verify

package
v0.8.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 19 Imported by: 0

Documentation

Overview

Package verify composes the CEM seams into the frozen repository-conformant verifier: exact-patch (cem/0.1) and canonical (cem/0.2, cem/0.3) verification with the frozen validation precedence, mechanical byte and Go structural proofs, and same-path evidence drift.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func Candidate

func Candidate(ctx context.Context, repository *gitauth.Repository, document *wire.Map, patchBytes []byte) error

Candidate validates a freshly derived or resumed candidate map against the canonical patch bytes without target-side artifact binding: prepare is the preceding candidate phase and must ignore inherited target sidecar state.

Types

type CanonicalOptions

type CanonicalOptions struct {
	ExpectedBase string // required independent producer baseline
	Target       string // required caller target revision
	// RawMapBytes is the exact bounded raw cem/0.2 input being verified, used
	// for the target-side sidecar artifact binding.
	RawMapBytes []byte
}

CanonicalOptions configure 0.2 canonical verification.

type DriftItem

type DriftItem struct {
	EvidenceID    string
	Status        DriftStatus
	TargetBlobOid string     // empty for deleted
	TargetSpan    *wire.Span // exact target range for stable and relocated
}

DriftItem reports one evidence record's target drift.

type DriftStatus

type DriftStatus string

DriftStatus enumerates the frozen same-path drift states.

const (
	DriftStable    DriftStatus = "stable"
	DriftRelocated DriftStatus = "relocated"
	DriftStale     DriftStatus = "stale"
	DriftAmbiguous DriftStatus = "ambiguous"
	DriftDeleted   DriftStatus = "deleted"
)

func ClassifySpan

func ClassifySpan(targetExists, unchanged bool, targetData, needle []byte, original wire.Span) (DriftStatus, *wire.Span)

ClassifySpan applies the frozen same-path drift classifier to facts gathered by either a verifier or a producer simulating the target.

type ExactOptions

type ExactOptions struct {
	// ExpectedBase, when non-empty, independently resolves and checks the
	// map's baseRevision at its historical position after digest validation.
	ExpectedBase string
	// Target, when non-empty, runs the inherited evidence drift check.
	Target string
}

ExactOptions configure 0.1 exact-patch verification.

type Outcome

type Outcome struct {
	BaseRevision   string
	TargetRevision string // empty when no target was checked
	Drift          []DriftItem
}

Outcome reports one accepted verification.

func Canonical

func Canonical(ctx context.Context, repository *gitauth.Repository, document *wire.Map, options CanonicalOptions) (*Outcome, bool, error)

Canonical verifies a cem/0.2 map with independent base and target authority, deriving the canonical patch itself. It follows the frozen stage-7/8/9 precedence: expected-base resolution and equality, target resolution, the base-side historical-sidecar check, the target-side raw artifact comparison, canonical derivation, inherited verification, then drift.

The returned bound flag reports whether independent repository derivation and target binding both completed (CEM-CB-014): it is false for every failure before the canonical patch was derived, and true from the digest check onward, so callers claim "canonical" assurance only when it was actually established.

func Exact

func Exact(ctx context.Context, repository *gitauth.Repository, document *wire.Map, patchBytes []byte, options ExactOptions) (*Outcome, error)

Exact verifies a cem/0.1 map against exact caller-supplied patch bytes.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL