installer

package
v0.0.0-...-9112b7b Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 10, 2026 License: Apache-2.0 Imports: 37 Imported by: 0

README

UAP installer SDK

Public process-local installer API for a standard local Agent Plugins package (plugin.json + MCP/skills). Constructor, inspect, Recover, and prepare/apply for install, update, repair, refresh_projection, and remove are published. One client uses Request.ClientID. Two explicitly registered clients use Request.Targets for install/update/repair with the same operation verb. OpenCode install/update/repair groups return ErrUnsupported before preparation: per-target native host snapshots are not part of the group handle yet. Single-target OpenCode keeps its explicit Prepare/Apply host authority contract. Historical group removal retains its Claude/Codex boundary. Selected removal requires the explicitly registered adapter's typed native-intent reconciler. install-group as an operation name is invalid. Two PackageRoot values in one install or update group stay unpublished. Repair of mixed live revisions uses per-target PackageRoot so each binding keeps its exact recorded digest. Group Repair with one PackageRoot across mixed live revisions is ErrUpdateRequired before effects.

Update and repair of a missing owned binding return ErrNotInstalled before mutation. Repair rematerializes a missing target of a live binding. Repair of one live binding uses that binding's recorded package, not the installation's latest Source.TreeDigest, so an older sibling can be repaired after a subset update. Repair of that same binding with a different digest stays ErrUpdateRequired. InspectedBinding.TreeDigest is that binding's recorded package digest; mixed live revisions are not collapsed to InspectedInstallation.TreeDigest. Apply ClientResult.TreeDigest is that same per-binding digest, including unchanged mixed group Repair. OnCommittedBinding receives the same per-binding digest, not the first group envelope. ProjectArgs BindingFacts use the envelope digest of the client being staged.

Single-target refresh_projection uses the same Prepare/Apply confirmation flow as repair, but requires the managed package to be intact. It restages the exact recorded package revision with current host ProjectArgs and the owned PLUGIN_DATA locator. Identical output returns OutcomeUnchanged; changed output commits a new managed projection digest. A damaged package needs repair first. OnCommittedBinding observes the committed projection before client activation. If that handoff fails, a repeat with the same package and args resumes the pending lifecycle without another directory receipt. Group projection refresh is not supported.

Contract

engine, err := uapinstaller.New(uapinstaller.Config{StateRoot: stateRoot, HelperExecutable: helper})
prepared, err := engine.Prepare(ctx, uapinstaller.Request{Operation: uapinstaller.OpInstall, ...})
defer prepared.Close()
result, err := engine.Apply(ctx, prepared, uapinstaller.Decision{Confirmed: true})

New validates paths and does not create directories, open a journal, or run a helper. ClientConfigRoot is an explicit request path; CODEX_HOME, CLAUDE_CONFIG_DIR, and HOME are not read as profile defaults. Directories are created on Recover or a confirmed Apply. Host seams may replace args of one declared MCP server and observe a committed binding before client activation. Optional Config.Assess and Request.Assessment are digest-bound: block and unavailable never become allow. Config.TrustedLocalPackages is the explicit policy for pre-authorized bundled/local bytes; no evaluator or decision is an error when that policy is false. Mixed group Repair assesses each distinct snapshot digest once; blocking any snapshot refuses Prepare without mutation. Same-root group Repair assesses that snapshot once. New, Inspect, Discover, and Recover do not invoke Assess. Coarse Config.Progress phases are observational. The engine does not import Notifications types and does not query a live Claude/Codex identity by default.

Prepare freezes the selected adapter's complete SelectedDelivery through the public Plan/DeliveryPlan and each group PlanTarget. Apply regenerates that adapter plan before effects, repeats all-target and recorded-binding checks after preflight/stage observers before mutation locks or native discovery, and guards the use case's subsequent replan too. Changed mode, physical/profile identity, tuple, components, digests or owned selector authority returns ErrPlanChanged. The prepared installation identity is reused for the commit. These typed fields use json:"-": diagnostic JSON cannot be replayed as confirmation authority. The existing digest-bound content assessment remains a separate decision.

BindingFacts in OnCommittedBinding, and Result binding/client selections, come from committed state; activation checks the matching committed selection, including its staged projection digest. Empty selections retain historical behavior. This is a public contract checkpoint with injected TEST adapters; the default registry and actual NewLocal availability are unchanged. It grants no native VS Code, Windows or macOS qualification.

Selected single/group removal freezes the complete persisted binding and data receipt through Plan, BindingFacts, result and RemoveInput. It validates every profile, target, managed digest and native scope before observers and repeats validation after them, under the one service lock, and at native dispatch and return. Constructor facts never replace removal authority. A historical adapter without the typed reconciler and read-only native registry capability refuses a persisted Local selection before commands. CLI registry inspection is ineligible for selected removal; the registered adapter reads its exact persisted profile.

Inspect includes exact Recovery.NativeIntents: installation/binding/profile, pending direction/attempt, complete selected tuple/components/selector and a digest of the persisted binding. It acquires no mutation or profile lock. Recover requires that exact typed observation and StateRoot, revalidates under one retained process lock, and invokes the selected Service reconciler with persisted facts. Recovery.StateDigest binds all state scopes; each complete journal is hashed. Checks before and after every reconciler and before kernel reads/acknowledgement reject new journals, changed receipts and foreign bindings. Only successful existing kernel/service transitions advance the retained expected scope. Journal recovery remains supported; stale/missing/foreign scopes and uncertain attempts stay unresolved. Native intent diagnostic JSON exposes existing domain facts, but a JSON round trip cannot restore the operational typed observation.

A complete selected Local plan without MCP needs no absent managed helper and skips host MCP argument projection, including a package with no MCP server. Selected MCP, historical plans and explicitly configured helper paths retain helper validation. No Local adapter is automatically registered by this seam.

Prepare copies Request and reports canonical Plan.TreeDigest with algorithm agentplugins-tree-sha256-v1. That value is the packagedigest source identity, not the installed packagesnapshot ArtifactDigest. Scratch TempRoot must not overlap the package source, including case, symlink, and Unicode NFC/NFD aliases when the filesystem presents them as the same directory. PackageRoot identifies the sealed bytes to read; optional SourceRoot identifies the stable local source when a host creates a fresh snapshot for every invocation. After a terminal remove, a later install of the missing client uses the explicit profile in the new request; sibling bindings and PLUGIN_DATA stay. An existing record whose TreeDigest does not match the snapshot, including an old-bridge artifact digest in that field, returns ErrUpdateRequired without rewriting state. Remove Prepare verifies the managed artifact and persisted target before any client deactivation. Last-client remove retains PLUGIN_DATA and reports data_retained. A later remove of that retained empty installation returns already_absent without creating a journal, including when a sibling client is still installed. LocalPackageTreeDigest reports that same canonical digest without writing state. Retained metadata Update of a different digest is SwitchRetained; a later Add is a separate Install. Plan of that Update is metadata-only. SwitchRetained Progress is prepare/preflight/commit/complete and does not report stage, activate, or verify. Cancelled SwitchRetained reports no Progress. RequiredComponents do not apply to SwitchRetained; completeness is checked on the following Install. A blocking Assess refuses SwitchRetained without rewriting retained source. A different plugin.json name is package_identity before mutation. A source already bound to another installation is source_collision. Successful SwitchRetained reports data_retained and a data_compatibility next action. An ambiguous Save of that metadata is retried; a remaining Save error is not unchanged even if Inspect already shows the desired digest. Plan of Install onto retained r1 with package r2 is ErrUpdateRequired and shows both phases before confirmation. Plan includes the helper protocol version and SHA-256 of the helper bytes; UAP managedstdio stores the same digest. Result.NextActions cover recover, update, reprepare, and activate after a managed commit whose client activation did not finish. Cancel before the first durable effect returns cancelled and writes no state. A host callback or context cancel after that commit returns incomplete with the binding retained; it is not a bool and does not roll the managed package back. Group retry reconciles each pending committed binding before the no-change shortcut and before client VerifyOnly; Inspect does not invoke that callback. Client.Materialization and Client.Activation stay separate fields.

Confirmed Apply re-reads live target/ownership before mutation and returns plan_changed instead of applying a stale confirmation. Discover reports supported Claude/Codex user-scope metadata, executable presence, and current bindings without creating state or executing found files. Inspect after a group install reports both live bindings and TreeDigest without mutating state or running a helper; Recover of that clean observation is already_recovered. Recover of a stale observation whose journals vanished still requires leftover swap artifacts to be absent; leftover .agentplugins-staging-* or .agentplugins-backup-* beside the recorded target is incomplete_recovery, not success. Inspect and Result expose per-client materialization/activation/authentication/verification and required components. The external sample's flagged path runs install → inspect → recover → repeat → update → repair → remove → SwitchRetained → reinstall. Passing -claude-config uses Request.Targets for the same verbs on Claude+Codex together.

Codex artifact removal requires Request.ExternalUninstalled. Confirmed Apply does not invent that attestation. A required missing helper or relative configured helper is rejected before the state file is written. Confirmed Apply returns recovery_required when Inspect sees a pending journal, unfinished receipt or native intent; it does not recover as a side effect of install/remove. Close during Apply returns ErrHandleBusy without releasing the sealed snapshot. Install of a different TreeDigest for an active binding returns ErrUpdateRequired before mutation. Update of one live client CompatibilityChecks remaining live siblings; missing sibling profile data returns ErrCompatibilityUnavailable before mutation.

External sample

example/ is a separate Go module. It does not use replace or import internal. From that directory:

GOWORK=off go get github.com/777genius/plugin-kit-ai/install/integrationctl/agentplugins@<commit>
GOWORK=off go run .

Or clone example/, run GOWORK=off go get of the same package path, then GOWORK=off go run .. A successful import prints external import ok without creating state. Pass -package, -state, -config, -helper, and -client-exe to run install → inspect → recover → repeat → update → repair → remove → SwitchRetained → reinstall. Inspect prints inspect-bindings for the live clients. Add -claude-config for the published Claude+Codex group path.

The public import path is github.com/777genius/plugin-kit-ai/install/integrationctl/agentplugins/installer.

Documentation

Overview

Package installer is the public UAP installer API for standard local Agent Plugins packages. Callers must not import raw Store or Kernel types through this package; composition stays inside New. Inspect reports pending native intents, journals and unfinished receipts without recovering them. Recover takes that observation and refuses a changed scope. Request.Targets selects two distinct registered clients. Historical group removal retains Claude/Codex limits; selected native removal needs its typed capability. Switch remains unpublished.

Index

Constants

This section is empty.

Variables

View Source
var (
	ErrInvalidConfig            = errors.New("installer config rejected")
	ErrUnsupported              = errors.New("installer operation is not published in this beta")
	ErrInvalidHandle            = errors.New("prepared operation does not belong to this engine")
	ErrHandleClosed             = errors.New("prepared operation is closed")
	ErrHandleBusy               = errors.New("prepared operation is applying")
	ErrAlreadyApplied           = errors.New("prepared operation already reached a terminal apply")
	ErrCancelled                = errors.New("installer apply canceled")
	ErrRecoveryRequired         = errors.New("installer recovery required")
	ErrPlanChanged              = errors.New("installer recovery plan changed")
	ErrInvalidRequest           = errors.New("installer request rejected")
	ErrAmbiguousInstallations   = errors.New("ambiguous installations")
	ErrIncomplete               = errors.New("required components missing from plan")
	ErrUpdateRequired           = errors.New("install cannot change an active revision; use update")
	ErrNotInstalled             = errors.New("update and repair require an existing owned binding")
	ErrAssessmentRejected       = errors.New("package assessment is not allow")
	ErrCompatibilityUnavailable = errors.New("sibling compatibility checks are unavailable")
	ErrTargetFactsUnavailable   = errors.New("target facts are unavailable or conflict with owned state")
)
View Source
var ErrHostTargetRequired = hostprep.ErrHostTargetRequired

Functions

This section is empty.

Types

type Assessment

type Assessment struct {
	TreeDigest string
	Outcome    AssessmentOutcome
	Reason     string
}

Assessment is a digest-bound content verdict. It is not a filesystem plan.

type AssessmentOutcome

type AssessmentOutcome string

AssessmentOutcome is the host-visible scanner verdict.

const (
	AssessmentAllow       AssessmentOutcome = "allow"
	AssessmentBlock       AssessmentOutcome = "block"
	AssessmentUnavailable AssessmentOutcome = "unavailable"
)

type BindingFacts

type BindingFacts struct {
	ProfileAuthority *domain.ProfileAuthority `json:"-"`
	// SelectedDelivery is immutable operational authority, excluded from diagnostic JSON.
	SelectedDelivery                           domain.SelectedDelivery `json:"-"`
	InstallationID, ClientID, BindingID, Scope string
	TargetPath, DataRoot, DataReceiptID        string
	OperationID, TreeDigest                    string
}

BindingFacts is the typed committed-binding view for host seams.

type ClientMetadata

type ClientMetadata struct {
	ClientID          string
	Scopes            []string
	ExecutablePresent bool
	ExecutablePath    string
	Bindings          []InspectedBinding
}

ClientMetadata is read-only provider surface. Discover does not execute files.

type ClientResult

type ClientResult struct {
	ProfileAuthority *domain.ProfileAuthority `json:"-"`
	// SelectedDelivery is immutable operational authority, excluded from diagnostic JSON.
	SelectedDelivery                                                  domain.SelectedDelivery `json:"-"`
	ClientID, BindingID, TreeDigest                                   string
	Materialization, Activation, Authentication, Policy, Verification string
	RequiredComponents                                                []string
}

ClientResult is the public per-client lifecycle view. Mapping is not a bool.

type ClientTarget

type ClientTarget struct {
	ClientID, ClientConfigRoot, ClientExecutable string
	PackageRoot                                  string
	ExternalUninstalled                          bool
}

ClientTarget is one registered selection in a mutating group request. Group removal retains the published Claude/Codex boundary.

type ComponentDecision

type ComponentDecision struct{ Kind, Name, Support, Reason string }

type Config

type Config struct {
	// OpenCodeProbe defaults to the explicit-target facade. New captures and pins
	// the allowlisted environment once; it never executes a probe.
	OpenCodeProbe            OpenCodeProbe
	OpenCodeProbeEnvironment []string
	// StateRoot is the owned UAP namespace. It is required and must be an
	// absolute clean path. New does not create it.
	StateRoot                                                                 string
	StateFile, LockFile, OperationsDir, PluginDataBase, ManagedRoot, TempRoot string
	HelperExecutable, HelperVersion                                           string
	// Registry is the explicit set of client adapters supported by this
	// executable. Nil is rejected rather than silently enabling every client.
	Registry *clients.Registry
	// EnableNativeObserver composes the namespace-aware client observer for
	// repair and recovery. Callers that provide a real command runner should
	// enable it; leaving it off retains the filesystem-only compatibility path.
	EnableNativeObserver bool
	Runner               ports.CommandRunner
	// ServerName selects the declared MCP server whose args the host may replace.
	ServerName string
	// ProjectArgs replaces args of ServerName. It is host-owned and must be
	// deterministic. A missing declared server or a callback error fails staging.
	ProjectArgs func(BindingFacts) ([]string, error)
	// OnCommittedBinding runs after the package commit and before activation.
	// Failed handoffs can be retried for the same binding and digest. Hosts must
	// make effects idempotent using those identities, not the attempt OperationID.
	OnCommittedBinding func(context.Context, BindingFacts) error
	// Assess is optional and digest-bound. The constructor does not start a
	// download scanner. When set, block and unavailable never become allow.
	Assess func(context.Context, string, string) (Assessment, error)
	// TrustedLocalPackages is an explicit policy for bundled or otherwise
	// pre-authorized local bytes. When false, Prepare requires either Assess or
	// a digest-bound Request.Assessment; nil is never an implicit allow.
	TrustedLocalPackages bool
	// Progress reports coarse phases. It must not return an error, prompt, or
	// start a nested installer.
	Progress func(ProgressEvent)
	// ClientExecutables are optional explicit client paths Discover Lstats
	// without executing. Empty entries fall back to PATH presence of the
	// well-known binary name. New copies the map.
	ClientExecutables map[string]string
}

Config is copied by New. Later mutation of the caller's value is ignored.

type Decision

type Decision struct {
	Confirmed bool
}

Decision is host UI confirmation, outside mutation locks.

type DeliveryPlan

type DeliveryPlan struct {
	ProfileAuthority *domain.ProfileAuthority `json:"-"`
	// SelectedDelivery is immutable operational authority, excluded from diagnostic JSON.
	SelectedDelivery                                       domain.SelectedDelivery `json:"-"`
	ActivePath                                             string
	Status, PackageMode, InstallIntent, PhysicalArtifactID string
	Activation, Authentication, Policy, Verification       string
	Components                                             []ComponentDecision
	UserActions, LocalActions, Warnings                    []string
	Diagnostics                                            []PlanDiagnostic
}

DeliveryPlan is the provider's presentation snapshot, without mutation APIs. LocalActions may contain host paths and are for private human output only.

type Engine

type Engine struct {
	// contains filtered or unexported fields
}

Engine is the process-local installer. It does not export Store or Kernel.

func New

func New(cfg Config) (*Engine, error)

New validates Config and copies it. It does not create directories, open a journal, or execute a helper or client.

func (*Engine) Apply

func (e *Engine) Apply(ctx context.Context, prepared *PreparedOperation, decision Decision) (result Result, err error)

Apply executes a prepared operation. A canceled decision returns before usecase mutation, recovery, and callbacks. Result is populated even when err != nil. Close during Apply returns ErrHandleBusy without releasing the snapshot.

func (*Engine) Discover

func (e *Engine) Discover() []ClientMetadata

Discover returns metadata for the explicitly registered providers, including executable presence and current bindings. It does not create state, run a helper, or execute a found file.

func (*Engine) Inspect

func (e *Engine) Inspect(_ context.Context) (Inspection, error)

Inspect is read-only. It does not recover journals or invoke host seams.

func (*Engine) LocalPackageTreeDigest

func (e *Engine) LocalPackageTreeDigest(ctx context.Context, packageRoot string) (string, error)

snapshotLocalPackage uses packagedigest executable overrides so Windows host FileMode (no 0111 on regular files) does not drop logical bin/ helpers from TreeDigest. AcquireLocal hashes POSIX bits from the checkout. LocalPackageTreeDigest is the canonical TreeDigest of a local package root. It snapshots into TempRoot, does not write installer state, and does not report Progress. Optional Assess still binds that digest.

func (*Engine) Prepare

func (e *Engine) Prepare(ctx context.Context, req Request) (*PreparedOperation, error)

Prepare captures a sealed snapshot for install or inspects owned state for remove. It does not mutate installed client config or the Notifications runtime ledger.

func (*Engine) Recover

func (e *Engine) Recover(ctx context.Context, observed Inspection) (Result, error)

Recover finishes already recorded UAP transactions for the observed scope. It reconciles only persisted selected native intents, without rediscovery. A new pending operation that was not in observed returns ErrPlanChanged without recovery.

func (*Engine) RecoverCurrent

func (e *Engine) RecoverCurrent(ctx context.Context) (Result, error)

RecoverCurrent inspects this root and recovers that exact live scope.

func (*Engine) ReserveIdentity

func (e *Engine) ReserveIdentity(req IdentityRequest) (IdentityReservation, error)

ReserveIdentity returns installation and binding IDs without creating TempRoot, capturing a snapshot, or mutating client config.

func (*Engine) SupportsClient

func (e *Engine) SupportsClient(clientID string) bool

SupportsClient reports whether the composition root registered the client for this engine. The facade never broadens a caller's explicit registry.

func (*Engine) SwitchRetained

func (e *Engine) SwitchRetained(ctx context.Context, req Request, decision Decision) (Result, error)

SwitchRetained is the §5.5.1 retained-only metadata update. It revises source/digest for a data_retained installation with zero live bindings. Active installations must use Update. RequiredComponents are ignored: this step does not install clients.

func (*Engine) VerifyProfileAuthority

func (e *Engine) VerifyProfileAuthority(ctx context.Context, installationID, bindingID string) error

VerifyProfileAuthority addresses only the recorded owner in this engine's explicit namespace.

type IdentityRequest

type IdentityRequest struct {
	ClientID       string
	InstallationID string
	Allocate       bool
	// DeclaredName is the plugin.json name used to derive a prospective
	// BindingID for a new install. Empty leaves BindingID unset until Prepare
	// or an existing binding is found.
	DeclaredName     string
	ClientConfigRoot string
}

IdentityRequest selects an installation without capturing a package snapshot.

type IdentityReservation

type IdentityReservation struct {
	InstallationID string
	BindingID      string
	Scope          string
	TargetPath     string
}

IdentityReservation is the §7.2 identity view. BindingID and TargetPath are filled from an existing binding, or derived from DeclaredName without staging when this is a new install.

type InspectedBinding

type InspectedBinding struct {
	ClientID, BindingID, Scope, TargetPath, DataRoot, TreeDigest string
	Materialization, Activation, Authentication, Verification    string
}

InspectedBinding is a public subset of one client binding.

type InspectedInstallation

type InspectedInstallation struct {
	InstallationID string
	TreeDigest     string
	Bindings       []InspectedBinding
	DataRetained   bool
	DataRoots      []string
}

InspectedInstallation is a public subset of one UAP installation.

type Inspection

type Inspection struct {
	StateRoot     string
	Installations []InspectedInstallation
	Recovery      RecoveryObservation
}

Inspection is a read-only view of owned UAP state. Recovery facts are limited identities, not raw JSON and not an executable plan.

type NextAction

type NextAction struct {
	Kind   string
	Reason string
}

NextAction is a structured follow-up. It is not a bool and not a retry token.

type OpenCodePreparedHost

type OpenCodePreparedHost = opencodehost.NativePrepared

OpenCodePreparedHost preserves the facade contract while sharing its pure, immutable native authority with the CLI's existing lifecycle consumer.

type OpenCodeProbe

type OpenCodeProbe = hostprep.Probe

OpenCodeProbe is a trusted composition port. It receives a fresh target copy on each call; production defaults to the one bounded explicit-target facade.

type Operation

type Operation string

Operation is the process-local lifecycle verb. Install, update, repair, and remove are published. Two registered mutation targets use Request.Targets.

const (
	OpInstall Operation = "install"
	OpRemove  Operation = "remove"
	OpUpdate  Operation = "update"
	OpRepair  Operation = "repair"
	// OpRefreshProjection re-renders an intact installed package with current
	// host projection inputs while retaining its exact package revision.
	OpRefreshProjection Operation = "refresh_projection"
)

type Outcome

type Outcome string

Outcome is the coarse public result. Mapping is not a bool.

const (
	OutcomeUnchanged  Outcome = "unchanged"
	OutcomeCompleted  Outcome = "completed"
	OutcomeIncomplete Outcome = "incomplete"
	OutcomeRecovery   Outcome = "recovery_required"
	OutcomeConflict   Outcome = "conflict"
	OutcomeCancelled  Outcome = "cancelled" //nolint:misspell // Preserve the public outcome wire value.
)

type PendingJournal

type PendingJournal struct {
	OperationID, Digest, BindingID, InstallationID, TargetPath, Phase string
}

PendingJournal is one open directory-swap journal.

type PendingNativeIntent

type PendingNativeIntent struct {
	Binding           BindingFacts
	Intent            domain.PendingNativeIntent `json:"-"`
	NativeProfileRoot string
	Digest            string
}

PendingNativeIntent exposes the exact persisted attempt and selected facts. Diagnostic serialization cannot grant selected-delivery authority. Digest binds the complete binding (including ownership and revision), not settings document bytes: unrelated foreign edits are reconciled by the native adapter.

func (PendingNativeIntent) MarshalJSON

func (pending PendingNativeIntent) MarshalJSON() ([]byte, error)

MarshalJSON renders the existing domain intent for diagnostics. Unmarshal does not restore Intent or Binding.SelectedDelivery (both json:"-"); a JSON round trip cannot create the typed observation accepted by Recover.

type PendingReceipt

type PendingReceipt struct {
	OperationID, BindingID, InstallationID, TargetPath, Phase string
	JournalPresent                                            bool
}

PendingReceipt is an unfinished state receipt, including state_committed after the matching journal was already removed.

type Plan

type Plan struct {
	ProfileAuthority   *domain.ProfileAuthority `json:"-"`
	OpenCodeProfile    *opencodehost.Profile    `json:",omitempty"`
	OpenCodeSelections []opencodehost.Selection `json:",omitempty"`
	// SelectedDelivery is immutable operational authority, excluded from diagnostic JSON.
	SelectedDelivery     domain.SelectedDelivery `json:"-"`
	Operation            Operation
	SourceRoot           string
	TreeDigest           string
	DigestAlgorithm      string
	ClientID             string
	ConfigRoot           string
	TargetPath           string
	InstallationID       string
	BindingID            string
	HelperVersion        string
	HelperDigest         string
	RequiredMissing      []string
	NoChange             bool
	Targets              []PlanTarget
	Delivery             DeliveryPlan
	Client               ClientResult
	RequiresConfirmation bool
}

Plan is an immutable copy for presentation. Operational paths are included because the embedding host already chose explicit roots.

type PlanDiagnostic

type PlanDiagnostic struct{ Severity, Boundary, Code, Path, Item, Message string }

type PlanTarget

type PlanTarget struct {
	ProfileAuthority *domain.ProfileAuthority `json:"-"`
	// SelectedDelivery is immutable operational authority, excluded from diagnostic JSON.
	SelectedDelivery                                        domain.SelectedDelivery `json:"-"`
	ClientID, ConfigRoot, TargetPath, BindingID, TreeDigest string
	NoChange                                                bool
}

PlanTarget is one client's prepared identity in a group handle.

type PreparedOperation

type PreparedOperation struct {
	// contains filtered or unexported fields
}

PreparedOperation owns a sealed source snapshot until Close or a terminal Apply.

func (*PreparedOperation) Close

func (p *PreparedOperation) Close() error

func (*PreparedOperation) Plan

func (p *PreparedOperation) Plan() Plan

type ProgressEvent

type ProgressEvent struct {
	Phase ProgressPhase
}

ProgressEvent is an observational checkpoint. The observer does not decide.

type ProgressPhase

type ProgressPhase string

ProgressPhase is a coarse installer phase. Percent complete is not invented.

const (
	ProgressPrepare   ProgressPhase = "prepare"
	ProgressPreflight ProgressPhase = "preflight"
	ProgressStage     ProgressPhase = "stage"
	ProgressCommit    ProgressPhase = "commit"
	ProgressActivate  ProgressPhase = "activate"
	ProgressVerify    ProgressPhase = "verify"
	ProgressComplete  ProgressPhase = "complete"
)

type RecoveryObservation

type RecoveryObservation struct {
	// StateDigest binds all persisted bindings, receipts and installation facts.
	StateDigest   string
	Required      bool
	Journals      []PendingJournal
	NativeIntents []PendingNativeIntent
	Receipts      []PendingReceipt
	Reason        string
}

RecoveryObservation is the §5.8 read-only pending-transaction view.

type RecoveryReport

type RecoveryReport struct {
	Resolved  []PendingReceipt
	Remaining []PendingReceipt
	Unknown   []PendingReceipt
}

RecoveryReport is the §5.8 resolved/remaining/unknown receipt view. It is populated even when Recover returns an error.

type Request

type Request struct {
	Operation   Operation
	PackageRoot string
	// SourceRoot is the stable absolute local source identity when PackageRoot
	// points at a host-owned sealed snapshot. Empty means PackageRoot itself.
	SourceRoot string
	// ExecutableFiles preserves a host-acquired snapshot's logical file modes.
	// Nil infers local package executables; a non-nil empty slice means none.
	// Supported for single-target requests only. Assessment still has to match
	// the resulting complete tree digest.
	ExecutableFiles    []string
	ClientID           string
	ClientConfigRoot   string
	ClientExecutable   string
	InstallationID     string
	OperationID        string
	Selector           string
	RequiredComponents []string
	// Assessment is a host decision for these exact local bytes. It is copied
	// and digest-checked by Prepare. Confirmation of the filesystem plan does
	// not create or alter this security decision.
	Assessment *Assessment
	// ExternalUninstalled is host attestation that the selected client's
	// native plugin was already removed, or was never activated. Confirmed
	// Apply does not invent this fact.
	ExternalUninstalled bool
	// Targets selects one explicit client or two Claude/Codex clients in a group.
	// Empty means the single ClientID fields. Groups keep the same Operation verb.
	Targets []ClientTarget
	// KnownTargets carries host-observed facts for installed sibling bindings
	// that are not selected by this operation. The installer verifies BindingID
	// against owned state before using ConfigRoot or Executable; it never reads a
	// host sidecar or guesses a profile from HOME.
	KnownTargets []TargetFacts
	// contains filtered or unexported fields
}

Request is copied by Prepare. Subsequent caller edits do not change the handle.

type Result

type Result struct {
	// Delivery is the actual lifecycle plan, absent when Apply stopped before planning.
	Delivery             *DeliveryPlan
	Operation            Operation
	InstallationID       string
	Outcome              Outcome
	Binding              BindingFacts
	ManualActions        []string
	Reason               string
	NoChange             bool
	Mutated              bool
	RequiresConfirmation bool
	DataRetained         bool
	Client               ClientResult
	Targets              []ClientResult
	NextActions          []NextAction
	// Recovery classifies observed receipts after Recover. Apply leaves it empty.
	Recovery RecoveryReport
}

Result is returned together with an error when part of the work already happened.

type TargetFacts

type TargetFacts struct {
	ClientID   string
	BindingID  string
	ConfigRoot string
	Executable string
}

TargetFacts is the request-scoped host view of one existing client binding. BindingID ties host-owned profile and executable paths to UAP-owned state.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL