Sigil documentation
ReferenceRust referencesigil-tee-material

sigil-tee-material · arm_cca

Source declarations, signatures and documentation for arm_cca.

Source: sigil/node/sigil-tee-material/src/arm_cca.rs. SHA-256: 26901b44b06c30155c29d08a5a0feb6cc4e8bce706d38adbadff645362db8c92.

This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.

arm_cca::validate_iak_pubkey

Validate a single IAK pubkey buffer. Returns the canonical 97-byte SEC1-uncompressed P-384 form.

pub fn validate_iak_pubkey(bytes: &[u8]) -> Result<[u8; SEC1_UNCOMPRESSED_LEN], ToolError>;

Source line: 32.

arm_cca::validate_realm_token

Validate a realm-token (COSE_Sign1) bytes blob — checks structural shape + that ES384 is the algorithm. Optionally verifies the signature against an IAK pubkey if one is supplied.

pub fn validate_realm_token(
    bytes: &[u8],
    iak_pubkey: Option<&[u8; SEC1_UNCOMPRESSED_LEN]>,
) -> Result<(), ToolError>;

Source line: 57.

arm_cca::emit_genesis_from_files

Build genesis from operator-supplied IAK pubkey files + RIM files

  • optional realm-token sample. The realm token (when present) must have a matching IAK pubkey in the input list, otherwise validation fails.
pub fn emit_genesis_from_files(
    iak_pubkey_paths: &[&Path],
    rim_paths: &[&Path],
    realm_token_path: Option<&Path>,
) -> Result<GenesisBundle, ToolError>;

Source line: 146.

arm_cca::emit_genesis_from_manifest

Emit a genesis bundle from a single text manifest file (one path per line, prefixed by iak: / rim: / realm-token:).

pub fn emit_genesis_from_manifest(manifest_path: &Path) -> Result<GenesisBundle, ToolError>;

Source line: 230.

On this page