(Debug, PartialEq, Eq)]
pub struct ApplicationAuthTranscriptV1 {
}Source line: 655.
protocol::ApplicationAuthTranscriptV1::from_confirmed_session
pub fn from_confirmed_session(
bootstrap: &SessionBootstrapV1,
channel_binding: &ChannelBinding,
inputs: OpaqueApplicationAuthInputs,
) -> Result<Self, ProtocolError>;Source line: 673.
protocol::ApplicationAuthTranscriptV1::to_deterministic_cbor
pub fn to_deterministic_cbor(&self) -> Result<Vec<u8>, ProtocolError>;Source line: 687.
protocol::ApplicationAuthTranscriptV1::proof_message
Domain-separated bytes for application-owned signing or proof generation.
pub fn proof_message(&self) -> Result<Vec<u8>, ProtocolError>;Source line: 787.
protocol::ApplicationAuthTranscriptV1::confirm_exact
Fail closed unless received bytes are the exact canonical reconstruction.
pub fn confirm_exact(&self, received: &[u8]) -> Result<(), ProtocolError>;Source line: 796.