Documentation
¶
Index ¶
- Constants
- func MarshalAnalyzerRequest(request AnalyzerRequest) ([]byte, error)
- func ValidateActualScheme(scheme, value Opaque) error
- func ValidateRequirementScheme(scheme, value Opaque) error
- type Admission
- type AdmissionAuthority
- type AdmissionContext
- type AdmissionVerifier
- type AnalyzerDiagnostic
- type AnalyzerRequest
- type AnalyzerResponse
- type AuthorityIssueError
- type CacheInputs
- type Clause
- type CompilationUnit
- type Component
- type ComponentRequirement
- type Core
- type CoreInput
- type CoreReceipt
- func (r CoreReceipt) Authority() Identity
- func (r CoreReceipt) CacheIdentity() Identity
- func (r CoreReceipt) CanonicalBytes() []byte
- func (r CoreReceipt) Digest() Identity
- func (r CoreReceipt) LiveAuthority() Identity
- func (r CoreReceipt) Passes() []ReceiptPass
- func (r CoreReceipt) RequestBytesDigest() Opaque
- func (r CoreReceipt) Revision() Opaque
- func (r CoreReceipt) StageDiagnostics() []StageDiagnostic
- func (r CoreReceipt) Terminal() ReceiptTerminal
- type DependencyEdge
- type ExactVerificationResult
- type Failure
- type Feature
- type FeatureState
- type Identity
- type ImmutableInput
- type InputHandle
- type Invocation
- type InvocationResult
- type Observation
- type Opaque
- type PinnedSnapshotVerifier
- type Platform
- type Profile
- type ProposedFact
- type ProtocolAdmissionVerifier
- type ProtocolLimits
- type Reason
- type ReceiptEvent
- type ReceiptPass
- type ReceiptPassKind
- type ReceiptTerminal
- type ReceiptTerminalState
- type RegistrySnapshot
- type Release
- type RepositoryLock
- type Request
- type Resolution
- type Semver
- type SemverRange
- type SnapshotVerifier
- type Stage
- type StageDiagnostic
Constants ¶
const ( AnalyzerProtocolV0 = "corvint-analyzer/v0" MaxProtocolBytes = 64 << 10 MaxFacts = 64 MaxDiagnostics = 32 )
const ( MaxOpaqueBytes = 128 MaxComponents = 64 MaxFeatures = 64 MaxEdgesPerProfile = 64 MaxEdgesPerRequest = 128 MaxProfiles = 64 MaxUnits = 64 MaxTargetsPerUnit = 16 MaxClauses = 32 MaxTermsPerClause = 64 MaxInputDigests = 64 MaxCandidateReleases = 64 MaxProviderCandidates = MaxCandidateReleases )
const ExactVerificationNotRun exactState = "NOT_RUN"
Variables ¶
This section is empty.
Functions ¶
func MarshalAnalyzerRequest ¶
func MarshalAnalyzerRequest(request AnalyzerRequest) ([]byte, error)
func ValidateActualScheme ¶
Types ¶
type AdmissionAuthority ¶
type AdmissionAuthority struct {
// contains filtered or unexported fields
}
type AdmissionContext ¶
type AdmissionContext struct {
Request AnalyzerRequest
}
type AdmissionVerifier ¶
type AdmissionVerifier interface {
Identity() Identity
VerifyAdmission(context.Context, AdmissionContext, AnalyzerResponse) (Admission, error)
}
type AnalyzerDiagnostic ¶
type AnalyzerDiagnostic struct {
Code Opaque `json:"code"`
}
type AnalyzerRequest ¶
type AnalyzerRequest struct {
Protocol Opaque `json:"protocol"`
RequestID Opaque `json:"requestId"`
ProfileIdentity Identity `json:"profileIdentity"`
LockDigest Opaque `json:"lockDigest"`
RegistrySnapshotDigest Opaque `json:"registrySnapshotDigest"`
TrustEpoch Opaque `json:"trustEpoch"`
ResolverDigest Opaque `json:"resolverDigest"`
ClauseID Opaque `json:"clauseId"`
CompilationUnitID Opaque `json:"compilationUnitId"`
Target Platform `json:"target"`
ProjectionDigest Opaque `json:"projectionDigest"`
ProjectionScheme Opaque `json:"projectionScheme"`
Inputs []InputHandle `json:"inputs"`
InputBinding Identity `json:"inputBinding"`
Features []Feature `json:"features"`
Limits ProtocolLimits `json:"limits"`
}
type AnalyzerResponse ¶
type AnalyzerResponse struct {
Protocol Opaque `json:"protocol"`
RequestID Opaque `json:"requestId"`
ProfileIdentity Identity `json:"profileIdentity"`
LockDigest Opaque `json:"lockDigest"`
RegistrySnapshotDigest Opaque `json:"registrySnapshotDigest"`
TrustEpoch Opaque `json:"trustEpoch"`
ResolverDigest Opaque `json:"resolverDigest"`
ClauseID Opaque `json:"clauseId"`
CompilationUnitID Opaque `json:"compilationUnitId"`
Target Platform `json:"target"`
ProjectionDigest Opaque `json:"projectionDigest"`
ProjectionScheme Opaque `json:"projectionScheme"`
Inputs []InputHandle `json:"inputs"`
InputBinding Identity `json:"inputBinding"`
Facts []ProposedFact `json:"facts"`
ProfileEvidence []InputHandle `json:"profileEvidence"`
Diagnostics []AnalyzerDiagnostic `json:"diagnostics"`
}
func DecodeAnalyzerResponse ¶
func DecodeAnalyzerResponse(raw []byte, request AnalyzerRequest) (AnalyzerResponse, error)
type AuthorityIssueError ¶
type AuthorityIssueError struct {
// contains filtered or unexported fields
}
AuthorityIssueError preserves closed stage diagnostics when the immutable authority could not be issued. It contains only canonical receipt evidence.
func (*AuthorityIssueError) Error ¶
func (err *AuthorityIssueError) Error() string
func (*AuthorityIssueError) Receipt ¶
func (err *AuthorityIssueError) Receipt() CoreReceipt
func (*AuthorityIssueError) Unwrap ¶
func (err *AuthorityIssueError) Unwrap() error
type CacheInputs ¶
type Clause ¶
type Clause struct {
ID Opaque
Host Platform
Target Platform
Profile Identity
ReleaseID Opaque
Protocol Opaque
Components []ComponentRequirement
Features []Feature
Dependencies []DependencyEdge
}
type CompilationUnit ¶
type ComponentRequirement ¶
type Core ¶
type Core struct {
// contains filtered or unexported fields
}
func NewStaticCore ¶
NewStaticCore is the production-facing constructor for a Core-owned, immutable native invocation selection. It does not qualify a profile.
func (*Core) IssueAdmissionAuthority ¶
func (core *Core) IssueAdmissionAuthority() (*AdmissionAuthority, error)
func (*Core) IssueAdmissionAuthorityContext ¶
func (core *Core) IssueAdmissionAuthorityContext(ctx context.Context) (*AdmissionAuthority, error)
IssueAdmissionAuthorityContext binds issuance, source retrieval, snapshot resolution, and request hashing to the caller's deadline.
type CoreInput ¶
type CoreInput struct {
Request Request
Inputs []ImmutableInput
RequestID, Revision Opaque
Limits ProtocolLimits
ArtifactPath, ExecutablePath string
RepositoryRoot, StagingParent string
ArtifactDigest, HostBinaryDigest Opaque
Verifier AdmissionVerifier
}
CoreInput is the Core-owned invocation state for one fixed native analyzer selection. Request bytes are deliberately absent: Core derives and hashes them after resolver closure, rather than accepting a caller digest.
type CoreReceipt ¶
type CoreReceipt struct {
// contains filtered or unexported fields
}
CoreReceipt owns canonical receipt bytes. Its accessors return copies so a verifier or caller cannot mutate the authority-bound record after issue.
func (CoreReceipt) Authority ¶
func (r CoreReceipt) Authority() Identity
func (CoreReceipt) CacheIdentity ¶
func (r CoreReceipt) CacheIdentity() Identity
func (CoreReceipt) CanonicalBytes ¶
func (r CoreReceipt) CanonicalBytes() []byte
func (CoreReceipt) Digest ¶
func (r CoreReceipt) Digest() Identity
func (CoreReceipt) LiveAuthority ¶
func (r CoreReceipt) LiveAuthority() Identity
func (CoreReceipt) Passes ¶
func (r CoreReceipt) Passes() []ReceiptPass
func (CoreReceipt) RequestBytesDigest ¶
func (r CoreReceipt) RequestBytesDigest() Opaque
func (CoreReceipt) Revision ¶
func (r CoreReceipt) Revision() Opaque
func (CoreReceipt) StageDiagnostics ¶
func (r CoreReceipt) StageDiagnostics() []StageDiagnostic
func (CoreReceipt) Terminal ¶
func (r CoreReceipt) Terminal() ReceiptTerminal
type DependencyEdge ¶
type ExactVerificationResult ¶
type Feature ¶
type Feature struct {
Name Opaque
State FeatureState
}
type FeatureState ¶
type FeatureState string
const ( FeatureEnabled FeatureState = "enabled" FeatureDisabled FeatureState = "disabled" FeatureUnknown FeatureState = "unknown" )
type ImmutableInput ¶
type InputHandle ¶
type Invocation ¶
type Invocation struct {
Authority *AdmissionAuthority
}
type InvocationResult ¶
type InvocationResult struct {
Candidate AnalyzerResponse
Observation Observation
Admission string
ExactVerification ExactVerificationResult
Stages []StageDiagnostic
Receipt CoreReceipt
StderrBytes int
}
func InvokeAnalyzer ¶
func InvokeAnalyzer(ctx context.Context, invocation Invocation) (InvocationResult, error)
type Observation ¶
type Observation string
const ( ObservationNone Observation = "none" ObservationObserved Observation = "OBSERVED" )
type PinnedSnapshotVerifier ¶
PinnedSnapshotVerifier is the production snapshot authority for the experimental static runtime. It is deliberately data-only: arbitrary callbacks cannot enter Core's hard-wall interval. A persisted signed registry replaces this pin in a promoted profile.
func (PinnedSnapshotVerifier) CloneSnapshotVerifier ¶
func (verify PinnedSnapshotVerifier) CloneSnapshotVerifier() SnapshotVerifier
func (PinnedSnapshotVerifier) VerifySnapshot ¶
func (verify PinnedSnapshotVerifier) VerifySnapshot(snapshot RegistrySnapshot) error
type Profile ¶
type Profile struct {
Components []Component
Host Platform
Features []Feature
Edges []DependencyEdge
// contains filtered or unexported fields
}
func NewProfile ¶
type ProposedFact ¶
type ProtocolAdmissionVerifier ¶
type ProtocolAdmissionVerifier struct{ Verifier Identity }
ProtocolAdmissionVerifier is the bounded production admission rule for the experimental static runtime. Protocol/schema/echo validation has already completed before it runs; no caller callback can outlive the hard wall. A promoted profile replaces this rule with another Core-owned bounded implementation, never an in-process plugin callback.
func (ProtocolAdmissionVerifier) CloneAdmissionVerifier ¶
func (verifier ProtocolAdmissionVerifier) CloneAdmissionVerifier() AdmissionVerifier
func (ProtocolAdmissionVerifier) Identity ¶
func (verifier ProtocolAdmissionVerifier) Identity() Identity
func (ProtocolAdmissionVerifier) VerifyAdmission ¶
func (verifier ProtocolAdmissionVerifier) VerifyAdmission(ctx context.Context, _ AdmissionContext, _ AnalyzerResponse) (Admission, error)
type ProtocolLimits ¶
type ProtocolLimits struct {
WallMilliseconds uint64 `json:"wallMilliseconds"`
MemoryBytes uint64 `json:"memoryBytes"`
MaxChildren uint64 `json:"maxChildren"`
MaxRequestBytes uint64 `json:"maxRequestBytes"`
MaxResponseBytes uint64 `json:"maxResponseBytes"`
MaxStderrBytes uint64 `json:"maxStderrBytes"`
}
type Reason ¶
type Reason string
const ( RegistryUntrusted Reason = "REGISTRY_UNTRUSTED" LockMismatch Reason = "LOCK_MISMATCH" NoCapabilityProvider Reason = "NO_CAPABILITY_PROVIDER" AmbiguousProvider Reason = "AMBIGUOUS_PROVIDER" BinaryDigestMismatch Reason = "BINARY_DIGEST_MISMATCH" HostPlatformUnsupported Reason = "HOST_PLATFORM_UNSUPPORTED" TargetPlatformUnsupported Reason = "TARGET_PLATFORM_UNSUPPORTED" ExecutableIdentityUnsafe Reason = "EXECUTABLE_IDENTITY_UNSAFE" ExecutableRace Reason = "EXECUTABLE_RACE" SchemeMissing Reason = "SCHEME_MISSING" SchemeInvalid Reason = "SCHEME_INVALID" SchemeUnknown Reason = "SCHEME_UNKNOWN" SchemeFutureVersion Reason = "SCHEME_FUTURE_VERSION" SchemeUnsupported Reason = "SCHEME_UNSUPPORTED" NoCompatibleClause Reason = "NO_COMPATIBLE_CLAUSE" AmbiguousClause Reason = "AMBIGUOUS_CLAUSE" FailureFeatureUnknown Reason = "FEATURE_UNKNOWN" ProtocolEchoMismatch Reason = "PROTOCOL_ECHO_MISMATCH" InputEvidenceMismatch Reason = "INPUT_EVIDENCE_MISMATCH" AdmissionRejected Reason = "ADMISSION_REJECTED" ExactVerifierNotRun Reason = "EXACT_VERIFIER_NOT_RUN" ExactVerifierUnsupported Reason = "EXACT_VERIFIER_UNSUPPORTED" LimitExceeded Reason = "LIMIT_EXCEEDED" Timeout Reason = "TIMEOUT" Cancelled Reason = "CANCELLED" AnalyzerFailure Reason = "ANALYZER_FAILURE" )
type ReceiptEvent ¶
type ReceiptEvent string
ReceiptEvent is one actual operation on the one monotonic receipt clock. Encoding and decoding deliberately remain different events: treating them as one interval would make a launch between them appear to overlap protocol.
const ( EventRegistry ReceiptEvent = "registry" EventLock ReceiptEvent = "lock" EventResolve ReceiptEvent = "resolve" EventCompatibility ReceiptEvent = "compatibility" EventDependency ReceiptEvent = "dependency" EventProtocolEncode ReceiptEvent = "protocol-encode" EventPreLaunch ReceiptEvent = "pre-launch" EventLaunch ReceiptEvent = "launch" EventProtocolDecode ReceiptEvent = "protocol-decode" EventAdmission ReceiptEvent = "admission" EventExact ReceiptEvent = "exact-verification" )
type ReceiptPass ¶
type ReceiptPass struct {
Kind ReceiptPassKind
Started time.Duration
Ended time.Duration
FirstFailure Stage
// contains filtered or unexported fields
}
ReceiptPass preserves one authority or invocation pass without flattening it into a prior pass. Events returns a defensive copy.
func (ReceiptPass) Events ¶
func (p ReceiptPass) Events() []StageDiagnostic
type ReceiptPassKind ¶
type ReceiptPassKind string
const ( PassAuthorityIssue ReceiptPassKind = "authority-issue" PassPreLaunchRefresh ReceiptPassKind = "pre-launch-refresh" PassPreAdmissionRefresh ReceiptPassKind = "pre-admission-refresh" PassInvocation ReceiptPassKind = "invocation-execution" PassAdmission ReceiptPassKind = "invocation-admission" PassInvocationGuard ReceiptPassKind = "invocation-guard" )
type ReceiptTerminal ¶
type ReceiptTerminal struct {
State ReceiptTerminalState
Reason Reason
ProcessStarted bool
ProcessCompleted bool
Termination analyzerexec.Termination
Cleanup analyzerexec.CleanupObservation
CleanupError analyzerexec.CleanupError
}
ReceiptTerminal is a closed, deterministic summary of a terminal attempt. It carries no raw error text, filesystem path, command, environment, or source body.
type ReceiptTerminalState ¶
type ReceiptTerminalState string
const ( ReceiptOpen ReceiptTerminalState = "OPEN" ReceiptSucceeded ReceiptTerminalState = "SUCCEEDED" ReceiptFailed ReceiptTerminalState = "FAILED" )
type RegistrySnapshot ¶
type Release ¶
type Release struct {
PluginID Opaque
CapabilityID Opaque
ReleaseID Opaque
BuildID Opaque
ManifestDigest Opaque
ArtifactDigest Opaque
HostBinaryDigest Opaque
Host Platform
Protocol Opaque
ProjectionDigest Opaque
ProjectionScheme Opaque
ResolverDigest Opaque
ClosedInputFamilyDigest Opaque
Clauses []Clause
}
type RepositoryLock ¶
type Request ¶
type Request struct {
Capability Opaque
Lock *RepositoryLock
Snapshot RegistrySnapshot
Verifier SnapshotVerifier
Profile Profile
Profiles []Profile
Unit CompilationUnit
Target Platform
Cache CacheInputs
}
type Resolution ¶
type Resolution struct {
CapabilityID Opaque
PluginID Opaque
Release Release
Profile Profile
Unit CompilationUnit
Target Platform
Clause Clause
CandidateSetDigest Identity
DependencyDigest Identity
Identity Identity
CacheIdentity Identity
RegistrySnapshotDigest Opaque
TrustEpoch Opaque
}
func Resolve ¶
func Resolve(request Request) (Resolution, error)
type SemverRange ¶
type SemverRange struct{ Lower, Upper Semver }
func ParseSemverRange ¶
func ParseSemverRange(raw string) (SemverRange, error)
func (SemverRange) Contains ¶
func (r SemverRange) Contains(v Semver) bool
type SnapshotVerifier ¶
type SnapshotVerifier interface{ VerifySnapshot(RegistrySnapshot) error }
type Stage ¶
type Stage string
const ( StageLock Stage = "lock" StageRegistry Stage = "registry" StageResolve Stage = "resolve" StageCompatibility Stage = "compatibility" StageDependency Stage = "dependency" StageLaunch Stage = "launch" StageProtocol Stage = "protocol" StageAdmission Stage = "admission" StageExactVerification Stage = "exact-verification" )
type StageDiagnostic ¶
type StageDiagnostic struct {
Stage Stage
Event ReceiptEvent
Result string
Started, Ended, Elapsed time.Duration
CleanupElapsed time.Duration
Cleanup analyzerexec.CleanupObservation
CleanupError analyzerexec.CleanupError
}