lrfrepo

package
v0.8.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 23 Imported by: 0

Documentation

Overview

Package lrfrepo issues canonical LRF results from verified repository authority.

Index

Constants

View Source
const DefaultOCMMapPath = ".corvint/change.ocm.json"

DefaultOCMMapPath is the oracle's default OCM map location.

View Source
const DefaultOCMReportPath = ".git/corvint/ocm-review.md"

Variables

This section is empty.

Functions

func CodeOf

func CodeOf(err error) string

CodeOf returns an LRF, CEM, or adapter error code.

func Evaluate

func Evaluate(ctx context.Context, root string, options Options) (lrf.Result, error)

Evaluate verifies all repository authority and evaluates the frozen LRF projection.

func OCMCountsAndWorklist

func OCMCountsAndWorklist(document wire.Value) (map[string]any, []any)

OCMCountsAndWorklist exposes the shared counts/worklist derivation so prepare reports exactly what status reports.

func PublishOCMReport

func PublishOCMReport(ctx context.Context, root, requested string, data []byte, publishReport bool) (string, error)

PublishOCMReport resolves and optionally publishes one bounded report. A false publish flag performs every path-safety check without writing.

func UnknownReasons

func UnknownReasons() []string

UnknownReasons returns the mark reason allowlist in the oracle's sorted order.

Types

type Error

type Error struct {
	Code    string
	Message string
}

Error is an adapter-owned structural or compatibility failure.

func (*Error) Error

func (e *Error) Error() string

type IntentScope

type IntentScope struct {
	Path       string
	BlobOID    string
	Start      int64
	End        int64
	SpanSHA256 string
}

IntentScope is the one exact pinned OCM intent scope of a verified universe.

type LinkOptions

type LinkOptions struct {
	MapPath      string
	CEMPath      string
	Output       string
	Obligation   string
	Hunks        []string
	TestPath     string
	Claims       []string
	ExpectedBase string
	Target       string
	// contains filtered or unexported fields
}

LinkOptions configure one `ocm link` invocation.

type LinkResult

type LinkResult struct {
	MapPath      string
	ObligationID string
	HunkIDs      []string
	ClaimIDs     []string
}

LinkResult reports what one link recorded.

func LinkOCM

func LinkOCM(ctx context.Context, root string, options LinkOptions) (*LinkResult, error)

LinkOCM links one obligation to CEM hunks and pinned test claims. It verifies the existing map FIRST: a link records a reviewer's judgement, so it may only be added to a map that still holds together.

type MarkOptions

type MarkOptions struct {
	MapPath    string
	Output     string
	Obligation string
	Reason     string
}

MarkOptions configure one `ocm mark` invocation.

type MarkResult

type MarkResult struct {
	MapPath      string
	ObligationID string
}

MarkResult reports what one mark changed.

func MarkOCM

func MarkOCM(ctx context.Context, root string, options MarkOptions) (*MarkResult, error)

MarkOCM applies one `ocm mark` and republishes the map. The map is re-read, mutated, and written whole; nothing is patched in place.

type OCMReadOptions

type OCMReadOptions struct {
	OCMPath           string
	CEMPath           string
	ExpectedBase      string
	Target            string
	ExpectedBaseGiven bool
	TargetGiven       bool
	MaxUnknown        *int
}

OCMReadOptions are the authority and policy inputs shared by status, verify, and report.

type OCMReadResult

type OCMReadResult struct {
	State         string
	Counts        map[string]any
	Worklist      []any
	PolicyIssues  []any
	Verification  map[string]any
	TestExecution map[string]any
	OCMAbsolute   string
	CEMAbsolute   string
	// OCMRaw is the exact OCM map bytes this verdict was computed from. A
	// caller that needs to bind a digest or re-parse the map to these bytes
	// (rather than re-reading the path, which can observe a different file
	// if it changes between reads) MUST use this field.
	OCMRaw []byte `json:"-"`
	// CEMRaw is the exact CEM map bytes used with OCMRaw for this verdict.
	CEMRaw []byte `json:"-"`
	// VerificationCause retains the failed check before standalone wire redaction.
	VerificationCause error `json:"-"`
}

OCMReadResult is the transport-neutral read verdict. Command-specific envelopes add only their tool name and path fields.

func ReadOCM

func ReadOCM(ctx context.Context, root string, options OCMReadOptions) (*OCMReadResult, error)

ReadOCM verifies one OCM through the same parser and repository authority used by LRF. Semantic failures are returned as verdicts; only unsupported profiles and operational failures return an error.

type Obligation

type Obligation struct {
	ID          string
	Disposition string
	Reason      string
	HunkIDs     []string
	ClaimIDs    []string
}

Obligation is one verified OCM obligation row in OCM order. The rows are surfaced alongside the LRF projection because a consumer of the intent closure needs the declared disposition and reason, which the LRF request deliberately does not carry.

type Options

type Options struct {
	CEMPath      string
	OCMPath      string
	PatchPath    string
	PatchGiven   bool
	ExpectedBase string
	Target       string
}

Options are the repository-authority inputs accepted by corvint lrf.

type PrepareOptions

type PrepareOptions struct {
	MapPath      string
	CEMPath      string
	IntentPath   string
	Target       string
	ExpectedBase string
	Replace      bool
	MaxUnknown   *int
}

PrepareOptions configure one `ocm prepare` invocation.

type PrepareResult

type PrepareResult struct {
	Document     wire.Value
	MapAbsolute  string
	CEMAbsolute  string
	Target       string
	IntentScope  map[string]any
	Resumed      bool
	Requirements []string
	StatusAction []any
}

PrepareResult reports what one prepare created or resumed.

func PrepareOCM

func PrepareOCM(ctx context.Context, root string, options PrepareOptions) (*PrepareResult, error)

PrepareOCM creates or safely resumes the local OCM reviewer artifact. It is the only write action that can invent a document, so it verifies the CEM first: every obligation it writes is derived from an intent blob pinned at a target the CEM already binds.

type PythonClaimEvidence

type PythonClaimEvidence struct {
	ClaimID       string
	Path          string
	BlobOID       string
	AnchorProfile string
	Reason        string
}

PythonClaimEvidence is one structurally re-derived Python claim. ClaimID identifies every selected edge that rests on the claim; Path and BlobOID pin its source, and AnchorProfile preserves the supported profile if frozen grammar rejection prevents TCQ from re-deriving it itself.

type Universe

type Universe struct {
	CEM            *wire.Map
	BaseRevision   string
	TargetRevision string
	// ObjectFormat is the repository's own format, exactly "sha1" or "sha256".
	ObjectFormat string
	PatchSHA256  string
	OCMSHA256    string
	Intent       IntentScope
	Obligations  []Obligation
	LRFRequest   lrf.Request
	PythonClaims []PythonClaimEvidence
}

Universe is one accepted verification: the declared universe as the shared verifier resolved it, plus the pure post-structural LRF projection derived from the same verified inputs and target Git objects. The LRF result itself is deliberately absent — a consumer recomputes it rather than accepting one.

func VerifyUniverse

func VerifyUniverse(ctx context.Context, root string, cemRaw, ocmRaw []byte, expectedBase, target string) (*Universe, error)

VerifyUniverse runs one shared OCM-consuming canonical verification over caller-supplied artifact bytes and returns the accepted universe.

Both revisions are required and independent: an inferred revision authority is refused by the canonical verifier itself, which is why neither is defaulted here.

func VerifyUniverseWithRepository

func VerifyUniverseWithRepository(ctx context.Context, repository *gitauth.Repository, cemRaw, ocmRaw []byte, expectedBase, target string) (*Universe, error)

VerifyUniverseWithRepository executes the same canonical verification using one caller-owned repository scope. It does not accept a precomputed result or an authority grant; the protected adapter supplies its separately budgeted immutable reader. Ordinary VerifyUniverse callers retain their uncached Open.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL