Documentation
¶
Overview ¶
Package authoritystore is the fixed read-only protected publication consumer. Production never accepts a caller-selected root, directory, key, or host tuple.
Index ¶
- Constants
- func AuditEvidenceParent(uint32, uint32) error
- func AuditEvidenceStageHandle(context.Context, *os.File, EvidenceManifest, uint32, uint32) error
- func AuditStagedEvidence(context.Context, string, EvidenceManifest, uint32, uint32) error
- func DecodeEvidenceManifest(raw []byte, result *EvidenceManifest) error
- func LoadExecutionRoot() (RootDocument, GenerationFloor, error)
- func OpenEvidencePublicationParent(uint32, uint32) (*os.File, error)
- func ReadExecutionFile(relative string, owner uint32, limit int) ([]byte, error)
- func ReadExecutionPolicy() ([]byte, error)
- func Resolve(ctx context.Context, handle string) (authorityevent.Resolution, error)
- func ValidateEvidenceManifest(m EvidenceManifest) error
- type ActiveEnrollment
- type DirectQualification
- type DirectRuntime
- type EvidenceFile
- type EvidenceManifest
- type EvidenceReference
- type GenerationFloor
- type HostQualification
- type Image
- type LifecycleObserver
- type LifecycleResolution
- func ResolveDirectLifecycle(ctx context.Context, stop bool, observe LifecycleObserver) (LifecycleResolution, error)
- func ResolveLifecycle(ctx context.Context, stop bool, observe LifecycleObserver) (LifecycleResolution, error)
- func ResolvePiLifecycle(ctx context.Context, stop bool, observe LifecycleObserver) (LifecycleResolution, error)
- type LifecycleScope
- type PiQualification
- type PiRuntime
- type ProcessInstance
- type RootDocument
- type SurfaceQualification
- type Target
- type Terminal
Constants ¶
const DirectRootProfile = "corvint-protected-root/2"
const EvidenceProfile = "corvint-protected-git-evidence/0"
const EvidenceReferenceProfile = "corvint-protected-git-reference/0"
const FloorProfile = "corvint-protected-generation-floor/0"
const MaxArtifact = 4 << 20
const MaxEvidenceBytes = 16 << 20
const MaxEvidenceManifest = 1 << 20
const MaxEvidenceObjects = 1024
const PiRootProfile = "corvint-protected-root/3"
const RootPath = "/Library/CorvintAuthority"
const RootProfile = "corvint-protected-root/1"
const TargetProfile = "corvint-protected-target/0"
const TerminalProfile = "corvint-protected-terminal/0"
Variables ¶
This section is empty.
Functions ¶
func AuditEvidenceParent ¶
func AuditStagedEvidence ¶
func DecodeEvidenceManifest ¶
func DecodeEvidenceManifest(raw []byte, result *EvidenceManifest) error
func LoadExecutionRoot ¶
func LoadExecutionRoot() (RootDocument, GenerationFloor, error)
LoadExecutionRoot is shared with the protected authority's one-shot phase. It validates only operator execution admission, not native host qualification.
func ReadExecutionFile ¶
ReadExecutionFile is the signer's bounded reader for the fixed private enrollment/journal/key and immutable version tree. It confers no OS access; the hook never invokes it and never reads the private signing key.
func ReadExecutionPolicy ¶
ReadExecutionPolicy reads only the fixed root-owned execution-policy file. Its caller checks the exact bytes against the independently loaded root pin.
func Resolve ¶
func Resolve(ctx context.Context, handle string) (authorityevent.Resolution, error)
Resolve reads the current independently accepted root and completed public artifacts from the fixed operator store. Missing installation is unavailable. It neither creates policy nor enrolls, signs, runs tests, or writes a ledger.
func ValidateEvidenceManifest ¶
func ValidateEvidenceManifest(m EvidenceManifest) error
ValidateEvidenceManifest checks a closed deterministic namespace. It cannot admit a reader, authenticate ownership or substitute for the file audit.
Types ¶
type ActiveEnrollment ¶
type ActiveEnrollment struct {
Profile string `json:"profile"`
EnrollmentHandle string `json:"enrollmentHandle"`
}
ActiveEnrollment is atomically published after the complete immutable bundle. It keeps the qualified adapter bytes stable across enrollment changes.
type DirectQualification ¶
type DirectQualification struct {
Profile string `json:"profile"`
EvidenceSHA256 string `json:"evidenceSHA256"`
Runtime DirectRuntime `json:"runtime"`
}
type DirectRuntime ¶
type DirectRuntime struct {
Topology string `json:"topology"`
Host string `json:"host"`
Surface string `json:"surface"`
BootSessionUUID string `json:"bootSessionUUID"`
HostInstance ProcessInstance `json:"hostInstance"`
HostImage Image `json:"hostImage"`
HostCDHash string `json:"hostCDHash"`
RuntimeAdmissionEvidenceSHA256 string `json:"runtimeAdmissionEvidenceSHA256"`
ParentPolicy string `json:"parentPolicy"`
OSBuild string `json:"osBuild"`
Architecture string `json:"architecture"`
}
DirectRuntime pins a process lifetime and current mapped native image. It is not an exec epoch, an authenticated event, or proof of a completed code audit.
type EvidenceFile ¶
type EvidenceManifest ¶
type EvidenceManifest struct {
Profile string `json:"profile"`
RootID string `json:"rootId"`
Epoch string `json:"epoch"`
Generation string `json:"generation"`
EnrollmentHandle string `json:"enrollmentHandle"`
CapsuleSHA256 string `json:"capsuleSHA256"`
Base string `json:"base"`
Target string `json:"target"`
Tree string `json:"tree"`
ObjectFormat string `json:"objectFormat"`
ReaderGID string `json:"readerGid"`
Files []EvidenceFile `json:"files"`
}
type EvidenceReference ¶
type EvidenceReference struct {
Profile string `json:"profile"`
EnrollmentHandle string `json:"enrollmentHandle"`
ManifestSHA256 string `json:"manifestSHA256"`
}
EvidenceReference contains no source bytes. The protected public publication binds the separately restricted evidence directory and its complete manifest.
type GenerationFloor ¶
type GenerationFloor struct {
Profile string `json:"profile"`
RootID string `json:"rootId"`
Epoch string `json:"epoch"`
Generation string `json:"generation"`
}
The floor is a separately protected operator-owned file, never overwritten by the consumer or signer. Restoring an older accepted-root cannot lower it.
type HostQualification ¶
type HostQualification struct {
Topology string `json:"topology"`
BootSessionUUID string `json:"bootSessionUUID"`
AppInstance ProcessInstance `json:"appInstance"`
ControlSocket string `json:"controlSocket,omitempty"`
QualifiedSurfaces []SurfaceQualification `json:"qualifiedSurfaces,omitempty"`
Profile string `json:"profile"`
Surface string `json:"surface"`
EvidenceSHA256 string `json:"evidenceSHA256"`
App Image `json:"app"`
Engine Image `json:"engine"`
AppCDHash string `json:"appCDHash"`
EngineCDHash string `json:"engineCDHash"`
OSBuild string `json:"osBuild"`
Architecture string `json:"architecture"`
}
type LifecycleObserver ¶
type LifecycleObserver func(context.Context, LifecycleScope) error
type LifecycleResolution ¶
type LifecycleResolution struct {
Scope LifecycleScope
Stop authorityevent.Resolution
}
func ResolveDirectLifecycle ¶
func ResolveDirectLifecycle(ctx context.Context, stop bool, observe LifecycleObserver) (LifecycleResolution, error)
ResolveDirectLifecycle selects only the closed QLF/1 root/2 pairing. It never accepts a root path, host identity or alternate computation from the caller.
func ResolveLifecycle ¶
func ResolveLifecycle(ctx context.Context, stop bool, observe LifecycleObserver) (LifecycleResolution, error)
ResolveLifecycle uses only the fixed protected store. Non-Stop context never opens an enrollment, publication, target capsule or private state. Stop obtains the active handle inside the protected scope and computes exactly once.
func ResolvePiLifecycle ¶
func ResolvePiLifecycle(ctx context.Context, stop bool, observe LifecycleObserver) (LifecycleResolution, error)
ResolvePiLifecycle selects only QLF/2 and the fixed root/3 store. A different installed host cannot be selected, substituted or downgraded by request input.
type LifecycleScope ¶
type LifecycleScope struct {
Pi bool
Direct bool
HostSHA256 string
RuntimeAdmissionEvidenceSHA256 string
RepositoryRoot string
ExpectedTarget string
QualifiedHostSHA256 string
EvidenceSHA256 string
AppSHA256 string
EngineSHA256 string
AdapterSHA256 string
OSBuild string
Architecture string
SupportScope string
QualifiedSurfaces []SurfaceQualification
}
LifecycleScope reports an independently admitted capability and the actual held repository. It does not authenticate occurrence of a caller's event. No process IDs, raw session identity or caller-selected paths are emitted. Candidate ExpectedTarget is an internal guard: the trusted observer must compare both common repository snapshots before context and before returning.
type PiQualification ¶
type PiQualification struct {
Profile string `json:"profile"`
EvidenceSHA256 string `json:"evidenceSHA256"`
Runtime PiRuntime `json:"runtime"`
QualifiedSurfaces []SurfaceQualification `json:"qualifiedSurfaces"`
}
type PiRuntime ¶
type PiRuntime DirectRuntime
PiRuntime pins the closed SDK image, which contains both native surfaces and every executable asset. It is a process lifetime, never an exec epoch.
type ProcessInstance ¶
type ProcessInstance struct {
PID uint32 `json:"pid,string"`
Started uint64 `json:"started,string"`
StartedUsec uint64 `json:"startedUsec,string"`
}
HostQualification is accepted independently only after every AHI requirement and native case passes for these exact images and OS. Runtime checks also require current Engine ancestry and live kernel code-directory hashes, plus App ancestry or a reciprocal shared-daemon socket relationship. AppInstance and BootSessionUUID bind the fresh resource-audited launch, not just its PID. Ordinary app ownership is not an execution authority boundary; these pins identify a qualified display host. The digest commits the separately reviewed qualification evidence; its mere presence in a candidate document never admits that document.
type RootDocument ¶
type RootDocument struct {
PiQualification *PiQualification `json:"-"`
DirectQualification *DirectQualification `json:"-"`
Profile string `json:"profile"`
Admission string `json:"admission"`
KeyClass string `json:"keyClass"`
RootID string `json:"rootId"`
PublicKey string `json:"publicKey"`
Epoch string `json:"epoch"`
Generation string `json:"generation"`
RepositoryID string `json:"repositoryId"`
RepositoryRoot string `json:"repositoryRoot"`
PolicySHA256 string `json:"policySHA256"`
Audience string `json:"audience"`
AuthorityUID string `json:"authorityUid"`
AuthorityGID string `json:"authorityGid"`
ReaderUID string `json:"readerUid"`
Revoked bool `json:"revoked"`
Checks []localauthority.Check `json:"checks"`
Consumer Image `json:"consumer"`
Git Image `json:"git"`
Adapter Image `json:"adapter"`
HostQualification *HostQualification `json:"hostQualification"`
RemediationAllowed bool `json:"remediationAllowed"`
}
RootDocument is read exclusively from root:wheel accepted-root.json, with safe ancestors and no ACL entries. Root admission is an operator action; installer/signer cannot create an OPERATOR_ACCEPTED document for themselves. authorityUID names the dedicated noninteractive publication owner.
func (RootDocument) MarshalJSON ¶
func (r RootDocument) MarshalJSON() ([]byte, error)
func (*RootDocument) UnmarshalJSON ¶
func (r *RootDocument) UnmarshalJSON(raw []byte) error