authorityevent

package
v0.8.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 8 Imported by: 0

Documentation

Overview

Package authorityevent defines the experimental native Stop transport. It grants no authority: only a protected host may supply a Resolver. The ordinary corvint command deliberately has no resolver until root admission exists.

Index

Constants

View Source
const MaxInput = 4096
View Source
const Profile = "corvint-authority-event/0"

Variables

This section is empty.

Functions

func DecisionForState

func DecisionForState(state string, active, permitted bool) (string, string)

DecisionForState shares the native Stop rule with the additive qualified lifecycle renderer. Callers must establish protected state independently.

func NativeOutput

func NativeOutput(result Result) map[string]string

NativeOutput contains only fixed host-facing text, never repository content. A display envelope is not a cryptographic receipt or evidence of host uptake.

Types

type Event

type Event struct {
	Profile          string `json:"profile"`
	Event            string `json:"event"`
	EnrollmentHandle string `json:"enrollmentHandle"`
	StopHookActive   bool   `json:"stopHookActive"`
}

func Parse

func Parse(raw []byte) (Event, error)

Parse rejects duplicates, unknown fields, null/missing values and trailing documents. Host event bodies are projected before reaching this boundary.

type QualificationExercise

type QualificationExercise struct {
	CampaignID    string
	StopPermitted bool
}

Resolution is an in-process trusted-boundary result, never an accepted wire input. Resolve must recompute the universe from protected enrollment, current policy and actual target; it must not read a producer's EMPTY field. The host digest identifies an independently admitted exact native tuple and complete AHI qualification, not a caller's version string or test fixture certificate. RootCurrent requires fresh, non-revoked, monotonic protected policy. The caller must execute this package from its immutable protected consumer release. QualificationExercise is supplied only by the protected resolver after current operator campaign admission. It is not part of any input schema.

type Resolution

type Resolution struct {
	Exercise            *QualificationExercise
	SupportScope        string
	QualifiedSurfaces   []string
	State               string
	UniverseSHA256      string
	RootCurrent         bool
	QualifiedHostSHA256 string
	RemediationAllowed  bool
}

type Resolver

type Resolver func(context.Context, string) (Resolution, error)

type Result

type Result struct {
	Qualification       string   `json:"qualification,omitempty"`
	CampaignID          string   `json:"campaignId,omitempty"`
	SupportScope        string   `json:"supportScope,omitempty"`
	QualifiedSurfaces   []string `json:"qualifiedSurfaces,omitempty"`
	EventSurface        string   `json:"eventSurface,omitempty"`
	Profile             string   `json:"profile"`
	RequestSHA256       string   `json:"requestSHA256"`
	Authority           string   `json:"authority"`
	Support             string   `json:"support"`
	State               string   `json:"state"`
	UniverseSHA256      string   `json:"universeSHA256,omitempty"`
	QualifiedHostSHA256 string   `json:"qualifiedHostSHA256,omitempty"`
	Decision            string   `json:"decision"`
	Reason              string   `json:"reason"`
}

func Handle

func Handle(ctx context.Context, event Event, resolve Resolver) Result

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL