sigil-tee-material · arm_cca
Source declarations, signatures and documentation for arm_cca.
Source: sigil/node/sigil-tee-material/src/arm_cca.rs. SHA-256: 26901b44b06c30155c29d08a5a0feb6cc4e8bce706d38adbadff645362db8c92.
This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.
arm_cca::validate_iak_pubkey
Validate a single IAK pubkey buffer. Returns the canonical 97-byte SEC1-uncompressed P-384 form.
pub fn validate_iak_pubkey(bytes: &[u8]) -> Result<[u8; SEC1_UNCOMPRESSED_LEN], ToolError>;Source line: 32.
arm_cca::validate_realm_token
Validate a realm-token (COSE_Sign1) bytes blob — checks structural shape + that ES384 is the algorithm. Optionally verifies the signature against an IAK pubkey if one is supplied.
pub fn validate_realm_token(
bytes: &[u8],
iak_pubkey: Option<&[u8; SEC1_UNCOMPRESSED_LEN]>,
) -> Result<(), ToolError>;Source line: 57.
arm_cca::emit_genesis_from_files
Build genesis from operator-supplied IAK pubkey files + RIM files
- optional realm-token sample. The realm token (when present) must have a matching IAK pubkey in the input list, otherwise validation fails.
pub fn emit_genesis_from_files(
iak_pubkey_paths: &[&Path],
rim_paths: &[&Path],
realm_token_path: Option<&Path>,
) -> Result<GenesisBundle, ToolError>;Source line: 146.
arm_cca::emit_genesis_from_manifest
Emit a genesis bundle from a single text manifest file (one path
per line, prefixed by iak: / rim: / realm-token:).
pub fn emit_genesis_from_manifest(manifest_path: &Path) -> Result<GenesisBundle, ToolError>;Source line: 230.