Documentation
¶
Overview ¶
Package opencodeevent consumes the bounded, neutral OpenCode observer wire. Optional product display context is desktop-only; webhooks remain neutral.
Index ¶
- Constants
- Variables
- func BridgeNativeDeadline(d notification.Deadline, rawBoot string) (notification.Deadline, error)
- func ClosedObject(raw []byte, required, optional []string) (map[string]json.RawMessage, error)
- func ReadOwnedBounded(ctx context.Context, input io.ReadCloser) ([]byte, error)
- func WriteClockSnapshot(args []string, output io.Writer, port SnapshotPort) int
- type Admission
- type AdmissionPort
- type AdmissionRequest
- type AdmissionStatus
- type ChannelGate
- type Clock
- type ClockAuthority
- type ClockPort
- type ClockSample
- type ClockSelection
- type ClockSnapshot
- type ComposedConsumer
- type Consumer
- type CounterPort
- type CounterSample
- type Entry
- type FactIdentity
- type Gate
- type GateFunc
- type Handoff
- type NativeTerminalIdentity
- type PrivateEvent
- type Provenance
- type Receipt
- type SnapshotPort
- type TerminalIdentityKind
- type TimePolicy
- type TrustedClock
- type WallPort
- type WebhookSender
Constants ¶
const MaxClockResponseBytes = 1024
Variables ¶
var ErrPrivateFrame = errors.New("invalid_frame")
Functions ¶
func BridgeNativeDeadline ¶ added in v1.48.0
func BridgeNativeDeadline(d notification.Deadline, rawBoot string) (notification.Deadline, error)
BridgeNativeDeadline preserves transport UUID spelling and NotAfter. It may only be used under a clock cell proving native RAW/Mach coordinate equality.
func ClosedObject ¶ added in v1.48.0
ClosedObject enforces exact casing, required keys and nonnull values. Callers validate the entire frame with strictjson first, including nested duplicates.
func ReadOwnedBounded ¶ added in v1.48.0
ReadOwnedBounded accepts only a handle whose Close unblocks Read (production os.Stdin). Cancellation closes and joins the reader before returning.
func WriteClockSnapshot ¶ added in v1.48.0
func WriteClockSnapshot(args []string, output io.Writer, port SnapshotPort) int
WriteClockSnapshot serves only the exact private command protocol.
Types ¶
type Admission ¶ added in v1.48.0
type Admission struct {
ControlRoot string
Clock ClockAuthority
TimePolicy TimePolicy
}
func (Admission) Admit ¶ added in v1.48.0
func (a Admission) Admit(ctx context.Context, r AdmissionRequest) (*Handoff, AdmissionStatus)
type AdmissionPort ¶ added in v1.48.0
type AdmissionPort interface {
Admit(context.Context, AdmissionRequest) (*Handoff, AdmissionStatus)
}
type AdmissionRequest ¶ added in v1.48.0
type AdmissionRequest struct {
Fact FactIdentity
Origin string
Provenance Provenance
Expected installruntime.PolicySnapshot
Executable, GOOS, GOARCH string
CommandStarted time.Time
}
type AdmissionStatus ¶ added in v1.48.0
type AdmissionStatus string
const ( Admitted AdmissionStatus = "admitted" InvalidFact AdmissionStatus = "invalid_fact" NotRegistered AdmissionStatus = "not_registered" SnapshotChanged AdmissionStatus = "snapshot_changed" TimeUnverified AdmissionStatus = "time_authority_unverified" Expired AdmissionStatus = "expired" Duplicate AdmissionStatus = "duplicate" Capacity AdmissionStatus = "capacity" )
type ChannelGate ¶
ChannelGate binds a product setup decision to the same event observation. Legacy test gates retain their existing allow-all-channel behavior.
type ClockAuthority ¶ added in v1.48.0
type ClockAuthority interface {
Snapshot(context.Context) (ClockSample, error)
}
ClockAuthority belongs to trusted system composition, never the wire sender. All ticks and epochs use integer nanoseconds; native qualification is external.
type ClockPort ¶ added in v1.48.0
type ClockPort struct {
Counter CounterPort
Wall WallPort
}
ClockPort is shared by the private helper and future admission. Wall is an anchor only: this port does not establish original event age or continuity.
func (ClockPort) SampleSnapshot ¶ added in v1.48.0
func (p ClockPort) SampleSnapshot() (ClockSnapshot, error)
type ClockSample ¶ added in v1.48.0
type ClockSelection ¶ added in v1.48.0
type ClockSelection struct {
Policy TimePolicy
CalibrationID, Generation string
TranslationBoundNS int64
}
ClockSelection is supplied only by trusted packaged composition. It binds the native clock and original source conversion, never a sender or config grant.
func SelectTrustedClock ¶ added in v1.48.0
func SelectTrustedClock(goos, goarch string) (ClockSelection, error)
SelectTrustedClock preserves the old platform-only diagnostic boundary. A platform is insufficient authority; event composition uses the exact image.
func SelectTrustedImageClock ¶ added in v1.48.0
func SelectTrustedImageClock(key opencodecodec.ImageKey) (ClockSelection, error)
type ClockSnapshot ¶ added in v1.48.0
type ClockSnapshot struct {
Boot, ClockDomain, ClockKind string
MonoLoNs, MonoHiNs, WallUnixNs, UncertaintyNs int64
}
func (ClockSnapshot) JSON ¶ added in v1.48.0
func (s ClockSnapshot) JSON() ([]byte, error)
JSON emits a closed protocol-1 object. It revalidates exported snapshots so later callers cannot accidentally serialize malformed or oversized authority.
type ComposedConsumer ¶ added in v1.48.0
type ComposedConsumer struct {
ControlRoot, Executable, GOOS, GOARCH string
Source SnapshotPort
Selection ClockSelection
ReadPolicy func(context.Context, string) (installruntime.PolicySnapshot, error)
Desktop func(*Handoff) notification.DeliveryPort
SendWebhook func(context.Context, *config.Config, webhook.SendContext) error
Assets config.AssetContext
}
ComposedConsumer is the production boundary: one snapshot and one E1 claim. Trusted ports permit independent test authority without a shipped test profile.
func (ComposedConsumer) Consume ¶ added in v1.48.0
func (c ComposedConsumer) Consume(ctx context.Context, started time.Time, input io.ReadCloser) Receipt
func (ComposedConsumer) ConsumeEntry ¶ added in v1.48.0
func (c ComposedConsumer) ConsumeEntry(entry *Entry, input io.ReadCloser) Receipt
ConsumeEntry lets the command start its budget before validating argv/env.
type Consumer ¶
type Consumer struct {
Gate Gate
Config *config.Config
Desktop notification.DeliveryPort
Clock Clock
SendWebhook WebhookSender
}
type CounterPort ¶ added in v1.48.0
type CounterPort interface{ SampleCounter() (CounterSample, bool) }
type CounterSample ¶ added in v1.48.0
CounterSample names the OS coordinate; neither caller-supplied quality nor wall time can authorize a counter kind.
type Entry ¶ added in v1.48.0
Entry owns the original timer and joined continuous watcher. E0 checks are independent of source qualification: availability alone grants no admission.
func BeginEntry ¶ added in v1.48.0
func (*Entry) Tighten ¶ added in v1.48.0
func (e *Entry) Tighten(p Provenance, policy TimePolicy) bool
type FactIdentity ¶ added in v1.48.0
type Gate ¶
Gate is the current, read-only opt-in and registration decision. A nil gate denies delivery. PR4 supplies the persisted implementation at composition.
type Handoff ¶ added in v1.48.0
type Handoff struct {
// contains filtered or unexported fields
}
Handoff is one durable claim for all channels. Close after bounded IO actually returns. Cancellation never reopens the claim or releases an active native ref.
func (*Handoff) Deadline ¶ added in v1.48.0
func (h *Handoff) Deadline() notification.Deadline
type NativeTerminalIdentity ¶ added in v1.48.0
type NativeTerminalIdentity struct {
Kind TerminalIdentityKind
ID string
}
NativeTerminalIdentity is supplied only after strict decoder/native binding validation. Neutral V1 decoding alone does not establish this authority.
type PrivateEvent ¶ added in v1.48.0
type PrivateEvent struct {
Event uap.ObservedEvent
Display json.RawMessage
Origin string
Fact FactIdentity
Provenance Provenance
}
func DecodePrivate ¶ added in v1.48.0
func DecodePrivate(raw []byte, selected ClockSelection) (PrivateEvent, error)
DecodePrivate retains SDK neutral decoding; only this closed additive frame can reach production admission. No opaque observationID parsing or restamping.
type Provenance ¶ added in v1.48.0
type Provenance struct {
Clock ClockSample
NativeCreatedNS, IngressTickNS, SpawnTickNS, DeadlineTickNS int64
SourceEpoch string
EpochStartedTickNS int64
TerminalBinding NativeTerminalIdentity
}
type Receipt ¶
type Receipt struct {
Status string `json:"status"`
Reason string `json:"reason,omitempty"`
Desktop string `json:"desktop,omitempty"`
Webhook string `json:"webhook,omitempty"`
}
Receipt contains only stable classification. It never includes event IDs, raw data, transport errors, configuration, or remote response content.
type SnapshotPort ¶ added in v1.48.0
type SnapshotPort interface{ SampleSnapshot() (ClockSnapshot, error) }
func NewSystemSnapshotPort ¶ added in v1.48.0
func NewSystemSnapshotPort() SnapshotPort
NewSystemSnapshotPort has no config, lease, store, provider or notification dependencies. Both helper and admission must sample this same OS coordinate.
type TerminalIdentityKind ¶ added in v1.48.0
type TerminalIdentityKind string
const ( V1FinalMessage TerminalIdentityKind = "v1_final_message" V2TerminalEvent TerminalIdentityKind = "v2_terminal_event" )
type TimePolicy ¶ added in v1.48.0
type TimePolicy struct {
ProfileID, RawKind, OriginalNativeAge string
NativeReadBoundNS, ComparisonBoundNS int64
}
TimePolicy is immutable trusted composition, selected from the qualified platform ledger. Wire provenance cannot select or enlarge either bound. R is native-only; T includes the independently qualified source/JS terms.
func (TimePolicy) Fence ¶ added in v1.48.0
func (p TimePolicy) Fence(boot, domain string) string
Fence binds the native coordinate and immutable policy, never a JS epoch. E2 derives the same digest from validated helper output and its fixed ledger.
type TrustedClock ¶ added in v1.48.0
type TrustedClock struct {
Source SnapshotPort
Selection ClockSelection
}
TrustedClock is a thin E0 adapter. Snapshot takes no sender arguments.
func (TrustedClock) Snapshot ¶ added in v1.48.0
func (c TrustedClock) Snapshot(ctx context.Context) (ClockSample, error)
type WebhookSender ¶
type WebhookSender func(*config.Config, webhook.SendContext) error
WebhookSender allows a single, non-replayed external attempt.