companionrelease

package
v0.8.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 39 Imported by: 0

Documentation

Overview

Package companionrelease assembles the optional companion distribution bundle (nine Go binaries plus five agent-host packages) for a single pinned target. It never mutates a caller-supplied checkout: every Git read is a plumbing read against HEAD, and every build/assembly step runs inside a caller-supplied scratch directory. Browser qualification is explicitly out of scope; see docs/specs/public-release-v0.md.

Package companionrelease builds the optional, darwin/arm64-only companion bundle (corvint-console, corvint-dashboard-snapshot, corvint, atm) described by docs/specs/public-release-v0.md PUB-V0-002/003/004. It never mutates a caller-supplied checkout: every read is either a Git object read against an explicit HEAD, or a bounded subprocess run in a scratch directory the caller owns. It builds, verifies, and retains a candidate; it never tags, pushes, or publishes anything.

Index

Constants

This section is empty.

Variables

View Source
var NotRunTargets = []string{"darwin/amd64", "linux/amd64", "linux/arm64", "windows/amd64"}

NotRunTargets are recorded verbatim in every report so a reader never infers qualification for a platform this build did not attempt.

Functions

func ValidateCoreInstalledReport

func ValidateCoreInstalledReport(body []byte) error

ValidateCoreInstalledReport is the closed core reader. It never accepts a historical editor receipt or substitutes an unmeasured axis for execution.

Types

type ArchiveEntry

type ArchiveEntry struct {
	Path string
	Mode int64
	Data []byte
}

ArchiveEntry is one file this package will place in a tar.gz it builds. Mode must be exactly 0o644 or 0o755; there is no other member kind.

type ArtifactManifest

type ArtifactManifest struct {
	Name                string `json:"name"`
	Kind                string `json:"kind"`
	Path                string `json:"path"`
	SHA256              string `json:"sha256,omitempty"`
	SizeBytes           int64  `json:"sizeBytes,omitempty"`
	Commit              string `json:"commit"`
	Tree                string `json:"tree"`
	SourceArchivePath   string `json:"sourceArchivePath"`
	SourceArchiveSHA256 string `json:"sourceArchiveSha256"`
	Support             string `json:"support,omitempty"`
}

type BuiltBinary

type BuiltBinary struct {
	Name       string
	Path       string
	SHA256     string
	Size       int64
	ModulePath string
}

BuiltBinary is one component binary this package has verified twice: two independent, cold-cache builds produced byte-identical output, and its on-disk buildinfo matches the pinned toolchain and target exactly.

type BundleManifest

type BundleManifest struct {
	Profile    json.RawMessage       `json:"profile,omitempty"`
	Target     string                `json:"target"`
	GoVersion  string                `json:"goVersion"`
	GitVersion string                `json:"gitVersion"`
	NotRun     []string              `json:"notRunTargets"`
	Components []ComponentManifest   `json:"components"`
	Artifacts  []ArtifactManifest    `json:"artifacts"`
	VSIXTools  VSIXToolchainManifest `json:"vsixToolchain"`
}

BundleManifest is the companion bundle's top-level, machine-readable record: the target it was built for and the exact toolchain and component identities that produced it.

func (BundleManifest) MarshalJSON

func (m BundleManifest) MarshalJSON() ([]byte, error)

type ComponentManifest

type ComponentManifest struct {
	Name                string `json:"name"`
	Module              string `json:"module"`
	BinaryPath          string `json:"binaryPath"`
	BinarySHA256        string `json:"binarySha256"`
	BinarySizeBytes     int64  `json:"binarySizeBytes"`
	Commit              string `json:"commit"`
	Tree                string `json:"tree"`
	SourceArchivePath   string `json:"sourceArchivePath"`
	SourceArchiveSHA256 string `json:"sourceArchiveSha256"`
}

ComponentManifest is one bundled binary's exact provenance: the commit and tree it was built from, the source archive that reproduces those bytes, and the binary's own digest.

type CoreInstalledOptions

type CoreInstalledOptions struct {
	InstalledOptions
	ExpectedNodeSHA256, ExpectedNPMSHA256      string
	GoAuthorityPath, ExpectedGoAuthoritySHA256 string
}

type CoreInstalledReport

type CoreInstalledReport struct {
	Profile      string               `json:"profile"`
	Status       string               `json:"status"`
	BundleSHA256 string               `json:"bundleSha256"`
	SourceCommit string               `json:"sourceCommit"`
	SourceTree   string               `json:"sourceTree"`
	NodeSHA256   string               `json:"nodeSha256"`
	NPMSHA256    string               `json:"npmSha256"`
	PythonSHA256 string               `json:"pythonSha256"`
	Identity     InstalledEvidence    `json:"identity"`
	Providers    []InstalledEvidence  `json:"providers"`
	Console      []InstalledEvidence  `json:"console"`
	Roadmap      []InstalledEvidence  `json:"roadmap"`
	Docs         []InstalledEvidence  `json:"docs"`
	Stages       []CoreInstalledStage `json:"stages"`
}

func RunCoreInstalledQualification

func RunCoreInstalledQualification(ctx context.Context, opts CoreInstalledOptions) (report CoreInstalledReport, err error)

RunCoreInstalledQualification runs only helpers reconstructed from the verified retained source. Failed scratch is evidence, never a successful report.

type CoreInstalledStage

type CoreInstalledStage struct {
	Name         string `json:"name"`
	StdoutSHA256 string `json:"stdoutSha256"`
	StderrSHA256 string `json:"stderrSha256"`
	Stdout       string `json:"stdout"`
	Stderr       string `json:"stderr"`
}

type CoreSource added in v0.8.1

type CoreSource struct {
	Commit     string
	Tree       string
	GitVersion string
	Archive    []byte // the exact source/corvint-src.tar.gz bytes the companion bundle carries
}

CoreSource is the hash-verified Corvint source archive of one clean checkout's HEAD, with the Git identity that produced it.

func CoreSourceArchive added in v0.8.1

func CoreSourceArchive(ctx context.Context, root, scratch string) (CoreSource, error)

CoreSourceArchive exports root's HEAD with the same verified reader and deterministic tar.gz the companion bundle uses for source/corvint-src.tar.gz. It takes no Corvint Tasks input, so a Core-only candidate can carry its own source archive (PRS-V1-005). scratch must be an existing private directory.

type Export

type Export struct {
	Root       string
	HeadCommit string
	HeadTree   string
	Files      []SourceFile // sorted by Path
	TotalBytes int64
}

Export is the exact, hash-verified regular-file content of one commit's tree, read twice by independent code paths that had to agree.

type InstalledEvidence

type InstalledEvidence struct {
	Name   string `json:"name"`
	SHA256 string `json:"sha256"`
	Raw    string `json:"raw"`
}

type InstalledOptions

type InstalledOptions struct {
	BundleDirectory, Scratch, OutputPath, NPMCache, BrowserCache string
	SourceRoot                                                   string
	NodePath, PythonPath, ExpectedCommit, ExpectedTree           string
	ExpectedPythonSHA256                                         string
}

type InstalledReport

type InstalledReport struct {
	Profile      string              `json:"profile"`
	Status       string              `json:"status"`
	BundleSHA256 string              `json:"bundleSha256"`
	SourceCommit string              `json:"sourceCommit"`
	SourceTree   string              `json:"sourceTree"`
	NodeSHA256   string              `json:"nodeSha256"`
	PythonSHA256 string              `json:"pythonSha256"`
	EditorHost   json.RawMessage     `json:"editorHost"`
	Roadmap      json.RawMessage     `json:"roadmap"`
	Docs         []InstalledEvidence `json:"docs"`
	Stages       []InstalledStage    `json:"stages"`
}

func RunInstalledQualification

func RunInstalledQualification(ctx context.Context, opts InstalledOptions) (report InstalledReport, err error)

RunInstalledQualification executes the installed browser/editor, automatic docs, and planning demonstrations only from a verified retained bundle and its retained Corvint source. It writes one result after every child and the owned scratch tree have been cleaned up.

type InstalledStage

type InstalledStage struct {
	Name         string `json:"name"`
	OutputSHA256 string `json:"outputSha256"`
}

type Options

type Options struct {
	CorvintRoot  string
	TaskmanRoot  string
	Target       string // must be exactly supportedTarget
	Scratch      string // scratch working directory; Run creates subdirs under it
	OutputParent string // directory the retained bundle is placed under; must not be inside CorvintRoot or TaskmanRoot
	BundleName   string // name of the retained bundle directory under OutputParent
	NPMCache     string // retained compatibility option; unused by core bundles
}

Options names the two clean checkout roots and the working directories this package needs. CorvintRoot and TaskmanRoot must already be verified clean checkouts of the two source modules (the caller is expected to have cloned them fresh; Run re-verifies cleanliness itself and never trusts the caller's claim).

type Report

type Report struct {
	Target          string
	Toolchain       Toolchain
	Manifest        BundleManifest
	BundlePath      string // retained directory holding the archive and its checksum
	ArchivePath     string // BundlePath/<BundleName>.tar.gz
	SmokeReportPath string
	ArchiveSHA256   string
	SHA256SUMS      string // the SHA256SUMS member inside the archive
	SmokeSteps      []SmokeStep
	NotRun          []string
}

Report is the human- and machine-readable record of one companion build. A zero-value Report (BundlePath == "") means nothing was retained: a build failure at any stage keeps no qualified output on disk.

func Run

func Run(ctx context.Context, opts Options) (*Report, error)

Run executes the full companion bundle pipeline: toolchain and target validation, clean-tree checks on both roots, source export, staging the verified export as the build tree, two independent builds per component, source archive assembly (built and compared twice), bundle archive assembly (built and compared twice), an independent tar.gz decode verification of each archive, an installed smoke test, and atomic retention of the bundle archive outside both checkout roots — in that order, so a smoke failure still leaves the qualified report unwritten and the bundle unretained.

type SmokeStep

type SmokeStep struct {
	Name            string `json:"name"`
	OK              bool   `json:"ok"`
	Detail          string `json:"detail"`
	BundleSHA256    string `json:"bundleSha256"`
	ComponentSHA256 string `json:"componentSha256,omitempty"`
	SourceCommit    string `json:"sourceCommit,omitempty"`
	SourceTree      string `json:"sourceTree,omitempty"`
	InvokedPath     string `json:"invokedPath,omitempty"`
}

SmokeStep is one recorded, pass/fail installed-artifact check.

type SourceFile

type SourceFile struct {
	Path string // repository-relative, forward-slash, no leading "./"
	Mode string // "100644" or "100755" only
	OID  string // the blob object id ls-tree reported
	Data []byte
}

SourceFile is one exported, hash-verified regular file from a single Git commit tree.

type Toolchain

type Toolchain struct {
	GoPath     string
	GoVersion  string
	GitPath    string
	GitVersion string
}

Toolchain records the exact, absolute Go and Git identities a companion build used, for the component manifest and the final report.

type VSIXToolchainManifest

type VSIXToolchainManifest struct {
	NodeVersion       string `json:"nodeVersion"`
	NodeSHA256        string `json:"nodeSha256"`
	NPMVersion        string `json:"npmVersion"`
	NPMSHA256         string `json:"npmSha256"`
	TypeScriptVersion string `json:"typeScriptVersion"`
	TypeScriptSHA256  string `json:"typeScriptSha256"`
	VSCEVersion       string `json:"vsceVersion"`
	VSCESHA256        string `json:"vsceSha256"`
	LockfileSHA256    string `json:"lockfileSha256"`
}

type VerifiedRetainedBundle

type VerifiedRetainedBundle struct {
	Directory      string
	ArchivePath    string
	ChecksumPath   string
	SmokePath      string
	ArchiveSHA256  string
	ChecksumSHA256 string
	SmokeSHA256    string
	Manifest       BundleManifest
	SmokeSteps     []SmokeStep
	// contains filtered or unexported fields
}

VerifiedRetainedBundle is an immutable, fully decoded retained companion bundle. Its archive members stay private so callers cannot alter the bytes between verification and extraction.

func VerifyRetainedBundle

func VerifyRetainedBundle(directory string) (*VerifiedRetainedBundle, error)

VerifyRetainedBundle admits the closed three-file retained bundle, verifies both sidecars and every manifest/checksum reference, and decodes the archive without writing any output.

func (*VerifiedRetainedBundle) CorvintSourceIdentity

func (v *VerifiedRetainedBundle) CorvintSourceIdentity() (commit, tree, archivePath string, err error)

CorvintSourceIdentity returns the single Corvint commit/tree/source archive identity shared by every Corvint-built component and artifact.

func (*VerifiedRetainedBundle) Entry

func (v *VerifiedRetainedBundle) Entry(path string) ([]byte, bool)

Entry returns a copy of one verified archive member.

func (*VerifiedRetainedBundle) Extract

func (v *VerifiedRetainedBundle) Extract(target string) (err error)

Extract writes verified bytes to a fresh target. Existing targets are refused, including empty directories, so qualification never merges trees.

func (*VerifiedRetainedBundle) ExtractSourceArchive

func (v *VerifiedRetainedBundle) ExtractSourceArchive(member, target string) error

ExtractSourceArchive materializes one verified source archive member into a fresh directory using the same closed decoder and bounds as the outer bundle.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL