Skip to content

Rust First Admission and Historical Trust

The Rust AdmissionService layers First Admission and Historical Trust above the six-stage Signed Document verifier (MWP-ADM-005). The language-independent flow is the local First Admission and Historical Trust runtime page, and the exact requirements are the local Admission clauses.

Public API Responsibility
AdmissionCurrentKeyResolver::resolve_current Return complete Organization-wide Registry evidence that the deployment asserts is current for this decision.
TrustedAdmissionContext::issue Issue the record ID, trusted acceptance instant, and accepting service only after authoritative absence.
AdmissionLog::lookup Return AdmissionLookup::Found or AdmissionLookup::AuthoritativeAbsence. Cache miss, timeout, or unauthenticated absence fails closed under MWP-ADM-003.
AdmissionLog::append_or_return_existing Atomically append candidate bytes or return the concurrent authoritative winner through an authenticated service identity.
AuthenticatedAdmissionRecord Bind returned record bytes to the service identity authenticated by the log adapter for MWP-ADM-009.
AdmissionService::prepare_first_admission Create and validate candidate evidence from an SDK-produced VerifiedSignedDocument; it does not append or imply admission.
AdmissionService::admit_first Verify current evidence, lookup, prepare after absence, append-or-return-existing, and validate the returned record under MWP-ADM-006.
AdmissionService::verify_historical_admission Rerun verification with historical Registry evidence and require an existing record without issuing context or appending under MWP-ADM-008.
PreparedFirstAdmission, AdmittedSignedDocument Preserve immutable verification and record evidence; FirstAdmissionRecord::bytes returns the validated bytes.

A caller-provided trust boolean is not an Admission lookup outcome and must never select the success path.

admit_first completes all six verification stages before log access. A found record is validated and returned without issuing trusted context or appending. After authoritative absence, the service issues context, prepares canonical candidate bytes, calls append_or_return_existing, and validates the record actually returned. A concurrent winner succeeds only when Schema, authentication, document binding, and trusted time satisfy MWP-ADM-009 and MWP-ADM-010.

verify_historical_admission uses KeyResolver, reruns all six stages, requires AdmissionLookup::Found, and never calls TrustedAdmissionContext::issue or AdmissionLog::append_or_return_existing. Matching record IDs recover the same authoritative record but do not prove Command freshness, signer authorization, state-machine acceptance, or portable log-proof verification under MWP-ADM-013 and MWP-ADM-014.

AdmissionOperationError preserves either the original six-stage verification failure or an AdmissionError. Admission failures expose wire code AUTH_INVALID_SIGNATURE, protected stage admission, and a typed AdmissionReason, as required by MWP-ADM-012. Adapters return AdmissionAdapterError; generic success or availability is not authenticated evidence.