Skip to content

TypeScript: @dnsid-ai/log-c2sp-tlog — functions

Part of Transparency log (@dnsid-ai/log-c2sp-tlog).

function advanceTrustedC2spCheckpoint(
store,
reference,
checkpoint,
witnessTime,
options?
): Promise<TrustedC2spCheckpoint>;

Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:70

Advances the stored trusted checkpoint for a log origin to checkpoint, guarding against split-view and rollback attacks: a same-size checkpoint must have the same root, and a larger one must be proven consistent by a consistency proof or a complete scan matching both checkpoint prefixes.

TrustedC2spCheckpointStore

ParsedC2spTlogLr

Checkpoint

Date

VerificationOptions & object = {}

Promise<TrustedC2spCheckpoint>

A defensive copy of the newly trusted checkpoint.

C2spTlogVerificationError on origin mismatch, rollback, root divergence, or missing/invalid consistency evidence.


function assertCanonicalJsonBytes(bytes, value?): void;

Defined in: packages/log-c2sp-tlog/src/canonical.ts:73

Asserts that bytes are exactly the canonical JSON serialization of value (which defaults to the parsed content of bytes).

Uint8Array

unknown = ...

void

C2spTlogParseError when the bytes are not canonical.


function c2spEnvelopeToEvent(obj): Promise<LogEvent>;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:93

Converts a parsed c2sp-tlog JSON envelope back into a protocol LogEvent, requiring a complete sigs object and consistent embedded key material (distinct entity/operational keys, matching signature kids).

unknown

Promise<LogEvent>

C2spTlogParseError when the envelope is malformed or inconsistent.


function c2spEventId(signedBytes): string;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:8

Logical ID of canonical signed bytes; signatures and Merkle indexes are excluded.

Uint8Array

string


function c2spTlogEntryBytes(prepared, context?): Promise<Uint8Array<ArrayBufferLike>>;

Defined in: packages/log-c2sp-tlog/src/writer.ts:179

Finalizes a fully signed prepared event into its canonical log entry bytes, re-verifying all required signatures and the entry’s parseability.

PreparedC2spTlogEvent

PreparedC2spVerificationContext = {}

Promise<Uint8Array<ArrayBufferLike>>

C2spTlogVerificationError when a required signature is missing or invalid.

C2spTlogParseError when the entry is malformed or oversized.


function canonicalBytes(value): Uint8Array;

Defined in: packages/log-c2sp-tlog/src/canonical.ts:48

UTF-8 encoding of canonicalJson.

unknown

Uint8Array


function canonicalizeC2spEvent(event, context?): Uint8Array;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:210

Serializes a fully signed event to its canonical c2sp-tlog entry bytes, requiring every signature the event type demands.

LogEvent

C2spEventContext = {}

Uint8Array

C2spTlogParseError when signatures are incomplete or the entry is oversized.


function canonicalJson(value): string;

Defined in: packages/log-c2sp-tlog/src/canonical.ts:13

Serializes a JSON value to its RFC 8785 (JCS-style) canonical form: lexicographically sorted object members, no whitespace, valid Unicode.

unknown

string

C2spTlogParseError for non-finite or negative-zero numbers, unpaired surrogates, undefined members, or non-JSON values.


function canonicalLogPrefix(raw): string;

Defined in: packages/log-c2sp-tlog/src/lr.ts:82

Canonicalizes a log-prefix URL: lowercase scheme and host, default ports and trailing slash removed, percent-encoding normalized.

string

string

C2spTlogParseError for userinfo, query/fragment, dot segments, encoded slashes, unsupported schemes, or TXT-delimiter characters.


function checkpointOrigin(logPrefix): string;

Defined in: packages/log-c2sp-tlog/src/lr.ts:103

Derives the C2SP checkpoint origin (host plus path, no scheme) from a canonical log prefix.

string

string


function checkpointPath(prefix): string;

Defined in: packages/log-c2sp-tlog/src/tiles.ts:4

URL of a log’s current checkpoint under the C2SP tlog-tiles layout.

string

string


function createC2spTlogVerificationRegistry(options): Promise<LogRegistry>;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:93

Creates a LogRegistry ready to verify c2sp-tlog lifecycle references. Trust policy is explicit and never inferred from an identity record, its lr, or the log prefix.

The default resource fetcher rejects unsafe destinations and redirects, connects through the validated DNS result, requires HTTP 200, bounds decoded bodies while reading, and applies finite request deadlines. The default checkpoint store is restart-ephemeral; inject durable storage when rollback protection must survive process restarts.

C2spTlogVerificationOptions

Promise<LogRegistry>


function createDefaultC2spBoundedResourceFetcher(transport?): C2spBoundedResourceFetcher;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:85

Creates the default public-resource fetcher. It uses connection-time SSRF checks, rejects redirects, requires HTTP 200, and bounds the decoded body while reading it. transport applies the same DNS server, CA bundle, and private-address exceptions as DnsidConfig.transport, so a private registry such as dnsid local is reachable for policy and log reads.

TransportConfig = {}

C2spBoundedResourceFetcher


function createDnsidManagedVerificationRegistry(options?): Promise<LogRegistry>;

Defined in: packages/log-c2sp-tlog/src/managed-verification-registry.ts:56

Creates a registry for the reviewed trust roots of DNSid-managed DNSid logs. Calling this separately named factory is an explicit application trust decision; the generic factory never selects these roots implicitly.

Trust snapshots are bundled with the SDK and selected only after parsing an exact canonical (scope, logPrefix) pair. Managed verification prefers signed stream bundles with safe raw-scan fallback.

DnsidManagedVerificationOptions = {}

Promise<LogRegistry>


function createFetchBackedC2spResourceFetcher(fetchImpl, guarantees): C2spBoundedResourceFetcher;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:96

Adapts trusted deployment fetch infrastructure to the bounded C2SP contract. The caller is responsible for truthfully declaring DNS/connection security; the adapter itself enforces HTTPS, status, redirect, timeout, cancellation, and response-size behavior.

FetchLike

C2spResourceFetchGuarantees

C2spBoundedResourceFetcher


function encodeEntryBundle(entries): Uint8Array;

Defined in: packages/log-c2sp-tlog/src/tiles.ts:43

Encodes entries as a C2SP tlog-tiles entry bundle with 16-bit big-endian length prefixes.

Uint8Array<ArrayBufferLike>[]

Uint8Array

C2spTlogParseError when an entry exceeds 65535 bytes.


function enforceCheckpointPolicy(
checkpoint,
origin,
policy,
scope,
nowMs?,
maxClockSkewMs?
): CheckpointPolicyResult;

Defined in: packages/log-c2sp-tlog/src/policy.ts:114

Enforces the local trust policy on a parsed checkpoint: origin and scope match, a valid signature from an accepted log key, and a satisfied witness quorum of timestamped cosignatures no further than maxClockSkewMs in the future. Public scope additionally requires a non-empty quorum rule.

Checkpoint

string

C2spTlogPolicy

string

number = ...

number = 0

CheckpointPolicyResult

The accepted witness timestamps and derived checkpoint witness time.

C2spTlogVerificationError when any requirement is not met.


function entryBundlePath(
prefix,
n,
width?
): string;

Defined in: packages/log-c2sp-tlog/src/tiles.ts:8

URL of entry bundle n under the C2SP tlog-tiles layout; width selects a partial bundle.

string

number

number

string


function eventToC2spEnvelope(
event,
context?,
includeSigs?
): C2spJsonEvent;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:34

Converts a protocol LogEvent into its c2sp-tlog JSON envelope (v: 1, kind: 'dnsid.lifecycle') with per-type payload fields, the log binding from context, and optionally the event’s existing signatures.

LogEvent

C2spEventContext = {}

boolean = true

C2spJsonEvent

C2spTlogParseError for unsupported event types, malformed lifecycle keys, or missing public-scope binding fields.


function generateC2spTlogStreamId(): string;

Defined in: packages/log-c2sp-tlog/src/lr.ts:27

Generates an opaque identity-instance stream ID using 128 bits of cryptographically secure randomness, encoded as unpadded base64url.

string


function inclusionRoot(
leaf,
index,
treeSize,
proof
): Uint8Array;

Defined in: packages/log-c2sp-tlog/src/merkle.ts:26

Recomputes the Merkle tree root implied by a leaf hash, its index, the tree size, and an RFC 6962 inclusion proof path.

Uint8Array

number

number

Uint8Array<ArrayBufferLike>[]

Uint8Array

Error when the index or tree size is out of range.


function leafHash(entryBytes): Uint8Array;

Defined in: packages/log-c2sp-tlog/src/merkle.ts:11

RFC 6962 leaf hash: SHA-256(0x00 || entry bytes).

Uint8Array

Uint8Array


function merkleRootFromEntries(entries): Uint8Array;

Defined in: packages/log-c2sp-tlog/src/merkle.ts:49

Computes the RFC 6962 Merkle root of an ordered list of entries (empty-tree root for no entries).

Uint8Array<ArrayBufferLike>[]

Uint8Array


function nodeHash(left, right): Uint8Array;

Defined in: packages/log-c2sp-tlog/src/merkle.ts:16

RFC 6962 interior node hash: SHA-256(0x01 || left || right).

Uint8Array

Uint8Array

Uint8Array


function normalizedOriginPolicy(policy, origin): NormalizedOriginPolicy;

Defined in: packages/log-c2sp-tlog/src/policy.ts:63

Resolves and validates the policy for origin: parses key strings, checks signature types (0x01 for log keys, 0x04 for witness cosignature keys), requires distinct underlying public keys, and normalizes the quorum rule.

C2spTlogPolicy

string

NormalizedOriginPolicy

C2spTlogVerificationError when the origin has no policy or the policy is invalid.


function parseC2spEventEntry(bytes, context?): Promise<LogEvent>;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:155

Parses a raw c2sp-tlog log entry (canonical JSON bytes, 1..65535 bytes) into a LogEvent, verifying the bytes are canonical and, for public scope, that the signed log binding matches context.

Uint8Array

C2spEventContext = {}

Promise<LogEvent>

C2spTlogParseError when the entry is oversized, non-canonical, or malformed.


function parseC2spPolicyFile(text): C2spTlogPolicy;

Defined in: packages/log-c2sp-tlog/src/policy.ts:136

Parses a C2SP tlog-policy file (log, witness, group, and exactly one quorum directive) into a C2spTlogPolicy keyed by log-key origin. All configured logs share the declared witnesses and quorum rule.

string

C2spTlogPolicy

C2spTlogVerificationError when a line is malformed, names collide, key types are unsupported, or the quorum directive is missing or repeated.


function parseC2spSignatures(
value,
type,
requireComplete?
): C2spSignatures;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:297

Parses and validates an envelope sigs object for an event type, rejecting roles the type does not allow.

unknown

string

boolean = true

When true, every required role must be present.

C2spSignatures

C2spTlogParseError when the object, a role, or a signature value is invalid.


function parseC2spStreamBundle(bytes, options): C2spStreamBundle;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:121

Parses and structurally validates a canonical-JSON stream bundle without verifying any signatures, proofs, or freshness: exact member sets, canonical base64url fields, a canonical bound lr, and strictly increasing event indexes.

Uint8Array

ParseC2spStreamBundleOptions

C2spStreamBundle

C2spTlogParseError when the bundle is oversized or malformed.


function parseC2spTlogLr(lr): ParsedC2spTlogLr;

Defined in: packages/log-c2sp-tlog/src/lr.ts:39

Parses and validates a c2sp-tlog: log reference as published in an identity record’s lr tag, requiring an already-canonical log prefix.

string

ParsedC2spTlogLr

C2spTlogParseError when any component is missing or non-canonical.


function parseC2spTlogTrustProfile(bytes): C2spTlogTrustProfile;

Defined in: packages/log-c2sp-tlog/src/trust-profile.ts:21

Parses and validates a dnsid-c2sp-tlog-trust-profile@v1 JSON document.

Uint8Array

C2spTlogTrustProfile


function parseCheckpoint(text): Checkpoint;

Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:16

Parses a C2SP checkpoint (c2sp.org/tlog-checkpoint) carried in a signed note: an origin line, decimal tree size, base64 root hash, then a blank line and signature lines. Signatures are parsed but not verified.

string

Checkpoint

C2spTlogParseError when the note body or a signature line is malformed.


function parseEntryBundle(bytes): Uint8Array<ArrayBufferLike>[];

Defined in: packages/log-c2sp-tlog/src/tiles.ts:23

Splits a C2SP tlog-tiles entry bundle (16-bit big-endian length prefix per entry) into individual entry byte strings.

Uint8Array

Uint8Array<ArrayBufferLike>[]

C2spTlogParseError when a length prefix or entry is truncated.


function parseJsonNoDuplicateMembers(bytes): unknown;

Defined in: packages/log-c2sp-tlog/src/canonical.ts:58

Parses UTF-8 JSON bytes, rejecting duplicate object member names anywhere in the document.

Uint8Array

unknown

C2spTlogParseError on invalid UTF-8, malformed JSON, or duplicate members.


function parseNoteSignature(line): NoteSignature;

Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:40

Parses a single C2SP signed-note signature line (— name base64), splitting the leading 4-byte key hash from the signature when present.

string

NoteSignature

C2spTlogParseError when the line does not match the signed-note format.


function parsePreparedC2spTlogEvent(
bytes,
lr,
context?
): Promise<PreparedC2spTlogEvent>;

Defined in: packages/log-c2sp-tlog/src/writer.ts:119

Reconstructs a prepared event from canonical envelope bytes (for example received from another signer), verifying canonical form, the log binding, ISSUANCE expectations, and every signature already present.

Uint8Array

string

PreparedC2spVerificationContext = {}

Promise<PreparedC2spTlogEvent>

C2spTlogParseError when the bytes or envelope are malformed.

C2spTlogVerificationError when expectations or existing signatures fail.


function parseSignedNoteVerifierKey(text): SignedNoteKey;

Defined in: packages/log-c2sp-tlog/src/signed-note.ts:17

Parses a C2SP signed-note (c2sp.org/signed-note) verifier key in either the name+keyid+base64 vkey form or the whitespace-separated name [ed25519] base64 form. The base64 payload may carry a leading signature-type byte before the 32-byte Ed25519 key.

string

SignedNoteKey

C2spTlogParseError when the key text is malformed.


function parseTlogProofV1(text): TlogProofV1;

Defined in: packages/log-c2sp-tlog/src/proof.ts:17

Parses a c2sp.org/tlog-proof@v1 document: magic line, optional extra line, index line, inclusion proof hashes, then a blank line and the embedded checkpoint.

string

TlogProofV1

C2spTlogParseError when any line or the embedded checkpoint is malformed.


function prepareC2spTlogEvent(event, context): C2spJsonEvent;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:229

Builds the unsigned envelope for an event about to be signed, validating the public-scope binding fields against context.

LogEvent

C2spEventContext

C2spJsonEvent

C2spTlogParseError when the event or its public binding is invalid.


function prepareC2spTlogEventForSigning(
event,
lr,
chain?
): PreparedC2spTlogEvent;

Defined in: packages/log-c2sp-tlog/src/writer.ts:96

Stages a lifecycle event for signing against a bound (index-free) log reference, deriving genesis chain metadata for public ISSUANCE and inbound MIGRATION events.

LogEvent

string

C2spChain

PreparedC2spTlogEvent

C2spTlogParseError when the reference, event, or chain metadata is invalid.


function registerC2spTlog(registry, options): void;

Defined in: packages/log-c2sp-tlog/src/index.ts:24

Registers the c2sp-tlog method on a protocol LogRegistry, constructing a C2spTlogReader per lr. Reader options are shared; this low-level registration does not propagate per-invocation signals.

LogRegistry

C2spTlogReaderOptions

void


function requiredC2spResourceFetchGuarantees(): C2spResourceFetchGuarantees;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:74

Returns a copy of the capabilities required by the safe standard-resource factory.

C2spResourceFetchGuarantees


function requiredC2spSignatureNames(type): keyof C2spSignatures[];

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:283

Signature roles a lifecycle event type must carry: ae+op for ISSUANCE, prev_op+new_op for KEY_ROTATION, ae for every other supported type.

string

keyof C2spSignatures[]

C2spTlogParseError for unsupported event types.


function signedC2spEntryBytes(bytes): Uint8Array;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:197

Extracts the signed byte string of a stored entry: the canonical envelope with the sigs member removed. These are the bytes each lifecycle signature covers.

Uint8Array

Uint8Array

C2spTlogParseError when the entry is oversized or non-canonical.


function signedC2spEventBytes(event, context?): Uint8Array;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:219

Canonical to-be-signed bytes for event: its envelope without signatures.

LogEvent

C2spEventContext = {}

Uint8Array


function signPreparedC2spTlogEvent(
prepared,
role,
keyProvider,
options?
): Promise<PreparedC2spTlogEvent>;

Defined in: packages/log-c2sp-tlog/src/writer.ts:143

Adds one role’s signature to a prepared event using the key provider, verifying the provider key matches the key the envelope requires for that role and that existing signatures remain valid.

PreparedC2spTlogEvent

C2spSignerRole

KeyProvider

SignPreparedC2spOptions = {}

Promise<PreparedC2spTlogEvent>

A new prepared event carrying the added signature.

C2spTlogVerificationError when the role is not required, already signed (without replaceExisting), or key/signature checks fail.


function stateHash(state): string;

Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:379

Base64url hash of a lifecycle state object (domain-separated SHA-256 over canonical JSON), as used in prev_state_hash.

unknown

string


function stitchVerifiedMigrationHistory(
domain,
currentEvents,
migration
): Promise<LogEvent[]>;

Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:47

Stitches a verified prior-log history onto the current log’s events for an inbound MIGRATION: the current events must begin with the MIGRATION, the prior history must establish the imported entity and active operational keys (and contain the ISSUANCE genesis), and the combined lifecycle must snapshot cleanly.

string

LogEvent[]

MigrationVerificationResult

Promise<LogEvent[]>

The prior history followed by the current events, in order.

C2spTlogVerificationError (INVALID_MIGRATION) when the prior history does not establish the imported keys or the MIGRATION is duplicated or missing.


function tilePath(
prefix,
level,
n,
width?
): string;

Defined in: packages/log-c2sp-tlog/src/tiles.ts:6

URL of hash tile n at level under the C2SP tlog-tiles layout; width selects a partial tile.

string

number

number

number

string


function validateC2spResourceFetcher(fetcher): void;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:108

Throws a deterministic error when a fetcher cannot safely read public standard resources.

C2spBoundedResourceFetcher

void


function verifiedCosignatureTimestamp(checkpoint, key): number | undefined;

Defined in: packages/log-c2sp-tlog/src/signed-note.ts:45

Finds a valid C2SP tlog-cosignature (type 0x04) by key on the checkpoint and returns its witnessed timestamp in epoch seconds.

Checkpoint

SignedNoteKey

number | undefined

The cosignature timestamp, or undefined when the key is not a cosignature key or no valid cosignature is present.


function verifyC2spConsistencyProof(
fromSize,
toSize,
fromRoot,
toRoot,
proof
): boolean;

Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:100

Verifies an RFC 6962 consistency proof that the tree of size fromSize with root fromRoot is a prefix of the tree of size toSize with root toRoot. Returns false rather than throwing on invalid input.

number

number

Uint8Array

Uint8Array

Uint8Array<ArrayBufferLike>[]

boolean


function verifyC2spStreamBundle(bytes, options): Promise<VerifiedC2spStreamBundle>;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:200

Verifies offline lifecycle evidence for an expected identity and log reference: checks the expected agent FQDN and log reference, the producer signature, the policy hash, checkpoint policy and trusted-checkpoint advancement, freshness and expiry windows, each event’s inclusion proof, and the complete lifecycle history, then confirms the bundle’s asserted state summary. The caller must independently trust the policy, bundle keys, and entity key; this does not verify the DNS identity record or current status.

Uint8Array

VerifyC2spStreamBundleOptions

Promise<VerifiedC2spStreamBundle>

The verified bundle, lifecycle, and active operational key thumbprint.

C2spTlogParseError when the bundle is malformed.

C2spTlogVerificationError when any verification step fails.


function verifyC2spTlogProof(
entryBytes,
proof,
policy,
origin?,
scope?,
nowMs?,
maxClockSkewMs?
): TlogProofV1;

Defined in: packages/log-c2sp-tlog/src/proof.ts:55

Verifies an entry’s inclusion proof: enforces the local checkpoint policy (log signature and witness quorum) and checks the RFC 6962 inclusion path against the checkpoint root.

Uint8Array

string | TlogProofV1

Parsed proof or raw tlog-proof@v1 text.

C2spTlogPolicy

string

string = 'testnet'

number = ...

number = 0

TlogProofV1

The parsed, verified proof.

C2spTlogParseError when a textual proof is malformed.

C2spTlogVerificationError when policy enforcement or the inclusion proof fails.


function verifyCheckpointSignature(checkpoint, key): boolean;

Defined in: packages/log-c2sp-tlog/src/signed-note.ts:34

Returns true when any checkpoint signature matches key by name/key ID and verifies over the signed note text.

Checkpoint

SignedNoteKey

boolean


function verifyInclusion(
entryBytes,
index,
treeSize,
rootHash,
proof
): boolean;

Defined in: packages/log-c2sp-tlog/src/merkle.ts:44

Checks an RFC 6962 inclusion proof for entryBytes at index against the expected tree root.

Uint8Array

number

number

Uint8Array

Uint8Array<ArrayBufferLike>[]

boolean


function verifyLifecycle(events, options?): Promise<void>;

Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:277

Verifies an ordered lifecycle: it must begin with ISSUANCE (or a verified inbound MIGRATION), every event signature must verify against the entity or operational key active at that point, KEY_ROTATION must prove possession of the new key, every scope must carry consistent seq/prev_* fields, and nothing may follow a terminal REVOCATION/RETIREMENT. MIGRATION is valid only as verified inbound genesis in the destination stream.

VerifiedLifecycleEvent[]

StreamVerifierOptions = {}

Promise<void>

C2spTlogVerificationError on any structural or key-continuity violation.

VerificationError (SignatureInvalid) when a signature fails to verify.


function verifyLoggedEventSignature(item, signerKey): Promise<void>;

Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:372

Verifies a single logged event’s primary signature against signerKey over the entry’s signed bytes.

VerifiedLifecycleEvent

DnsIdJWK

Promise<void>

C2spTlogVerificationError when the event has no signature.

VerificationError (SignatureInvalid) when verification fails.


function verifyNoteSignature(
message,
sig,
key
): boolean;

Defined in: packages/log-c2sp-tlog/src/signed-note.ts:60

Verifies one signed-note signature over message with an Ed25519 key. Supports plain log signatures (type 0x01) and timestamped C2SP cosignatures (type 0x04, cosignature/v1 preimage). Returns false rather than throwing.

string

NoteSignature

SignedNoteKey

boolean


function verifyStreamLifecycle(
entries,
domain,
options?
): Promise<VerifiedLifecycleEvent[]>;

Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:162

Extracts and verifies the lifecycle history for one agent domain from entries already authenticated by the accepted completeness mechanism: entries are processed in index order, other domains are skipped, identical signed payloads are deduplicated, and each candidate must keep the accumulated lifecycle valid under verifyLifecycle. A malformed entry that nevertheless carries a valid signatures for every role under verified predecessor authority is treated as a lifecycle violation, not skipped.

IndexedEntry[]

string

StreamVerifierOptions = {}

Promise<VerifiedLifecycleEvent[]>

The accepted events in log order.

C2spTlogVerificationError when the resulting lifecycle is invalid (for example no ISSUANCE event survives).


function writePreparedEvent(prepared, options): Promise<string>;

Defined in: packages/log-c2sp-tlog/src/writer.ts:209

Appends a finalized prepared event to the log via options.submit, running the required chain validation for non-genesis events.

PreparedC2spTlogEvent

C2spTlogAppendOptions

Promise<string>

The event’s log reference (<lr>@<index>).

C2spTlogVerificationError when finalization, chain validation, or the returned index is invalid.