provider

package
v0.8.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 24 Imported by: 0

Documentation

Overview

Package provider coordinates one explicitly requested, local Go test run.

This package is an experimental canonical transcript producer. Its receipts remain non-persistent, UNKNOWN-scope observations and never claim LPCV qualification.

Index

Constants

View Source
const (
	QualificationExperimentalTranscript = "EXPERIMENTAL_TRANSCRIPT"
	ScopeUnknown                        = "UNKNOWN"
	CoverageNone                        = "NONE"
	PersistenceNone                     = "NONE"
	GoVersion                           = "go1.27.1"
	EnvironmentProfile                  = "GO127_CGO0_OFFLINE_POSIX_0"
)
View Source
const (
	EventProfile = "go-live-event/0"
	RunProfile   = "go-live-run/0"
)

Variables

View Source
var (
	ErrDisabled             = errors.New("go-live provider: experimental provider is disabled")
	ErrExplicitAction       = errors.New("go-live provider: trusted local explicit action is required")
	ErrInvalidConfig        = errors.New("go-live provider: invalid configuration")
	ErrAuthorityUnavailable = errors.New("go-live provider: execution authority is unavailable")
	ErrAuthorityDrift       = errors.New("go-live provider: execution authority changed")
	ErrCleanupIncomplete    = errors.New("go-live provider: ephemeral cleanup is incomplete")
	ErrUnsupportedPlatform  = errors.New("go-live provider: unsupported platform")
	ErrDiscoveryLimit       = errors.New("go-live provider: discovery output limit exceeded")
)
View Source
var ErrReceiptInvalid = errors.New("go-live-receipt: invalid input")

Functions

func VerifyReceipt

func VerifyReceipt(input ReceiptInput, receipt Receipt) error

VerifyReceipt recomputes every identity and byte from the independently supplied post-run facts. It rejects gaps, duplicate terminals, extra bytes, stale attachment, and any non-canonical mutation.

Types

type AuthorityBinding

type AuthorityBinding struct {
	SourceIdentity       string
	ToolchainIdentity    string
	DependencyIdentity   string
	ModuleCacheDirectory string
	GoVersion            string
	GOOS                 string
	GOARCH               string
	CGOEnabled           string
	EnvironmentProfile   string
	GoWorkPath           string
}

type AuthorityRequest

type AuthorityRequest struct {
	RepositoryRoot     string
	WorkingDirectory   string
	GoExecutable       string
	GOROOT             string
	ExpectedGoVersion  string
	GOOS               string
	GOARCH             string
	CGOEnabled         string
	EnvironmentProfile string
	ModuleMode         ModuleMode
	Packages           []string
}

type CanonicalBinding

type CanonicalBinding struct {
	CapabilityID             string
	CapabilityPreimage       []byte
	PlanID                   string
	PlanPreimage             []byte
	VerifierExecutableSHA256 string
}

type CanonicalBindingRequest

type CanonicalBindingRequest struct {
	DiscoveryID        string
	EnvironmentSHA256  string
	PackagePatterns    []string
	CWDPathSHA256      string
	DependencyIdentity string
	ModuleMode         ModuleMode
	SourceIdentity     string
	ToolchainIdentity  string
	Environment        []CanonicalEnvironmentVariable
}

type CanonicalEnvironmentVariable

type CanonicalEnvironmentVariable struct {
	Name        string
	ValueSHA256 string
}

type Config

type Config struct {
	ExperimentalEnabled        bool
	ExplicitTrustedLocalAction bool
	RepositoryRoot             string
	WorkingDirectory           string
	TemporaryParent            string
	GoExecutable               string
	GOROOT                     string
	GOOS                       string
	GOARCH                     string
	ModuleMode                 ModuleMode
	Packages                   []string
	Timeout                    time.Duration
	OutputLimitBytes           int64
	Authority                  ExecutionAuthority
}

Config contains no ambient defaults. Every filesystem and toolchain value that can affect the child is explicit and validated before authority is acquired. No provider run is possible without a complete authority lease.

type ConformanceContext

type ConformanceContext struct {
	ActualEnvironmentSHA256  string   `json:"actualEnvironmentSha256"`
	CapabilityID             string   `json:"capabilityId"`
	CapabilityPreimageBase64 string   `json:"capabilityPreimageBase64"`
	DiscoveredPackagePaths   []string `json:"discoveredPackagePaths"`
	DiscoveryID              string   `json:"discoveryId"`
	GOARCH                   string   `json:"goarch"`
	GOOS                     string   `json:"goos"`
	ListedPackages           []string `json:"listedPackages"`
	Nonce                    string   `json:"nonce"`
	PlanID                   string   `json:"planId"`
	PlanPreimageBase64       string   `json:"planPreimageBase64"`
	RequestedPackagePatterns []string `json:"requestedPackagePatterns"`
	RequestedRunnerPackages  []string `json:"requestedRunnerPackages"`
	ToolchainID              string   `json:"toolchainId"`
	VerifierExecutableSHA256 string   `json:"verifierExecutableSha256"`
}

type DecoderStatus

type DecoderStatus string
const (
	DecoderComplete  DecoderStatus = "COMPLETE"
	DecoderRejected  DecoderStatus = "REJECTED"
	DecoderTruncated DecoderStatus = "TRUNCATED"
)

type DiscoveryRequest

type DiscoveryRequest struct {
	GoExecutable     string
	WorkingDirectory string
	Environment      []gorunner.EnvironmentVariable
	PackagePatterns  []string
	RunRoot          string
}

DiscoveryRequest freezes the exact environment and writable run root shared by listing and execution. Discover must directly run the pinned Go executable with godiscovery.ClosedFields, no -e and no shell, then return a verified closed document. Non-zero exit, any stderr, decode error, or drift is an error.

type DiscoveryResult

type DiscoveryResult struct {
	ExitCode    int
	Commitments godiscovery.Commitments
}

type Execution

type Execution string
const (
	ExecutionPassed     Execution = "PASSED"
	ExecutionFailed     Execution = "FAILED"
	ExecutionIncomplete Execution = "INCOMPLETE"
)

type ExecutionAuthority

type ExecutionAuthority interface {
	Acquire(ctx context.Context, request AuthorityRequest) (ExecutionLease, error)
}

ExecutionAuthority is supplied by the parent source, discovery, toolchain, and dependency-verification layer. Acquire must fail unless it can bind all four identities. The lease keeps them stable until Release. In particular, ModuleCacheDirectory is a separately verified, complete, read-only offline dependency materialization; it is not created or deleted by this provider.

type ExecutionLease

type ExecutionLease interface {
	Binding() AuthorityBinding
	Discover(ctx context.Context, request DiscoveryRequest, stdout, stderr io.Writer) (DiscoveryResult, error)
	Revalidate(ctx context.Context) error
	Release(ctx context.Context) error
}

ExecutionLease represents caller-verified, pinned execution inputs. Revalidate is the mandatory complete verifier boundary: it must revalidate every admitted source, workspace/vendor/local-replacement, dependency, and toolchain entry, honor ctx, and return only after its bounded verification subprocesses and I/O have quiesced. It runs immediately before launch and after descendant cleanup. Provider-local pathname checks are defense in depth and do not replace or claim this semantic completeness.

type ModuleMode

type ModuleMode string
const (
	ModuleReadonly  ModuleMode = "MODULE_READONLY"
	ModuleWorkspace ModuleMode = "WORKSPACE"
	ModuleVendor    ModuleMode = "VENDOR"
)

type Receipt

type Receipt struct {
	RunID      string
	WEI        string
	Events     [][]byte
	Run        []byte
	Transcript []byte
}

Receipt is a caller-owned, non-persistent canonical transcript. Event and Run members include their terminal LF; Transcript is their exact concatenation.

func ComposeReceipt

func ComposeReceipt(input ReceiptInput) (Receipt, error)

ComposeReceipt binds normalized Go facts to the final WEI, emits consecutive evidence events, and closes them with exactly one terminal run document.

type ReceiptIdentityLease

type ReceiptIdentityLease interface {
	ObserveReceiptIdentities(ctx context.Context) (ReceiptIdentityObservation, error)
	BindCanonical(ctx context.Context, request CanonicalBindingRequest) (CanonicalBinding, error)
}

ReceiptIdentityLease is the optional canonical-receipt extension. The observations are independently recomputable bare digests, not asserted IDs. A canonical request fails before launch when its authority lacks this seam.

type ReceiptIdentityObservation

type ReceiptIdentityObservation struct {
	SourceSHA256    string
	ToolchainSHA256 string
}

type ReceiptInput

type ReceiptInput struct {
	ActualEnvironmentSHA256   string
	CapabilityID              string
	PlanID                    string
	Nonce                     string
	Discovery                 godiscovery.Document
	DiscoveryCanonical        []byte
	Events                    []gotest.Event
	Observation               gotest.Observation
	Runner                    gorunner.Result
	Decoder                   DecoderStatus
	SourcePreSHA256           string
	SourcePostSHA256          string
	ToolchainPreSHA256        string
	ToolchainPostSHA256       string
	EphemeralDeletionComplete bool
	ProviderFailure           bool
}

ReceiptInput contains only facts available after execution, post-identity observation, and provider-owned state deletion. It contains no raw output or environment values. Empty post identities mean that axis is UNKNOWN.

type Transcript

type Transcript struct {
	Qualification              string
	Scope                      string
	Coverage                   string
	Persistence                string
	LPCVQualified              bool
	CanonicalTerminalSupported bool
	Execution                  Execution
	Authority                  AuthorityBinding
	Discovery                  godiscovery.Document
	DiscoveryCanonical         []byte
	ConformanceContext         ConformanceContext
	Runner                     gorunner.Result
	Observation                gotest.Observation
	RunnerError                error
	DecodeError                error
	AuthorityError             error
	CleanupError               error
	EphemeralDeletionComplete  bool
	Receipt                    Receipt
}

func Execute

func Execute(ctx context.Context, config Config) (transcript Transcript, returnErr error)

Execute runs a trusted repository's explicit package selection with a minimal child environment. Returned runner bytes, normalized observations, and canonical receipt are caller-owned transient values.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL