0.3.0: UCANs, device request and ownership proofs (draft to run CI) - #3
Merged
Merged
Conversation
…a-go v0.17.0
A Python node can mint and present macula 12's post-quantum UCANs, serve
procedures gated on them, prove a device's request to a realm, and prove
ownership of a request to a service such as mcl_om.
- abi: macula-go v0.17.0 (132d134), its header; the ctypes table gains the
ten new functions and the no_provider kind (NoProviderError).
- NodeKey.ucan; Pool.call/open_stream(ucan=, proofs=); Pool.serve/
serve_stream(policy=UcanRequired|RealmMemberRequired); macula_py.ucan
proof_id and key_id, held to macula's UCAN vectors (0e2724cc). The
verdicts are reached end to end over the test stations in both profiles,
for calls and opens: served, unauthorized, malformed_frame.
- NodeKey.device_request_proof and device_request_message, held to the
realm's vector; NodeKey.ownership_proof and ownership_proof_message, held
to mcl_om's. A "caller" is refused in both.
- scripts/interop: a payload signed here crosses a station into mcl_om's own
verifier (in macula's pinned CI image), and a join session signed here goes
through the realm's own verifier: each accepted once, refused changed and
replayed. A live check serves a gated procedure on one station.
- Stopping a procedure is answered by the library ("the procedure was
withdrawn"), as v0.15.0's contract has it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- NodeKey.ucan(prf="<one id>") split the id into 96 one-character parents; it is refused (TypeError), as proofs= already was. The docstring says what macula does with two parents: minted, and refused by every provider. - An older libmacula passes the ABI version check (new functions keep it) and lacks the new functions: load now names the floor, macula-go v0.17.0. - device_request_proof/ownership_proof raise on a NULL result instead of returning None; their docstrings say signing runs on the calling thread. - README: key_id takes the realm key as carried. scripts/interop/README.md records the last run's versions and verdicts. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Draft only to run CI on the exact sha before main and the v0.3.0 tag go through the push gate.
🤖 Generated with Claude Code