postmergeworkflow

package
v1.0.0-rc.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 24 Imported by: 0

Documentation

Overview

SPDX-License-Identifier: AGPL-3.0-or-later Derived from internal/tasks/safeopen/at_linux.go at 29a6db884ed795f7694c316433896d190e1ab508; kept private for decision 0397.

SPDX-License-Identifier: AGPL-3.0-or-later Derived from internal/tasks/safeopen/open_unix.go at 29a6db884ed795f7694c316433896d190e1ab508; kept private for decision 0397. Native replay owns this narrow no-follow boundary (decision 0397). Every directory component is opened atomically with O_DIRECTORY|O_NOFOLLOW.

Package postmergeworkflow implements an experimental credential-free replay harness. Adapter observations are evidence to compare, not workflow authority.

Index

Constants

View Source
const MaxBytes = 4 << 20
View Source
const NativeManifestProfile = "postmerge-runtime-manifest/1"
View Source
const NativeProfile = "postmerge-replay/1"

NativeProfile is the experimental intake/refusal route, not whole-workflow qualification.

View Source
const Profile = "postmerge-replay/0"

Variables

This section is empty.

Functions

func Decode

func Decode(b []byte, v any) error

Decode rejects duplicate keys as well as unknown fields. Duplicate keys are otherwise silently overwritten by encoding/json, including policy bindings.

func FixtureProfile

func FixtureProfile(name string) string

FixtureProfile is only a bounded dispatch hint. Each route still performs its full strict decode; malformed hints fall through to the unchanged /0 refusal.

func SHA256

func SHA256(b []byte) string

Types

type Approval

type Approval struct {
	Binding     connector.Binding `json:"binding"`
	Field       string            `json:"field"`
	ValueSHA256 string            `json:"value_sha256"`
	Label       Label             `json:"label"`
}

type ArtifactRef

type ArtifactRef struct {
	Path   string `json:"path"`
	SHA256 string `json:"sha256"`
	Bytes  int64  `json:"bytes"`
}

ArtifactRef describes exact private bytes; it does not attest native execution.

type Expected

type Expected struct {
	AffectedFlows []string            `json:"affected_flows"`
	Followup      bool                `json:"followup"`
	TestGaps      []string            `json:"test_gaps"`
	Defects       []connector.Finding `json:"defects"`
	Labels        map[string]Label    `json:"labels"`
}

type Fixture

type Fixture struct {
	Profile    string            `json:"profile"`
	Connector  connector.Fixture `json:"connector"`
	SourceItem string            `json:"source_item"`
	Expected   Expected          `json:"expected"`
}

type Implementation

type Implementation struct {
	SourceCommit     string `json:"source_commit"`
	SourceTree       string `json:"source_tree"`
	ExecutableSHA256 string `json:"executable_sha256"`
}

type Label

type Label struct {
	Basis          string `json:"basis"` // generated | human-verified
	EvidenceSHA256 string `json:"evidence_sha256"`
	Human          string `json:"human"`
	Approval       string `json:"approval"`
}

type Mismatch

type Mismatch struct {
	Field          string `json:"field"`
	Basis          string `json:"basis"`
	ExpectedSHA256 string `json:"expected_sha256"`
	ObservedSHA256 string `json:"observed_sha256"`
}

type NativeManifest

type NativeManifest struct {
	Profile        string         `json:"profile"`
	Mode           string         `json:"mode"`
	Implementation Implementation `json:"implementation"`
	Product        struct {
		Base  string `json:"base"`
		Merge string `json:"merge"`
		Tree  string `json:"tree"`
	} `json:"product"`
	FixtureSHA256   string `json:"fixture_sha256"`
	ReaderCandidate struct {
		Path   string `json:"path"`
		SHA256 string `json:"sha256"`
	} `json:"reader_candidate"`
	RetainedOutputRoot string `json:"retained_output_root"`
}

type NativePolicy

type NativePolicy struct {
	Profile        string           `json:"profile"`
	Connector      connector.Policy `json:"connector"`
	Manifest       string           `json:"manifest"`
	ManifestSHA256 string           `json:"manifest_sha256"`
}

type NativeReport

type NativeReport struct {
	Profile                 string            `json:"profile"`
	Binding                 connector.Binding `json:"binding"`
	FixtureSHA256           string            `json:"fixture_sha256"`
	PolicySHA256            string            `json:"policy_sha256"`
	ManifestSHA256          string            `json:"manifest_sha256"`
	Implementation          Implementation    `json:"implementation"`
	Status                  string            `json:"status"`
	Reasons                 []string          `json:"reasons"`
	Stages                  []NativeStage     `json:"stages"`
	ComparisonStatus        string            `json:"comparison_status"`
	GeneratedMismatches     []Mismatch        `json:"generated_mismatches"`
	HumanVerifiedMismatches []Mismatch        `json:"human_verified_mismatches"`
	WorkflowQualification   string            `json:"workflow_qualification"`
}

func ReplayNative

func ReplayNative(ctx context.Context, root, fixtureFile, policyFile, change string) (NativeReport, error)

ReplayNative observes the real connector, intake and delta only. Expected labels never enter author input; a failed delta forbids every downstream operation, and the unintegrated follow-up stage blocks the rest.

type NativeStage

type NativeStage struct {
	Name          string        `json:"name"`
	Disposition   string        `json:"disposition"`
	NativeProfile string        `json:"native_profile"`
	Inputs        []ArtifactRef `json:"inputs"`
	Output        *ArtifactRef  `json:"output"`
	Reasons       []string      `json:"reasons"`
}

type Policy

type Policy struct {
	Profile          string           `json:"profile"`
	Connector        connector.Policy `json:"connector"`
	Executable       string           `json:"executable"`
	ExecutableSHA256 string           `json:"executable_sha256"`
	Args             []string         `json:"args"`
	RuntimeSHA256    string           `json:"runtime_sha256"`
	Registry         string           `json:"registry"`
	RegistrySHA256   string           `json:"registry_sha256"`
}

Policy is a separate host-owned input. The fixture cannot choose an executable, arguments, connector binding, runtime configuration or human label registry.

type Registry

type Registry struct {
	Profile   string     `json:"profile"`
	Approvals []Approval `json:"approvals"`
}

type Report

type Report struct {
	Profile       string            `json:"profile"`
	Binding       connector.Binding `json:"binding"`
	FixtureSHA256 string            `json:"fixture_sha256"`
	PolicySHA256  string            `json:"policy_sha256"`
	Status        string            `json:"status"` // MATCH | MISMATCH | BLOCKED
	Reasons       []string          `json:"reasons"`
	// Mismatches are reported separately by the basis of the expectation
	// they contradict; a generated expectation never counts as human-verified.
	HumanVerifiedMismatches []Mismatch `json:"human_verified_mismatches"`
	GeneratedMismatches     []Mismatch `json:"generated_mismatches"`
	DeferredStages          []string   `json:"deferred_stages"`
	RecordingSHA256         string     `json:"recording_sha256"`
	Recording               string     `json:"recording_jsonl"`
	WorkflowQualification   string     `json:"workflow_qualification"`
	Limits                  []string   `json:"limits"`
}

func Replay

func Replay(ctx context.Context, root, fixtureFile, policyFile, change string) (Report, error)

Replay executes the exact pinned bytes twice, in fresh private working directories. Minimal env is not OS isolation; the report retains that limit. Input files are never modified and no live connector writer is constructed.

type Request

type Request struct {
	Profile       string            `json:"profile"`
	Binding       connector.Binding `json:"binding"`
	FixtureSHA256 string            `json:"fixture_sha256"`
	RuntimeSHA256 string            `json:"runtime_sha256"`
}

type Result

type Result struct {
	Request
	AffectedFlows        []string            `json:"affected_flows"`
	DocumentationTargets []string            `json:"documentation_targets"`
	TestGaps             []string            `json:"test_gaps"`
	Defects              []connector.Finding `json:"defects"`
	Input                connector.Input     `json:"connector_input"`
	Stages               []Stage             `json:"stages"`
}

type Stage

type Stage struct {
	Name           string `json:"name"`
	Status         string `json:"status"` // observed | blocked | not-applicable | deferred
	ArtifactSHA256 string `json:"artifact_sha256"`
}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL