载入中...
搜索中...
未找到
SnapshotHash.h 文件参考

Injectable content-digest provider for snapshots, with an honest default. 更多...

#include "common/Identity.h"
#include "common/Result.h"
#include "common/Snapshot.h"
#include <memory>
#include <string>
#include <string_view>

浏览源代码.

类

class  eve::ISnapshotContentHasher
 One content-digest implementation usable for snapshot sealing and verification. 更多...
 

命名空间

namespace  eve
 Build metadata (engine git commit, build time, third-party version).
 

枚举

enum class  eve::ContentDigestKind : std::uint8_t { eve::NonCryptographic , eve::Cryptographic }
 What a digest implementation actually guarantees, stated rather than implied. 更多...
 

函数

std::string_view eve::contentDigestKindName (ContentDigestKind kind) noexcept
 Stable protocol spelling of a digest kind.
 
std::shared_ptr< ISnapshotContentHasher > eve::builtinSnapshotContentHasher ()
 The engine's built-in content hasher.
 
ISnapshotContentHasher * eve::registeredSnapshotContentHasher () noexcept
 The currently registered hasher, if a module registered one.
 
Result< void > eve::registerBuiltinSnapshotHasher ()
 Register the built-in hasher, unless a module already registered one.
 
SnapshotHashProvider eve::snapshotContentHashProvider ()
 A SnapshotHashProvider backed by the active hasher.
 
std::string_view eve::activeSnapshotHashAlgorithm () noexcept
 Id of the algorithm snapshotContentHashProvider currently uses.
 

详细描述

Injectable content-digest provider for snapshots, with an honest default.

SnapshotEnvelope::contentHash is an integrity and identity check: it detects a corrupted or mismatched envelope. It is not a security boundary, and the engine must not pretend otherwise, so the algorithm is a named, replaceable provider rather than a hidden default:

  • ISnapshotContentHasher is a capability. A project that needs a cryptographic digest registers its own implementation.
  • The engine ships one built-in hasher whose name says what it is (fnv1a64x2-noncrypto) and whose digestKind() reports NonCryptographic, so a caller can tell from the data which guarantee it actually has.
  • snapshotContentHashProvider() is the bridge used by script and tooling paths that cannot inject a std::function: it uses the registered hasher, and otherwise the built-in one. That substitution is stated rather than silent, and activeSnapshotHashAlgorithm() lets a caller observe which algorithm is in effect and record it next to the data it produced.

The digest input is always the canonical serialization assembled by common/Snapshot.*; a hasher never sees ECS state and never defines what is hashed.

在文件 SnapshotHash.h 中定义.