moonbit-json-jcs

    Strict JSON parsing and deterministic JSON canonicalization for MoonBit.

    json
    canonicalization
    jcs
    rfc8785
    integrity
    Download zip
    Version
    0.1.0
    License
    Apache-2.0
    Last updated
    last month
    Downloads
    6

    Dependencies

    #moonbit-json-jcs

    #Bounded input APIs

    For untrusted input, canonicalize_json_with_limits, digest_json_with_limits, and prepare_document_with_limits enforce a DocumentLimits budget before canonicalization, hashing, or audit collection.

    MoonBit 原生的 RFC 8785 JSON Canonicalization Scheme(JCS)库和命令行 检查工具。它把严格 JSON 文本转换为确定性的 UTF-8 字节,适合内容寻址、 签名前预处理、配置审计和 CI 校验。

    模块名为 xlyyyyyy112/moonbit-json-jcs,公开仓库地址为 https://github.com/xlyyyyyy112/moonbit-json-jcs。项目许可证为 Apache-2.0。

    #目标与边界

    项目提供:

    • 严格 JSON 解析:边界检查、重复 key、转义、Unicode surrogate、数字语法和 尾随内容诊断;
    • RFC 8785 规范化:UTF-16 code unit key 排序、字符串转义、IEEE-754/Ryu 最短数字表示;
    • SHA-256 canonical digest、批量 manifest、规范态检查和幂等性检查;
    • JSON Pointer 查询、语义 diff、描述性 change plan、JSON Patch 和 RFC 7396 Merge Patch;
    • 资源限制、结构/源码统计、token 流、路径枚举、脱敏和审计画像;
    • CLI 的 canonicalize、validate、inspect、digest、diff、pretty、 tokens、diagnose、profile、compare 命令。

    不提供 JSON Schema、完整 JSONPath、运行时签名/密钥管理、流式 SAX 解析或 WebAssembly runtime。SHA-256 只用于对 canonical bytes 做摘要,不声称实现 签名协议。

    #安装与检查

    需要 MoonBit 工具链。源码依赖会由 Moon 自动获取:

    moon check --deny-warn moon test --deny-warn

    作为依赖使用时,导入模块根包并调用 parse、canonicalize、 canonical_digest 或 inspect_json。正式版本会发布到 mooncakes.io。

    #CLI 示例

    moon run cmd/main -- canonicalize '[1, true, null]' moon run cmd/main -- digest '[1, true, null]' moon run cmd/main -- inspect --json '[1, true, null]' moon run cmd/main -- diff '[1]' '[2]'

    inspect --json 输出稳定的统计、canonical 文本、SHA-256 和错误字段;非法 输入会打印诊断并以非零状态结束。PowerShell 中包含双引号的 JSON 建议使用 反引号或从文件读取后再传入。

    #MoonBit API 示例

    ///|
    let value = parse("{\"b\":2,\"a\":1}") catch { error => panic() }

    ///|
    let canonical = canonicalize(value) catch { error => panic() }
    // canonical == "{\"a\":1,\"b\":2}"

    ///|
    let digest = canonical_digest(value) catch { error => panic() }

    parse_with_limits 可在处理不可信输入前限制深度、值数量、数组/对象规模、 字符串长度和数字 token 长度;evaluate_policy 可实现“必须已经 canonical” 或“只报告不阻断”的 CI 门禁。

    #第三方代码与参考

    • 规范依据:RFC 8785,用于 key 排序、 字符串序列化和数字表示的行为定义;
    • gmlewis/sha256@0.17.32,Apache-2.0,仓库: https://github.com/gmlewis/moonbit-sha256。本项目只调用其公开 Digest 接口,不复制其实现;
    • 数字解析和最短表示使用 MoonBit core 的 parse_double 与 Ryu 实现。

    #开发状态

    当前代码和测试以公开仓库为准,mooncakes.io 发布版本会在 CHANGELOG 中记录。 每个新增功能都应带真实二进制/文本 fixture,并保持 moon fmt、moon info、moon check --deny-warn、moon test --deny-warn 全绿。

    AnalysisReport

    pub(all) struct AnalysisReport {
    valid : Bool
    stats : JsonStats
    canonical : String?
    digest : String?
    error : String?
    }

    The result of inspecting a JSON document. A failed report still contains the zero stats value so callers can render one stable response shape.

    AnalysisReport::to_json

    fn AnalysisReport::to_json(self : AnalysisReport) -> String

    Render a report as JSON without relying on a host JSON implementation.

    AnalysisReport::to_text

    fn AnalysisReport::to_text(self : AnalysisReport) -> String

    Render a report as a stable, line-oriented summary suitable for terminals.

    CanonicalCheck

    pub(all) struct CanonicalCheck {
    valid_json : Bool
    canonical : Bool
    normalized : String?
    reason : String?
    }

    Result of checking whether a JSON document is already in JCS form.

    CanonicalDocument

    pub(all) struct CanonicalDocument {
    canonical : String
    digest : String
    byte_length : Int
    stats : JsonStats
    issue_count : Int
    }

    Fully prepared canonical document and its audit metadata.

    CanonicalDocument::summary

    fn CanonicalDocument::summary(self : CanonicalDocument) -> String

    CanonicalDocument::to_json

    fn CanonicalDocument::to_json(self : CanonicalDocument) -> String

    CanonicalError

    pub enum CanonicalError {
    InvalidNumber(String, String)
    NonFiniteNumber(String)
    }

    A value that cannot be represented by JCS canonical JSON.

    CanonicalError::kind

    fn CanonicalError::kind(self : CanonicalError) -> String

    CanonicalError::message

    fn CanonicalError::message(self : CanonicalError) -> String

    CanonicalError::to_json

    fn CanonicalError::to_json(self : CanonicalError) -> String

    CanonicalIssue

    pub(all) struct CanonicalIssue {
    path : String
    kind : CanonicalIssueKind
    source : String
    canonical : String
    }

    CanonicalIssue::to_text

    fn CanonicalIssue::to_text(self : CanonicalIssue) -> String

    CanonicalIssueKind

    pub enum CanonicalIssueKind {
    NumberSpelling
    ObjectMemberOrder
    }

    A semantic reason a parsed value would change under JCS normalization.

    CanonicalIssueKind::to_string

    fn CanonicalIssueKind::to_string(self : CanonicalIssueKind) -> String

    CanonicalPolicy

    pub enum CanonicalPolicy {
    RequireCanonical
    Normalize
    ReportOnly
    }

    How a caller should respond when valid JSON is not already canonical.

    CanonicalPolicy::to_json

    fn CanonicalPolicy::to_json(self : CanonicalPolicy) -> String

    CanonicalPolicy::to_string

    fn CanonicalPolicy::to_string(self : CanonicalPolicy) -> String

    ChangeOperation

    pub enum ChangeOperation {
    Add
    Remove
    Replace
    }

    A deterministic, review-friendly change plan derived from two documents. It is descriptive rather than an in-place mutator, so callers can review or approve changes before applying them in their own storage layer.

    ChangeOperation::to_json

    fn ChangeOperation::to_json(self : ChangeOperation) -> String

    ChangeOperation::to_string

    fn ChangeOperation::to_string(self : ChangeOperation) -> String

    ChangePlan

    pub(all) struct ChangePlan {
    path : String
    operation : ChangeOperation
    before : String?
    after : String?
    }

    ChangePlan::to_json

    fn ChangePlan::to_json(self : ChangePlan) -> String

    ComparisonReport

    pub(all) struct ComparisonReport {
    valid : Bool
    canonical_equal : Bool
    left_digest : String?
    right_digest : String?
    differences : Array[JsonDiff]
    error : String?
    }

    Combined comparison result for two JSON documents.

    ComparisonReport::to_json

    fn ComparisonReport::to_json(self : ComparisonReport) -> String

    DiffKind

    pub enum DiffKind {
    Added
    Removed
    Changed
    TypeChanged
    }

    The semantic kind of a difference between two JSON values.

    DiffKind::to_string

    fn DiffKind::to_string(self : DiffKind) -> String

    DigestEntry

    pub(all) struct DigestEntry {
    name : String
    digest : String
    byte_length : Int
    }

    One named canonical document in a reproducible digest manifest.

    DocumentLimits

    pub(all) struct DocumentLimits {
    max_depth : Int
    max_values : Int
    max_array_length : Int
    max_object_members : Int
    max_string_length : Int
    max_number_length : Int
    }

    Resource limits for untrusted JSON documents. Limits are checked after strict parsing, before a caller stores or hashes a potentially huge tree.

    DocumentLimits::default

    DocumentLimits::to_json

    fn DocumentLimits::to_json(self : DocumentLimits) -> String

    JsonDiff

    pub(all) struct JsonDiff {
    path : String
    kind : DiffKind
    left : String?
    right : String?
    }

    One difference, addressed by an RFC 6901-style JSON Pointer.

    JsonDiff::to_text

    fn JsonDiff::to_text(self : JsonDiff) -> String

    JsonEvent

    pub enum JsonEvent {
    BeginObject(String, Int)
    EndObject(String)
    BeginArray(String, Int)
    EndArray(String)
    Scalar(String, String, String)
    }

    Structural events emitted in document order for streaming-style consumers.

    JsonEvent::to_json

    fn JsonEvent::to_json(self : JsonEvent) -> String

    JsonEvent::to_text

    fn JsonEvent::to_text(self : JsonEvent) -> String

    JsonProfile

    pub(all) struct JsonProfile {
    stats : JsonStats
    key_count : Int
    unique_key_count : Int
    max_key_length : Int
    max_string_length : Int
    negative_zero_count : Int
    canonical_issue_count : Int
    }

    Additional audit metrics beyond the structural counters in JsonStats.

    JsonProfile::to_json

    fn JsonProfile::to_json(self : JsonProfile) -> String

    JsonStats

    pub(all) struct JsonStats {
    value_count : Int
    object_count : Int
    array_count : Int
    string_count : Int
    number_count : Int
    boolean_count : Int
    null_count : Int
    max_depth : Int
    max_array_length : Int
    max_object_members : Int
    }

    Counts and shape measurements for one JSON document.

    JsonStats::empty

    fn JsonStats::empty() -> JsonStats

    JsonStats::to_json

    fn JsonStats::to_json(self : JsonStats) -> String

    Render the metrics as a deterministic JSON object for scripts and CI.

    JsonToken

    pub(all) struct JsonToken {
    kind : JsonTokenKind
    lexeme : String
    start : Int
    end : Int
    }

    JsonToken::to_json

    fn JsonToken::to_json(self : JsonToken) -> String

    JsonTokenKind

    pub enum JsonTokenKind {
    LeftBrace
    RightBrace
    LeftBracket
    RightBracket
    Colon
    Comma
    StringLiteral
    NumberLiteral
    TrueLiteral
    FalseLiteral
    NullLiteral
    End
    }

    Lexical token categories exposed for diagnostics and editor integrations.

    JsonTokenKind::to_string

    fn JsonTokenKind::to_string(self : JsonTokenKind) -> String

    JsonValue

    pub enum JsonValue {
    Null
    Bool(Bool)
    Number(String)
    String(String)
    Array(Array[JsonValue])
    Object(Array[(String, JsonValue)])
    }

    A parsed JSON value. Number retains its input token until the JCS number serializer is applied; this prevents an early, host-specific conversion.

    KeyFrequency

    pub(all) struct KeyFrequency {
    key : String
    count : Int
    }

    Frequency of one object member name across a document tree.

    LimitViolation

    pub enum LimitViolation {
    DepthExceeded(String, Int)
    ValuesExceeded(String, Int)
    ArrayTooLong(String, Int)
    ObjectTooLarge(String, Int)
    StringTooLong(String, Int)
    NumberTooLong(String, Int)
    }

    LimitViolation::message

    fn LimitViolation::message(self : LimitViolation) -> String

    LimitViolation::to_json

    fn LimitViolation::to_json(self : LimitViolation) -> String

    NumberInfo

    pub(all) struct NumberInfo {
    original : String
    canonical : String
    kind : NumberKind
    negative_zero : Bool
    }

    NumberInfo::summary

    fn NumberInfo::summary(self : NumberInfo) -> String

    NumberInfo::to_json

    fn NumberInfo::to_json(self : NumberInfo) -> String

    NumberKind

    pub enum NumberKind {
    Zero
    Integer
    Fraction
    Exponent
    }

    The broad lexical shape of a JSON number, before IEEE-754 normalization.

    NumberKind::to_string

    fn NumberKind::to_string(self : NumberKind) -> String

    ParseError

    pub enum ParseError {
    UnexpectedEnd(Int)
    UnexpectedCharacter(Int, Char)
    Expected(Int, String)
    InvalidEscape(Int, String)
    InvalidNumber(Int, String)
    DuplicateKey(Int, String)
    TrailingContent(Int)
    }

    A source-positioned reason why strict JSON parsing failed.

    ParseError::kind

    fn ParseError::kind(self : ParseError) -> String

    ParseError::location

    fn ParseError::location(self : ParseError, input : String) -> SourceLocation

    ParseError::message

    fn ParseError::message(self : ParseError) -> String

    ParseError::to_json

    fn ParseError::to_json(self : ParseError) -> String

    PatchOperation

    pub enum PatchOperation {
    Add(String, JsonValue)
    Remove(String)
    Replace(String, JsonValue)
    }

    A JSON Patch-like operation over a parsed value. Paths use RFC 6901 JSON Pointer syntax, and operations are applied in array order.

    PatchOperation::to_json

    fn PatchOperation::to_json(self : PatchOperation) -> String

    PatchOperation::to_text

    fn PatchOperation::to_text(self : PatchOperation) -> String

    PolicyDecision

    pub(all) struct PolicyDecision {
    accepted : Bool
    canonical : String?
    digest : String?
    issues : Array[CanonicalIssue]
    error : String?
    }

    PolicyDecision::to_text

    fn PolicyDecision::to_text(self : PolicyDecision) -> String

    SelectedValue

    pub(all) struct SelectedValue {
    path : String
    value : JsonValue
    }

    A selected subtree retained with the pointer that identified it.

    SelectedValue::to_text

    fn SelectedValue::to_text(self : SelectedValue) -> String

    SourceLocation

    pub(all) struct SourceLocation {
    offset : Int
    line : Int
    column : Int
    }

    One-based line/column information for a character offset.

    SourceLocation::to_string

    fn SourceLocation::to_string(self : SourceLocation) -> String

    SourceStats

    pub(all) struct SourceStats {
    character_count : Int
    line_count : Int
    whitespace_count : Int
    token_count : Int
    max_token_length : Int
    source_bytes : Int
    }

    Source-level measurements collected alongside lexical tokens.

    SourceStats::to_json

    fn SourceStats::to_json(self : SourceStats) -> String

    SourceStats::to_text

    fn SourceStats::to_text(self : SourceStats) -> String

    TreeIssue

    pub(all) struct TreeIssue {
    path : String
    kind : TreeIssueKind
    detail : String
    }

    TreeIssue::to_text

    fn TreeIssue::to_text(self : TreeIssue) -> String

    TreeIssueKind

    pub enum TreeIssueKind {
    DuplicateKey
    InvalidNumber
    DepthLimit
    }

    Validate invariants of a manually constructed JsonValue tree. Parsed input already satisfies these checks, but the API protects callers constructing values from another decoder or an in-memory transformation.

    TreeIssueKind::to_string

    fn TreeIssueKind::to_string(self : TreeIssueKind) -> String

    apply_merge_patch

    fn apply_merge_patch(target : JsonValue, patch : JsonValue) -> JsonValue

    Apply RFC 7396-style JSON Merge Patch semantics. Object members are merged recursively, null removes a member, and every other value replaces target.

    apply_patch

    fn apply_patch(value : JsonValue, operations : Array[PatchOperation]) -> Result[JsonValue, String]

    apply_patch_documents

    fn apply_patch_documents(input : String, operations : Array[PatchOperation]) -> Result[String, String]

    canonical_byte_length

    fn canonical_byte_length(value : JsonValue) -> Result[Int, CanonicalError]

    canonical_bytes

    fn canonical_bytes(value : JsonValue) -> Result[Bytes, CanonicalError]

    Return the canonical UTF-8 bytes of a parsed value.

    canonical_digest

    fn canonical_digest(value : JsonValue) -> Result[String, CanonicalError]

    Canonicalize a value and return the lowercase hexadecimal SHA-256 digest of its UTF-8 canonical representation. Hashing canonical bytes gives semantically equivalent JSON documents a stable content identifier.

    canonical_digest_bytes

    fn canonical_digest_bytes(value : JsonValue) -> Result[String, CanonicalError]

    canonical_idempotent

    fn canonical_idempotent(value : JsonValue) -> Result[Bool, CanonicalError]

    Check the core JCS invariant that canonicalizing an already canonical value is idempotent.

    canonical_idempotent_document

    fn canonical_idempotent_document(input : String) -> Result[Bool, String]

    canonical_issues

    fn canonical_issues(value : JsonValue) -> Array[CanonicalIssue]

    Inspect parsed values for semantic normalization changes. Whitespace and string escaping require source text and are covered by check_canonical; this API focuses on values where the parser has already discarded layout.

    canonical_number_token

    fn canonical_number_token(token : String) -> Result[String, CanonicalError]

    canonical_size

    fn canonical_size(value : JsonValue) -> Result[Int, CanonicalError]

    canonicalize

    fn canonicalize(value : JsonValue) -> Result[String, CanonicalError]

    Serialize a parsed value without insignificant whitespace. Object members are sorted recursively using UTF-16 code units, as required by RFC 8785. Number spelling is normalized by canonical_number and is kept separate so its IEEE-754 policy can be tested independently.

    canonicalize_json

    fn canonicalize_json(input : String) -> Result[String, String]

    Canonicalize a complete JSON document in one call.

    canonicalize_json_with_limits

    fn canonicalize_json_with_limits(input : String, limits : DocumentLimits) -> Result[String, String]

    Canonicalize untrusted input only after enforcing the caller's resource budget. The parsed tree is reused, so the input is not parsed twice.

    canonicalize_many

    fn canonicalize_many(inputs : Array[String]) -> Result[Array[String], String]

    canonicalize_many_text

    fn canonicalize_many_text(inputs : Array[String]) -> String

    change_plan

    fn change_plan(left : JsonValue, right : JsonValue) -> Array[ChangePlan]

    Convert semantic differences into a stable operation list.

    change_plan_documents

    fn change_plan_documents(left : String, right : String) -> Result[Array[ChangePlan], String]

    change_plan_text

    fn change_plan_text(plan : Array[ChangePlan]) -> String

    check_canonical

    fn check_canonical(input : String) -> CanonicalCheck

    Check syntax and compare the source byte-for-byte with its canonical form. This deliberately reports non-canonical but valid JSON separately from malformed JSON so formatters and CI can choose different policies.

    check_limits

    fn check_limits(value : JsonValue, limits : DocumentLimits) -> LimitViolation?

    Return the first limit violation in deterministic document order.

    child_count

    fn child_count(value : JsonValue) -> Int

    cli_help

    fn cli_help() -> String

    compare_documents

    fn compare_documents(left : String, right : String) -> ComparisonReport

    compare_object_keys

    fn compare_object_keys(left : String, right : String) -> Int

    Compare two member names by the UTF-16 code-unit ordering required by JCS.

    diagnose_document

    fn diagnose_document(input : String) -> Result[Array[CanonicalIssue], String]

    diff_documents

    fn diff_documents(left : String, right : String) -> Result[Array[JsonDiff], String]

    Parse and compare two documents, returning parser diagnostics as text.

    diff_json

    fn diff_json(left : JsonValue, right : JsonValue) -> Array[JsonDiff]

    Compare two parsed documents semantically. Object member order is ignored, while arrays remain ordered. The result is stable in left-to-right path order, which makes it suitable for review output and snapshot tests.

    diffs_json

    fn diffs_json(differences : Array[JsonDiff]) -> String

    digest_batch

    fn digest_batch(documents : Array[(String, String)]) -> Result[Array[DigestEntry], String]

    digest_dependency

    fn digest_dependency() -> String

    digest_json

    fn digest_json(input : String) -> Result[String, String]

    Hash a JSON document after parsing and canonicalizing it.

    digest_json_with_limits

    fn digest_json_with_limits(input : String, limits : DocumentLimits) -> Result[String, String]

    Hash untrusted input after enforcing resource limits during parsing.

    digest_manifest

    fn digest_manifest(documents : Array[(String, String)]) -> Result[String, String]

    Build a canonical JSON array describing a named document set. Sorting by name makes the manifest independent of filesystem traversal order.

    enforce_canonical

    fn enforce_canonical(input : String, limits : DocumentLimits) -> Result[String, String]

    enumerate_paths

    fn enumerate_paths(value : JsonValue) -> Array[(String, String)]

    Return canonical path/value pairs in depth-first order. This is useful for audit UIs that need to show exactly which values contributed to a digest.

    evaluate_policy

    fn evaluate_policy(input : String, limits : DocumentLimits, policy : CanonicalPolicy) -> PolicyDecision

    Evaluate syntax, resource limits, canonical form, and semantic issues as a single policy decision suitable for a CI gate.

    events_text

    fn events_text(events : Array[JsonEvent]) -> String

    format_parse_error

    fn format_parse_error(input : String, error : ParseError) -> String

    inspect_json

    fn inspect_json(input : String) -> AnalysisReport

    Parse, analyze, canonicalize, and hash one JSON document in one call.

    inspect_number

    fn inspect_number(token : String) -> Result[NumberInfo, CanonicalError]

    Parse and normalize one JSON number token while retaining useful audit metadata about the original spelling.

    inspect_source

    fn inspect_source(input : String) -> Result[SourceStats, String]

    is_canonical_json

    fn is_canonical_json(input : String) -> Bool

    is_container

    fn is_container(value : JsonValue) -> Bool

    issues_json

    fn issues_json(issues : Array[CanonicalIssue]) -> String

    issues_text

    fn issues_text(issues : Array[CanonicalIssue]) -> String

    key_frequencies

    fn key_frequencies(value : JsonValue) -> Array[KeyFrequency]

    key_frequencies_json

    fn key_frequencies_json(value : JsonValue) -> String

    keys_are_canonical

    fn keys_are_canonical(keys : Array[String]) -> Bool

    library_version

    fn library_version() -> String

    Library release metadata kept in one place for CLI hosts and package UIs.

    manifest_digest

    fn manifest_digest(documents : Array[(String, String)]) -> Result[String, String]

    merge_patch_documents

    fn merge_patch_documents(target : String, patch : String) -> Result[String, String]

    parse

    fn parse(input : String) -> Result[JsonValue, ParseError]

    Parse one complete strict JSON document. Object keys are checked while they are still textual so duplicate-key diagnostics do not depend on a map's overwrite behaviour.

    parse_with_limits

    fn parse_with_limits(input : String, limits : DocumentLimits) -> Result[JsonValue, String]

    Parse a document and enforce resource limits before returning its tree.

    patch_add

    fn patch_add(path : String, value : JsonValue) -> PatchOperation

    patch_remove

    fn patch_remove(path : String) -> PatchOperation

    patch_replace

    fn patch_replace(path : String, value : JsonValue) -> PatchOperation

    policy_normalize

    fn policy_normalize() -> CanonicalPolicy

    policy_report

    fn policy_report() -> CanonicalPolicy

    policy_require

    fn policy_require() -> CanonicalPolicy

    prepare_document

    fn prepare_document(input : String) -> Result[CanonicalDocument, String]

    Parse, normalize, hash, and collect metrics once for repeated consumers.

    prepare_document_with_limits

    fn prepare_document_with_limits(input : String, limits : DocumentLimits) -> Result[CanonicalDocument, String]

    Prepare a document while enforcing limits before collecting audit data.

    pretty_document

    fn pretty_document(input : String, indent_width : Int) -> Result[String, String]

    pretty_json

    fn pretty_json(value : JsonValue, indent_width : Int) -> Result[String, CanonicalError]

    Render a parsed value as deterministic human-readable JSON. Unlike canonicalize, this adds indentation and line breaks for review output.

    profile_document

    fn profile_document(input : String) -> Result[JsonProfile, String]

    profile_text

    fn profile_text(profile : JsonProfile) -> String

    profile_value

    fn profile_value(value : JsonValue) -> JsonProfile

    project_document

    fn project_document(input : String, pointers : Array[String]) -> Result[String, String]

    Project selected values into a deterministic array of {path,value} records. This preserves pointer order because callers often use it to generate small review artifacts from a large document.

    project_license

    fn project_license() -> String

    redact_document

    fn redact_document(input : String, pointers : Array[String], replacement_json : String) -> Result[String, String]

    Replace selected JSON Pointer values before logging or displaying a document. The original value is never mutated and the result is canonical.

    run_cli

    fn run_cli(args : Array[String]) -> (Bool, String)

    Execute the command-line protocol without touching process-global state. This small pure boundary keeps the CLI testable and lets another host embed the same commands without copying argument handling.

    scalar_paths

    fn scalar_paths(value : JsonValue) -> Array[String]

    select_document

    fn select_document(input : String, pointer : String) -> Result[JsonValue, String]

    select_many

    fn select_many(value : JsonValue, pointers : Array[String]) -> Result[Array[SelectedValue], String]

    select_pointer

    fn select_pointer(value : JsonValue, pointer : String) -> Result[JsonValue, String]

    Select a value using an RFC 6901 JSON Pointer. The empty pointer selects the document root; object keys use ~0 and ~1 escaping.

    selected_text

    fn selected_text(values : Array[SelectedValue]) -> String

    sha256_bytes

    fn sha256_bytes(bytes : Bytes) -> String

    Hash arbitrary UTF-8 bytes with the same lowercase SHA-256 representation used by canonical_digest.

    sort_object_keys

    fn sort_object_keys(keys : Array[String]) -> Array[String]

    source_location

    fn source_location(input : String, offset : Int) -> SourceLocation

    specification

    fn specification() -> String

    supported_commands

    fn supported_commands() -> Array[String]

    token_summary

    fn token_summary(tokens : Array[JsonToken]) -> String

    tokenize

    fn tokenize(input : String) -> Result[Array[JsonToken], ParseError]

    Tokenize a strict JSON document. Parsing first guarantees that string escapes and number boundaries have already passed the same RFC checks as the value parser; the scanner then preserves source spans and lexemes.

    utf16_sort_units

    fn utf16_sort_units(value : String) -> Array[Int]

    Expose the exact UTF-16 sort units used for an object member name.

    validate_tree

    fn validate_tree(value : JsonValue, max_depth : Int) -> Array[TreeIssue]

    value_kind_name

    fn value_kind_name(value : JsonValue) -> String

    verify_digest

    fn verify_digest(input : String, expected : String) -> Result[Bool, String]

    verify_manifest

    fn verify_manifest(manifest : String, documents : Array[(String, String)]) -> Result[Bool, String]

    Verify a manifest by recomputing every named document and comparing the canonical manifest bytes, including deterministic entry ordering.

    walk_events

    fn walk_events(value : JsonValue) -> Array[JsonEvent]