source

package
v0.8.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 19 Imported by: 0

Documentation

Index

Constants

View Source
const (
	MaxSourceBytes    uint64 = 16 << 20
	MaxAggregateBytes uint64 = 256 << 20
	MaxPhysicalBytes  uint64 = 1 << 30
	MaxArtifactCount  uint64 = 10_000
	MaxPathBytes             = 4096
)
View Source
const MaxTraceStoreEntries = 1_000

Variables

This section is empty.

Functions

This section is empty.

Types

type Budget

type Budget struct {
	// contains filtered or unexported fields
}

Budget is a view of the shared whole-invocation source ledger. Logical reservations are keyed by product source identity and are never refunded or double charged across acquisition or repository-stability retries. Physical bytes are charged independently for every actual read, including rejected reads. Overflow probes belong to one whole-scan attempt view.

func NewBudget

func NewBudget(limit uint64) *Budget

func (*Budget) ChargePhysical

func (b *Budget) ChargePhysical(bytes uint64) BudgetResult

ChargePhysical accounts actual bytes already returned by the operating system. Callers must stop immediately when it rejects a charge.

func (*Budget) ForWholeScanAttempt

func (b *Budget) ForWholeScanAttempt() *Budget

ForWholeScanAttempt returns a fresh overflow-probe allowance backed by the same invocation-wide logical and physical byte ledger.

func (*Budget) PhysicalUsed

func (b *Budget) PhysicalUsed() uint64

func (*Budget) Preflight

func (b *Budget) Preflight(adapterID string, configuredOrdinal, declaredBound uint64) BudgetResult

Preflight atomically reserves the declared logical size for one configured source. Repeating a key with an equal or smaller bound is free; growth only charges the delta. A rejected reservation does not partially mutate state.

func (*Budget) Used

func (b *Budget) Used() uint64

type BudgetCode

type BudgetCode uint8
const (
	BudgetInvalid BudgetCode = iota
	BudgetOK
	BudgetLogicalExhausted
	BudgetPhysicalExhausted
)

type BudgetResult

type BudgetResult struct {
	// contains filtered or unexported fields
}

BudgetResult is a closed, text-free budget decision.

func (BudgetResult) Allowed

func (r BudgetResult) Allowed() bool

func (BudgetResult) Code

func (r BudgetResult) Code() BudgetCode

type Clock

type Clock struct {
	// contains filtered or unexported fields
}

Clock is a closed acquisition-time source. Its zero value is invalid; use ProcessClock or FixedClock so production and conformance cannot select an ambient or caller-defined clock implementation.

func FixedClock

func FixedClock(value time.Time) (Clock, error)

func ProcessClock

func ProcessClock() Clock

type Evidence

type Evidence struct {
	// contains filtered or unexported fields
}

Evidence is an internal, non-serializable stable-read envelope.

func (Evidence) AdapterID

func (e Evidence) AdapterID() string

func (Evidence) ByteCount

func (e Evidence) ByteCount() uint64

func (Evidence) ConfiguredOrdinal

func (e Evidence) ConfiguredOrdinal() uint64

func (Evidence) ContentSHA256

func (e Evidence) ContentSHA256() string

func (Evidence) End

func (e Evidence) End() time.Time

func (Evidence) FileIdentityAfter

func (e Evidence) FileIdentityAfter() FileIdentity

func (Evidence) FileIdentityBefore

func (e Evidence) FileIdentityBefore() FileIdentity

func (Evidence) Start

func (e Evidence) Start() time.Time

func (Evidence) Validity

func (e Evidence) Validity() Validity

type FileIdentity

type FileIdentity struct {
	// contains filtered or unexported fields
}

func (FileIdentity) ModTimeNanoseconds

func (i FileIdentity) ModTimeNanoseconds() int64

func (FileIdentity) Mode

func (i FileIdentity) Mode() uint32

func (FileIdentity) PlatformIdentity

func (i FileIdentity) PlatformIdentity() PlatformIdentity

func (FileIdentity) Size

func (i FileIdentity) Size() uint64

type IssueCode

type IssueCode string
const (
	IssueNone                    IssueCode = ""
	IssueInvalidRegistration     IssueCode = "DASHBOARD_INVALID_ARGUMENT"
	IssueInvalidPath             IssueCode = "DASHBOARD_INVALID_ARGUMENT"
	IssueSourceUnavailable       IssueCode = "SOURCE_NOT_PRESENT"
	IssueSourceUnreadable        IssueCode = "SOURCE_INACCESSIBLE"
	IssueSourceSymlink           IssueCode = "SOURCE_SYMLINK"
	IssueSourceHardLinked        IssueCode = "SOURCE_MULTILINK_UNQUALIFIED"
	IssueSourceNotRegular        IssueCode = "SOURCE_SPECIAL_FILE"
	IssueSourceTooLarge          IssueCode = "SOURCE_OVERSIZED"
	IssueAggregateBudgetExceeded IssueCode = "DASHBOARD_RESOURCE_EXHAUSTED"
	IssueSourceUnstable          IssueCode = "SOURCE_CHANGED_DURING_READ"
	IssueStoreChanged            IssueCode = "STORE_CHANGED"
	IssueTraceStoreBound         IssueCode = "TRACE_STORE_BOUND"
)

type Kind

type Kind string

Kind is a closed identifier for a dashboard source family.

const (
	KindUnknown          Kind = "unknown"
	KindQueryEnvelope    Kind = "query-envelope"
	KindImpactEnvelope   Kind = "impact-envelope"
	KindLocalTrace       Kind = "LOCAL_TRACE_STORE"
	KindCEM              Kind = "cem"
	KindOCM              Kind = "ocm"
	KindFrontier         Kind = "frontier"
	KindPulseReceipt     Kind = "pulse-receipt"
	KindLiveVerification Kind = "live-verification"
	KindHarnessEvent     Kind = "harness-event"
	KindSpecIndex        Kind = "spec-index"
	KindBeamfallShadow   Kind = "beamfall-shadow"
)

type ObjectFormat

type ObjectFormat string
const (
	ObjectFormatSHA1   ObjectFormat = "sha1"
	ObjectFormatSHA256 ObjectFormat = "sha256"
)

type PlatformIdentity

type PlatformIdentity struct {
	Kind               string
	Device             uint64
	Inode              uint64
	LinkCount          uint64
	FileIndex          uint64
	VolumeSerialNumber uint64
}

type Result

type Result struct {
	Kind       Kind       `json:"kind"`
	VerifierID VerifierID `json:"verifier_id"`
	Validity   Validity   `json:"validity"`
	Bytes      uint64     `json:"bytes"`
	SHA256     *string    `json:"sha256"`
	Issue      IssueCode  `json:"issue_code"`
	Evidence   *Evidence  `json:"-"`
	// contains filtered or unexported fields
}

Result is deliberately closed: it cannot carry source contents, paths, or operating-system error text.

func Read

func Read(root *os.Root, relativePath string, kind Kind, verifier VerifierID, budget *Budget, consume StableConsumer) Result

Read snapshots one explicitly registered source beneath root. The caller is responsible for opening and independently authorizing root.

func ReadOrdinal

func ReadOrdinal(root *os.Root, relativePath string, configuredOrdinal uint64, kind Kind, verifier VerifierID, budget *Budget, consume StableConsumer) Result

ReadOrdinal performs the exact stable-read acquisition for one configured source. configuredOrdinal is evidence only and never participates in a path or product source identifier.

func ReadOrdinalWithClock

func ReadOrdinalWithClock(root *os.Root, relativePath string, configuredOrdinal uint64, kind Kind, verifier VerifierID, budget *Budget, clock Clock, consume StableConsumer) Result

ReadOrdinalWithClock is the closed conformance-capable acquisition entry. Production callers pass ProcessClock; only an explicitly constructed FixedClock can supply deterministic observation boundaries.

type StableConsumer

type StableConsumer func(StableContent)

StableConsumer receives admitted content after all stability checks pass. It cannot mutate the admitted buffer or recover its registered path.

type StableContent

type StableContent struct {
	// contains filtered or unexported fields
}

StableContent is an immutable view of the exact bytes admitted by Read. Reader returns a fresh in-memory reader; it never reopens the source path.

func (StableContent) Len

func (content StableContent) Len() uint64

func (StableContent) Reader

func (content StableContent) Reader() io.Reader

func (StableContent) SHA256

func (content StableContent) SHA256() string

type TraceMemberConsumer

type TraceMemberConsumer func(revision string, content StableContent, evidence Evidence)

type TraceMemberResult

type TraceMemberResult struct {
	Revision string
	Result   Result
}

type TraceStoreEvidence

type TraceStoreEvidence struct {
	// contains filtered or unexported fields
}

func (TraceStoreEvidence) ConfiguredOrdinal

func (e TraceStoreEvidence) ConfiguredOrdinal() uint64

func (TraceStoreEvidence) DirectoryAfter

func (e TraceStoreEvidence) DirectoryAfter() FileIdentity

func (TraceStoreEvidence) DirectoryBefore

func (e TraceStoreEvidence) DirectoryBefore() FileIdentity

func (TraceStoreEvidence) End

func (e TraceStoreEvidence) End() time.Time

func (TraceStoreEvidence) EntryCount

func (e TraceStoreEvidence) EntryCount() uint64

func (TraceStoreEvidence) Start

func (e TraceStoreEvidence) Start() time.Time

type TraceStoreResult

type TraceStoreResult struct {
	Validity Validity
	Issue    IssueCode
	Limit    uint64
	Members  []TraceMemberResult
	Evidence *TraceStoreEvidence
}

func ScanTraceStore

func ScanTraceStore(root *os.Root, relativeDirectory string, configuredOrdinal uint64, format ObjectFormat, budget *Budget, consume TraceMemberConsumer) TraceStoreResult

ScanTraceStore performs bounded, no-follow pre/post enumeration and stable acquisition of immediate revision-named members. It retries the entire store once when the directory identity set changes. It does not interpret traces.

func ScanTraceStoreWithClock

func ScanTraceStoreWithClock(root *os.Root, relativeDirectory string, configuredOrdinal uint64, format ObjectFormat, budget *Budget, clock Clock, consume TraceMemberConsumer) TraceStoreResult

type Validity

type Validity string
const (
	ValidityInvalid      Validity = "INVALID"
	ValidityStable       Validity = "VALID"
	ValidityNotPresent   Validity = "NOT_PRESENT"
	ValidityInaccessible Validity = "INACCESSIBLE"
	ValidityUnsupported  Validity = "UNSUPPORTED"
)

type VerifierID

type VerifierID string

VerifierID names a closed, versioned verifier contract. This package records the identifier; it never invokes a verifier.

const (
	VerifierUnknown            VerifierID = "unknown"
	VerifierContextEnvelopeV1  VerifierID = "corvint-context-envelope/1"
	VerifierLocalTraceV1       VerifierID = "go-local-trace-v1"
	VerifierCEMV01             VerifierID = "cem/0.1"
	VerifierCEMV02             VerifierID = "cem/0.2"
	VerifierOCMV01Experimental VerifierID = "ocm/0.1-experimental"
	VerifierFrontierV0         VerifierID = "frontier/0"
	VerifierPulseSnapshotV0    VerifierID = "corvint-pulse-snapshot/0"
	VerifierGoLiveRunV0        VerifierID = "go-live-run/0"
	VerifierHarnessEventV0     VerifierID = "corvint-harness-event/0"
	VerifierSpecIndexV0        VerifierID = "corvint-spec-index/0"
	VerifierFirstRunResultV0   VerifierID = "cem-first-run-result/0"
	VerifierFirstRunResultV01  VerifierID = "cem-first-run-result/0.1"
)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL