authoritystore

package
v0.8.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 23 Imported by: 0

Documentation

Overview

Package authoritystore is the fixed read-only protected publication consumer. Production never accepts a caller-selected root, directory, key, or host tuple.

Index

Constants

View Source
const DirectRootProfile = "corvint-protected-root/2"
View Source
const EvidenceProfile = "corvint-protected-git-evidence/0"
View Source
const EvidenceReferenceProfile = "corvint-protected-git-reference/0"
View Source
const FloorProfile = "corvint-protected-generation-floor/0"
View Source
const MaxArtifact = 4 << 20
View Source
const MaxEvidenceBytes = 16 << 20
View Source
const MaxEvidenceManifest = 1 << 20
View Source
const MaxEvidenceObjects = 1024
View Source
const PiRootProfile = "corvint-protected-root/3"
View Source
const RootPath = "/Library/CorvintAuthority"
View Source
const RootProfile = "corvint-protected-root/1"
View Source
const TargetProfile = "corvint-protected-target/0"
View Source
const TerminalProfile = "corvint-protected-terminal/0"

Variables

This section is empty.

Functions

func AuditEvidenceParent

func AuditEvidenceParent(uint32, uint32) error

func DecodeEvidenceManifest

func DecodeEvidenceManifest(raw []byte, result *EvidenceManifest) error

func LoadExecutionRoot

func LoadExecutionRoot() (RootDocument, GenerationFloor, error)

LoadExecutionRoot is shared with the protected authority's one-shot phase. It validates only operator execution admission, not native host qualification.

func OpenEvidencePublicationParent

func OpenEvidencePublicationParent(uint32, uint32) (*os.File, error)

func ReadExecutionFile

func ReadExecutionFile(relative string, owner uint32, limit int) ([]byte, error)

ReadExecutionFile is the signer's bounded reader for the fixed private enrollment/journal/key and immutable version tree. It confers no OS access; the hook never invokes it and never reads the private signing key.

func ReadExecutionPolicy

func ReadExecutionPolicy() ([]byte, error)

ReadExecutionPolicy reads only the fixed root-owned execution-policy file. Its caller checks the exact bytes against the independently loaded root pin.

func Resolve

func Resolve(ctx context.Context, handle string) (authorityevent.Resolution, error)

Resolve reads the current independently accepted root and completed public artifacts from the fixed operator store. Missing installation is unavailable. It neither creates policy nor enrolls, signs, runs tests, or writes a ledger.

func ValidateEvidenceManifest

func ValidateEvidenceManifest(m EvidenceManifest) error

ValidateEvidenceManifest checks a closed deterministic namespace. It cannot admit a reader, authenticate ownership or substitute for the file audit.

Types

type ActiveEnrollment

type ActiveEnrollment struct {
	Profile          string `json:"profile"`
	EnrollmentHandle string `json:"enrollmentHandle"`
}

ActiveEnrollment is atomically published after the complete immutable bundle. It keeps the qualified adapter bytes stable across enrollment changes.

type DirectQualification

type DirectQualification struct {
	Profile        string        `json:"profile"`
	EvidenceSHA256 string        `json:"evidenceSHA256"`
	Runtime        DirectRuntime `json:"runtime"`
}

type DirectRuntime

type DirectRuntime struct {
	Topology                       string          `json:"topology"`
	Host                           string          `json:"host"`
	Surface                        string          `json:"surface"`
	BootSessionUUID                string          `json:"bootSessionUUID"`
	HostInstance                   ProcessInstance `json:"hostInstance"`
	HostImage                      Image           `json:"hostImage"`
	HostCDHash                     string          `json:"hostCDHash"`
	RuntimeAdmissionEvidenceSHA256 string          `json:"runtimeAdmissionEvidenceSHA256"`
	ParentPolicy                   string          `json:"parentPolicy"`
	OSBuild                        string          `json:"osBuild"`
	Architecture                   string          `json:"architecture"`
}

DirectRuntime pins a process lifetime and current mapped native image. It is not an exec epoch, an authenticated event, or proof of a completed code audit.

type EvidenceFile

type EvidenceFile struct {
	Path        string `json:"path"`
	Size        string `json:"size"`
	SHA256      string `json:"sha256"`
	OID         string `json:"oid,omitempty"`
	Kind        string `json:"kind,omitempty"`
	DecodedSize string `json:"decodedSize,omitempty"`
}

type EvidenceManifest

type EvidenceManifest struct {
	Profile          string         `json:"profile"`
	RootID           string         `json:"rootId"`
	Epoch            string         `json:"epoch"`
	Generation       string         `json:"generation"`
	EnrollmentHandle string         `json:"enrollmentHandle"`
	CapsuleSHA256    string         `json:"capsuleSHA256"`
	Base             string         `json:"base"`
	Target           string         `json:"target"`
	Tree             string         `json:"tree"`
	ObjectFormat     string         `json:"objectFormat"`
	ReaderGID        string         `json:"readerGid"`
	Files            []EvidenceFile `json:"files"`
}

type EvidenceReference

type EvidenceReference struct {
	Profile          string `json:"profile"`
	EnrollmentHandle string `json:"enrollmentHandle"`
	ManifestSHA256   string `json:"manifestSHA256"`
}

EvidenceReference contains no source bytes. The protected public publication binds the separately restricted evidence directory and its complete manifest.

type GenerationFloor

type GenerationFloor struct {
	Profile    string `json:"profile"`
	RootID     string `json:"rootId"`
	Epoch      string `json:"epoch"`
	Generation string `json:"generation"`
}

The floor is a separately protected operator-owned file, never overwritten by the consumer or signer. Restoring an older accepted-root cannot lower it.

type HostQualification

type HostQualification struct {
	Topology          string                 `json:"topology"`
	BootSessionUUID   string                 `json:"bootSessionUUID"`
	AppInstance       ProcessInstance        `json:"appInstance"`
	ControlSocket     string                 `json:"controlSocket,omitempty"`
	QualifiedSurfaces []SurfaceQualification `json:"qualifiedSurfaces,omitempty"`
	Profile           string                 `json:"profile"`
	Surface           string                 `json:"surface"`
	EvidenceSHA256    string                 `json:"evidenceSHA256"`
	App               Image                  `json:"app"`
	Engine            Image                  `json:"engine"`
	AppCDHash         string                 `json:"appCDHash"`
	EngineCDHash      string                 `json:"engineCDHash"`
	OSBuild           string                 `json:"osBuild"`
	Architecture      string                 `json:"architecture"`
}

type Image

type Image struct {
	Path   string `json:"path"`
	SHA256 string `json:"sha256"`
}

type LifecycleObserver

type LifecycleObserver func(context.Context, LifecycleScope) error

type LifecycleResolution

type LifecycleResolution struct {
	Scope LifecycleScope
	Stop  authorityevent.Resolution
}

func ResolveDirectLifecycle

func ResolveDirectLifecycle(ctx context.Context, stop bool, observe LifecycleObserver) (LifecycleResolution, error)

ResolveDirectLifecycle selects only the closed QLF/1 root/2 pairing. It never accepts a root path, host identity or alternate computation from the caller.

func ResolveLifecycle

func ResolveLifecycle(ctx context.Context, stop bool, observe LifecycleObserver) (LifecycleResolution, error)

ResolveLifecycle uses only the fixed protected store. Non-Stop context never opens an enrollment, publication, target capsule or private state. Stop obtains the active handle inside the protected scope and computes exactly once.

func ResolvePiLifecycle

func ResolvePiLifecycle(ctx context.Context, stop bool, observe LifecycleObserver) (LifecycleResolution, error)

ResolvePiLifecycle selects only QLF/2 and the fixed root/3 store. A different installed host cannot be selected, substituted or downgraded by request input.

type LifecycleScope

type LifecycleScope struct {
	Pi                             bool
	Direct                         bool
	HostSHA256                     string
	RuntimeAdmissionEvidenceSHA256 string
	RepositoryRoot                 string
	ExpectedTarget                 string
	QualifiedHostSHA256            string
	EvidenceSHA256                 string
	AppSHA256                      string
	EngineSHA256                   string
	AdapterSHA256                  string
	OSBuild                        string
	Architecture                   string
	SupportScope                   string
	QualifiedSurfaces              []SurfaceQualification
}

LifecycleScope reports an independently admitted capability and the actual held repository. It does not authenticate occurrence of a caller's event. No process IDs, raw session identity or caller-selected paths are emitted. Candidate ExpectedTarget is an internal guard: the trusted observer must compare both common repository snapshots before context and before returning.

type PiQualification

type PiQualification struct {
	Profile           string                 `json:"profile"`
	EvidenceSHA256    string                 `json:"evidenceSHA256"`
	Runtime           PiRuntime              `json:"runtime"`
	QualifiedSurfaces []SurfaceQualification `json:"qualifiedSurfaces"`
}

type PiRuntime

type PiRuntime DirectRuntime

PiRuntime pins the closed SDK image, which contains both native surfaces and every executable asset. It is a process lifetime, never an exec epoch.

type ProcessInstance

type ProcessInstance struct {
	PID         uint32 `json:"pid,string"`
	Started     uint64 `json:"started,string"`
	StartedUsec uint64 `json:"startedUsec,string"`
}

HostQualification is accepted independently only after every AHI requirement and native case passes for these exact images and OS. Runtime checks also require current Engine ancestry and live kernel code-directory hashes, plus App ancestry or a reciprocal shared-daemon socket relationship. AppInstance and BootSessionUUID bind the fresh resource-audited launch, not just its PID. Ordinary app ownership is not an execution authority boundary; these pins identify a qualified display host. The digest commits the separately reviewed qualification evidence; its mere presence in a candidate document never admits that document.

type RootDocument

type RootDocument struct {
	PiQualification     *PiQualification       `json:"-"`
	DirectQualification *DirectQualification   `json:"-"`
	Profile             string                 `json:"profile"`
	Admission           string                 `json:"admission"`
	KeyClass            string                 `json:"keyClass"`
	RootID              string                 `json:"rootId"`
	PublicKey           string                 `json:"publicKey"`
	Epoch               string                 `json:"epoch"`
	Generation          string                 `json:"generation"`
	RepositoryID        string                 `json:"repositoryId"`
	RepositoryRoot      string                 `json:"repositoryRoot"`
	PolicySHA256        string                 `json:"policySHA256"`
	Audience            string                 `json:"audience"`
	AuthorityUID        string                 `json:"authorityUid"`
	AuthorityGID        string                 `json:"authorityGid"`
	ReaderUID           string                 `json:"readerUid"`
	Revoked             bool                   `json:"revoked"`
	Checks              []localauthority.Check `json:"checks"`
	Consumer            Image                  `json:"consumer"`
	Git                 Image                  `json:"git"`
	Adapter             Image                  `json:"adapter"`
	HostQualification   *HostQualification     `json:"hostQualification"`
	RemediationAllowed  bool                   `json:"remediationAllowed"`
}

RootDocument is read exclusively from root:wheel accepted-root.json, with safe ancestors and no ACL entries. Root admission is an operator action; installer/signer cannot create an OPERATOR_ACCEPTED document for themselves. authorityUID names the dedicated noninteractive publication owner.

func (RootDocument) MarshalJSON

func (r RootDocument) MarshalJSON() ([]byte, error)

func (*RootDocument) UnmarshalJSON

func (r *RootDocument) UnmarshalJSON(raw []byte) error

type SurfaceQualification

type SurfaceQualification struct {
	Surface        string `json:"surface"`
	EvidenceSHA256 string `json:"evidenceSHA256"`
}

type Target

type Target struct {
	Profile        string `json:"profile"`
	RepositoryID   string `json:"repositoryId"`
	RepositoryRoot string `json:"repositoryRoot"`
	Base           string `json:"base"`
	Target         string `json:"target"`
	Tree           string `json:"tree"`
}

type Terminal

type Terminal struct {
	Profile       string `json:"profile"`
	Nonce         string `json:"nonce"`
	State         string `json:"state"`
	ReceiptSHA256 string `json:"receiptSHA256"`
}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL