//! # ksg-verify-v2 — the third party's side, on core v2 //! //! `reference-impl/crates/ksg-verify` carried over to `ksg-core-v2` //! (documents of major version 3). The success metric is the same one the MVP //! inherits from v0.3 §1.4: a verifier accepts the evidence **without a single //! request to the issuer or the operator** — an export's bytes in, a verdict //! out. //! //! # What changed against core v1's verifier //! //! | Core v1 | Here | Why | //! |---|---|---| //! | the journal of entries (`FinalExport`, one `Page`) | gone | core v2 has one work journal: the one under the movable seal (spec v2 §10) | //! | the transparency log and its checkpoints | gone | no log in core v2 (spec v2 §17) | //! | every anchor read, the moment thrown away | every anchor read by the core's one rule, and its bound reported per record | audit of 30.09, Ya-1: one model of time | //! | statuses not exported | a status section export is a form of its own, its anchors read the same way | audit of 30.09, Ya-2 | //! //! # What the verifier brings, and why //! //! | Input | From where | Why not from the export | //! |---|---|---| //! | the export | the party presenting it | — | //! | the container identifier | the container's initiation document | a journal of another container would pass as this one | //! | the class | the container's packet | a forgery would declare itself `light` and skip every anchor | //! | the key set | the keys the verifier accepts for this container | keys shipped with the evidence prove nothing about who holds them | //! | a reader of the anchoring network | the verifier's own | an anchor's `proof` is opaque until read | //! //! # No reader, no time //! //! Without a reader a verifier confirms signatures, chain and order of a //! light journal, and **refuses** anything whose anchors it would have to //! read — it does not report a weaker result silently. pub mod channel; pub mod clock; pub mod file; pub mod solana; pub mod testkeys; use ksg_core_v2::anchor::{Attestation, AttestationVerifier}; use ksg_core_v2::crypto::hash::Hash; use ksg_core_v2::crypto::sign::{KeySet, Profile, PublicKey}; use ksg_core_v2::doc::{Class, Timestamp, Uri}; use ksg_core_v2::error::Invalid; use ksg_core_v2::journal::{ verify_bound_point, verify_bound_read, Body, BoundExport, BoundPoint, Mode, Party, }; use ksg_core_v2::section::StatusExport; use serde::Serialize; /// Which form the bytes were. #[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize)] #[serde(rename_all = "snake_case")] pub enum Form { /// A [`BoundExport`]: the journal under the movable seal (spec v2 §10). Bound, /// One [`BoundPoint`]: a page of it under the movable seal. BoundPoint, /// A [`StatusExport`]: the status section with its anchors (spec v2 §11). Statuses, } /// The upper time bound of one anchored record, as the reader established it. #[derive(Debug, Clone, PartialEq, Eq, Serialize)] pub struct Bound { /// The record's number (journal) or the status record's number. pub record: u64, /// The earliest moment a read anchor proves; spec v2 §7.2. pub not_after: String, } /// The verdict, in a form a person and a program can both read. #[derive(Debug, Clone, PartialEq, Eq, Serialize)] pub struct Report { /// `true` only when every check passed. pub accepted: bool, /// Which form was checked, when the bytes were recognised. pub form: Option