Documentation
¶
Overview ¶
Package proofabstraction implements the experimental exact proof-projection relation described by PPA-V0. It proves only non-strengthening relative to a supplied source envelope; it does not establish source truth.
Index ¶
- Constants
- func Compile(source Envelope, request Request) (Envelope, Certificate, error)
- func MarshalCertificate(value Certificate) ([]byte, error)
- func MarshalEnvelope(value Envelope) ([]byte, error)
- func MarshalRequest(value Request) ([]byte, error)
- func Verify(source Envelope, request Request, destination Envelope, ...) error
- type Action
- type ActionKind
- type AuthorityClass
- type Certificate
- type Claim
- type ClaimRelation
- type Code
- type Completeness
- type CompletenessRelation
- type Envelope
- type Error
- type Evidence
- type EvidenceAccounting
- type EvidenceClass
- type EvidenceState
- type Frontier
- type FrontierAccounting
- type FrontierKind
- type OmittedClaim
- type Reason
- type Recovery
- type Relation
- type Repository
- type Request
- type Verdict
Constants ¶
const ( EnvelopeProfile = "corvint-proof-state/0-experimental" RequestProfile = "corvint-proof-preserving-abstraction-request/0-experimental" CertificateProfile = "corvint-proof-preserving-abstraction-certificate/0-experimental" AlgorithmProfile = "corvint-exact-proof-projection/0" CertificateClaim = "RELATIVE_NON_STRENGTHENING" MaxArtifactBytes = 4 << 20 MaxClaims = 2_048 MaxEvidence = 4_096 MaxFrontier = 4_096 MaxClaimEvidence = 64 MaxTokenBytes = 256 )
Variables ¶
This section is empty.
Functions ¶
func Compile ¶
func Compile(source Envelope, request Request) (Envelope, Certificate, error)
Compile builds a destination projection and certificate, then verifies the non-strengthening relation before returning either artifact.
func MarshalCertificate ¶
func MarshalCertificate(value Certificate) ([]byte, error)
MarshalCertificate emits one deterministic, newline-free certificate.
func MarshalEnvelope ¶
MarshalEnvelope emits one deterministic, newline-free wire object.
func MarshalRequest ¶
MarshalRequest emits one deterministic, newline-free request.
Types ¶
type Action ¶
type Action struct {
ClaimID string `json:"claimId"`
Action ActionKind `json:"action"`
Reason *Reason `json:"reason"`
}
type ActionKind ¶
type ActionKind string
const ( ActionRetain ActionKind = "RETAIN" ActionDemoteToUnknown ActionKind = "DEMOTE_TO_UNKNOWN" ActionOmit ActionKind = "OMIT" )
type AuthorityClass ¶
type AuthorityClass string
const ( AuthorityRepositoryAccepted AuthorityClass = "REPOSITORY_ACCEPTED" AuthorityOwningVerifier AuthorityClass = "OWNING_VERIFIER" AuthorityProviderQualified AuthorityClass = "PROVIDER_QUALIFIED" AuthorityAdapterQualified AuthorityClass = "ADAPTER_QUALIFIED" AuthorityCallerReported AuthorityClass = "CALLER_REPORTED" AuthorityAdvisory AuthorityClass = "ADVISORY" AuthorityNone AuthorityClass = "NONE" )
type Certificate ¶
type Certificate struct {
Profile string `json:"profile"`
Algorithm string `json:"algorithm"`
Claim string `json:"claim"`
SourceEnvelopeID string `json:"sourceEnvelopeId"`
DestinationEnvelopeID string `json:"destinationEnvelopeId"`
RequestSHA256 string `json:"requestSha256"`
Repository Repository `json:"repository"`
PolicySHA256 string `json:"policySha256"`
PurposeSHA256 string `json:"purposeSha256"`
CompletenessRelation CompletenessRelation `json:"completenessRelation"`
ClaimRelations []ClaimRelation `json:"claimRelations"`
OmittedClaims []OmittedClaim `json:"omittedClaims"`
EvidenceAccounting []EvidenceAccounting `json:"evidenceAccounting"`
FrontierAccounting FrontierAccounting `json:"frontierAccounting"`
CertificateID string `json:"certificateId,omitempty"`
}
func DecodeCertificate ¶
func DecodeCertificate(raw []byte) (Certificate, error)
DecodeCertificate accepts only the exact canonical encoding.
type Claim ¶
type Claim struct {
ID string `json:"id,omitempty"`
StatementSHA256 string `json:"statementSha256"`
ScopeSHA256 string `json:"scopeSha256"`
Critical bool `json:"critical"`
Verdict Verdict `json:"verdict"`
AuthorityClass AuthorityClass `json:"authorityClass"`
EvidenceClasses []EvidenceClass `json:"evidenceClasses"`
Evidence []string `json:"evidence"`
CounterEvidence []string `json:"counterEvidence"`
UnknownReasons []string `json:"unknownReasons"`
}
type ClaimRelation ¶
type Code ¶
type Code string
Code is a stable verifier failure classification.
const ( Noncanonical Code = "NONCANONICAL" LimitExceeded Code = "LIMIT_EXCEEDED" SourceIDMismatch Code = "SOURCE_ID_MISMATCH" SnapshotChanged Code = "SNAPSHOT_CHANGED" PolicyChanged Code = "POLICY_CHANGED" ClaimAdded Code = "CLAIM_ADDED" ClaimIdentityChanged Code = "CLAIM_IDENTITY_CHANGED" VerdictStrengthened Code = "VERDICT_STRENGTHENED" AuthorityChanged Code = "AUTHORITY_CHANGED" CriticalClaimWeakened Code = "CRITICAL_CLAIM_WEAKENED" ConflictHidden Code = "CONFLICT_HIDDEN" UnknownHidden Code = "UNKNOWN_HIDDEN" EvidenceAdded Code = "EVIDENCE_ADDED" EvidenceMutated Code = "EVIDENCE_MUTATED" FrontierRemoved Code = "FRONTIER_REMOVED" OmissionUnaccounted Code = "OMISSION_UNACCOUNTED" CompletenessStrengthened Code = "COMPLETENESS_STRENGTHENED" CertificateMismatch Code = "CERTIFICATE_MISMATCH" )
type Completeness ¶
type Completeness string
const ( CompletenessComplete Completeness = "COMPLETE" CompletenessPartial Completeness = "PARTIAL" CompletenessUnknown Completeness = "UNKNOWN" )
type CompletenessRelation ¶
type CompletenessRelation string
const ( CompletenessEqual CompletenessRelation = "EQUAL" CompletenessWeakenedToPartial CompletenessRelation = "WEAKENED_TO_PARTIAL" )
type Envelope ¶
type Envelope struct {
Profile string `json:"profile"`
Repository Repository `json:"repository"`
PolicySHA256 string `json:"policySha256"`
PurposeSHA256 string `json:"purposeSha256"`
Completeness Completeness `json:"completeness"`
Claims []Claim `json:"claims"`
Evidence []Evidence `json:"evidence"`
Frontier []Frontier `json:"frontier"`
EnvelopeID string `json:"envelopeId,omitempty"`
}
func BindEnvelope ¶
BindEnvelope validates and content-addresses a complete canonical envelope.
func DecodeEnvelope ¶
DecodeEnvelope accepts only the exact canonical encoding.
type Error ¶
type Error struct {
Code Code
}
Error reports one fail-closed protocol or non-strengthening violation.
type Evidence ¶
type Evidence struct {
ID string `json:"id,omitempty"`
SourceProfile string `json:"sourceProfile"`
ExternalID string `json:"externalId"`
ContentSHA256 string `json:"contentSha256"`
}
func BindEvidence ¶
BindEvidence validates and content-addresses one evidence wrapper.
type EvidenceAccounting ¶
type EvidenceAccounting struct {
EvidenceID string `json:"evidenceId"`
State EvidenceState `json:"state"`
SourceClaimIDs []string `json:"sourceClaimIds"`
}
type EvidenceClass ¶
type EvidenceClass string
const ( EvidenceDeclared EvidenceClass = "DECLARED" EvidenceImplemented EvidenceClass = "IMPLEMENTED" EvidenceVerified EvidenceClass = "VERIFIED" EvidenceObserved EvidenceClass = "OBSERVED" EvidenceInferred EvidenceClass = "INFERRED" )
type EvidenceState ¶
type EvidenceState string
const ( EvidencePreserved EvidenceState = "PRESERVED" EvidenceOmitted EvidenceState = "OMITTED" )
type Frontier ¶
type Frontier struct {
ID string `json:"id,omitempty"`
ClaimID string `json:"claimId"`
Kind FrontierKind `json:"kind"`
Reason string `json:"reason"`
SourceEnvelopeID *string `json:"sourceEnvelopeId"`
Recovery Recovery `json:"recovery"`
}
func BindFrontier ¶
BindFrontier validates and content-addresses one frontier atom. Envelope binding later verifies whether its claim is present or intentionally absent.
type FrontierAccounting ¶
type FrontierKind ¶
type FrontierKind string
const ( FrontierSourceUnknown FrontierKind = "SOURCE_UNKNOWN" FrontierSourceConflict FrontierKind = "SOURCE_CONFLICT" FrontierSourceExclusion FrontierKind = "SOURCE_EXCLUSION" FrontierAbstractedClaim FrontierKind = "ABSTRACTED_CLAIM" )