Documentation
¶
Overview ¶
ProfileAuthority is structural evidence for future opted-in consumers, not an authorization grant or an OS observation. It deliberately uses only stdlib.
Index ¶
- Constants
- Variables
- func ChatGPTPreparedAction(path, name string) string
- func ClientDisplayName(id ClientID) string
- func ComputeClientBindingID(installationID, clientID, scope, targetLocator string) string
- func ComputePhysicalArtifactID(declaredName, installationID string) string
- func ComputeSourceBindingID(source SourceIdentity) string
- func ExpectedDirectoryDelivery(client ClientID) (string, bool)
- func FatalLoad(code, path, message string, cause error) error
- func IsSupportedClient(id ClientID) bool
- func NewInstallationID() (string, error)
- func RequiresNativeProjector(id ClientID) bool
- func SameClientBackend(first, second ClientID) bool
- func SameProfileAuthority(a, b *ProfileAuthority) bool
- func SelectedMCPNames(plan DeliveryPlan) []string
- func SharesBackend(first, second ClientID) bool
- func ShouldReadOnlyVerify(id ClientID, executable string, intent InstallIntent) bool
- func SortSecurityFindings(findings []SecurityFinding)
- func ValidateAppBindingIdentity(appKey, id, mcpServer string) error
- func ValidateChatGPTAppID(id string) error
- func ValidateContext7PreparationPackage(e PackageEnvelope) error
- type ActivationMode
- type ActivationOutcome
- type ActivationRequest
- type ActivationState
- type AppBinding
- type AppComponent
- type AuthenticationRequirement
- type AuthenticationState
- type Author
- type CatalogAppBinding
- type CatalogCompatibility
- type CatalogEvidence
- type CatalogPlugin
- type CatalogResolution
- type CatalogV1
- type ChatGPTLocalMapping
- type ClientBinding
- type ClientCapabilities
- type ClientDefinition
- type ClientID
- type ClientPackageRevision
- type ClientSurface
- type ClientTraits
- type CompatibilityHints
- type ComponentDecision
- type ComponentInventory
- type ComponentKind
- type ComponentReadinessError
- type CursorDeliveryFacts
- type CursorHookReceipt
- type DataReceipt
- type DataReceiptState
- type DeactivationOutcome
- type DeactivationRequest
- type DeliveryPlan
- type DeliveryTarget
- type DetectedClient
- type DetectionStatus
- type Diagnostic
- type DirectoryAppBinding
- type DirectoryBuildProvenance
- type DirectoryDiagnostic
- type DirectoryDistribution
- type DirectoryEvidence
- type DirectoryEvidenceArtifact
- type DirectoryEvidenceTrust
- type DirectoryIcon
- type DirectoryMinimumCapabilities
- type DirectoryOperation
- type DirectoryOrigin
- type DirectoryProduct
- type DirectoryRelease
- type DirectoryReleasePolicy
- type DirectoryResolvePurpose
- type DirectoryResolveRequest
- type DirectoryRevocation
- type DirectorySelection
- type DirectorySnapshot
- type DirectorySource
- type DirectoryTarget
- type DistributionKind
- type DistributionStatus
- type ExecutableKind
- type FailureBoundary
- type InstallIntent
- type InstallPreference
- type InstallScope
- type Installation
- type LifecycleKind
- type LoadError
- type LoadInput
- type LocalDeliveryFacts
- type LocalEntryAbsence
- type LocalEntryObservation
- func (o *LocalEntryObservation) Clone() *LocalEntryObservation
- func (o *LocalEntryObservation) Equal(other *LocalEntryObservation) bool
- func (o *LocalEntryObservation) Facts() LocalEntryObservationFacts
- func (o *LocalEntryObservation) MarshalJSON() ([]byte, error)
- func (o *LocalEntryObservation) UnmarshalJSON(raw []byte) error
- func (o *LocalEntryObservation) Validate() error
- type LocalEntryObservationFacts
- type LocalQualifiedTuple
- type MCPComponent
- type MCPServer
- type MaterializationState
- type MutationReceipt
- type NativeAttemptIdentity
- type NativeEffectState
- type NativeIdentityObservation
- type NativeIdentityState
- type NativeIntentDirection
- type NativeObjectOwnership
- type OpenAIMCPAuthHint
- type OpenCodeHostAuthority
- type OpenCodeTransitionEntry
- type OpenCodeTransitionPrepared
- type OpenCodeTransitionReceipt
- type OriginMode
- type OwnedProfileEntry
- type PackageBinding
- type PackageEnvelope
- type PackageLimits
- type PackageMode
- type PackageSnapshot
- type PendingNativeIntent
- type PhysicalProfileOwner
- type PlanRequest
- type PlanStatus
- type PluginDataCompatibility
- type PluginDataDecision
- type PluginDataDisposition
- type PluginDataOwnership
- type PluginManifest
- type PolicyState
- type ProfileAuthority
- type ProfileAuthorityEntry
- type ProfileAuthorityFacts
- type RecordedDirectoryRelease
- type ReleaseStatus
- type SchemaIdentity
- type SecurityAssessment
- type SecurityCounts
- type SecurityEvaluationInput
- type SecurityEvidenceSource
- type SecurityFinding
- type SecurityOutcome
- type SecurityPolicy
- type SecurityRequirement
- type SecurityScanner
- type SecuritySubject
- type SelectedDelivery
- func (d SelectedDelivery) CanonicalDigest() string
- func (d SelectedDelivery) CursorFacts() (CursorDeliveryFacts, bool)
- func (d SelectedDelivery) CursorOwnership(r CursorHookReceipt) NativeObjectOwnership
- func (d SelectedDelivery) EffectiveTraits(id ClientID) ClientTraits
- func (d SelectedDelivery) IsZero() bool
- func (d SelectedDelivery) LocalFacts() (LocalDeliveryFacts, bool)
- func (d SelectedDelivery) MarshalJSON() ([]byte, error)
- func (d SelectedDelivery) Mode() string
- func (d SelectedDelivery) OwnsProfileEntry(objects []NativeObjectOwnership) bool
- func (d SelectedDelivery) ProfileRoot() string
- func (d SelectedDelivery) ProjectionDigest() string
- func (d SelectedDelivery) SameProfile(other SelectedDelivery) bool
- func (d SelectedDelivery) SameSelection(other SelectedDelivery) bool
- func (d SelectedDelivery) SharesBackend(id ClientID) bool
- func (d *SelectedDelivery) UnmarshalJSON(raw []byte) error
- func (d SelectedDelivery) Validate() error
- func (d SelectedDelivery) ValidateClient(id ClientID) error
- func (d SelectedDelivery) ValidateCursorObjects(objects []NativeObjectOwnership) error
- func (d SelectedDelivery) ValidateCursorReceipt(r CursorHookReceipt) error
- func (d SelectedDelivery) ValidatePlan(plan DeliveryPlan, canonicalDigest string) error
- func (d SelectedDelivery) WithProjectionDigest(digest string) (SelectedDelivery, error)
- type Severity
- type Skill
- type SourceBinding
- type SourceIdentity
- type StagedDelivery
- type StateDecisionDisposition
- type StateFileV2
- type StdioRequirement
- type SupportLevel
- type VerificationState
- type VersionedDocument
Constants ¶
const ( TreeDigestAlgorithm = "agentplugins-tree-sha256-v1" DefaultMaxFiles = 10_000 DefaultMaxFileBytes = int64(64 << 20) DefaultMaxTreeBytes = int64(256 << 20) DefaultMaxDepth = 64 )
const ( CatalogSchemaV1 = "https://github.com/777genius/universal-agent-plugins/schemas/catalog-v1.schema.json" CatalogSchemaV2 = "https://github.com/777genius/universal-agent-plugins/schemas/catalog-v2.schema.json" )
const ( ClientCodex ClientID = "codex" ClientChatGPT ClientID = "chatgpt" ClientCursor ClientID = "cursor" ClientCopilot ClientID = "copilot" ClientVSCode ClientID = "vscode" ClientKiro ClientID = "kiro" ClientClaude ClientID = "claude" ClientGemini ClientID = "gemini" ClientOpenCode ClientID = "opencode" ClientCline ClientID = "cline" ClientWindsurf ClientID = "windsurf" ClientGrok ClientID = "grok" ClientKimi ClientID = "kimi" DetectionNotDetected DetectionStatus = "not_detected" DetectionDetected DetectionStatus = "detected" ScopeUser InstallScope = "user" ScopeProject InstallScope = "project" PackageNative PackageMode = "native" PackageProjection PackageMode = "compatibility_projection" PackageBridge PackageMode = "client_bridge" PackagePrepared PackageMode = "prepared_package" ActivationAutomatic ActivationMode = "automatic" ActivationByClient ActivationMode = "client_managed" ActivationByUser ActivationMode = "manual" SupportNative SupportLevel = "native" SupportProjected SupportLevel = "projected" SupportPrepared SupportLevel = "prepared" SupportUnsupported SupportLevel = "unsupported" PlanReady PlanStatus = "ready" PlanPrepared PlanStatus = "prepared" PlanManualActivationRequired PlanStatus = "manual_activation_required" PlanUnsupported PlanStatus = "unsupported" ComponentSkill ComponentKind = "skill" ComponentMCPServer ComponentKind = "mcp_server" ComponentApp ComponentKind = "app" ComponentExtension ComponentKind = "extension" )
const ( DistributionActive DistributionStatus = "active" DistributionSuspended DistributionStatus = "suspended" ReleaseActive ReleaseStatus = "active" ReleaseSuperseded ReleaseStatus = "superseded" ReleaseRevoked ReleaseStatus = "revoked" )
const ( SecurityReportSchemaVersion = 1 SecurityScannerID = "lintai" SecurityScannerVersion = "0.1.3" SecurityPolicyID = "agent-plugin-install" SecurityPolicyVersion = 2 )
const ( LegacyStateSchemaVersion = 2 PreviousStateSchemaVersion = 3 StateSchemaVersion = 4 )
const ( OriginModeDirectory OriginMode = "directory" OriginModeDirect OriginMode = "direct" DistributionUpstream DistributionKind = "upstream" DistributionCommunityBridge DistributionKind = "community_bridge" DistributionCommunity DistributionKind = "community" DataReceiptOwned DataReceiptState = "owned" DataReceiptUnknown DataReceiptState = "unknown" DataReceiptStale DataReceiptState = "stale" NativeIdentityAbsent NativeIdentityState = "absent" NativeIdentityManaged NativeIdentityState = "managed" NativeIdentityUnmanaged NativeIdentityState = "unmanaged" NativeIdentityIndeterminate NativeIdentityState = "indeterminate" PluginDataNone PluginDataDisposition = "none" PluginDataRetained PluginDataDisposition = "retained" PluginDataOwnershipNone PluginDataOwnership = "none" PluginDataOwnershipOwned PluginDataOwnership = "owned" PluginDataOwnershipIndeterminate PluginDataOwnership = "indeterminate" PluginDataCompatibilityNotApplicable PluginDataCompatibility = "not_applicable" PluginDataCompatibilityNotProven PluginDataCompatibility = "not_proven" )
const ( MaterializationAbsent MaterializationState = "absent" MaterializationStaged MaterializationState = "staged" MaterializationMaterialized MaterializationState = "materialized" MaterializationDegraded MaterializationState = "degraded" ActivationNotRequired ActivationState = "not_required" ActivationPrepared ActivationState = "prepared" ActivationManual ActivationState = "manual_activation_required" ActivationActive ActivationState = "active" ActivationFailed ActivationState = "failed" AuthenticationNotRequired AuthenticationState = "not_required" AuthenticationNotChecked AuthenticationState = "not_checked" AuthenticationPending AuthenticationState = "auth_pending" AuthenticationComplete AuthenticationState = "authenticated" AuthenticationFailed AuthenticationState = "failed" PolicyAllowed PolicyState = "allowed" PolicyBlocked PolicyState = "blocked" PolicyApprovalRequired PolicyState = "approval_required" VerificationNotRun VerificationState = "not_run" VerificationPackageValid VerificationState = "package_validated" VerificationInstalled VerificationState = "installation_verified" VerificationRuntime VerificationState = "runtime_verified" VerificationFailed VerificationState = "failed" )
const ( LoaderKindAgentPlugins = "agent_plugins" FormatIDAgentPluginsV1 = "agent-plugins/1.0.0" FormatIDOpenAIPlugin = "openai-agent-plugin/current" LoaderKindLegacy = "legacy" FormatIDLegacyV1 = "plugin-kit-ai/v1" PluginSchemaV1 = "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json" MCPSchemaV1 = "https://agent-plugins.org/schemas/1.0.0/mcp.schema.json" )
const ChatGPTMappedPreparationAction = "Install Context7 from your personal marketplace in ChatGPT, then select it in a new chat."
ChatGPTMappedPreparationAction applies only after the personal mapping exists.
const ChatGPTRegistrationAction = "" /* 366-byte string literal not displayed */
const Context7ChatGPTURL = "https://mcp.context7.com/mcp"
const Context7OAuthURL = "https://mcp.context7.com/mcp/oauth"
const DeliveryCursorUserStopV1 = "cursor-user-stop-v1"
const DeliveryVSCodeLocalV1 = "vscode-local-v1"
const DirectoryEvidenceTrustCutoverSequence uint64 = 15
const PluginDataCompatibilityWarning = "" /* 135-byte string literal not displayed */
Variables ¶
Functions ¶
func ChatGPTPreparedAction ¶
ChatGPTPreparedAction names the local artifact after successful preparation.
func ClientDisplayName ¶
func ComputeClientBindingID ¶
func ComputeSourceBindingID ¶
func ComputeSourceBindingID(source SourceIdentity) string
func ExpectedDirectoryDelivery ¶
ExpectedDirectoryDelivery returns the signed Directory delivery contract for a logical client surface. Directory delivery describes the public packaging boundary, not the installer's internal PackageMode spelling.
func IsSupportedClient ¶
func NewInstallationID ¶
func RequiresNativeProjector ¶
RequiresNativeProjector reports whether staging this client must produce native object ownership through a Projector. A missing projector is fail-closed: empty native objects would look like a successful stage.
func SameClientBackend ¶
func SameProfileAuthority ¶
func SameProfileAuthority(a, b *ProfileAuthority) bool
func SelectedMCPNames ¶
func SelectedMCPNames(plan DeliveryPlan) []string
SelectedMCPNames is the deterministic delivery set, after static support and local readiness decisions. Consumers must not infer delivery from the envelope.
func SharesBackend ¶
SharesBackend is the two-argument form of a shared physical backend. Copilot and VS Code are the only pair today; callers should not name them.
func ShouldReadOnlyVerify ¶
func ShouldReadOnlyVerify(id ClientID, executable string, intent InstallIntent) bool
ShouldReadOnlyVerify reports whether verify-only Activate is meaningful for this client given the host executable and install intent. The branches are the declared traits, not a ClientID list: native-config always, CLI-registry hosts that expose a managed launcher or OpenAI auth hints or a sibling backend when an executable is present, and prepare-capable hosts that are not ChatGPT-style personal mapping when the intent is prepare or the executable names the client.
func SortSecurityFindings ¶
func SortSecurityFindings(findings []SecurityFinding)
func ValidateAppBindingIdentity ¶
ValidateAppBindingIdentity validates the signed identity tuple shared by Directory and legacy Catalog app bindings. URL and legacy runtime evidence are validated at their respective source boundaries.
func ValidateChatGPTAppID ¶
func ValidateContext7PreparationPackage ¶
func ValidateContext7PreparationPackage(e PackageEnvelope) error
Types ¶
type ActivationMode ¶
type ActivationMode string
type ActivationOutcome ¶
type ActivationOutcome struct {
LocalEntryObservation *LocalEntryObservation `json:"-"`
Activation ActivationState `json:"activation"`
Authentication AuthenticationState `json:"authentication"`
Policy PolicyState `json:"policy"`
Verification VerificationState `json:"verification"`
UserActions []string `json:"user_actions,omitempty"`
LocalActions []string `json:"-"`
ActivationAttested bool `json:"activation_attested,omitempty"`
AuthenticationAttested bool `json:"authentication_attested,omitempty"`
// AuthoritativeObservation marks recognized negative verifier evidence.
// It is transient control-plane metadata and is never persisted as state.
AuthoritativeObservation bool `json:"-"`
// Native effect evidence is transient and distinct from client verification.
NativeEffect NativeEffectState `json:"-"`
NativeObjects []NativeObjectOwnership `json:"-"`
}
type ActivationRequest ¶
type ActivationRequest struct {
// PackageUnchanged means activation reuses the committed, verified managed
// package without a new package transaction. External CLI effects may still
// be required; VerifyOnly describes those effects independently.
PackageUnchanged bool `json:"-"`
NativeAttempt NativeAttemptIdentity `json:"-"`
Client DetectedClient `json:"client"`
Plan DeliveryPlan `json:"plan"`
Delivery StagedDelivery `json:"delivery"`
DeclaredName string `json:"declared_name"`
Replacing bool `json:"replacing"`
Interactive bool `json:"interactive"`
BackendExecutable string `json:"-"`
// PreviousNativeObjects binds replacement preflight to the exact native
// objects recorded by the currently installed package revision.
PreviousNativeObjects []NativeObjectOwnership `json:"-"`
// VerifyOnly forbids client mutation and asks the provider to inspect the
// current client state. ActivationComplete is an explicit user attestation
// accepted only when verification is unavailable or returns unknown evidence.
VerifyOnly bool `json:"verify_only,omitempty"`
ActivationComplete bool `json:"activation_complete,omitempty"`
}
type ActivationState ¶
type ActivationState string
type AppBinding ¶
type AppBinding struct {
Alias string `json:"alias"`
ID string `json:"id"`
Optional bool `json:"optional,omitempty"`
Required bool `json:"required,omitempty"`
Raw json.RawMessage `json:"-"`
}
AppBinding references a connection that was registered outside the package. The CLI validates and projects this reference but never claims ownership of the remote connection.
type AppComponent ¶
type AppComponent struct {
Present bool `json:"present"`
Declared bool `json:"declared"`
Enabled bool `json:"enabled"`
Raw json.RawMessage `json:"-"`
Bindings map[string]AppBinding `json:"bindings,omitempty"`
}
AppComponent is the typed, lossless representation of the official root .app.json compatibility file.
type AuthenticationRequirement ¶
type AuthenticationRequirement string
const ( AuthenticationRequirementNotRequired AuthenticationRequirement = "not_required" AuthenticationRequirementRequired AuthenticationRequirement = "required" AuthenticationRequirementUnknown AuthenticationRequirement = "unknown" )
type AuthenticationState ¶
type AuthenticationState string
type CatalogAppBinding ¶
type CatalogCompatibility ¶
type CatalogCompatibility struct {
Package string `json:"package"`
Verification string `json:"verification"`
Authentication AuthenticationRequirement `json:"authentication"`
AppBinding *CatalogAppBinding `json:"app_binding,omitempty"`
Evidence []DirectoryEvidence `json:"evidence,omitempty"`
EvidenceOutcomes map[string]string `json:"evidence_outcomes,omitempty"`
}
type CatalogEvidence ¶
type CatalogEvidence struct {
SchemaVersion int `json:"schema_version"`
CatalogVersion string `json:"catalog_version"`
Repository string `json:"repository"`
Revision string `json:"revision"`
Digest string `json:"digest"`
MinimumCLIVersion string `json:"minimum_cli_version"`
AgentPluginsSchema string `json:"agent_plugins_schema"`
Compatibility map[string]CatalogCompatibility `json:"compatibility,omitempty"`
CurrentEvidence []DirectoryEvidence `json:"current_evidence,omitempty"`
}
CatalogEvidence is an immutable, versioned snapshot of the catalog facts used to resolve a package. It is kept separate from author-controlled plugin.json metadata so neither source can overwrite the other as schemas evolve.
type CatalogPlugin ¶
type CatalogPlugin struct {
Name string `json:"name"`
Version string `json:"version"`
AgentPluginsSchema string `json:"agent_plugins_schema"`
MinimumCLIVersion string `json:"minimum_cli_version"`
SourcePath string `json:"source_path"`
TreeDigest string `json:"tree_digest"`
ManifestDigest string `json:"manifest_digest"`
Components []string `json:"components"`
Compatibility map[string]CatalogCompatibility `json:"compatibility"`
OpenAIMCPAuth map[string]OpenAIMCPAuthHint `json:"openai_mcp_auth,omitempty"`
}
type CatalogResolution ¶
type CatalogResolution struct {
Entry CatalogPlugin `json:"entry"`
SourceReference string `json:"source_reference"`
CatalogDigest string `json:"catalog_digest"`
Hints CompatibilityHints `json:"hints,omitempty"`
Evidence CatalogEvidence `json:"evidence"`
}
type ChatGPTLocalMapping ¶
type ChatGPTLocalMapping struct {
ProductID string `json:"product_id"`
Repository string `json:"repository"`
PackagePath string `json:"package_path"`
Server string `json:"server"`
URL string `json:"url"`
AppID string `json:"app_id"`
}
ChatGPTLocalMapping is a personal registration receipt, never catalog evidence. It is retained in private installer state across remove, including purge-data. Reinstallation revalidates its source and endpoint before projecting it.
func (ChatGPTLocalMapping) IsLegacyContext7Registration ¶
func (m ChatGPTLocalMapping) IsLegacyContext7Registration() bool
IsLegacyContext7Registration identifies receipts written by the broken 0.1.56 OAuth guidance. They may be replaced only by an explicit new app ID.
func (ChatGPTLocalMapping) Validate ¶
func (m ChatGPTLocalMapping) Validate() error
func (ChatGPTLocalMapping) ValidatePackage ¶
func (m ChatGPTLocalMapping) ValidatePackage(e PackageEnvelope) error
type ClientBinding ¶
type ClientBinding struct {
ProfileAuthority *ProfileAuthority `json:"profile_authority,omitempty"`
ProfileNamespace string `json:"profile_namespace,omitempty"`
LocalEntryObservation *LocalEntryObservation `json:"local_entry_observation,omitempty"`
SelectedDelivery SelectedDelivery `json:"selected_delivery,omitzero"`
PendingNativeIntent *PendingNativeIntent `json:"pending_native_intent,omitempty"`
InstallIntent InstallIntent `json:"install_intent,omitempty"`
ClientBindingID string `json:"client_binding_id"`
ClientID string `json:"client_id"`
Scope string `json:"scope"`
TargetLocator string `json:"target_locator"`
PhysicalArtifact string `json:"physical_artifact_id"`
Materialization MaterializationState `json:"materialization"`
Activation ActivationState `json:"activation"`
Authentication AuthenticationState `json:"authentication"`
Policy PolicyState `json:"policy"`
Verification VerificationState `json:"verification"`
PackageRevision *ClientPackageRevision `json:"package_revision,omitempty"`
DataReceiptID string `json:"data_receipt_id,omitempty"`
AffectedSurfaces []string `json:"affected_surfaces,omitempty"`
// NativeProfileRoot binds a registration to its selected native profile.
NativeProfileRoot string `json:"native_profile_root,omitempty"`
// NativeActivationAttempt marks a potentially unacknowledged native effect.
NativeActivationAttempt string `json:"native_activation_attempt,omitempty"`
NativeObjects []NativeObjectOwnership `json:"native_objects,omitempty"`
Receipts []MutationReceipt `json:"receipts,omitempty"`
UpdatedAt string `json:"updated_at"`
}
func (ClientBinding) ValidateLocalEntryObservation ¶
func (binding ClientBinding) ValidateLocalEntryObservation() error
ValidateLocalEntryObservation checks linkage, including independently recorded selector ownership. A pending revision transition may retain the old sealed basis until a verified outcome replaces it; it must retain the same profile.
type ClientCapabilities ¶
type ClientCapabilities struct {
ClientID ClientID `json:"client_id"`
PackageMode PackageMode `json:"package_mode"`
ActivationMode ActivationMode `json:"activation_mode"`
Scopes []InstallScope `json:"scopes"`
SkillSupport SupportLevel `json:"skill_support"`
MCPTransports map[string]SupportLevel `json:"mcp_transports,omitempty"`
AppSupport SupportLevel `json:"app_support"`
ExtensionSupport SupportLevel `json:"extension_support"`
}
type ClientDefinition ¶
type ClientDefinition struct {
ID ClientID
DisplayName string
BackendFamily string
DirectoryDelivery string
CatalogPackage string
LegacyCatalogRequired bool
// PlansWithoutHostPresence marks a client that is not installed on this
// machine at all. Planning for it produces a prepared artifact plus
// instructions, so "not detected here" is not a planning failure.
PlansWithoutHostPresence bool
// DirectoryPreparationPurpose is the single bounded resolve purpose this
// client may acquire source under. An empty value means the client has
// none, which is the normal case.
DirectoryPreparationPurpose DirectoryResolvePurpose
Capabilities ClientCapabilities
// Traits are installer policy for this client. They are not part of the
// public JSON capabilities contract and must not be serialized onto it.
Traits ClientTraits
}
ClientDefinition is the declarative identity contract shared by the CLI, Directory validation, planning, and read-only detection. Operational client mutation remains in client-specific adapters and is intentionally not part of this registry.
func ClientDefinitionFor ¶
func ClientDefinitionFor(id ClientID) (ClientDefinition, bool)
func ClientDefinitions ¶
func ClientDefinitions() []ClientDefinition
ClientDefinitions returns registry entries in stable user-facing order.
type ClientID ¶
type ClientID string
func BackendSiblings ¶
BackendSiblings returns the other clients installed through the same backend, in registry order. Copilot and VS Code are the only pair today: a package installed through the Copilot CLI is what VS Code then discovers.
func ParseClientID ¶
ParseClientID folds case and whitespace, maps known aliases onto canonical ids, and otherwise returns the lowercased value. Unknown names are not rejected here so later diagnostics can name the supported targets.
func SupportedClientIDs ¶
func SupportedClientIDs() []ClientID
type ClientPackageRevision ¶
type ClientPackageRevision struct {
Version string `json:"version,omitempty"`
ResolvedRevision string `json:"resolved_revision,omitempty"`
TreeDigest string `json:"tree_digest"`
ManifestDigest string `json:"manifest_digest"`
DistributionID string `json:"distribution_id,omitempty"`
ReleaseSequence uint64 `json:"release_sequence,omitempty"`
CatalogEvidence *CatalogEvidence `json:"catalog_evidence,omitempty"`
}
ClientPackageRevision records the exact portable package revision that was projected into one client. Installation.Package is the latest accepted revision, while individual clients may temporarily converge one at a time.
type ClientSurface ¶
type ClientTraits ¶
type ClientTraits struct {
InstallIntents []InstallIntent
LifecycleKind LifecycleKind
UsesManagedStdioLauncher bool
HonorsOpenAIMCPAuthHints bool
SupportsPreparedRecovery bool
RequiresPersonalMappingForPrepare bool
ReportsMCPToolNamespaceCollision bool
BindsNativeProfileRoot bool
TracksNativeEffects bool
}
ClientTraits are the declarative installer policies that used to hide behind ClientID switches. They are not serialized; a new client is added by filling this struct on its ClientDefinition row, not by teaching usecase another id.
func ClientTraitsFor ¶
func ClientTraitsFor(id ClientID) ClientTraits
ClientTraitsFor returns the declared traits for a known client. Unknown ids yield the zero value, which admits no prepare intent and no native lifecycle.
func (ClientTraits) Allows ¶
func (traits ClientTraits) Allows(intent InstallIntent) bool
Allows reports whether this client's table lists the intent. Validate still accepts historical empty automatic intent even when the slice omits it; callers that need that exception must go through Validate.
type CompatibilityHints ¶
type CompatibilityHints struct {
// Compatibility preserves generic, per-client catalog requirements. The
// OpenAI map remains for legacy projection consumers and is not authoritative
// for whether authentication is required.
Compatibility map[string]CatalogCompatibility `json:"compatibility,omitempty"`
OpenAIMCPAuth map[string]OpenAIMCPAuthHint `json:"openai_mcp_auth,omitempty"`
}
type ComponentDecision ¶
type ComponentDecision struct {
Kind ComponentKind `json:"kind"`
Name string `json:"name"`
Support SupportLevel `json:"support"`
Reason string `json:"reason,omitempty"`
}
type ComponentInventory ¶
type ComponentInventory struct {
MCPPresent bool `json:"mcp_present"`
MCPEnabled bool `json:"mcp_enabled"`
MCPServers []string `json:"mcp_servers,omitempty"`
InvalidMCPServer []string `json:"invalid_mcp_servers,omitempty"`
AppPresent bool `json:"app_present,omitempty"`
AppBindings []string `json:"app_bindings,omitempty"`
Skills []string `json:"skills,omitempty"`
InvalidSkills []string `json:"invalid_skills,omitempty"`
InvalidSkillsRoot bool `json:"invalid_skills_root,omitempty"`
Extensions []string `json:"extensions,omitempty"`
}
type ComponentKind ¶
type ComponentKind string
type ComponentReadinessError ¶
type ComponentReadinessError struct{ Code, Message string }
ComponentReadinessError describes an expected local delivery limitation. Unexpected ownership, filesystem, and consistency errors remain fatal.
func (*ComponentReadinessError) Error ¶
func (e *ComponentReadinessError) Error() string
type CursorDeliveryFacts ¶
type CursorDeliveryFacts struct {
ProfileRoot string `json:"profile_root"`
HooksPath string `json:"hooks_path"`
ProfileIdentity string `json:"profile_identity"`
CursorVersion string `json:"cursor_version"`
TargetOS string `json:"target_os"`
TargetArch string `json:"target_arch"`
QualificationID string `json:"qualification_id"`
Executable string `json:"executable"`
Selector string `json:"selector"`
Shell string `json:"shell"`
ObjectID string `json:"object_id"`
EntryDigest string `json:"entry_digest"`
CanonicalDigest string `json:"canonical_digest"`
ProjectionDigest string `json:"projection_digest,omitempty"`
PlannedReceipt CursorHookReceipt `json:"planned_receipt"`
OriginalExists bool `json:"original_exists"`
OriginalRawDigest string `json:"original_raw_digest"`
}
CursorDeliveryFacts is a value packet for one fixed user Stop route. The planned receipt and raw basis belong to this attempt, never to acknowledged ownership. No foreign document or mutable authority is retained.
func (*CursorDeliveryFacts) UnmarshalJSON ¶
func (f *CursorDeliveryFacts) UnmarshalJSON(raw []byte) error
type CursorHookReceipt ¶
type CursorHookReceipt struct {
Version int `json:"version"`
Event string `json:"event"`
Executable string `json:"executable"`
Selector string `json:"selector"`
Shell string `json:"shell"`
EntryDigest string `json:"entry_digest"`
RemainderDigest string `json:"remainder_digest"`
}
CursorHookReceipt carries the primitive facts of the pure hook planner. Zero is no ownership proof; omitzero preserves Local and legacy wire bytes.
func (*CursorHookReceipt) UnmarshalJSON ¶
func (r *CursorHookReceipt) UnmarshalJSON(raw []byte) error
type DataReceipt ¶
type DataReceipt struct {
DataReceiptID string `json:"data_receipt_id"`
PhysicalBackend string `json:"physical_backend_id"`
Scope string `json:"scope"`
Locator string `json:"locator"`
OwnershipDigest string `json:"ownership_digest"`
State DataReceiptState `json:"state"`
CreatedAt string `json:"created_at,omitempty"`
UpdatedAt string `json:"updated_at,omitempty"`
}
DataReceipt proves ownership of one persistent PLUGIN_DATA directory. It is installation-level because multiple logical clients can share one physical backend. Package replacement and binding removal never consume the receipt.
type DataReceiptState ¶
type DataReceiptState string
type DeactivationOutcome ¶
type DeactivationOutcome struct {
Activation ActivationState `json:"activation"`
ArtifactRemovalAllowed bool `json:"artifact_removal_allowed"`
ExternalRemovalComplete bool `json:"external_removal_complete"`
UserActions []string `json:"user_actions,omitempty"`
LocalActions []string `json:"-"`
}
type DeactivationRequest ¶
type DeactivationRequest struct {
LocalEntryObservation *LocalEntryObservation `json:"-"`
RemoveOwnedEntry bool `json:"-"`
SelectedDelivery SelectedDelivery `json:"-"`
Client DetectedClient `json:"client"`
DeclaredName string `json:"declared_name"`
CurrentActivation ActivationState `json:"current_activation"`
Interactive bool `json:"interactive"`
ExternalUninstalled bool `json:"external_uninstalled"`
Confirmed bool `json:"confirmed"`
PhysicalArtifactID string `json:"physical_artifact_id"`
BackendExecutable string `json:"-"`
ManagedArtifactPath string `json:"-"`
NativeObjects []NativeObjectOwnership `json:"-"`
}
type DeliveryPlan ¶
type DeliveryPlan struct {
PreviousNativeObjects []NativeObjectOwnership `json:"-"`
LocalEntryObservation *LocalEntryObservation `json:"-"`
SelectedDelivery SelectedDelivery `json:"-"`
OpenCodeHost OpenCodeHostAuthority `json:"-"`
PersonalChatGPTPreparation bool `json:"-"`
InstallIntent InstallIntent `json:"install_intent,omitempty"`
ClientID ClientID `json:"client_id"`
Scope InstallScope `json:"scope"`
Status PlanStatus `json:"status"`
PackageMode PackageMode `json:"package_mode"`
Activation ActivationState `json:"activation"`
Authentication AuthenticationState `json:"authentication"`
Policy PolicyState `json:"policy"`
Verification VerificationState `json:"verification"`
PhysicalArtifactID string `json:"physical_artifact_id"`
// DeclaredName and NativeRegistry* are preflight-only identity inputs. They
// are deliberately excluded from public output because registry locators
// can reveal local user paths.
DeclaredName string `json:"-"`
DeclaredVersion string `json:"-"`
NativeRegistryRoot string `json:"-"`
NativeRegistryExecutable string `json:"-"`
// LocalPreparationAuthorized records validated package evidence or an explicit
// personal Context7 registration receipt that permits
// creation of the local prepared package even when a remote, manually
// activated registry cannot be observed. It is never evidence that the
// remote identity is free, activated, authenticated, or verified.
LocalPreparationAuthorized bool `json:"-"`
Components []ComponentDecision `json:"components,omitempty"`
UserActions []string `json:"user_actions,omitempty"`
// LocalActions can contain operational paths and are rendered only in
// human-readable output. They must never be emitted by the public JSON API.
LocalActions []string `json:"-"`
Warnings []string `json:"warnings,omitempty"`
Diagnostics []Diagnostic `json:"diagnostics,omitempty"`
// TargetRoot and ActivePath are intentionally excluded from public JSON.
TargetAnchor string `json:"-"`
TargetRoot string `json:"-"`
ActivePath string `json:"-"`
// contains filtered or unexported fields
}
func (DeliveryPlan) ProfileAuthority ¶
func (p DeliveryPlan) ProfileAuthority() *ProfileAuthority
func (DeliveryPlan) ProfileNamespace ¶
func (p DeliveryPlan) ProfileNamespace() string
func (DeliveryPlan) WithProfileAuthority ¶
func (p DeliveryPlan) WithProfileAuthority(token *ProfileAuthority, namespace string) DeliveryPlan
type DeliveryTarget ¶
type DeliveryTarget struct {
TargetAnchor string `json:"-"`
TargetRoot string `json:"-"`
ActivePath string `json:"-"`
// contains filtered or unexported fields
}
DeliveryTarget contains deterministic operational paths computed from the configured client roots. Persisted state must be checked against this value before any destructive operation.
func (DeliveryTarget) ProfileAuthority ¶
func (p DeliveryTarget) ProfileAuthority() *ProfileAuthority
func (DeliveryTarget) ProfileNamespace ¶
func (p DeliveryTarget) ProfileNamespace() string
func (DeliveryTarget) WithProfileAuthority ¶
func (p DeliveryTarget) WithProfileAuthority(token *ProfileAuthority, namespace string) DeliveryTarget
type DetectedClient ¶
type DetectedClient struct {
ProfileAuthority *ProfileAuthority `json:"-"`
ProfileNamespace string `json:"-"`
OpenCodeHost OpenCodeHostAuthority `json:"-"`
ClientID ClientID `json:"client_id"`
DisplayName string `json:"display_name"`
Status DetectionStatus `json:"status"`
Version string `json:"version,omitempty"`
Surfaces []ClientSurface `json:"surfaces,omitempty"`
// ExecutablePath and ConfigRoot are operational locators. They must never be
// emitted by the public JSON renderer because they can reveal the user home.
ExecutablePath string `json:"-"`
ConfigRoot string `json:"-"`
// DetectionError is private diagnostic evidence. A failed client must not
// contribute paths or become a lifecycle target.
DetectionError error `json:"-"`
}
type DetectionStatus ¶
type DetectionStatus string
type Diagnostic ¶
type DirectoryAppBinding ¶
type DirectoryDiagnostic ¶
type DirectoryDistribution ¶
type DirectoryDistribution struct {
SchemaVersion int `json:"schema_version"`
ID string `json:"id"`
ProductID string `json:"product_id"`
Kind DistributionKind `json:"kind"`
Status DistributionStatus `json:"status"`
Packager string `json:"packager"`
Releases []DirectoryRelease `json:"releases"`
ReleasePolicies []DirectoryReleasePolicy `json:"release_policies"`
}
type DirectoryEvidence ¶
type DirectoryEvidence struct {
SchemaVersion int `json:"schema_version"`
ID string `json:"id"`
ProductID string `json:"product_id,omitempty"`
DistributionID string `json:"distribution_id"`
ReleaseSequence uint64 `json:"release_sequence"`
PackageTreeDigest string `json:"package_tree_digest"`
ManifestDigest string `json:"manifest_digest,omitempty"`
SourceRepository string `json:"source_repository,omitempty"`
SourceRevision string `json:"source_revision,omitempty"`
SourcePath string `json:"source_path,omitempty"`
Level string `json:"level"`
Outcome string `json:"outcome"`
Client ClientID `json:"client,omitempty"`
ClientVersion string `json:"client_version,omitempty"`
InstallerVersion string `json:"installer_version,omitempty"`
AdapterVersion string `json:"adapter_version,omitempty"`
OS string `json:"os,omitempty"`
Architecture string `json:"architecture,omitempty"`
DependencyIdentity string `json:"dependency_identity,omitempty"`
ObservedAt string `json:"observed_at,omitempty"`
Artifact DirectoryEvidenceArtifact `json:"artifact"`
Trust *DirectoryEvidenceTrust `json:"trust,omitempty"`
}
func (DirectoryEvidence) HasTrustedEligibilityProvenance ¶
func (e DirectoryEvidence) HasTrustedEligibilityProvenance() bool
HasTrustedEligibilityProvenance applies the schema-1 compatibility rule for evidence that can block or promote a release. Static schema gates require reproducible workflow provenance. Materialization and client runtime gates may also use exact evidence explicitly reviewed by the signed Directory publisher.
func (DirectoryEvidence) HasTrustedEligibilityProvenanceAtSequence ¶
func (e DirectoryEvidence) HasTrustedEligibilityProvenanceAtSequence(sequence uint64) bool
HasTrustedEligibilityProvenanceAtSequence applies the eligibility-level rules after recognizing the historical or current provenance lane.
func (DirectoryEvidence) HasTrustedProvenance ¶
func (e DirectoryEvidence) HasTrustedProvenance() bool
HasTrustedProvenance reports whether evidence carries one of the provenance forms recognized by Directory schema 1. GitHub Actions provenance is bound to the repository and revision containing the evidence artifact; an external provenance is trusted only when the signed Directory publisher marked it as reviewed and supplied no forged workflow fields.
func (DirectoryEvidence) HasTrustedProvenanceAtSequence ¶
func (e DirectoryEvidence) HasTrustedProvenanceAtSequence(sequence uint64) bool
HasTrustedProvenanceAtSequence recognizes both immutable schema-1 evidence lanes. Sequences 1-14 used release-bound legacy identity fields; sequence 15 and later use the explicit trust object. A populated trust object always uses the current path so domain-only fixtures cannot accidentally become legacy.
type DirectoryEvidenceTrust ¶
type DirectoryEvidenceTrust struct {
Kind string `json:"kind"`
Workflow string `json:"workflow,omitempty"`
SourceRef string `json:"source_ref,omitempty"`
SourceDigest string `json:"source_digest,omitempty"`
BundleManifest *DirectoryEvidenceArtifact `json:"bundle_manifest,omitempty"`
LaunchArtifact *DirectoryEvidenceArtifact `json:"launch_artifact,omitempty"`
ObserverArtifact *DirectoryEvidenceArtifact `json:"observer_artifact,omitempty"`
EvidenceIndex *DirectoryEvidenceArtifact `json:"evidence_index,omitempty"`
}
type DirectoryIcon ¶
type DirectoryOperation ¶
type DirectoryOperation string
const ( DirectoryInstall DirectoryOperation = "install" DirectoryNewTarget DirectoryOperation = "new_target" DirectoryUpdate DirectoryOperation = "update" DirectoryRepair DirectoryOperation = "repair" DirectoryRematerialize DirectoryOperation = "rematerialize" DirectoryRemove DirectoryOperation = "remove" DirectoryReproduce DirectoryOperation = "reproduce" )
type DirectoryOrigin ¶
type DirectoryOrigin struct {
ProductID string `json:"product_id"`
DistributionID string `json:"distribution_id"`
DistributionKind DistributionKind `json:"distribution_kind"`
DesiredReleaseSequence uint64 `json:"desired_release_sequence"`
SnapshotSchema int `json:"snapshot_schema,omitempty"`
SnapshotSequence uint64 `json:"snapshot_sequence,omitempty"`
SnapshotDigest string `json:"snapshot_digest,omitempty"`
}
DirectoryOrigin is the minimum signed Directory provenance needed to make lifecycle decisions without copying mutable product or policy metadata into local state. DistributionID and DesiredReleaseSequence, bound to Installation.Source.ResolvedRevision, form the immutable desired release identity.
type DirectoryProduct ¶
type DirectoryProduct struct {
SchemaVersion int `json:"schema_version"`
ID string `json:"id"`
DisplayName string `json:"display_name"`
Description string `json:"description"`
ManifestName string `json:"manifest_name"`
Aliases []string `json:"aliases"`
ReservedAliases []string `json:"reserved_aliases"`
Categories []string `json:"categories"`
Icon *DirectoryIcon `json:"icon,omitempty"`
MinimumCapabilities DirectoryMinimumCapabilities `json:"minimum_capabilities"`
DefaultDistribution string `json:"default_distribution"`
Distributions []string `json:"distributions"`
}
type DirectoryRelease ¶
type DirectoryRelease struct {
Sequence uint64 `json:"sequence"`
PackageVersion string `json:"package_version"`
ManifestName string `json:"manifest_name"`
AgentPluginsSchema string `json:"agent_plugins_schema"`
PackageSource DirectorySource `json:"package_source"`
TreeDigestAlgorithm string `json:"tree_digest_algorithm"`
BuildProvenance *DirectoryBuildProvenance `json:"build_provenance,omitempty"`
TreeDigest string `json:"tree_digest"`
ManifestDigest string `json:"manifest_digest"`
Components []string `json:"components"`
PublishedAt string `json:"published_at"`
}
type DirectoryReleasePolicy ¶
type DirectoryReleasePolicy struct {
ReleaseSequence uint64 `json:"release_sequence"`
Status ReleaseStatus `json:"status"`
MinimumInstallerVersion string `json:"minimum_installer_version"`
Targets []DirectoryTarget `json:"targets"`
CurrentEvidence []string `json:"current_evidence"`
}
type DirectoryResolvePurpose ¶
type DirectoryResolvePurpose string
DirectoryResolvePurpose distinguishes normal target eligibility from the bounded acquisition of source for local preparation. The zero value retains normal resolution; callers must explicitly opt in after validating intent.
const DirectoryResolveContext7ChatGPTPreparation DirectoryResolvePurpose = "context7_chatgpt_preparation"
DirectoryResolveContext7ChatGPTPreparation permits only source acquisition for Context7 ChatGPT user-scope local preparation, pending mapping validation. Its selection is not signed ChatGPT compatibility or installation authority.
type DirectoryResolveRequest ¶
type DirectoryResolveRequest struct {
Purpose DirectoryResolvePurpose
Selector string
Targets []ClientID
Scope InstallScope
InstallerVersion string
ClientVersions map[ClientID]string
OS string
Architecture string
DependencyIdentity map[ClientID]string
SchemaVersion string
RequiredComponents []string
Operation DirectoryOperation
Recorded *RecordedDirectoryRelease
}
type DirectoryRevocation ¶
type DirectorySelection ¶
type DirectorySelection struct {
ProductID string `json:"product_id"`
DistributionID string `json:"distribution_id"`
DistributionKind DistributionKind `json:"distribution_kind"`
ReleaseSequence uint64 `json:"release_sequence"`
PackageVersion string `json:"package_version"`
Source DirectorySource `json:"source"`
TreeDigestAlgorithm string `json:"tree_digest_algorithm"`
TreeDigest string `json:"tree_digest"`
ManifestDigest string `json:"manifest_digest"`
SnapshotSequence uint64 `json:"snapshot_sequence"`
Fallback bool `json:"fallback"`
Diagnostics []DirectoryDiagnostic `json:"diagnostics,omitempty"`
}
func ResolveDirectory ¶
func ResolveDirectory(snapshot DirectorySnapshot, request DirectoryResolveRequest) (DirectorySelection, error)
ResolveDirectory is deterministic and side-effect free. It selects one distribution and one release for the complete target set; acquisition failure is intentionally not a fallback input.
type DirectorySnapshot ¶
type DirectorySnapshot struct {
SnapshotSchemaVersion int `json:"snapshot_schema_version"`
Sequence uint64 `json:"sequence"`
PublicationID string `json:"publication_id"`
SourceCommit string `json:"source_commit"`
GeneratedAt string `json:"generated_at"`
ExpiresAt string `json:"expires_at"`
Products []DirectoryProduct `json:"products"`
Distributions []DirectoryDistribution `json:"distributions"`
Evidence []DirectoryEvidence `json:"evidence"`
Revocations []DirectoryRevocation `json:"revocations"`
}
DirectorySnapshot is the authenticated schema-1 domain document. Transport, signature verification, time, and persistence deliberately live outside the domain package.
type DirectorySource ¶
type DirectoryTarget ¶
type DirectoryTarget struct {
Client ClientID `json:"client"`
Scopes []InstallScope `json:"scopes"`
Delivery string `json:"delivery"`
Authentication AuthenticationRequirement `json:"authentication"`
AppBinding *DirectoryAppBinding `json:"app_binding,omitempty"`
}
type DistributionKind ¶
type DistributionKind string
type DistributionStatus ¶
type DistributionStatus string
type ExecutableKind ¶
type ExecutableKind string
const ( ExecutableBare ExecutableKind = "bare" ExecutableBundled ExecutableKind = "bundled" )
type FailureBoundary ¶
type FailureBoundary string
const ( BoundaryPlugin FailureBoundary = "plugin" BoundaryMCP FailureBoundary = "mcp" BoundaryMCPServer FailureBoundary = "mcp_server" BoundaryApp FailureBoundary = "app" BoundarySkill FailureBoundary = "skill" BoundaryExtension FailureBoundary = "extension" )
type InstallIntent ¶
type InstallIntent string
InstallIntent is persisted per binding. Empty historical state means automatic.
const ( InstallIntentAutomatic InstallIntent = "" InstallIntentPrepare InstallIntent = "prepare" )
func (*InstallIntent) UnmarshalJSON ¶
func (intent *InstallIntent) UnmarshalJSON(data []byte) error
func (InstallIntent) Validate ¶
func (intent InstallIntent) Validate(client ClientID) error
type InstallPreference ¶
type InstallPreference struct {
ClientID ClientID `json:"client_id"`
Scope InstallScope `json:"scope"`
InstallIntent InstallIntent `json:"install_intent"`
}
InstallPreference retains user intent after owned artifacts are removed. It carries no ownership or runtime verification evidence.
type InstallScope ¶
type InstallScope string
type Installation ¶
type Installation struct {
LocalChatGPTMapping *ChatGPTLocalMapping `json:"local_chatgpt_mapping,omitempty"`
InstallPreferences []InstallPreference `json:"install_preferences,omitempty"`
InstallationID string `json:"installation_id"`
DeclaredName string `json:"declared_name"`
Source SourceBinding `json:"source"`
Package PackageBinding `json:"package"`
OriginMode OriginMode `json:"origin_mode,omitempty"`
Directory *DirectoryOrigin `json:"directory,omitempty"`
OperationGroupID string `json:"operation_group_id,omitempty"`
DataReceipts map[string]DataReceipt `json:"data_receipts,omitempty"`
DataRetained bool `json:"data_retained,omitempty"`
Clients map[string]ClientBinding `json:"clients"`
NeedsRebind bool `json:"needs_rebind,omitempty"`
CreatedAt string `json:"created_at"`
UpdatedAt string `json:"updated_at"`
}
type LifecycleKind ¶
type LifecycleKind string
LifecycleKind is how the installer drives a client's host after a package is on disk. It is policy, not a serialized capability: JSON ClientCapabilities stay the public compatibility contract.
const ( LifecycleCLIRegistry LifecycleKind = "cli_registry" LifecycleNativeConfig LifecycleKind = "native_config" LifecycleManual LifecycleKind = "manual" LifecyclePrepared LifecycleKind = "prepared" )
type LoadError ¶
type LoadError struct {
Diagnostic Diagnostic
Cause error
}
type LoadInput ¶
type LoadInput struct {
SnapshotRoot string
TreeDigest string
ExecutableFiles []string
Source SourceIdentity
}
type LocalDeliveryFacts ¶
type LocalDeliveryFacts struct {
ProfileRoot string `json:"profile_root"`
SettingsPath string `json:"settings_path"`
ProfileIdentity string `json:"profile_identity"`
SettingsIdentity string `json:"settings_identity"`
Tuple LocalQualifiedTuple `json:"qualified_tuple"`
NativeStop bool `json:"native_stop"`
MCPServers []string `json:"mcp_servers,omitempty"`
Skills []string `json:"skills,omitempty"`
CanonicalDigest string `json:"canonical_digest"`
ProjectionDigest string `json:"projection_digest,omitempty"`
Registration OwnedProfileEntry `json:"registration"`
}
LocalDeliveryFacts describes one qualified physical profile and projection. These are adapter-established facts, not discovery from HOME or current env.
type LocalEntryAbsence ¶
type LocalEntryAbsence struct {
// contains filtered or unexported fields
}
LocalEntryAbsence classifies a parser-confirmed missing selector at one sealed revision. It grants no ownership or receipt. The adapter must first validate independently owned recorded authority; generic verification errors never qualify for absence restoration.
func NewLocalEntryAbsence ¶
func NewLocalEntryAbsence(basis SelectedDelivery) (*LocalEntryAbsence, error)
func (*LocalEntryAbsence) Error ¶
func (e *LocalEntryAbsence) Error() string
func (*LocalEntryAbsence) Matches ¶
func (e *LocalEntryAbsence) Matches(observation *LocalEntryObservation) bool
Matches compares the complete recorded revision, including qualification and desired selection. A zero classification or historical nil grants nothing.
type LocalEntryObservation ¶
type LocalEntryObservation struct {
// contains filtered or unexported fields
}
LocalEntryObservation records a verified entry at one sealed revision. It does not establish ownership; the producer must independently verify it.
func NewLocalEntryObservation ¶
func NewLocalEntryObservation(facts LocalEntryObservationFacts) (*LocalEntryObservation, error)
func (*LocalEntryObservation) Clone ¶
func (o *LocalEntryObservation) Clone() *LocalEntryObservation
func (*LocalEntryObservation) Equal ¶
func (o *LocalEntryObservation) Equal(other *LocalEntryObservation) bool
func (*LocalEntryObservation) Facts ¶
func (o *LocalEntryObservation) Facts() LocalEntryObservationFacts
func (*LocalEntryObservation) MarshalJSON ¶
func (o *LocalEntryObservation) MarshalJSON() ([]byte, error)
func (*LocalEntryObservation) UnmarshalJSON ¶
func (o *LocalEntryObservation) UnmarshalJSON(raw []byte) error
func (*LocalEntryObservation) Validate ¶
func (o *LocalEntryObservation) Validate() error
type LocalEntryObservationFacts ¶
type LocalEntryObservationFacts struct {
RevisionBasis SelectedDelivery `json:"revision_basis"`
Enabled bool `json:"enabled"`
ReceiptDigest string `json:"receipt_digest"`
}
type LocalQualifiedTuple ¶
type MCPComponent ¶
type MCPComponent struct {
Present bool `json:"present"`
Enabled bool `json:"enabled"`
SchemaURI string `json:"schema_uri,omitempty"`
Raw json.RawMessage `json:"-"`
Servers map[string]MCPServer `json:"servers,omitempty"`
InvalidServer map[string]Diagnostic `json:"invalid_servers,omitempty"`
}
type MCPServer ¶
type MCPServer struct {
Name string `json:"name"`
Type string `json:"type"`
Raw json.RawMessage `json:"-"`
Decoded map[string]any `json:"config"`
StdioRequirement *StdioRequirement `json:"stdio_requirement,omitempty"`
}
type MaterializationState ¶
type MaterializationState string
type MutationReceipt ¶
type MutationReceipt struct {
DirectoryProof json.RawMessage `json:"physical_directory_proof,omitempty"`
ProfileOwners []PhysicalProfileOwner `json:"profile_owners,omitempty"`
DataReceiptID string `json:"data_receipt_id,omitempty"`
OperationID string `json:"operation_id"`
OperationGroupID string `json:"operation_group_id,omitempty"`
Sequence int `json:"sequence"`
MutationType string `json:"mutation_type"`
ClientBindingID string `json:"client_binding_id"`
ActivePath string `json:"active_path,omitempty"`
StagingPath string `json:"staging_path,omitempty"`
BackupPath string `json:"backup_path,omitempty"`
BeforeDigest string `json:"before_digest,omitempty"`
AfterDigest string `json:"after_digest,omitempty"`
Phase string `json:"phase"`
}
type NativeAttemptIdentity ¶
type NativeAttemptIdentity struct {
OperationID, InstallationID, BindingID, NativeRoot string
}
NativeAttemptIdentity is transient authority from the existing durable fence, never package input or a second operation allocator.
type NativeEffectState ¶
type NativeEffectState string
NativeEffectState records observed configuration effects, never inferred merely from an activation or verification error.
const ( NativeEffectUnchanged NativeEffectState = "unchanged" NativeEffectCommitted NativeEffectState = "committed" NativeEffectUncertain NativeEffectState = "uncertain" )
type NativeIdentityObservation ¶
type NativeIdentityObservation struct {
State NativeIdentityState `json:"state"`
Digest string `json:"digest,omitempty"`
ReceiptReconciled bool `json:"receipt_reconciled,omitempty"`
NativeDiscoveryReconciled bool `json:"native_discovery_reconciled,omitempty"`
NativeDiscoveryState NativeIdentityState `json:"-"`
NativeDiscoveryAttempted bool `json:"-"`
}
type NativeIdentityState ¶
type NativeIdentityState string
type NativeIntentDirection ¶
type NativeIntentDirection string
const ( NativeIntentRegister NativeIntentDirection = "register" NativeIntentRemove NativeIntentDirection = "remove" )
type NativeObjectOwnership ¶
type NativeObjectOwnership struct {
CursorReceipt CursorHookReceipt `json:"cursor_receipt,omitzero"`
ObjectID string `json:"object_id"`
Kind string `json:"kind"`
LogicalName string `json:"logical_name,omitempty"`
Path string `json:"path,omitempty"`
SourceRelative string `json:"source_relative,omitempty"`
BeforeDigest string `json:"before_digest,omitempty"`
ManagedDigest string `json:"managed_digest,omitempty"`
ProtectionClass string `json:"protection_class"`
UserModified bool `json:"user_modified,omitempty"`
}
type OpenAIMCPAuthHint ¶
type OpenCodeHostAuthority ¶
OpenCodeHostAuthority is a read-only, immutable prepared-host port. It does no probing. The client contract owns the closed parent profile snapshot.
type OpenCodeTransitionEntry ¶
type OpenCodeTransitionEntry struct {
LogicalID, Name string
SourceReceipt, TargetReceipt OpenCodeTransitionReceipt
PreviouslyOwnedTarget *OpenCodeTransitionReceipt
}
type OpenCodeTransitionPrepared ¶
type OpenCodeTransitionPrepared struct {
Path string
OriginalBytes, TargetBytes []byte
OriginalMode uint32
OriginalExists bool
TargetHash, SourceCodec, TargetCodec string
Entries []OpenCodeTransitionEntry
}
OpenCodeTransitionPrepared is a host-neutral detached handoff. The private provider record adds exact state and skill intent under the outer operation lock.
type OpenCodeTransitionReceipt ¶
type OpenCodeTransitionReceipt struct{ Version, Path, Codec, Name, Digest string }
type OriginMode ¶
type OriginMode string
type OwnedProfileEntry ¶
type OwnedProfileEntry struct {
ObjectID string `json:"object_id"`
Selector string `json:"selector"`
DesiredValue *bool `json:"desired_value"`
PreviousValue *bool `json:"previous_value,omitempty"`
}
OwnedProfileEntry stores only the owned selector and bool authority, never foreign settings or a whole-document preimage. Nil PreviousValue means absent; an explicit false remains false across JSON and recovery.
func (OwnedProfileEntry) Ownership ¶
func (entry OwnedProfileEntry) Ownership(settingsPath string) NativeObjectOwnership
Ownership is the selected adapter's receipt for a profile entry. The digest binds the exact bool, including false, rather than unrelated document bytes.
type PackageBinding ¶
type PackageBinding struct {
LoaderKind string `json:"loader_kind"`
FormatID string `json:"format_id"`
SchemaURI string `json:"schema_uri"`
DeclaredName string `json:"declared_name"`
Version string `json:"version,omitempty"`
ManifestDigest string `json:"manifest_digest"`
Inventory ComponentInventory `json:"inventory"`
}
type PackageEnvelope ¶
type PackageEnvelope struct {
LocalChatGPTMapping *ChatGPTLocalMapping `json:"-"`
LoaderKind string `json:"loader_kind"`
FormatID string `json:"format_id"`
SchemaURI string `json:"schema_uri"`
SchemaVersion string `json:"schema_version"`
ManifestSchema SchemaIdentity `json:"manifest_schema"`
Manifest PluginManifest `json:"manifest"`
MCP MCPComponent `json:"mcp"`
App AppComponent `json:"app"`
Skills map[string]Skill `json:"skills,omitempty"`
Inventory ComponentInventory `json:"inventory"`
Diagnostics []Diagnostic `json:"diagnostics,omitempty"`
CatalogEvidence *CatalogEvidence `json:"catalog_evidence,omitempty"`
Source SourceIdentity `json:"source"`
TreeDigest string `json:"tree_digest"`
ManifestDigest string `json:"manifest_digest"`
ExecutableFiles []string `json:"executable_files,omitempty"`
SnapshotRoot string `json:"-"`
}
type PackageLimits ¶
type PackageMode ¶
type PackageMode string
type PackageSnapshot ¶
type PackageSnapshot struct {
Root string `json:"-"`
TreeDigest string `json:"tree_digest"`
DigestAlgorithm string `json:"digest_algorithm"`
FileCount int `json:"file_count"`
TotalBytes int64 `json:"total_bytes"`
ExecutableFiles []string `json:"executable_files,omitempty"`
Source SourceIdentity `json:"source"`
AcquiredAt time.Time `json:"-"`
}
type PendingNativeIntent ¶
type PendingNativeIntent struct {
PreviousCursorObject NativeObjectOwnership `json:"previous_cursor_object,omitzero"`
ProfileAuthority *ProfileAuthority `json:"profile_authority,omitempty"`
ProfileNamespace string `json:"profile_namespace,omitempty"`
LocalEntryObservation *LocalEntryObservation `json:"local_entry_observation,omitempty"`
RemoveOwnedEntry bool `json:"remove_owned_entry"`
AttemptID string `json:"attempt_id"`
Direction NativeIntentDirection `json:"direction"`
Delivery SelectedDelivery `json:"selected_delivery"`
}
PendingNativeIntent is the owned decision persisted in the existing binding before native effects. Reverse removal authority is as durable as registration. SelectedDelivery carries only the owned entry, never foreign document bytes.
func (*PendingNativeIntent) Clone ¶
func (intent *PendingNativeIntent) Clone() *PendingNativeIntent
func (PendingNativeIntent) Validate ¶
func (intent PendingNativeIntent) Validate(binding ClientBinding) error
type PhysicalProfileOwner ¶
type PhysicalProfileOwner struct {
Namespace string `json:"namespace"`
InstallationID string `json:"installation_id"`
ClientID string `json:"client_id"`
ClientBindingID string `json:"client_binding_id"`
Authority *ProfileAuthority `json:"authority"`
}
PhysicalProfileOwner freezes durable scope independently of a surviving binding.
type PlanRequest ¶
type PlanRequest struct {
PreviousNativeObjects []NativeObjectOwnership `json:"-"`
LocalEntryObservation *LocalEntryObservation `json:"-"`
Envelope PackageEnvelope
Client DetectedClient
Scope InstallScope
PhysicalArtifactID string
InstallIntent InstallIntent
Detected map[ClientID]DetectedClient
}
PlanRequest carries everything the planner needs for one delivery decision. Detected is the surface map used for backends a client shares with another logical client; a nil map means the planner falls back to the one its composition root configured.
type PlanStatus ¶
type PlanStatus string
type PluginDataCompatibility ¶
type PluginDataCompatibility string
type PluginDataDecision ¶
type PluginDataDecision struct {
Disposition PluginDataDisposition `json:"disposition"`
Present bool `json:"present"`
ReceiptCount int `json:"receipt_count"`
Ownership PluginDataOwnership `json:"ownership"`
Compatibility PluginDataCompatibility `json:"compatibility"`
Warning string `json:"warning,omitempty"`
}
PluginDataDecision is the public switch decision for persistent plugin data. It deliberately exposes ownership evidence without exposing the owned path.
type PluginDataDisposition ¶
type PluginDataDisposition string
type PluginDataOwnership ¶
type PluginDataOwnership string
type PluginManifest ¶
type PluginManifest struct {
SchemaURI string `json:"schema_uri"`
Name string `json:"name"`
Version string `json:"version,omitempty"`
Description string `json:"description,omitempty"`
Author *Author `json:"author,omitempty"`
Homepage string `json:"homepage,omitempty"`
Repository string `json:"repository,omitempty"`
License string `json:"license,omitempty"`
Keywords []string `json:"keywords,omitempty"`
Extensions map[string]json.RawMessage `json:"extensions,omitempty"`
RawExtensions json.RawMessage `json:"-"`
Unknown map[string]json.RawMessage `json:"unknown,omitempty"`
Raw json.RawMessage `json:"-"`
}
type PolicyState ¶
type PolicyState string
type ProfileAuthority ¶
type ProfileAuthority struct {
// contains filtered or unexported fields
}
An immutable canonical encoding avoids retaining caller-owned DTO slices.
func CloneProfileAuthority ¶
func CloneProfileAuthority(a *ProfileAuthority) *ProfileAuthority
func NewProfileAuthority ¶
func NewProfileAuthority(f ProfileAuthorityFacts) (ProfileAuthority, error)
func (ProfileAuthority) Equal ¶
func (a ProfileAuthority) Equal(b ProfileAuthority) bool
func (ProfileAuthority) Facts ¶
func (a ProfileAuthority) Facts() ProfileAuthorityFacts
func (ProfileAuthority) IsZero ¶
func (a ProfileAuthority) IsZero() bool
func (ProfileAuthority) MarshalJSON ¶
func (a ProfileAuthority) MarshalJSON() ([]byte, error)
func (*ProfileAuthority) UnmarshalJSON ¶
func (a *ProfileAuthority) UnmarshalJSON(b []byte) error
type ProfileAuthorityEntry ¶
type ProfileAuthorityFacts ¶
type ProfileAuthorityFacts struct {
Version int `json:"version"`
CanonicalRoot string `json:"canonical_root"`
Ancestry []ProfileAuthorityEntry `json:"ancestry"`
}
type RecordedDirectoryRelease ¶
type RecordedDirectoryRelease struct {
ProductID string
DistributionID string
ReleaseSequence uint64
Repository string
ResolvedRevision string
Path string
TreeDigestAlgorithm string
TreeDigest string
ManifestDigest string
}
RecordedDirectoryRelease binds a Directory tuple to every immutable source and package identity field retained by installed state. Empty optional fields mean that older or per-client state did not retain that field; populated fields must match the current signed snapshot exactly.
type ReleaseStatus ¶
type ReleaseStatus string
type SchemaIdentity ¶
SchemaIdentity makes a document's schema URI and interpreted version explicit without replacing its lossless Raw representation.
type SecurityAssessment ¶
type SecurityAssessment struct {
SchemaVersion int `json:"schema_version"`
Subject SecuritySubject `json:"subject"`
Scanner SecurityScanner `json:"scanner"`
Policy SecurityPolicy `json:"policy"`
Outcome SecurityOutcome `json:"outcome"`
Counts SecurityCounts `json:"counts"`
ScannedFiles int `json:"scanned_files"`
ReportDigest string `json:"report_digest"`
Findings []SecurityFinding `json:"findings,omitempty"`
Evidence SecurityEvidenceSource `json:"evidence_source,omitempty"`
}
func (SecurityAssessment) Validate ¶
func (assessment SecurityAssessment) Validate(requirement SecurityRequirement, subject SecuritySubject) error
type SecurityCounts ¶
type SecurityEvaluationInput ¶
type SecurityEvaluationInput struct {
SnapshotRoot string
TreeDigest string
ManifestDigest string
Trusted *SecurityAssessment
}
type SecurityEvidenceSource ¶
type SecurityEvidenceSource string
const ( SecurityEvidenceSignedIndex SecurityEvidenceSource = "signed_index" SecurityEvidenceCache SecurityEvidenceSource = "cache" SecurityEvidenceLocalScan SecurityEvidenceSource = "local_scan" )
type SecurityFinding ¶
type SecurityOutcome ¶
type SecurityOutcome string
const ( SecurityNoBlockingFindings SecurityOutcome = "no_blocking_findings" SecurityWarnings SecurityOutcome = "warnings" SecurityBlockingFindings SecurityOutcome = "blocking_findings" )
type SecurityPolicy ¶
type SecurityRequirement ¶
type SecurityRequirement struct {
Scanner SecurityScanner
Policy SecurityPolicy
}
type SecurityScanner ¶
type SecuritySubject ¶
type SelectedDelivery ¶
type SelectedDelivery struct {
// contains filtered or unexported fields
}
SelectedDelivery is a frozen selected-mode record. Its zero value preserves historical ClientID policy. Accessors return copies, including pointer bools; copying a plan or assessment cannot expose mutable constructor inputs. It is operational authority and must not appear in public diagnostic JSON.
func NewCursorDelivery ¶
func NewCursorDelivery(facts CursorDeliveryFacts) (SelectedDelivery, error)
func NewLocalDelivery ¶
func NewLocalDelivery(facts LocalDeliveryFacts) (SelectedDelivery, error)
func (SelectedDelivery) CanonicalDigest ¶
func (d SelectedDelivery) CanonicalDigest() string
func (SelectedDelivery) CursorFacts ¶
func (d SelectedDelivery) CursorFacts() (CursorDeliveryFacts, bool)
func (SelectedDelivery) CursorOwnership ¶
func (d SelectedDelivery) CursorOwnership(r CursorHookReceipt) NativeObjectOwnership
func (SelectedDelivery) EffectiveTraits ¶
func (d SelectedDelivery) EffectiveTraits(id ClientID) ClientTraits
EffectiveTraits preserves historical traits for an absent mode; a Local record supplies only the few lifecycle facts demonstrated by this delivery. Callers validate the record before using these facts to authorize effects.
func (SelectedDelivery) IsZero ¶
func (d SelectedDelivery) IsZero() bool
func (SelectedDelivery) LocalFacts ¶
func (d SelectedDelivery) LocalFacts() (LocalDeliveryFacts, bool)
func (SelectedDelivery) MarshalJSON ¶
func (d SelectedDelivery) MarshalJSON() ([]byte, error)
func (SelectedDelivery) Mode ¶
func (d SelectedDelivery) Mode() string
func (SelectedDelivery) OwnsProfileEntry ¶
func (d SelectedDelivery) OwnsProfileEntry(objects []NativeObjectOwnership) bool
func (SelectedDelivery) ProfileRoot ¶
func (d SelectedDelivery) ProfileRoot() string
func (SelectedDelivery) ProjectionDigest ¶
func (d SelectedDelivery) ProjectionDigest() string
func (SelectedDelivery) SameProfile ¶
func (d SelectedDelivery) SameProfile(other SelectedDelivery) bool
SameProfile fences immutable physical entry authority across an explicitly reviewed projection refresh. A fresh qualified tuple/component selection is allowed there; ordinary add/update/repair require SameSelection.
func (SelectedDelivery) SameSelection ¶
func (d SelectedDelivery) SameSelection(other SelectedDelivery) bool
SameSelection excludes revision digests: update/refresh can change projected bytes, but cannot silently change profile, shell, components or authority.
func (SelectedDelivery) SharesBackend ¶
func (d SelectedDelivery) SharesBackend(id ClientID) bool
func (*SelectedDelivery) UnmarshalJSON ¶
func (d *SelectedDelivery) UnmarshalJSON(raw []byte) error
Decoding retains unknown mode evidence so mutation can refuse without reinterpreting it as a historical receipt. No constructor/environment reads.
func (SelectedDelivery) Validate ¶
func (d SelectedDelivery) Validate() error
func (SelectedDelivery) ValidateClient ¶
func (d SelectedDelivery) ValidateClient(id ClientID) error
ValidateClient keeps the fixed Cursor client identity with its selection. Historical and Local selections retain their existing caller validations.
func (SelectedDelivery) ValidateCursorObjects ¶
func (d SelectedDelivery) ValidateCursorObjects(objects []NativeObjectOwnership) error
ValidateCursorObjects rejects zero, foreign and duplicate hook authority.
func (SelectedDelivery) ValidateCursorReceipt ¶
func (d SelectedDelivery) ValidateCursorReceipt(r CursorHookReceipt) error
func (SelectedDelivery) ValidatePlan ¶
func (d SelectedDelivery) ValidatePlan(plan DeliveryPlan, canonicalDigest string) error
ValidatePlan binds selected facts to actual package/projection inputs. Native shell and filesystem qualification belongs to the selected adapter in U4b.
func (SelectedDelivery) WithProjectionDigest ¶
func (d SelectedDelivery) WithProjectionDigest(digest string) (SelectedDelivery, error)
WithProjectionDigest seals the result of the existing stager, separately from canonical package identity. It does not change the original selected record.
type Skill ¶
type Skill struct {
Name string `json:"name"`
Description string `json:"description"`
License string `json:"license,omitempty"`
Compatibility string `json:"compatibility,omitempty"`
Metadata map[string]any `json:"metadata,omitempty"`
AllowedTools string `json:"allowed_tools,omitempty"`
RelativePath string `json:"relative_path"`
Raw []byte `json:"-"`
}
type SourceBinding ¶
type SourceBinding struct {
SourceBindingID string `json:"source_binding_id"`
RequestedSource string `json:"requested_source"`
CanonicalSource string `json:"canonical_source"`
Repository string `json:"repository,omitempty"`
PackageSubpath string `json:"package_subpath,omitempty"`
ResolvedRevision string `json:"resolved_revision"`
TreeDigest string `json:"tree_digest"`
Publisher string `json:"publisher,omitempty"`
}
type SourceIdentity ¶
type SourceIdentity struct {
RequestedSource string `json:"requested_source,omitempty"`
CanonicalSource string `json:"canonical_source,omitempty"`
Repository string `json:"repository,omitempty"`
PackageSubpath string `json:"package_subpath,omitempty"`
ResolvedRevision string `json:"resolved_revision,omitempty"`
SourceBindingHint string `json:"source_binding_hint,omitempty"`
}
type StagedDelivery ¶
type StateDecisionDisposition ¶
type StateDecisionDisposition string
const ( StateDecisionOld StateDecisionDisposition = "old" StateDecisionDesired StateDecisionDisposition = "desired" StateDecisionUnknown StateDecisionDisposition = "unknown" )
type StateFileV2 ¶
type StateFileV2 struct {
SchemaVersion int `json:"schema_version"`
Installations []Installation `json:"installations"`
TransactionReceipts []MutationReceipt `json:"transaction_receipts,omitempty"`
}
type StdioRequirement ¶
type StdioRequirement struct {
Command string `json:"command"`
Kind ExecutableKind `json:"kind"`
BundledRelativePath string `json:"bundled_relative_path,omitempty"`
UsesPluginRoot bool `json:"uses_plugin_root,omitempty"`
UsesPluginData bool `json:"uses_plugin_data,omitempty"`
}
StdioRequirement is inert preflight metadata. Loading a package records the executable and standard environment contract but never resolves or runs it.
type SupportLevel ¶
type SupportLevel string
type VerificationState ¶
type VerificationState string
type VersionedDocument ¶
type VersionedDocument struct {
Schema SchemaIdentity `json:"schema"`
Raw json.RawMessage `json:"raw"`
Unknown map[string]json.RawMessage `json:"unknown,omitempty"`
}
VersionedDocument preserves author-controlled JSON independently of any catalog or legacy metadata that describes the same package.
Source Files
¶
- acquisition.go
- catalog.go
- chatgpt_mapping.go
- clients.go
- delivery.go
- delivery_validation.go
- directory.go
- directory_context7_preparation.go
- errors.go
- identity.go
- install_intent.go
- local_entry_absence.go
- local_entry_observation.go
- local_entry_observation_json.go
- native_effect.go
- native_intent.go
- native_transition.go
- planning.go
- profile_authority.go
- security.go
- selection.go
- state.go
- traits.go
- types.go