Skip to content

TypeScript: @dnsid-ai/log-c2sp-tlog — interfaces

Part of Transparency log (@dnsid-ai/log-c2sp-tlog).

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:29

Fetches one C2SP resource while enforcing the supplied decoded-byte limit during the read. Implementations must require HTTP 200, reject redirects, honor cancellation and the finite timeout, and provide truthful security capabilities.

fetchBounded(
url,
maxBytes,
options
): Promise<Uint8Array<ArrayBufferLike>>;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:30

string

number

C2spResourceFetchOptions

Promise<Uint8Array<ArrayBufferLike>>

securityGuarantees(): C2spResourceFetchGuarantees;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:31

C2spResourceFetchGuarantees


Defined in: packages/log-c2sp-tlog/src/writer.ts:32

Chain metadata linking a non-genesis event to its predecessor in the stream.

optional previousEventId?: string;

Defined in: packages/log-c2sp-tlog/src/writer.ts:34

optional previousStateHash?: string;

Defined in: packages/log-c2sp-tlog/src/writer.ts:35

sequence: number;

Defined in: packages/log-c2sp-tlog/src/writer.ts:33


Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:34

Fetches RFC 6962 consistency proofs between two tree sizes of a log.

fetchConsistencyProof(
reference,
fromSize,
toSize,
signal?
): Promise<Uint8Array<ArrayBufferLike>[]>;

Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:35

ParsedC2spTlogLr

number

number

AbortSignal

Promise<Uint8Array<ArrayBufferLike>[]>


Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18

Log binding and chaining context stamped into (and expected of) a c2sp-tlog event envelope.

optional logOrigin?: string;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18

optional lr?: string;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18

optional prevEventId?: string;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18

optional prevStateHash?: string;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18

optional scope?: string;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18

optional seq?: number;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18

optional streamId?: string;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18


Defined in: packages/log-c2sp-tlog/src/stream-source.ts:8

Security properties required by the standard-resource verification factory.

boundsResponseDuringRead: boolean;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:13

connectsToValidatedAddress: boolean;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:12

httpsOnly: boolean;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:9

rejectsRedirects: boolean;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:10

validatesAllResolvedAddresses: boolean;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:11


Defined in: packages/log-c2sp-tlog/src/stream-source.ts:17

Cancellation and deadline controls for one bounded resource read.

optional signal?: AbortSignal;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:18

timeoutMs: number;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:20

Finite timeout in milliseconds.


Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:23

Resource limits for the complete standard tlog-tiles scan. Bundle geometry is fixed at 256 entries.

optional maxCheckpointBytes?: number;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:27

Maximum checkpoint response size in bytes (default 1,048,576).

optional maxEntryBundleBytes?: number;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:29

Maximum size of one entry-bundle response (default exactly 16,777,472 bytes).

optional maxTotalEntryBytes?: number;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:31

Maximum combined size of all entry bundles (default 268,435,456 bytes).

optional maxTreeSize?: number;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:25

Maximum accepted checkpoint tree size (default 1,000,000).


Defined in: packages/log-c2sp-tlog/src/event-codec.ts:24

Envelope sigs object keyed by signer role: accountable entity, operational countersignature, previous/new operational key.

optional ae?: C2spSignatureValue;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:24

optional new_op?: C2spSignatureValue;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:24

optional op?: C2spSignatureValue;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:24

optional prev_op?: C2spSignatureValue;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:24


Defined in: packages/log-c2sp-tlog/src/event-codec.ts:22

One envelope signature: signing key ID and unpadded base64url signature.

kid: string;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:22

sig: string;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:22


Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:52

Parsed dnsid-c2sp-stream-bundle (v1): self-contained, offline-verifiable evidence for one agent’s lifecycle stream — a witnessed checkpoint, the stream’s events with inclusion proofs, a state summary, an expiry, and the producer’s signature.

bytes: Uint8Array;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:65

checkpoint: Checkpoint;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:55

checkpointBytes: Uint8Array;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:56

completenessMode: "trusted-index";

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:59

completeThroughSize: number;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:58

events: C2spStreamBundleEvent[];

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:60

expires: number;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:62

fqdn: string;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:53

policyHash: Uint8Array;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:57

reference: ParsedC2spTlogLr;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:54

signature: C2spStreamBundleSignature;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:63

signedBytes: Uint8Array;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:64

state: C2spStreamBundleState;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:61


Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:26

One bundled lifecycle event: log index, raw entry bytes, and its inclusion proof path.

entryBytes: Uint8Array;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:28

index: number;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:27

proof: Uint8Array<ArrayBufferLike>[];

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:29


Defined in: packages/log-c2sp-tlog/src/reader.ts:29

Independently trusted inputs and limits for preferred stream-bundle reads.

bundleKeys: SignedNoteKey[];

Defined in: packages/log-c2sp-tlog/src/reader.ts:31

checkpointFreshnessMs: number;

Defined in: packages/log-c2sp-tlog/src/reader.ts:33

optional maxBundleBytes?: number;

Defined in: packages/log-c2sp-tlog/src/reader.ts:34

maxBundleLifetimeMs: number;

Defined in: packages/log-c2sp-tlog/src/reader.ts:32

optional maxEvents?: number;

Defined in: packages/log-c2sp-tlog/src/reader.ts:35

policyDocument: Uint8Array;

Defined in: packages/log-c2sp-tlog/src/reader.ts:30

optional required?: boolean;

Defined in: packages/log-c2sp-tlog/src/reader.ts:37

Disables raw-scan fallback when the bundle endpoint is unavailable.


Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:40

Bundle producer’s Ed25519 signature over the bundle’s signed bytes.

alg: "EdDSA";

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:41

kid: string;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:42

value: Uint8Array;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:43


Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:33

Bundle-asserted lifecycle summary, checked against the verified history.

eventCount: number;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:34

lastEventType: string;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:35

loggedState: "UNKNOWN" | "ACTIVE" | "RETIRED" | "REVOKED";

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:36


Defined in: packages/log-c2sp-tlog/src/writer.ts:67

Options for writePreparedEvent; submit performs the deployment-specific append.

optional entityKey?: DnsIdJWK;

Defined in: packages/log-c2sp-tlog/src/writer.ts:54

Trusted accountable-entity key. Required when countersigning or serializing ISSUANCE.

PreparedC2spVerificationContext.entityKey

optional expectedFqdn?: string;

Defined in: packages/log-c2sp-tlog/src/writer.ts:50

Locally expected DNS identity. Required when countersigning or serializing ISSUANCE.

PreparedC2spVerificationContext.expectedFqdn

optional expectedGovernanceId?: string;

Defined in: packages/log-c2sp-tlog/src/writer.ts:52

Locally expected governance identifier. Required when countersigning or serializing ISSUANCE.

PreparedC2spVerificationContext.expectedGovernanceId

optional idempotencyKey?: string;

Defined in: packages/log-c2sp-tlog/src/writer.ts:70

optional operationalKey?: DnsIdJWK;

Defined in: packages/log-c2sp-tlog/src/writer.ts:56

Trusted initial operational key. Required when countersigning or serializing ISSUANCE.

PreparedC2spVerificationContext.operationalKey

optional previousOperationalKey?: DnsIdJWK;

Defined in: packages/log-c2sp-tlog/src/writer.ts:57

PreparedC2spVerificationContext.previousOperationalKey

submit: (entryBytes, idempotencyKey?) => Promise<{
index: number;
}>;

Defined in: packages/log-c2sp-tlog/src/writer.ts:69

Appends the finished entry bytes to the log and returns its assigned index.

Uint8Array

string

Promise<{ index: number; }>

optional validateChain?: (prepared) => Promise<void>;

Defined in: packages/log-c2sp-tlog/src/writer.ts:72

Required for non-genesis events to validate authoritative prior stream state.

PreparedC2spTlogEvent

Promise<void>


Defined in: packages/log-c2sp-tlog/src/policy.ts:15

Local trust configuration for one checkpoint origin. Keys may be parsed or in signed-note verifier-key text form.

logKeys: (string | SignedNoteKey)[];

Defined in: packages/log-c2sp-tlog/src/policy.ts:17

Accepted log signing keys; each key name must equal the origin.

optional quorum?: number;

Defined in: packages/log-c2sp-tlog/src/policy.ts:21

Flat witness quorum count; superseded by quorumRule when both are set.

optional quorumRule?: C2spTlogQuorumRule;

Defined in: packages/log-c2sp-tlog/src/policy.ts:22

optional unchained?: boolean;

Defined in: packages/log-c2sp-tlog/src/policy.ts:24

Ignored: every scope requires a logical predecessor chain.

optional witnessKeys?: (string | SignedNoteKey)[];

Defined in: packages/log-c2sp-tlog/src/policy.ts:19

Witness cosignature keys used by the flat quorum count when no quorumRule is given.


Defined in: packages/log-c2sp-tlog/src/policy.ts:28

Local C2SP tlog trust policy: per-origin rules, optionally pinned to one lr scope.

origins: Record<string, C2spTlogOriginPolicy>;

Defined in: packages/log-c2sp-tlog/src/policy.ts:30

optional scope?: string;

Defined in: packages/log-c2sp-tlog/src/policy.ts:29


Defined in: packages/log-c2sp-tlog/src/reader.ts:41

Configuration for C2spTlogReader; only policy is required.

optional allowedClockSkew?: number;

Defined in: packages/log-c2sp-tlog/src/reader.ts:57

Accepted timestamp clock skew in milliseconds (default zero).

optional checkpointMaxAge?: number;

Defined in: packages/log-c2sp-tlog/src/reader.ts:59

Maximum checkpoint age in milliseconds; required by verifyNonRevocation.

optional consistencyProofSource?: C2spConsistencyProofSource;

Defined in: packages/log-c2sp-tlog/src/reader.ts:68

optional entityKey?: DnsIdJWK;

Defined in: packages/log-c2sp-tlog/src/reader.ts:55

Trusted accountable-entity key for lifecycle verification.

optional maxCheckpointBytes?: number;

Defined in: packages/log-c2sp-tlog/src/reader.ts:61

optional maxEntryBundleBytes?: number;

Defined in: packages/log-c2sp-tlog/src/reader.ts:62

optional maxTotalEntryBytes?: number;

Defined in: packages/log-c2sp-tlog/src/reader.ts:63

optional maxTreeSize?: number;

Defined in: packages/log-c2sp-tlog/src/reader.ts:60

policy: C2spTlogPolicy;

Defined in: packages/log-c2sp-tlog/src/reader.ts:43

Local trust policy: accepted log keys and witness quorum per origin.

optional proofs?: Record<string, string | TlogProofV1>;

Defined in: packages/log-c2sp-tlog/src/reader.ts:51

Inclusion proofs by entry index, required by readEvent for historical refs.

optional requestTimeoutMs?: number;

Defined in: packages/log-c2sp-tlog/src/reader.ts:64

optional resourceFetcher?: C2spBoundedResourceFetcher;

Defined in: packages/log-c2sp-tlog/src/reader.ts:45

Bounded resource fetcher for the default ScanStreamSource and stream-bundle reads.

optional signal?: AbortSignal;

Defined in: packages/log-c2sp-tlog/src/reader.ts:65

optional streamBundle?: C2spStreamBundleReaderOptions;

Defined in: packages/log-c2sp-tlog/src/reader.ts:49

Preferred verified per-domain bundle source. Raw scans are the bounded fallback for unavailable bundles or missing consistency evidence.

optional streamSource?: StreamSource;

Defined in: packages/log-c2sp-tlog/src/reader.ts:47

Alternative raw evidence source; defaults to a complete tlog-tiles scan.

optional trustedCheckpointStore?: TrustedC2spCheckpointStore;

Defined in: packages/log-c2sp-tlog/src/reader.ts:67

optional unchained?: boolean;

Defined in: packages/log-c2sp-tlog/src/reader.ts:53

Ignored: all scopes require logical predecessor chains.

optional verifyMigration?: (event, options?) => Promise<MigrationVerificationResult>;

Defined in: packages/log-c2sp-tlog/src/reader.ts:66

MigrationEvent

VerificationOptions

Promise<MigrationVerificationResult>


Defined in: packages/log-c2sp-tlog/src/trust-profile.ts:12

Independently distributed trust for one exact DNSid C2SP log.

bundleVerifierKeys: SignedNoteKey[];

Defined in: packages/log-c2sp-tlog/src/trust-profile.ts:17

logPrefix: string;

Defined in: packages/log-c2sp-tlog/src/trust-profile.ts:15

policyDocument: Uint8Array;

Defined in: packages/log-c2sp-tlog/src/trust-profile.ts:16

scope: C2spTlogScope;

Defined in: packages/log-c2sp-tlog/src/trust-profile.ts:14

version: 1;

Defined in: packages/log-c2sp-tlog/src/trust-profile.ts:13


Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:38

Options for createC2spTlogVerificationRegistry. Exactly one of trustProfile, policyDocument, and policyUrl is required.

optional allowedClockSkew?: number;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:71

Accepted timestamp clock skew in milliseconds (default zero).

optional bundleVerifierKeys?: SignedNoteKey[];

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:56

Independently trusted stream-bundle signer keys. Mutually exclusive with trustProfile.

optional checkpointMaxAge?: number;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:69

Maximum accepted checkpoint age in milliseconds for fresh logged-state and non-revocation checks. Omission intentionally makes those operations fail closed.

optional maxBundleLifetimeMs?: number;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:58

Maximum bundle expiry distance from its witnessed checkpoint. Required with bundle verifier keys.

optional maxPolicyBytes?: number;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:75

Maximum policy size in bytes (default 1,048,576).

optional maxStreamBundleBytes?: number;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:60

Maximum decoded stream-bundle response size (default 8 MiB).

optional maxStreamBundleEvents?: number;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:62

Maximum lifecycle events in one stream bundle (default 10,000).

optional policyDocument?: Uint8Array<ArrayBufferLike>;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:42

Independently trusted C2SP tlog-policy bytes, parsed locally.

optional policyUrl?: string;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:44

Independently trusted absolute HTTPS URL of a C2SP tlog-policy document.

optional requestTimeoutMs?: number;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:77

Finite timeout for each policy/log resource request (default 10 seconds).

optional requireStreamBundle?: boolean;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:64

Fail instead of using the bounded raw scanner when the bundle endpoint is unavailable.

optional resourceFetcher?: C2spBoundedResourceFetcher;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:46

Bounded transport used for both policy and standard log resources.

optional scanLimits?: C2spScanLimits;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:54

Optional overrides for the built-in complete scanner’s secure limits.

optional signal?: AbortSignal;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:79

Cancels policy retrieval and later reads made by readers from this registry.

optional transport?: TransportConfig;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:52

DNS server, CA bundle, and private-address exceptions for the default resource fetcher; pass the same DnsidConfig.transport given to the IdentityManager when verifying against a private registry such as dnsid local. Mutually exclusive with resourceFetcher.

optional trustedCheckpointStore?: TrustedC2spCheckpointStore;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:73

Persistence for accepted checkpoints. The default is process-lifetime only.

optional trustProfile?: C2spTlogTrustProfile;

Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:40

Independently distributed trust profile for one exact log.


Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:7

Parsed C2SP tlog-checkpoint: origin, tree size, SHA-256 root hash, and the signed-note signatures over signedText.

origin: string;

Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:7

rootHash: Uint8Array;

Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:7

signatures: NoteSignature[];

Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:7

signedText: string;

Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:7

treeSize: number;

Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:7


Defined in: packages/log-c2sp-tlog/src/policy.ts:49

Outcome of checkpoint policy enforcement.

acceptedWitnessTimestamps: number[];

Defined in: packages/log-c2sp-tlog/src/policy.ts:51

Epoch-second timestamps of the accepted witness cosignatures.

optional checkpointWitnessTime?: Date;

Defined in: packages/log-c2sp-tlog/src/policy.ts:53

Earliest accepted witness timestamp; undefined when the quorum rule required no witnesses.


Defined in: packages/log-c2sp-tlog/src/managed-verification-registry.ts:38

Shared infrastructure for createDnsidManagedVerificationRegistry.

optional resourceFetcher?: C2spBoundedResourceFetcher;

Defined in: packages/log-c2sp-tlog/src/managed-verification-registry.ts:40

Bounded transport shared by every managed log reader.

optional signal?: AbortSignal;

Defined in: packages/log-c2sp-tlog/src/managed-verification-registry.ts:44

Cancels reads made by readers from this registry.

optional trustedCheckpointStore?: TrustedC2spCheckpointStore;

Defined in: packages/log-c2sp-tlog/src/managed-verification-registry.ts:42

Persistence shared by every managed log reader. The default is restart-ephemeral.


Defined in: packages/log-c2sp-tlog/src/stream-source.ts:35

A raw log entry together with its index in the tree.

bytes: Uint8Array;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:35

index: number;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:35


Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:13

Keys and history established by verifying an inbound MIGRATION against the prior log.

activeOperationalKey: DnsIdJWK;

Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:17

Operational key active at the prior log’s final entry.

entityKey: DnsIdJWK;

Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:15

Accountable-entity key established by the prior log’s lifecycle.

priorHistory: LogEvent[];

Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:19

Fully verified prior-log lifecycle through the migration’s finalEntryRef.

optional priorHistoryReferences?: string[];

Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:21

Verified log reference for each priorHistory event, in the same order. Required for logged-state evidence.


Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:5

One C2SP signed-note signature line: signer name, optional 4-byte key hash, and raw signature bytes.

optional keyHash?: Uint8Array<ArrayBufferLike>;

Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:5

name: string;

Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:5

raw: string;

Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:5

signature: Uint8Array;

Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:5


Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:69

Size limits applied while parsing an untrusted stream bundle.

maxBundleBytes: number;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:70

maxEvents: number;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:71


Defined in: packages/log-c2sp-tlog/src/lr.ts:8

Components of a parsed c2sp-tlog:<scope>:<logPrefix>#<streamId>[@index] log reference.

optional entryIndex?: number;

Defined in: packages/log-c2sp-tlog/src/lr.ts:16

logPrefix: string;

Defined in: packages/log-c2sp-tlog/src/lr.ts:11

lr: string;

Defined in: packages/log-c2sp-tlog/src/lr.ts:15

Canonical bound reference without an entry index.

method: "c2sp-tlog";

Defined in: packages/log-c2sp-tlog/src/lr.ts:9

origin: string;

Defined in: packages/log-c2sp-tlog/src/lr.ts:13

scope: C2spTlogScope;

Defined in: packages/log-c2sp-tlog/src/lr.ts:10

streamId: string;

Defined in: packages/log-c2sp-tlog/src/lr.ts:12


Defined in: packages/log-c2sp-tlog/src/writer.ts:39

Immutable lifecycle event staged for signing and append: envelope, signed bytes, and the roles still required.

readonly envelope: Readonly<C2spJsonEvent>;

Defined in: packages/log-c2sp-tlog/src/writer.ts:41

readonly eventId: string;

Defined in: packages/log-c2sp-tlog/src/writer.ts:43

readonly reference: ParsedC2spTlogLr;

Defined in: packages/log-c2sp-tlog/src/writer.ts:40

readonly requiredSignatures: readonly C2spSignerRole[];

Defined in: packages/log-c2sp-tlog/src/writer.ts:44

readonly signedBytes: Uint8Array;

Defined in: packages/log-c2sp-tlog/src/writer.ts:42


Defined in: packages/log-c2sp-tlog/src/writer.ts:48

Trusted expectations a prepared event (and its existing signatures) is validated against.

optional entityKey?: DnsIdJWK;

Defined in: packages/log-c2sp-tlog/src/writer.ts:54

Trusted accountable-entity key. Required when countersigning or serializing ISSUANCE.

optional expectedFqdn?: string;

Defined in: packages/log-c2sp-tlog/src/writer.ts:50

Locally expected DNS identity. Required when countersigning or serializing ISSUANCE.

optional expectedGovernanceId?: string;

Defined in: packages/log-c2sp-tlog/src/writer.ts:52

Locally expected governance identifier. Required when countersigning or serializing ISSUANCE.

optional operationalKey?: DnsIdJWK;

Defined in: packages/log-c2sp-tlog/src/writer.ts:56

Trusted initial operational key. Required when countersigning or serializing ISSUANCE.

optional previousOperationalKey?: DnsIdJWK;

Defined in: packages/log-c2sp-tlog/src/writer.ts:57


Defined in: packages/log-c2sp-tlog/src/stream-source.ts:43

Configuration for ScanStreamSource; the byte/size limits bound untrusted responses.

authenticateCheckpoint: (checkpoint) => void | Promise<void>;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:45

Called with the parsed checkpoint before any entries are fetched; throw to reject it.

Checkpoint

void | Promise<void>

optional maxCheckpointBytes?: number;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:47

optional maxEntryBundleBytes?: number;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:48

optional maxTotalEntryBytes?: number;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:49

optional maxTreeSize?: number;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:46

optional requestTimeoutMs?: number;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:51

Finite deadline for each resource read (default 10 seconds).

optional signal?: AbortSignal;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:53

Cancels current and subsequent resource reads.


Defined in: packages/log-c2sp-tlog/src/signed-note.ts:7

Trusted C2SP signed-note verifier key: Ed25519 public key with optional 4-byte key ID and signature-type byte.

keyBytes: Uint8Array;

Defined in: packages/log-c2sp-tlog/src/signed-note.ts:7

optional keyId?: Uint8Array<ArrayBufferLike>;

Defined in: packages/log-c2sp-tlog/src/signed-note.ts:7

kind: "ed25519";

Defined in: packages/log-c2sp-tlog/src/signed-note.ts:7

name: string;

Defined in: packages/log-c2sp-tlog/src/signed-note.ts:7

optional signatureType?: Uint8Array<ArrayBufferLike>;

Defined in: packages/log-c2sp-tlog/src/signed-note.ts:7


Defined in: packages/log-c2sp-tlog/src/writer.ts:61

Options for signPreparedC2spTlogEvent.

optional entityKey?: DnsIdJWK;

Defined in: packages/log-c2sp-tlog/src/writer.ts:54

Trusted accountable-entity key. Required when countersigning or serializing ISSUANCE.

PreparedC2spVerificationContext.entityKey

optional expectedFqdn?: string;

Defined in: packages/log-c2sp-tlog/src/writer.ts:50

Locally expected DNS identity. Required when countersigning or serializing ISSUANCE.

PreparedC2spVerificationContext.expectedFqdn

optional expectedGovernanceId?: string;

Defined in: packages/log-c2sp-tlog/src/writer.ts:52

Locally expected governance identifier. Required when countersigning or serializing ISSUANCE.

PreparedC2spVerificationContext.expectedGovernanceId

optional operationalKey?: DnsIdJWK;

Defined in: packages/log-c2sp-tlog/src/writer.ts:56

Trusted initial operational key. Required when countersigning or serializing ISSUANCE.

PreparedC2spVerificationContext.operationalKey

optional previousOperationalKey?: DnsIdJWK;

Defined in: packages/log-c2sp-tlog/src/writer.ts:57

PreparedC2spVerificationContext.previousOperationalKey

optional replaceExisting?: boolean;

Defined in: packages/log-c2sp-tlog/src/writer.ts:63

Allow overwriting an existing signature for the same role.


Defined in: packages/log-c2sp-tlog/src/stream-source.ts:37

Log evidence loaded from a source: the checkpoint, entries, and whether every entry up to the tree size is present.

checkpoint: Checkpoint;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:37

complete: boolean;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:37

entries: IndexedEntry[];

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:37


Defined in: packages/log-c2sp-tlog/src/stream-source.ts:40

Supplies checkpoint-plus-entries evidence for a log prefix.

load(prefix, options?): Promise<StreamEvidence>;

Defined in: packages/log-c2sp-tlog/src/stream-source.ts:40

string

AbortSignal

Promise<StreamEvidence>


Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:24

Options controlling lifecycle verification of a stream’s entries.

optional checkpointIntegrationTimeMs?: number;

Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:30

Latest acceptable event timestamp (checkpoint witness time plus skew), in epoch milliseconds. Required.

optional logOrigin?: string;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18

C2spEventContext.logOrigin

optional lr?: string;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18

C2spEventContext.lr

optional prevEventId?: string;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18

C2spEventContext.prevEventId

optional prevStateHash?: string;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18

C2spEventContext.prevStateHash

optional scope?: string;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18

C2spEventContext.scope

optional seq?: number;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18

C2spEventContext.seq

optional signal?: AbortSignal;

Defined in: packages/protocol/src/verification-budget.ts:6

VerificationOptions.signal

optional signerKey?: DnsIdJWK;

Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:28

Trusted accountable-entity key the lifecycle’s entity key must match.

optional streamId?: string;

Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18

C2spEventContext.streamId

optional timeoutMs?: number;

Defined in: packages/protocol/src/verification-budget.ts:5

Overall invocation budget, including all discovery and evidence. Default: 30 seconds.

VerificationOptions.timeoutMs

optional unchained?: boolean;

Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:26

Ignored: every scope requires the logical predecessor chain.

optional verifyMigration?: (event, options?) => Promise<MigrationVerificationResult>;

Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:32

Verifies an inbound MIGRATION’s prior-log history and returns the migrated keys.

MigrationEvent

VerificationOptions

Promise<MigrationVerificationResult>


Defined in: packages/log-c2sp-tlog/src/proof.ts:8

Parsed C2SP tlog-proof@v1: entry index, inclusion proof hashes, and the checkpoint the proof leads to.

checkpoint: Checkpoint;

Defined in: packages/log-c2sp-tlog/src/proof.ts:8

optional extra?: string[];

Defined in: packages/log-c2sp-tlog/src/proof.ts:8

hashes: Uint8Array<ArrayBufferLike>[];

Defined in: packages/log-c2sp-tlog/src/proof.ts:8

index: number;

Defined in: packages/log-c2sp-tlog/src/proof.ts:8


Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:9

Latest policy-accepted checkpoint remembered for a log origin, with its witnessed time.

origin: string;

Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:10

rootHash: Uint8Array;

Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:12

treeSize: number;

Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:11

witnessTime: Date;

Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:13


Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:17

Persistence for per-origin trusted checkpoints, updated with optimistic compare-and-swap semantics.

compareAndSwap(
origin,
expected,
candidate,
signal?
): Promise<boolean>;

Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:25

Atomically replaces expected with candidate; returns false on a lost race. Implementations must honor cancellation at the commit boundary: an aborted signal must prevent a pending write, not merely reject its returned promise.

string

TrustedC2spCheckpoint | undefined

TrustedC2spCheckpoint

AbortSignal

Promise<boolean>

load(origin, signal?): Promise<TrustedC2spCheckpoint | undefined>;

Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:19

Returns the currently trusted checkpoint for origin, if any.

string

AbortSignal

Promise<TrustedC2spCheckpoint | undefined>


Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:102

Result of successful stream bundle verification.

activeOperationalKeyThumbprint: string;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:110

Thumbprint of the agent’s operational key after the last verified event.

bundle: C2spStreamBundle;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:103

checkpointWitnessTime: Date;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:111

events: VerifiedLifecycleEvent[];

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:104

optional historyReferences?: string[];

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:108

Verified log reference aligned with each stitched lifecycle event, when prior migration boundaries were supplied.

lifecycle: LogEvent[];

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:106

The verified lifecycle events in log order.


Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:11

A lifecycle event accepted by stream verification, with its log index, leaf hash, and raw entry bytes.

bytes: Uint8Array;

Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:11

event: LogEvent;

Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:11

index: number;

Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:11

leafHash: Uint8Array;

Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:11


Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:75

Trusted inputs and freshness limits for verifying a stream bundle.

bundleKeys: SignedNoteKey[];

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:83

Trusted bundle-producer keys (with key IDs) accepted for the bundle signature.

checkpointFreshnessMs: number;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:89

Maximum accepted checkpoint age relative to now.

optional consistencyProofSource?: C2spConsistencyProofSource;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:96

entityKey: DnsIdJWK;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:85

Trusted accountable-entity key for the identity record.

expectedFqdn: string;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:77

DNS name of the agent the bundle must describe.

expectedLogReference: string;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:79

Canonical bound c2sp-tlog lr the bundle must reference.

maxBundleBytes: number;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:70

ParseC2spStreamBundleOptions.maxBundleBytes

maxBundleLifetimeMs: number;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:87

Maximum allowed distance between checkpoint witness time and bundle expiry.

optional maxClockSkewMs?: number;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:92

maxEvents: number;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:71

ParseC2spStreamBundleOptions.maxEvents

optional maxTreeSize?: number;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:91

Maximum accepted checkpoint tree size (default 1,000,000).

optional nowMs?: number;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:93

policyBytes: Uint8Array;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:81

Local C2SP policy file bytes; their hash must match the bundle’s policy_hash.

optional signal?: AbortSignal;

Defined in: packages/protocol/src/verification-budget.ts:6

VerificationOptions.signal

optional timeoutMs?: number;

Defined in: packages/protocol/src/verification-budget.ts:5

Overall invocation budget, including all discovery and evidence. Default: 30 seconds.

VerificationOptions.timeoutMs

trustedCheckpointStore: TrustedC2spCheckpointStore;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:95

optional verifyMigration?: (event, options?) => Promise<MigrationVerificationResult>;

Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:94

MigrationEvent

VerificationOptions

Promise<MigrationVerificationResult>