TypeScript: @dnsid-ai/log-c2sp-tlog — interfaces
Part of Transparency log (@dnsid-ai/log-c2sp-tlog).
Interfaces
Section titled “Interfaces”C2spBoundedResourceFetcher
Section titled “C2spBoundedResourceFetcher”Defined in: packages/log-c2sp-tlog/src/stream-source.ts:29
Fetches one C2SP resource while enforcing the supplied decoded-byte limit during the read. Implementations must require HTTP 200, reject redirects, honor cancellation and the finite timeout, and provide truthful security capabilities.
Methods
Section titled “Methods”fetchBounded()
Section titled “fetchBounded()”fetchBounded( url, maxBytes, options): Promise<Uint8Array<ArrayBufferLike>>;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:30
Parameters
Section titled “Parameters”string
maxBytes
Section titled “maxBytes”number
options
Section titled “options”Returns
Section titled “Returns”Promise<Uint8Array<ArrayBufferLike>>
securityGuarantees()
Section titled “securityGuarantees()”securityGuarantees(): C2spResourceFetchGuarantees;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:31
Returns
Section titled “Returns”C2spChain
Section titled “C2spChain”Defined in: packages/log-c2sp-tlog/src/writer.ts:32
Chain metadata linking a non-genesis event to its predecessor in the stream.
Properties
Section titled “Properties”previousEventId?
Section titled “previousEventId?”optional previousEventId?: string;Defined in: packages/log-c2sp-tlog/src/writer.ts:34
previousStateHash?
Section titled “previousStateHash?”optional previousStateHash?: string;Defined in: packages/log-c2sp-tlog/src/writer.ts:35
sequence
Section titled “sequence”sequence: number;Defined in: packages/log-c2sp-tlog/src/writer.ts:33
C2spConsistencyProofSource
Section titled “C2spConsistencyProofSource”Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:34
Fetches RFC 6962 consistency proofs between two tree sizes of a log.
Methods
Section titled “Methods”fetchConsistencyProof()
Section titled “fetchConsistencyProof()”fetchConsistencyProof( reference, fromSize, toSize, signal?): Promise<Uint8Array<ArrayBufferLike>[]>;Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:35
Parameters
Section titled “Parameters”reference
Section titled “reference”fromSize
Section titled “fromSize”number
toSize
Section titled “toSize”number
signal?
Section titled “signal?”AbortSignal
Returns
Section titled “Returns”Promise<Uint8Array<ArrayBufferLike>[]>
C2spEventContext
Section titled “C2spEventContext”Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18
Log binding and chaining context stamped into (and expected of) a c2sp-tlog event envelope.
Extended by
Section titled “Extended by”Properties
Section titled “Properties”logOrigin?
Section titled “logOrigin?”optional logOrigin?: string;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18
optional lr?: string;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18
prevEventId?
Section titled “prevEventId?”optional prevEventId?: string;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18
prevStateHash?
Section titled “prevStateHash?”optional prevStateHash?: string;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18
scope?
Section titled “scope?”optional scope?: string;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18
optional seq?: number;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18
streamId?
Section titled “streamId?”optional streamId?: string;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18
C2spResourceFetchGuarantees
Section titled “C2spResourceFetchGuarantees”Defined in: packages/log-c2sp-tlog/src/stream-source.ts:8
Security properties required by the standard-resource verification factory.
Properties
Section titled “Properties”boundsResponseDuringRead
Section titled “boundsResponseDuringRead”boundsResponseDuringRead: boolean;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:13
connectsToValidatedAddress
Section titled “connectsToValidatedAddress”connectsToValidatedAddress: boolean;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:12
httpsOnly
Section titled “httpsOnly”httpsOnly: boolean;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:9
rejectsRedirects
Section titled “rejectsRedirects”rejectsRedirects: boolean;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:10
validatesAllResolvedAddresses
Section titled “validatesAllResolvedAddresses”validatesAllResolvedAddresses: boolean;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:11
C2spResourceFetchOptions
Section titled “C2spResourceFetchOptions”Defined in: packages/log-c2sp-tlog/src/stream-source.ts:17
Cancellation and deadline controls for one bounded resource read.
Properties
Section titled “Properties”signal?
Section titled “signal?”optional signal?: AbortSignal;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:18
timeoutMs
Section titled “timeoutMs”timeoutMs: number;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:20
Finite timeout in milliseconds.
C2spScanLimits
Section titled “C2spScanLimits”Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:23
Resource limits for the complete standard tlog-tiles scan. Bundle geometry is fixed at 256 entries.
Properties
Section titled “Properties”maxCheckpointBytes?
Section titled “maxCheckpointBytes?”optional maxCheckpointBytes?: number;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:27
Maximum checkpoint response size in bytes (default 1,048,576).
maxEntryBundleBytes?
Section titled “maxEntryBundleBytes?”optional maxEntryBundleBytes?: number;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:29
Maximum size of one entry-bundle response (default exactly 16,777,472 bytes).
maxTotalEntryBytes?
Section titled “maxTotalEntryBytes?”optional maxTotalEntryBytes?: number;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:31
Maximum combined size of all entry bundles (default 268,435,456 bytes).
maxTreeSize?
Section titled “maxTreeSize?”optional maxTreeSize?: number;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:25
Maximum accepted checkpoint tree size (default 1,000,000).
C2spSignatures
Section titled “C2spSignatures”Defined in: packages/log-c2sp-tlog/src/event-codec.ts:24
Envelope sigs object keyed by signer role: accountable entity, operational countersignature, previous/new operational key.
Properties
Section titled “Properties”optional ae?: C2spSignatureValue;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:24
new_op?
Section titled “new_op?”optional new_op?: C2spSignatureValue;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:24
optional op?: C2spSignatureValue;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:24
prev_op?
Section titled “prev_op?”optional prev_op?: C2spSignatureValue;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:24
C2spSignatureValue
Section titled “C2spSignatureValue”Defined in: packages/log-c2sp-tlog/src/event-codec.ts:22
One envelope signature: signing key ID and unpadded base64url signature.
Properties
Section titled “Properties”kid: string;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:22
sig: string;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:22
C2spStreamBundle
Section titled “C2spStreamBundle”Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:52
Parsed dnsid-c2sp-stream-bundle (v1): self-contained, offline-verifiable
evidence for one agent’s lifecycle stream — a witnessed checkpoint, the
stream’s events with inclusion proofs, a state summary, an expiry, and the
producer’s signature.
Properties
Section titled “Properties”bytes: Uint8Array;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:65
checkpoint
Section titled “checkpoint”checkpoint: Checkpoint;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:55
checkpointBytes
Section titled “checkpointBytes”checkpointBytes: Uint8Array;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:56
completenessMode
Section titled “completenessMode”completenessMode: "trusted-index";Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:59
completeThroughSize
Section titled “completeThroughSize”completeThroughSize: number;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:58
events
Section titled “events”events: C2spStreamBundleEvent[];Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:60
expires
Section titled “expires”expires: number;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:62
fqdn: string;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:53
policyHash
Section titled “policyHash”policyHash: Uint8Array;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:57
reference
Section titled “reference”reference: ParsedC2spTlogLr;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:54
signature
Section titled “signature”signature: C2spStreamBundleSignature;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:63
signedBytes
Section titled “signedBytes”signedBytes: Uint8Array;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:64
state: C2spStreamBundleState;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:61
C2spStreamBundleEvent
Section titled “C2spStreamBundleEvent”Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:26
One bundled lifecycle event: log index, raw entry bytes, and its inclusion proof path.
Properties
Section titled “Properties”entryBytes
Section titled “entryBytes”entryBytes: Uint8Array;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:28
index: number;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:27
proof: Uint8Array<ArrayBufferLike>[];Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:29
C2spStreamBundleReaderOptions
Section titled “C2spStreamBundleReaderOptions”Defined in: packages/log-c2sp-tlog/src/reader.ts:29
Independently trusted inputs and limits for preferred stream-bundle reads.
Properties
Section titled “Properties”bundleKeys
Section titled “bundleKeys”bundleKeys: SignedNoteKey[];Defined in: packages/log-c2sp-tlog/src/reader.ts:31
checkpointFreshnessMs
Section titled “checkpointFreshnessMs”checkpointFreshnessMs: number;Defined in: packages/log-c2sp-tlog/src/reader.ts:33
maxBundleBytes?
Section titled “maxBundleBytes?”optional maxBundleBytes?: number;Defined in: packages/log-c2sp-tlog/src/reader.ts:34
maxBundleLifetimeMs
Section titled “maxBundleLifetimeMs”maxBundleLifetimeMs: number;Defined in: packages/log-c2sp-tlog/src/reader.ts:32
maxEvents?
Section titled “maxEvents?”optional maxEvents?: number;Defined in: packages/log-c2sp-tlog/src/reader.ts:35
policyDocument
Section titled “policyDocument”policyDocument: Uint8Array;Defined in: packages/log-c2sp-tlog/src/reader.ts:30
required?
Section titled “required?”optional required?: boolean;Defined in: packages/log-c2sp-tlog/src/reader.ts:37
Disables raw-scan fallback when the bundle endpoint is unavailable.
C2spStreamBundleSignature
Section titled “C2spStreamBundleSignature”Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:40
Bundle producer’s Ed25519 signature over the bundle’s signed bytes.
Properties
Section titled “Properties”alg: "EdDSA";Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:41
kid: string;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:42
value: Uint8Array;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:43
C2spStreamBundleState
Section titled “C2spStreamBundleState”Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:33
Bundle-asserted lifecycle summary, checked against the verified history.
Properties
Section titled “Properties”eventCount
Section titled “eventCount”eventCount: number;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:34
lastEventType
Section titled “lastEventType”lastEventType: string;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:35
loggedState
Section titled “loggedState”loggedState: "UNKNOWN" | "ACTIVE" | "RETIRED" | "REVOKED";Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:36
C2spTlogAppendOptions
Section titled “C2spTlogAppendOptions”Defined in: packages/log-c2sp-tlog/src/writer.ts:67
Options for writePreparedEvent; submit performs the deployment-specific append.
Extends
Section titled “Extends”Properties
Section titled “Properties”entityKey?
Section titled “entityKey?”optional entityKey?: DnsIdJWK;Defined in: packages/log-c2sp-tlog/src/writer.ts:54
Trusted accountable-entity key. Required when countersigning or serializing ISSUANCE.
Inherited from
Section titled “Inherited from”PreparedC2spVerificationContext.entityKey
expectedFqdn?
Section titled “expectedFqdn?”optional expectedFqdn?: string;Defined in: packages/log-c2sp-tlog/src/writer.ts:50
Locally expected DNS identity. Required when countersigning or serializing ISSUANCE.
Inherited from
Section titled “Inherited from”PreparedC2spVerificationContext.expectedFqdn
expectedGovernanceId?
Section titled “expectedGovernanceId?”optional expectedGovernanceId?: string;Defined in: packages/log-c2sp-tlog/src/writer.ts:52
Locally expected governance identifier. Required when countersigning or serializing ISSUANCE.
Inherited from
Section titled “Inherited from”PreparedC2spVerificationContext.expectedGovernanceId
idempotencyKey?
Section titled “idempotencyKey?”optional idempotencyKey?: string;Defined in: packages/log-c2sp-tlog/src/writer.ts:70
operationalKey?
Section titled “operationalKey?”optional operationalKey?: DnsIdJWK;Defined in: packages/log-c2sp-tlog/src/writer.ts:56
Trusted initial operational key. Required when countersigning or serializing ISSUANCE.
Inherited from
Section titled “Inherited from”PreparedC2spVerificationContext.operationalKey
previousOperationalKey?
Section titled “previousOperationalKey?”optional previousOperationalKey?: DnsIdJWK;Defined in: packages/log-c2sp-tlog/src/writer.ts:57
Inherited from
Section titled “Inherited from”PreparedC2spVerificationContext.previousOperationalKey
submit
Section titled “submit”submit: (entryBytes, idempotencyKey?) => Promise<{ index: number;}>;Defined in: packages/log-c2sp-tlog/src/writer.ts:69
Appends the finished entry bytes to the log and returns its assigned index.
Parameters
Section titled “Parameters”entryBytes
Section titled “entryBytes”Uint8Array
idempotencyKey?
Section titled “idempotencyKey?”string
Returns
Section titled “Returns”Promise<{
index: number;
}>
validateChain?
Section titled “validateChain?”optional validateChain?: (prepared) => Promise<void>;Defined in: packages/log-c2sp-tlog/src/writer.ts:72
Required for non-genesis events to validate authoritative prior stream state.
Parameters
Section titled “Parameters”prepared
Section titled “prepared”Returns
Section titled “Returns”Promise<void>
C2spTlogOriginPolicy
Section titled “C2spTlogOriginPolicy”Defined in: packages/log-c2sp-tlog/src/policy.ts:15
Local trust configuration for one checkpoint origin. Keys may be parsed or in signed-note verifier-key text form.
Properties
Section titled “Properties”logKeys
Section titled “logKeys”logKeys: (string | SignedNoteKey)[];Defined in: packages/log-c2sp-tlog/src/policy.ts:17
Accepted log signing keys; each key name must equal the origin.
quorum?
Section titled “quorum?”optional quorum?: number;Defined in: packages/log-c2sp-tlog/src/policy.ts:21
Flat witness quorum count; superseded by quorumRule when both are set.
quorumRule?
Section titled “quorumRule?”optional quorumRule?: C2spTlogQuorumRule;Defined in: packages/log-c2sp-tlog/src/policy.ts:22
unchained?
Section titled “unchained?”optional unchained?: boolean;Defined in: packages/log-c2sp-tlog/src/policy.ts:24
Deprecated
Section titled “Deprecated”Ignored: every scope requires a logical predecessor chain.
witnessKeys?
Section titled “witnessKeys?”optional witnessKeys?: (string | SignedNoteKey)[];Defined in: packages/log-c2sp-tlog/src/policy.ts:19
Witness cosignature keys used by the flat quorum count when no quorumRule is given.
C2spTlogPolicy
Section titled “C2spTlogPolicy”Defined in: packages/log-c2sp-tlog/src/policy.ts:28
Local C2SP tlog trust policy: per-origin rules, optionally pinned to one lr scope.
Properties
Section titled “Properties”origins
Section titled “origins”origins: Record<string, C2spTlogOriginPolicy>;Defined in: packages/log-c2sp-tlog/src/policy.ts:30
scope?
Section titled “scope?”optional scope?: string;Defined in: packages/log-c2sp-tlog/src/policy.ts:29
C2spTlogReaderOptions
Section titled “C2spTlogReaderOptions”Defined in: packages/log-c2sp-tlog/src/reader.ts:41
Configuration for C2spTlogReader; only policy is required.
Properties
Section titled “Properties”allowedClockSkew?
Section titled “allowedClockSkew?”optional allowedClockSkew?: number;Defined in: packages/log-c2sp-tlog/src/reader.ts:57
Accepted timestamp clock skew in milliseconds (default zero).
checkpointMaxAge?
Section titled “checkpointMaxAge?”optional checkpointMaxAge?: number;Defined in: packages/log-c2sp-tlog/src/reader.ts:59
Maximum checkpoint age in milliseconds; required by verifyNonRevocation.
consistencyProofSource?
Section titled “consistencyProofSource?”optional consistencyProofSource?: C2spConsistencyProofSource;Defined in: packages/log-c2sp-tlog/src/reader.ts:68
entityKey?
Section titled “entityKey?”optional entityKey?: DnsIdJWK;Defined in: packages/log-c2sp-tlog/src/reader.ts:55
Trusted accountable-entity key for lifecycle verification.
maxCheckpointBytes?
Section titled “maxCheckpointBytes?”optional maxCheckpointBytes?: number;Defined in: packages/log-c2sp-tlog/src/reader.ts:61
maxEntryBundleBytes?
Section titled “maxEntryBundleBytes?”optional maxEntryBundleBytes?: number;Defined in: packages/log-c2sp-tlog/src/reader.ts:62
maxTotalEntryBytes?
Section titled “maxTotalEntryBytes?”optional maxTotalEntryBytes?: number;Defined in: packages/log-c2sp-tlog/src/reader.ts:63
maxTreeSize?
Section titled “maxTreeSize?”optional maxTreeSize?: number;Defined in: packages/log-c2sp-tlog/src/reader.ts:60
policy
Section titled “policy”policy: C2spTlogPolicy;Defined in: packages/log-c2sp-tlog/src/reader.ts:43
Local trust policy: accepted log keys and witness quorum per origin.
proofs?
Section titled “proofs?”optional proofs?: Record<string, string | TlogProofV1>;Defined in: packages/log-c2sp-tlog/src/reader.ts:51
Inclusion proofs by entry index, required by readEvent for historical refs.
requestTimeoutMs?
Section titled “requestTimeoutMs?”optional requestTimeoutMs?: number;Defined in: packages/log-c2sp-tlog/src/reader.ts:64
resourceFetcher?
Section titled “resourceFetcher?”optional resourceFetcher?: C2spBoundedResourceFetcher;Defined in: packages/log-c2sp-tlog/src/reader.ts:45
Bounded resource fetcher for the default ScanStreamSource and stream-bundle reads.
signal?
Section titled “signal?”optional signal?: AbortSignal;Defined in: packages/log-c2sp-tlog/src/reader.ts:65
streamBundle?
Section titled “streamBundle?”optional streamBundle?: C2spStreamBundleReaderOptions;Defined in: packages/log-c2sp-tlog/src/reader.ts:49
Preferred verified per-domain bundle source. Raw scans are the bounded fallback for unavailable bundles or missing consistency evidence.
streamSource?
Section titled “streamSource?”optional streamSource?: StreamSource;Defined in: packages/log-c2sp-tlog/src/reader.ts:47
Alternative raw evidence source; defaults to a complete tlog-tiles scan.
trustedCheckpointStore?
Section titled “trustedCheckpointStore?”optional trustedCheckpointStore?: TrustedC2spCheckpointStore;Defined in: packages/log-c2sp-tlog/src/reader.ts:67
unchained?
Section titled “unchained?”optional unchained?: boolean;Defined in: packages/log-c2sp-tlog/src/reader.ts:53
Deprecated
Section titled “Deprecated”Ignored: all scopes require logical predecessor chains.
verifyMigration?
Section titled “verifyMigration?”optional verifyMigration?: (event, options?) => Promise<MigrationVerificationResult>;Defined in: packages/log-c2sp-tlog/src/reader.ts:66
Parameters
Section titled “Parameters”options?
Section titled “options?”Returns
Section titled “Returns”Promise<MigrationVerificationResult>
C2spTlogTrustProfile
Section titled “C2spTlogTrustProfile”Defined in: packages/log-c2sp-tlog/src/trust-profile.ts:12
Independently distributed trust for one exact DNSid C2SP log.
Properties
Section titled “Properties”bundleVerifierKeys
Section titled “bundleVerifierKeys”bundleVerifierKeys: SignedNoteKey[];Defined in: packages/log-c2sp-tlog/src/trust-profile.ts:17
logPrefix
Section titled “logPrefix”logPrefix: string;Defined in: packages/log-c2sp-tlog/src/trust-profile.ts:15
policyDocument
Section titled “policyDocument”policyDocument: Uint8Array;Defined in: packages/log-c2sp-tlog/src/trust-profile.ts:16
scope: C2spTlogScope;Defined in: packages/log-c2sp-tlog/src/trust-profile.ts:14
version
Section titled “version”version: 1;Defined in: packages/log-c2sp-tlog/src/trust-profile.ts:13
C2spTlogVerificationOptions
Section titled “C2spTlogVerificationOptions”Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:38
Options for createC2spTlogVerificationRegistry. Exactly one of
trustProfile, policyDocument, and policyUrl is required.
Properties
Section titled “Properties”allowedClockSkew?
Section titled “allowedClockSkew?”optional allowedClockSkew?: number;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:71
Accepted timestamp clock skew in milliseconds (default zero).
bundleVerifierKeys?
Section titled “bundleVerifierKeys?”optional bundleVerifierKeys?: SignedNoteKey[];Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:56
Independently trusted stream-bundle signer keys. Mutually exclusive with trustProfile.
checkpointMaxAge?
Section titled “checkpointMaxAge?”optional checkpointMaxAge?: number;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:69
Maximum accepted checkpoint age in milliseconds for fresh logged-state and non-revocation checks. Omission intentionally makes those operations fail closed.
maxBundleLifetimeMs?
Section titled “maxBundleLifetimeMs?”optional maxBundleLifetimeMs?: number;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:58
Maximum bundle expiry distance from its witnessed checkpoint. Required with bundle verifier keys.
maxPolicyBytes?
Section titled “maxPolicyBytes?”optional maxPolicyBytes?: number;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:75
Maximum policy size in bytes (default 1,048,576).
maxStreamBundleBytes?
Section titled “maxStreamBundleBytes?”optional maxStreamBundleBytes?: number;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:60
Maximum decoded stream-bundle response size (default 8 MiB).
maxStreamBundleEvents?
Section titled “maxStreamBundleEvents?”optional maxStreamBundleEvents?: number;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:62
Maximum lifecycle events in one stream bundle (default 10,000).
policyDocument?
Section titled “policyDocument?”optional policyDocument?: Uint8Array<ArrayBufferLike>;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:42
Independently trusted C2SP tlog-policy bytes, parsed locally.
policyUrl?
Section titled “policyUrl?”optional policyUrl?: string;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:44
Independently trusted absolute HTTPS URL of a C2SP tlog-policy document.
requestTimeoutMs?
Section titled “requestTimeoutMs?”optional requestTimeoutMs?: number;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:77
Finite timeout for each policy/log resource request (default 10 seconds).
requireStreamBundle?
Section titled “requireStreamBundle?”optional requireStreamBundle?: boolean;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:64
Fail instead of using the bounded raw scanner when the bundle endpoint is unavailable.
resourceFetcher?
Section titled “resourceFetcher?”optional resourceFetcher?: C2spBoundedResourceFetcher;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:46
Bounded transport used for both policy and standard log resources.
scanLimits?
Section titled “scanLimits?”optional scanLimits?: C2spScanLimits;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:54
Optional overrides for the built-in complete scanner’s secure limits.
signal?
Section titled “signal?”optional signal?: AbortSignal;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:79
Cancels policy retrieval and later reads made by readers from this registry.
transport?
Section titled “transport?”optional transport?: TransportConfig;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:52
DNS server, CA bundle, and private-address exceptions for the default resource fetcher; pass
the same DnsidConfig.transport given to the IdentityManager when verifying against a private
registry such as dnsid local. Mutually exclusive with resourceFetcher.
trustedCheckpointStore?
Section titled “trustedCheckpointStore?”optional trustedCheckpointStore?: TrustedC2spCheckpointStore;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:73
Persistence for accepted checkpoints. The default is process-lifetime only.
trustProfile?
Section titled “trustProfile?”optional trustProfile?: C2spTlogTrustProfile;Defined in: packages/log-c2sp-tlog/src/verification-registry.ts:40
Independently distributed trust profile for one exact log.
Checkpoint
Section titled “Checkpoint”Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:7
Parsed C2SP tlog-checkpoint: origin, tree size, SHA-256 root hash, and the signed-note signatures over signedText.
Properties
Section titled “Properties”origin
Section titled “origin”origin: string;Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:7
rootHash
Section titled “rootHash”rootHash: Uint8Array;Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:7
signatures
Section titled “signatures”signatures: NoteSignature[];Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:7
signedText
Section titled “signedText”signedText: string;Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:7
treeSize
Section titled “treeSize”treeSize: number;Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:7
CheckpointPolicyResult
Section titled “CheckpointPolicyResult”Defined in: packages/log-c2sp-tlog/src/policy.ts:49
Outcome of checkpoint policy enforcement.
Properties
Section titled “Properties”acceptedWitnessTimestamps
Section titled “acceptedWitnessTimestamps”acceptedWitnessTimestamps: number[];Defined in: packages/log-c2sp-tlog/src/policy.ts:51
Epoch-second timestamps of the accepted witness cosignatures.
checkpointWitnessTime?
Section titled “checkpointWitnessTime?”optional checkpointWitnessTime?: Date;Defined in: packages/log-c2sp-tlog/src/policy.ts:53
Earliest accepted witness timestamp; undefined when the quorum rule required no witnesses.
DnsidManagedVerificationOptions
Section titled “DnsidManagedVerificationOptions”Defined in: packages/log-c2sp-tlog/src/managed-verification-registry.ts:38
Shared infrastructure for createDnsidManagedVerificationRegistry.
Properties
Section titled “Properties”resourceFetcher?
Section titled “resourceFetcher?”optional resourceFetcher?: C2spBoundedResourceFetcher;Defined in: packages/log-c2sp-tlog/src/managed-verification-registry.ts:40
Bounded transport shared by every managed log reader.
signal?
Section titled “signal?”optional signal?: AbortSignal;Defined in: packages/log-c2sp-tlog/src/managed-verification-registry.ts:44
Cancels reads made by readers from this registry.
trustedCheckpointStore?
Section titled “trustedCheckpointStore?”optional trustedCheckpointStore?: TrustedC2spCheckpointStore;Defined in: packages/log-c2sp-tlog/src/managed-verification-registry.ts:42
Persistence shared by every managed log reader. The default is restart-ephemeral.
IndexedEntry
Section titled “IndexedEntry”Defined in: packages/log-c2sp-tlog/src/stream-source.ts:35
A raw log entry together with its index in the tree.
Properties
Section titled “Properties”bytes: Uint8Array;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:35
index: number;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:35
MigrationVerificationResult
Section titled “MigrationVerificationResult”Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:13
Keys and history established by verifying an inbound MIGRATION against the prior log.
Properties
Section titled “Properties”activeOperationalKey
Section titled “activeOperationalKey”activeOperationalKey: DnsIdJWK;Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:17
Operational key active at the prior log’s final entry.
entityKey
Section titled “entityKey”entityKey: DnsIdJWK;Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:15
Accountable-entity key established by the prior log’s lifecycle.
priorHistory
Section titled “priorHistory”priorHistory: LogEvent[];Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:19
Fully verified prior-log lifecycle through the migration’s finalEntryRef.
priorHistoryReferences?
Section titled “priorHistoryReferences?”optional priorHistoryReferences?: string[];Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:21
Verified log reference for each priorHistory event, in the same order. Required for logged-state evidence.
NoteSignature
Section titled “NoteSignature”Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:5
One C2SP signed-note signature line: signer name, optional 4-byte key hash, and raw signature bytes.
Properties
Section titled “Properties”keyHash?
Section titled “keyHash?”optional keyHash?: Uint8Array<ArrayBufferLike>;Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:5
name: string;Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:5
raw: string;Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:5
signature
Section titled “signature”signature: Uint8Array;Defined in: packages/log-c2sp-tlog/src/checkpoint.ts:5
ParseC2spStreamBundleOptions
Section titled “ParseC2spStreamBundleOptions”Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:69
Size limits applied while parsing an untrusted stream bundle.
Extended by
Section titled “Extended by”Properties
Section titled “Properties”maxBundleBytes
Section titled “maxBundleBytes”maxBundleBytes: number;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:70
maxEvents
Section titled “maxEvents”maxEvents: number;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:71
ParsedC2spTlogLr
Section titled “ParsedC2spTlogLr”Defined in: packages/log-c2sp-tlog/src/lr.ts:8
Components of a parsed c2sp-tlog:<scope>:<logPrefix>#<streamId>[@index] log reference.
Properties
Section titled “Properties”entryIndex?
Section titled “entryIndex?”optional entryIndex?: number;Defined in: packages/log-c2sp-tlog/src/lr.ts:16
logPrefix
Section titled “logPrefix”logPrefix: string;Defined in: packages/log-c2sp-tlog/src/lr.ts:11
lr: string;Defined in: packages/log-c2sp-tlog/src/lr.ts:15
Canonical bound reference without an entry index.
method
Section titled “method”method: "c2sp-tlog";Defined in: packages/log-c2sp-tlog/src/lr.ts:9
origin
Section titled “origin”origin: string;Defined in: packages/log-c2sp-tlog/src/lr.ts:13
scope: C2spTlogScope;Defined in: packages/log-c2sp-tlog/src/lr.ts:10
streamId
Section titled “streamId”streamId: string;Defined in: packages/log-c2sp-tlog/src/lr.ts:12
PreparedC2spTlogEvent
Section titled “PreparedC2spTlogEvent”Defined in: packages/log-c2sp-tlog/src/writer.ts:39
Immutable lifecycle event staged for signing and append: envelope, signed bytes, and the roles still required.
Properties
Section titled “Properties”envelope
Section titled “envelope”readonly envelope: Readonly<C2spJsonEvent>;Defined in: packages/log-c2sp-tlog/src/writer.ts:41
eventId
Section titled “eventId”readonly eventId: string;Defined in: packages/log-c2sp-tlog/src/writer.ts:43
reference
Section titled “reference”readonly reference: ParsedC2spTlogLr;Defined in: packages/log-c2sp-tlog/src/writer.ts:40
requiredSignatures
Section titled “requiredSignatures”readonly requiredSignatures: readonly C2spSignerRole[];Defined in: packages/log-c2sp-tlog/src/writer.ts:44
signedBytes
Section titled “signedBytes”readonly signedBytes: Uint8Array;Defined in: packages/log-c2sp-tlog/src/writer.ts:42
PreparedC2spVerificationContext
Section titled “PreparedC2spVerificationContext”Defined in: packages/log-c2sp-tlog/src/writer.ts:48
Trusted expectations a prepared event (and its existing signatures) is validated against.
Extended by
Section titled “Extended by”Properties
Section titled “Properties”entityKey?
Section titled “entityKey?”optional entityKey?: DnsIdJWK;Defined in: packages/log-c2sp-tlog/src/writer.ts:54
Trusted accountable-entity key. Required when countersigning or serializing ISSUANCE.
expectedFqdn?
Section titled “expectedFqdn?”optional expectedFqdn?: string;Defined in: packages/log-c2sp-tlog/src/writer.ts:50
Locally expected DNS identity. Required when countersigning or serializing ISSUANCE.
expectedGovernanceId?
Section titled “expectedGovernanceId?”optional expectedGovernanceId?: string;Defined in: packages/log-c2sp-tlog/src/writer.ts:52
Locally expected governance identifier. Required when countersigning or serializing ISSUANCE.
operationalKey?
Section titled “operationalKey?”optional operationalKey?: DnsIdJWK;Defined in: packages/log-c2sp-tlog/src/writer.ts:56
Trusted initial operational key. Required when countersigning or serializing ISSUANCE.
previousOperationalKey?
Section titled “previousOperationalKey?”optional previousOperationalKey?: DnsIdJWK;Defined in: packages/log-c2sp-tlog/src/writer.ts:57
ScanStreamSourceOptions
Section titled “ScanStreamSourceOptions”Defined in: packages/log-c2sp-tlog/src/stream-source.ts:43
Configuration for ScanStreamSource; the byte/size limits bound untrusted responses.
Properties
Section titled “Properties”authenticateCheckpoint
Section titled “authenticateCheckpoint”authenticateCheckpoint: (checkpoint) => void | Promise<void>;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:45
Called with the parsed checkpoint before any entries are fetched; throw to reject it.
Parameters
Section titled “Parameters”checkpoint
Section titled “checkpoint”Returns
Section titled “Returns”void | Promise<void>
maxCheckpointBytes?
Section titled “maxCheckpointBytes?”optional maxCheckpointBytes?: number;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:47
maxEntryBundleBytes?
Section titled “maxEntryBundleBytes?”optional maxEntryBundleBytes?: number;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:48
maxTotalEntryBytes?
Section titled “maxTotalEntryBytes?”optional maxTotalEntryBytes?: number;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:49
maxTreeSize?
Section titled “maxTreeSize?”optional maxTreeSize?: number;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:46
requestTimeoutMs?
Section titled “requestTimeoutMs?”optional requestTimeoutMs?: number;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:51
Finite deadline for each resource read (default 10 seconds).
signal?
Section titled “signal?”optional signal?: AbortSignal;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:53
Cancels current and subsequent resource reads.
SignedNoteKey
Section titled “SignedNoteKey”Defined in: packages/log-c2sp-tlog/src/signed-note.ts:7
Trusted C2SP signed-note verifier key: Ed25519 public key with optional 4-byte key ID and signature-type byte.
Properties
Section titled “Properties”keyBytes
Section titled “keyBytes”keyBytes: Uint8Array;Defined in: packages/log-c2sp-tlog/src/signed-note.ts:7
keyId?
Section titled “keyId?”optional keyId?: Uint8Array<ArrayBufferLike>;Defined in: packages/log-c2sp-tlog/src/signed-note.ts:7
kind: "ed25519";Defined in: packages/log-c2sp-tlog/src/signed-note.ts:7
name: string;Defined in: packages/log-c2sp-tlog/src/signed-note.ts:7
signatureType?
Section titled “signatureType?”optional signatureType?: Uint8Array<ArrayBufferLike>;Defined in: packages/log-c2sp-tlog/src/signed-note.ts:7
SignPreparedC2spOptions
Section titled “SignPreparedC2spOptions”Defined in: packages/log-c2sp-tlog/src/writer.ts:61
Options for signPreparedC2spTlogEvent.
Extends
Section titled “Extends”Properties
Section titled “Properties”entityKey?
Section titled “entityKey?”optional entityKey?: DnsIdJWK;Defined in: packages/log-c2sp-tlog/src/writer.ts:54
Trusted accountable-entity key. Required when countersigning or serializing ISSUANCE.
Inherited from
Section titled “Inherited from”PreparedC2spVerificationContext.entityKey
expectedFqdn?
Section titled “expectedFqdn?”optional expectedFqdn?: string;Defined in: packages/log-c2sp-tlog/src/writer.ts:50
Locally expected DNS identity. Required when countersigning or serializing ISSUANCE.
Inherited from
Section titled “Inherited from”PreparedC2spVerificationContext.expectedFqdn
expectedGovernanceId?
Section titled “expectedGovernanceId?”optional expectedGovernanceId?: string;Defined in: packages/log-c2sp-tlog/src/writer.ts:52
Locally expected governance identifier. Required when countersigning or serializing ISSUANCE.
Inherited from
Section titled “Inherited from”PreparedC2spVerificationContext.expectedGovernanceId
operationalKey?
Section titled “operationalKey?”optional operationalKey?: DnsIdJWK;Defined in: packages/log-c2sp-tlog/src/writer.ts:56
Trusted initial operational key. Required when countersigning or serializing ISSUANCE.
Inherited from
Section titled “Inherited from”PreparedC2spVerificationContext.operationalKey
previousOperationalKey?
Section titled “previousOperationalKey?”optional previousOperationalKey?: DnsIdJWK;Defined in: packages/log-c2sp-tlog/src/writer.ts:57
Inherited from
Section titled “Inherited from”PreparedC2spVerificationContext.previousOperationalKey
replaceExisting?
Section titled “replaceExisting?”optional replaceExisting?: boolean;Defined in: packages/log-c2sp-tlog/src/writer.ts:63
Allow overwriting an existing signature for the same role.
StreamEvidence
Section titled “StreamEvidence”Defined in: packages/log-c2sp-tlog/src/stream-source.ts:37
Log evidence loaded from a source: the checkpoint, entries, and whether every entry up to the tree size is present.
Properties
Section titled “Properties”checkpoint
Section titled “checkpoint”checkpoint: Checkpoint;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:37
complete
Section titled “complete”complete: boolean;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:37
entries
Section titled “entries”entries: IndexedEntry[];Defined in: packages/log-c2sp-tlog/src/stream-source.ts:37
StreamSource
Section titled “StreamSource”Defined in: packages/log-c2sp-tlog/src/stream-source.ts:40
Supplies checkpoint-plus-entries evidence for a log prefix.
Methods
Section titled “Methods”load()
Section titled “load()”load(prefix, options?): Promise<StreamEvidence>;Defined in: packages/log-c2sp-tlog/src/stream-source.ts:40
Parameters
Section titled “Parameters”prefix
Section titled “prefix”string
options?
Section titled “options?”signal?
Section titled “signal?”AbortSignal
Returns
Section titled “Returns”Promise<StreamEvidence>
StreamVerifierOptions
Section titled “StreamVerifierOptions”Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:24
Options controlling lifecycle verification of a stream’s entries.
Extends
Section titled “Extends”Properties
Section titled “Properties”checkpointIntegrationTimeMs?
Section titled “checkpointIntegrationTimeMs?”optional checkpointIntegrationTimeMs?: number;Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:30
Latest acceptable event timestamp (checkpoint witness time plus skew), in epoch milliseconds. Required.
logOrigin?
Section titled “logOrigin?”optional logOrigin?: string;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18
Inherited from
Section titled “Inherited from”optional lr?: string;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18
Inherited from
Section titled “Inherited from”prevEventId?
Section titled “prevEventId?”optional prevEventId?: string;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18
Inherited from
Section titled “Inherited from”prevStateHash?
Section titled “prevStateHash?”optional prevStateHash?: string;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18
Inherited from
Section titled “Inherited from”C2spEventContext.prevStateHash
scope?
Section titled “scope?”optional scope?: string;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18
Inherited from
Section titled “Inherited from”optional seq?: number;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18
Inherited from
Section titled “Inherited from”signal?
Section titled “signal?”optional signal?: AbortSignal;Defined in: packages/protocol/src/verification-budget.ts:6
Inherited from
Section titled “Inherited from”signerKey?
Section titled “signerKey?”optional signerKey?: DnsIdJWK;Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:28
Trusted accountable-entity key the lifecycle’s entity key must match.
streamId?
Section titled “streamId?”optional streamId?: string;Defined in: packages/log-c2sp-tlog/src/event-codec.ts:18
Inherited from
Section titled “Inherited from”timeoutMs?
Section titled “timeoutMs?”optional timeoutMs?: number;Defined in: packages/protocol/src/verification-budget.ts:5
Overall invocation budget, including all discovery and evidence. Default: 30 seconds.
Inherited from
Section titled “Inherited from”unchained?
Section titled “unchained?”optional unchained?: boolean;Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:26
Deprecated
Section titled “Deprecated”Ignored: every scope requires the logical predecessor chain.
verifyMigration?
Section titled “verifyMigration?”optional verifyMigration?: (event, options?) => Promise<MigrationVerificationResult>;Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:32
Verifies an inbound MIGRATION’s prior-log history and returns the migrated keys.
Parameters
Section titled “Parameters”options?
Section titled “options?”Returns
Section titled “Returns”Promise<MigrationVerificationResult>
TlogProofV1
Section titled “TlogProofV1”Defined in: packages/log-c2sp-tlog/src/proof.ts:8
Parsed C2SP tlog-proof@v1: entry index, inclusion proof hashes, and the checkpoint the proof leads to.
Properties
Section titled “Properties”checkpoint
Section titled “checkpoint”checkpoint: Checkpoint;Defined in: packages/log-c2sp-tlog/src/proof.ts:8
extra?
Section titled “extra?”optional extra?: string[];Defined in: packages/log-c2sp-tlog/src/proof.ts:8
hashes
Section titled “hashes”hashes: Uint8Array<ArrayBufferLike>[];Defined in: packages/log-c2sp-tlog/src/proof.ts:8
index: number;Defined in: packages/log-c2sp-tlog/src/proof.ts:8
TrustedC2spCheckpoint
Section titled “TrustedC2spCheckpoint”Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:9
Latest policy-accepted checkpoint remembered for a log origin, with its witnessed time.
Properties
Section titled “Properties”origin
Section titled “origin”origin: string;Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:10
rootHash
Section titled “rootHash”rootHash: Uint8Array;Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:12
treeSize
Section titled “treeSize”treeSize: number;Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:11
witnessTime
Section titled “witnessTime”witnessTime: Date;Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:13
TrustedC2spCheckpointStore
Section titled “TrustedC2spCheckpointStore”Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:17
Persistence for per-origin trusted checkpoints, updated with optimistic compare-and-swap semantics.
Methods
Section titled “Methods”compareAndSwap()
Section titled “compareAndSwap()”compareAndSwap( origin, expected, candidate, signal?): Promise<boolean>;Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:25
Atomically replaces expected with candidate; returns false on a lost race.
Implementations must honor cancellation at the commit boundary: an aborted
signal must prevent a pending write, not merely reject its returned promise.
Parameters
Section titled “Parameters”origin
Section titled “origin”string
expected
Section titled “expected”TrustedC2spCheckpoint | undefined
candidate
Section titled “candidate”signal?
Section titled “signal?”AbortSignal
Returns
Section titled “Returns”Promise<boolean>
load()
Section titled “load()”load(origin, signal?): Promise<TrustedC2spCheckpoint | undefined>;Defined in: packages/log-c2sp-tlog/src/checkpoint-trust.ts:19
Returns the currently trusted checkpoint for origin, if any.
Parameters
Section titled “Parameters”origin
Section titled “origin”string
signal?
Section titled “signal?”AbortSignal
Returns
Section titled “Returns”Promise<TrustedC2spCheckpoint | undefined>
VerifiedC2spStreamBundle
Section titled “VerifiedC2spStreamBundle”Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:102
Result of successful stream bundle verification.
Properties
Section titled “Properties”activeOperationalKeyThumbprint
Section titled “activeOperationalKeyThumbprint”activeOperationalKeyThumbprint: string;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:110
Thumbprint of the agent’s operational key after the last verified event.
bundle
Section titled “bundle”bundle: C2spStreamBundle;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:103
checkpointWitnessTime
Section titled “checkpointWitnessTime”checkpointWitnessTime: Date;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:111
events
Section titled “events”events: VerifiedLifecycleEvent[];Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:104
historyReferences?
Section titled “historyReferences?”optional historyReferences?: string[];Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:108
Verified log reference aligned with each stitched lifecycle event, when prior migration boundaries were supplied.
lifecycle
Section titled “lifecycle”lifecycle: LogEvent[];Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:106
The verified lifecycle events in log order.
VerifiedLifecycleEvent
Section titled “VerifiedLifecycleEvent”Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:11
A lifecycle event accepted by stream verification, with its log index, leaf hash, and raw entry bytes.
Properties
Section titled “Properties”bytes: Uint8Array;Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:11
event: LogEvent;Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:11
index: number;Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:11
leafHash
Section titled “leafHash”leafHash: Uint8Array;Defined in: packages/log-c2sp-tlog/src/stream-verifier.ts:11
VerifyC2spStreamBundleOptions
Section titled “VerifyC2spStreamBundleOptions”Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:75
Trusted inputs and freshness limits for verifying a stream bundle.
Extends
Section titled “Extends”Properties
Section titled “Properties”bundleKeys
Section titled “bundleKeys”bundleKeys: SignedNoteKey[];Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:83
Trusted bundle-producer keys (with key IDs) accepted for the bundle signature.
checkpointFreshnessMs
Section titled “checkpointFreshnessMs”checkpointFreshnessMs: number;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:89
Maximum accepted checkpoint age relative to now.
consistencyProofSource?
Section titled “consistencyProofSource?”optional consistencyProofSource?: C2spConsistencyProofSource;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:96
entityKey
Section titled “entityKey”entityKey: DnsIdJWK;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:85
Trusted accountable-entity key for the identity record.
expectedFqdn
Section titled “expectedFqdn”expectedFqdn: string;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:77
DNS name of the agent the bundle must describe.
expectedLogReference
Section titled “expectedLogReference”expectedLogReference: string;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:79
Canonical bound c2sp-tlog lr the bundle must reference.
maxBundleBytes
Section titled “maxBundleBytes”maxBundleBytes: number;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:70
Inherited from
Section titled “Inherited from”ParseC2spStreamBundleOptions.maxBundleBytes
maxBundleLifetimeMs
Section titled “maxBundleLifetimeMs”maxBundleLifetimeMs: number;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:87
Maximum allowed distance between checkpoint witness time and bundle expiry.
maxClockSkewMs?
Section titled “maxClockSkewMs?”optional maxClockSkewMs?: number;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:92
maxEvents
Section titled “maxEvents”maxEvents: number;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:71
Inherited from
Section titled “Inherited from”ParseC2spStreamBundleOptions.maxEvents
maxTreeSize?
Section titled “maxTreeSize?”optional maxTreeSize?: number;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:91
Maximum accepted checkpoint tree size (default 1,000,000).
nowMs?
Section titled “nowMs?”optional nowMs?: number;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:93
policyBytes
Section titled “policyBytes”policyBytes: Uint8Array;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:81
Local C2SP policy file bytes; their hash must match the bundle’s policy_hash.
signal?
Section titled “signal?”optional signal?: AbortSignal;Defined in: packages/protocol/src/verification-budget.ts:6
Inherited from
Section titled “Inherited from”timeoutMs?
Section titled “timeoutMs?”optional timeoutMs?: number;Defined in: packages/protocol/src/verification-budget.ts:5
Overall invocation budget, including all discovery and evidence. Default: 30 seconds.
Inherited from
Section titled “Inherited from”trustedCheckpointStore
Section titled “trustedCheckpointStore”trustedCheckpointStore: TrustedC2spCheckpointStore;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:95
verifyMigration?
Section titled “verifyMigration?”optional verifyMigration?: (event, options?) => Promise<MigrationVerificationResult>;Defined in: packages/log-c2sp-tlog/src/stream-bundle.ts:94
Parameters
Section titled “Parameters”options?
Section titled “options?”Returns
Section titled “Returns”Promise<MigrationVerificationResult>