Skip to main content

Module signature

Module signature 

Source
Expand description

Manifest signature verification. Pure — no I/O.

Signing protects integrity and provenance, not authorization (that’s the consent dialog, a later slice). A valid signature means “this manifest and module are intact and were produced by the holder of this key.”

The signed payload is canonical(manifest-without-signature) ‖ module_hash, so the signature binds the wasm module’s bytes, not just the metadata — a swapped module fails verification even with an untouched manifest. Content plugins carry no module, so their payload omits the hash. Canonicalisation is serde_json over the manifest value with the signature key removed; serde_json’s default Map is key-ordered, so the bytes are reproducible by the signing tool.

Functions§

sha256
SHA-256 of bytes, as a fixed 32-byte array. Used to hash a plugin’s wasm module for inclusion in the signed payload (content plugins sign over the manifest alone).
signing_payload
The exact bytes a manifest’s signature is computed over: the manifest serialised to JSON with its signature field removed, followed by the module hash (when the plugin ships one). Pure and deterministic, so both the signer and the verifier produce identical input.
verify_signature
Verify a manifest’s ed25519 signature over signing_payload. Pass the module’s sha256 for code-bearing plugins, None for content plugins. Returns a user-facing error string on any failure (wrong alg, malformed key/signature, or a verification mismatch) — never panics.