Verify a chunked dataset
Build a real Weft manifest and distinguish content integrity from chain anchoring.
Start with deterministic chunks
Weft's actual Rust package is weave-weft; import it as weave_weft. Use a path dependency to models/weft in an authorized checkout. This function builds a manifest and signs its exact canonical signing payload with a caller-supplied Ed25519 signing key.
[dependencies]
weave-weft = { path = "../weave/models/weft" }
ed25519-dalek = "2"use ed25519_dalek::{Signer, SigningKey};
use weave_weft::{
chunk::{chunk_bytes, ChunkConfig},
manifest::{ArtifactMetadata, ManifestProducer, WeftManifest,
WEFT_MANIFEST_SCHEMA, WEFT_MANIFEST_VERSION},
tree::MerkleTree,
};
fn signed_manifest(
bytes: &[u8],
config: ChunkConfig,
producer_did: String,
artifact: ArtifactMetadata,
key: &SigningKey,
) -> weave_weft::Result<WeftManifest> {
let chunks = chunk_bytes(bytes, config)?;
let root = MerkleTree::from_leaves(chunks.iter().map(|c| c.id).collect())?.root();
let mut manifest = WeftManifest {
schema: WEFT_MANIFEST_SCHEMA.to_string(),
version: WEFT_MANIFEST_VERSION,
root,
chunk_size: config.chunk_size() as u64,
chunk_count: chunks.len() as u64,
total_len: bytes.len() as u64,
chunks,
parity: None,
producer: ManifestProducer {
did: producer_did,
signing_key_id: None,
signature: Vec::new(),
},
artifact,
};
manifest.producer.signature = key.sign(&manifest.signing_payload()?).to_bytes().to_vec();
manifest.validate()?;
Ok(manifest)
}The unsigned draft exists only in memory: it is signed before validation or publication. This function is source-checked; it was not compiled or executed in this docs pass.
Verify the producer and payload
The caller is responsible for binding producer_did to the supplied key through a trusted identity resolver. Structural validate() checks do not establish that binding. A consumer verifies the producer signature, manifest version and chunk/root integrity against the expected artifact. Use the manifest and fetch references for the exact inputs and error types.
Persist, publish and retrieve
LocalWeftStore offers a real local store; the dht feature enables the live DHT adapter. Read local storage, discovery and live adapter before choosing transport. Reader/chunk APIs can avoid a single contiguous input buffer, but the local store retains chunks in memory. They do not establish constant-memory processing.
Chain anchoring is a separate operation
The optional MARS and Sigil metadata fields are informational until a real accepted transaction or registry receipt is linked and verified. This example performs no chain transaction and supplies no no-op anchor fallback. Follow the configured network's Sigil evidence flow and MARS docs for that boundary.