Documentation
¶
Overview ¶
Package verify composes the CEM seams into the frozen repository-conformant verifier: exact-patch (cem/0.1) and canonical (cem/0.2, cem/0.3) verification with the frozen validation precedence, mechanical byte and Go structural proofs, and same-path evidence drift.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func Candidate ¶
func Candidate(ctx context.Context, repository *gitauth.Repository, document *wire.Map, patchBytes []byte) error
Candidate validates a freshly derived or resumed candidate map against the canonical patch bytes without target-side artifact binding: prepare is the preceding candidate phase and must ignore inherited target sidecar state.
Types ¶
type CanonicalOptions ¶
type CanonicalOptions struct {
ExpectedBase string // required independent producer baseline
Target string // required caller target revision
// RawMapBytes is the exact bounded raw cem/0.2 input being verified, used
// for the target-side sidecar artifact binding.
RawMapBytes []byte
}
CanonicalOptions configure 0.2 canonical verification.
type DriftItem ¶
type DriftItem struct {
EvidenceID string
Status DriftStatus
TargetBlobOid string // empty for deleted
TargetSpan *wire.Span // exact target range for stable and relocated
}
DriftItem reports one evidence record's target drift.
type DriftStatus ¶
type DriftStatus string
DriftStatus enumerates the frozen same-path drift states.
const ( DriftStable DriftStatus = "stable" DriftRelocated DriftStatus = "relocated" DriftStale DriftStatus = "stale" DriftAmbiguous DriftStatus = "ambiguous" DriftDeleted DriftStatus = "deleted" )
func ClassifySpan ¶
func ClassifySpan(targetExists, unchanged bool, targetData, needle []byte, original wire.Span) (DriftStatus, *wire.Span)
ClassifySpan applies the frozen same-path drift classifier to facts gathered by either a verifier or a producer simulating the target.
type ExactOptions ¶
type ExactOptions struct {
// ExpectedBase, when non-empty, independently resolves and checks the
// map's baseRevision at its historical position after digest validation.
ExpectedBase string
// Target, when non-empty, runs the inherited evidence drift check.
Target string
}
ExactOptions configure 0.1 exact-patch verification.
type Outcome ¶
type Outcome struct {
BaseRevision string
TargetRevision string // empty when no target was checked
Drift []DriftItem
}
Outcome reports one accepted verification.
func Canonical ¶
func Canonical(ctx context.Context, repository *gitauth.Repository, document *wire.Map, options CanonicalOptions) (*Outcome, bool, error)
Canonical verifies a cem/0.2 map with independent base and target authority, deriving the canonical patch itself. It follows the frozen stage-7/8/9 precedence: expected-base resolution and equality, target resolution, the base-side historical-sidecar check, the target-side raw artifact comparison, canonical derivation, inherited verification, then drift.
The returned bound flag reports whether independent repository derivation and target binding both completed (CEM-CB-014): it is false for every failure before the canonical patch was derived, and true from the digest check onward, so callers claim "canonical" assurance only when it was actually established.