crates/veilvoice-guard/src/manifest.rs
veilvoice-guard · 730 lines · read the source here · or on GitHub
The integrity manifest: what the files were, and what they are now.
Format
Deliberately a text format, one record per line:
VEILGUARD1
<sha256 hex> <size> <path>
...
Text rather than a packed binary layout because the point of the file is to be checkable. Someone who suspects tampering can read it with cat and compare a digest by hand with sha256sum, without this crate and without trusting it. A binary format would have been marginally smaller and would have made the honest response to "prove it" be "run my tool again".
Paths are stored with forward slashes so a manifest written on Windows still reads on Linux, and are rejected if they contain a newline -- otherwise a filename could forge a record.
In plain words
The written record of what VeilVoice's files were, so a later check can tell whether they still are.
It is plain text on purpose: you can read it, diff it and keep a copy somewhere else. A record you cannot inspect is one you have to take on trust, which rather defeats the point of having it.
WHAT THIS FILE CONTAINS
730 lines defining 18 functions (15 public), 4 types and 1 constant. Everything below is read out of the source, so it cannot disagree with the code.
The types it owns.
struct Entryline 43 · One recorded file.enum Changeline 52 · How a file differs from its record.struct Reportline 110 · The result of checking a manifest against the disk.struct Manifestline 126 · A record of a set of files.
What happens when it runs. These are the ways in: public, and nothing else in this file calls them, so they are what an outside caller reaches first.
Change::pathline 84 · The path this change concerns.Change::describeline 94 · A single line for a terminal or a log.Report::is_cleanline 119 · Whether anything at all differs.Manifest::ofline 190 · Record every readable file in paths.
reachesdigest_of,normalise,unrecordableManifest::lenline 215 · How many files are recorded.Manifest::is_emptyline 220 · Whether nothing is recorded.Manifest::pathsline 225 · The recorded paths, in order.Manifest::checkline 234 · Compare the record against what is on disk now.
reachesdigest_of,normaliseManifest::saveline 370 · Write the manifest to path in the clear.
reachesto_textManifest::loadline 381 · Read a manifest written by Manifest::save.
reachesparse,unrecordableManifest::sealline 395 · Seal the manifest under a passphrase.
reachesto_textManifest::open_sealedline 424 · Open a manifest sealed by Manifest::seal.
reachesparse,unrecordablefiles_inline 441 · Every file directly inside dir, for use as check's extra argument.
WHAT CALLS WHAT
The functions this file defines, and the calls between them. An edge means the callee's name appears, called, inside the caller's body. This is a syntactic reading, not a type-resolved one.
The same graph as Mermaid source
%%{init: {"theme":"base","themeVariables":{"background":"#1a1b26","primaryColor":"#1f2335","primaryTextColor":"#c0caf5","primaryBorderColor":"#7aa2f7","secondaryColor":"#16161e","tertiaryColor":"#16161e","lineColor":"#737aa2","textColor":"#c0caf5","mainBkg":"#1f2335","nodeBorder":"#7aa2f7","clusterBkg":"#16161e","clusterBorder":"#2f3549","fontFamily":"ui-monospace, SFMono-Regular, Consolas, monospace","fontSize":"14px"}}}%%
flowchart TD
n_path(["Change::path<br/>line 84"])
n_describe(["Change::describe<br/>line 94"])
n_is_clean(["Report::is_clean<br/>line 119"])
n_normalise["normalise<br/>line 134"]
n_unrecordable["unrecordable<br/>line 157"]
n_digest_of["digest_of<br/>line 173"]
n_of(["Manifest::of<br/>line 190"])
n_len(["Manifest::len<br/>line 215"])
n_is_empty(["Manifest::is_empty<br/>line 220"])
n_paths(["Manifest::paths<br/>line 225"])
n_check(["Manifest::check<br/>line 234"])
n_to_text["Manifest::to_text<br/>line 275"]
n_parse["Manifest::parse<br/>line 285"]
n_save(["Manifest::save<br/>line 370"])
n_load(["Manifest::load<br/>line 381"])
n_seal(["Manifest::seal<br/>line 395"])
n_open_sealed(["Manifest::open_sealed<br/>line 424"])
n_files_in(["files_in<br/>line 441"])
n_check --> n_digest_of
n_check --> n_normalise
n_load --> n_parse
n_of --> n_digest_of
n_of --> n_normalise
n_of --> n_unrecordable
n_open_sealed --> n_parse
n_parse --> n_unrecordable
n_save --> n_to_text
n_seal --> n_to_text
click n_path href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-guard/src/manifest.rs#L84" "open the source"
click n_describe href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-guard/src/manifest.rs#L94" "open the source"
click n_is_clean href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-guard/src/manifest.rs#L119" "open the source"
click n_normalise href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-guard/src/manifest.rs#L134" "open the source"
click n_unrecordable href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-guard/src/manifest.rs#L157" "open the source"
click n_digest_of href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-guard/src/manifest.rs#L173" "open the source"
click n_of href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-guard/src/manifest.rs#L190" "open the source"
click n_len href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-guard/src/manifest.rs#L215" "open the source"
click n_is_empty href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-guard/src/manifest.rs#L220" "open the source"
click n_paths href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-guard/src/manifest.rs#L225" "open the source"
click n_check href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-guard/src/manifest.rs#L234" "open the source"
click n_to_text href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-guard/src/manifest.rs#L275" "open the source"
click n_parse href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-guard/src/manifest.rs#L285" "open the source"
click n_save href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-guard/src/manifest.rs#L370" "open the source"
click n_load href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-guard/src/manifest.rs#L381" "open the source"
click n_seal href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-guard/src/manifest.rs#L395" "open the source"
click n_open_sealed href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-guard/src/manifest.rs#L424" "open the source"
click n_files_in href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-guard/src/manifest.rs#L441" "open the source"
classDef entry fill:#1f2335,stroke:#7aa2f7,color:#c0caf5
class n_path,n_describe,n_is_clean,n_of,n_len,n_is_empty,n_paths,n_check,n_save,n_load,n_seal,n_open_sealed,n_files_in entry
classDef api fill:#1f2335,stroke:#7dcfff,color:#c0caf5
class n_to_text,n_parse api
classDef helper fill:#1f2335,stroke:#bb9af7,color:#c0caf5
class n_normalise,n_unrecordable,n_digest_of helper
This site loads no third-party script, so it cannot run Mermaid; the diagram above is the same nodes and edges drawn by the generator instead. GitHub renders the source below directly.
ITEMS
| Item | Line | Documentation |
|---|---|---|
MAGIC pub(crate) const | 39 | Magic first line. |
Entry pub struct | 43 | One recorded file. |
Change pub enum | 52 | How a file differs from its record. |
Change::path pub fn | 84 | The path this change concerns. |
Change::describe pub fn | 94 | A single line for a terminal or a log. |
Report pub struct | 110 | The result of checking a manifest against the disk. |
Report::is_clean pub fn | 119 | Whether anything at all differs. |
Manifest pub struct | 126 | A record of a set of files. |
normalise fn | 134 | Normalise a path for storage: forward slashes, no leading ./. |
unrecordable fn | 157 | Why this path cannot go in a manifest, if it cannot. |
digest_of fn | 173 | |
Manifest::of pub fn | 190 | Record every readable file in paths. |
Manifest::len pub fn | 215 | How many files are recorded. |
Manifest::is_empty pub fn | 220 | Whether nothing is recorded. |
Manifest::paths pub fn | 225 | The recorded paths, in order. |
Manifest::check pub fn | 234 | Compare the record against what is on disk now. |
Manifest::to_text pub fn | 275 | Serialise to the text format described at the top of this module. |
Manifest::parse pub fn | 285 | Parse the text format. |
Manifest::save pub fn | 370 | Write the manifest to path in the clear. |
Manifest::load pub fn | 381 | Read a manifest written by Manifest::save. |
Manifest::seal pub fn | 395 | Seal the manifest under a passphrase. |
Manifest::open_sealed pub fn | 424 | Open a manifest sealed by Manifest::seal. |
files_in pub fn | 441 | Every file directly inside dir, for use as check's extra argument. |