Expand description
Manifest signature verification. Pure — no I/O.
Signing protects integrity and provenance, not authorization (that’s the consent dialog, a later slice). A valid signature means “this manifest and module are intact and were produced by the holder of this key.”
The signed payload is canonical(manifest-without-signature) ‖ module_hash, so the signature binds the wasm module’s bytes, not just
the metadata — a swapped module fails verification even with an
untouched manifest. Content plugins carry no module, so their payload
omits the hash. Canonicalisation is serde_json over the manifest value
with the signature key removed; serde_json’s default Map is
key-ordered, so the bytes are reproducible by the signing tool.
Functions§
- sha256
- SHA-256 of
bytes, as a fixed 32-byte array. Used to hash a plugin’s wasm module for inclusion in the signed payload (content plugins sign over the manifest alone). - signing_
payload - The exact bytes a manifest’s signature is computed over: the manifest
serialised to JSON with its
signaturefield removed, followed by the module hash (when the plugin ships one). Pure and deterministic, so both the signer and the verifier produce identical input. - verify_
signature - Verify a manifest’s ed25519 signature over
signing_payload. Pass the module’ssha256for code-bearing plugins,Nonefor content plugins. Returns a user-facing error string on any failure (wrong alg, malformed key/signature, or a verification mismatch) — never panics.