Documentation
¶
Overview ¶
Package provider coordinates one explicitly requested, local Go test run.
This package is an experimental canonical transcript producer. Its receipts remain non-persistent, UNKNOWN-scope observations and never claim LPCV qualification.
Index ¶
- Constants
- Variables
- func VerifyReceipt(input ReceiptInput, receipt Receipt) error
- type AuthorityBinding
- type AuthorityRequest
- type CanonicalBinding
- type CanonicalBindingRequest
- type CanonicalEnvironmentVariable
- type Config
- type ConformanceContext
- type DecoderStatus
- type DiscoveryRequest
- type DiscoveryResult
- type Execution
- type ExecutionAuthority
- type ExecutionLease
- type ModuleMode
- type Receipt
- type ReceiptIdentityLease
- type ReceiptIdentityObservation
- type ReceiptInput
- type Transcript
Constants ¶
const ( QualificationExperimentalTranscript = "EXPERIMENTAL_TRANSCRIPT" ScopeUnknown = "UNKNOWN" CoverageNone = "NONE" PersistenceNone = "NONE" GoVersion = "go1.27.1" EnvironmentProfile = "GO127_CGO0_OFFLINE_POSIX_0" )
const ( EventProfile = "go-live-event/0" RunProfile = "go-live-run/0" )
Variables ¶
var ( ErrDisabled = errors.New("go-live provider: experimental provider is disabled") ErrExplicitAction = errors.New("go-live provider: trusted local explicit action is required") ErrInvalidConfig = errors.New("go-live provider: invalid configuration") ErrAuthorityDrift = errors.New("go-live provider: execution authority changed") ErrCleanupIncomplete = errors.New("go-live provider: ephemeral cleanup is incomplete") ErrUnsupportedPlatform = errors.New("go-live provider: unsupported platform") ErrDiscoveryLimit = errors.New("go-live provider: discovery output limit exceeded") )
var ErrReceiptInvalid = errors.New("go-live-receipt: invalid input")
Functions ¶
func VerifyReceipt ¶
func VerifyReceipt(input ReceiptInput, receipt Receipt) error
VerifyReceipt recomputes every identity and byte from the independently supplied post-run facts. It rejects gaps, duplicate terminals, extra bytes, stale attachment, and any non-canonical mutation.
Types ¶
type AuthorityBinding ¶
type AuthorityRequest ¶
type CanonicalBinding ¶
type CanonicalBindingRequest ¶
type CanonicalBindingRequest struct {
DiscoveryID string
EnvironmentSHA256 string
PackagePatterns []string
CWDPathSHA256 string
DependencyIdentity string
ModuleMode ModuleMode
SourceIdentity string
ToolchainIdentity string
Environment []CanonicalEnvironmentVariable
}
type Config ¶
type Config struct {
ExperimentalEnabled bool
ExplicitTrustedLocalAction bool
RepositoryRoot string
WorkingDirectory string
TemporaryParent string
GoExecutable string
GOROOT string
GOOS string
GOARCH string
ModuleMode ModuleMode
Packages []string
Timeout time.Duration
OutputLimitBytes int64
Authority ExecutionAuthority
}
Config contains no ambient defaults. Every filesystem and toolchain value that can affect the child is explicit and validated before authority is acquired. No provider run is possible without a complete authority lease.
type ConformanceContext ¶
type ConformanceContext struct {
ActualEnvironmentSHA256 string `json:"actualEnvironmentSha256"`
CapabilityID string `json:"capabilityId"`
CapabilityPreimageBase64 string `json:"capabilityPreimageBase64"`
DiscoveredPackagePaths []string `json:"discoveredPackagePaths"`
DiscoveryID string `json:"discoveryId"`
GOARCH string `json:"goarch"`
GOOS string `json:"goos"`
ListedPackages []string `json:"listedPackages"`
Nonce string `json:"nonce"`
PlanID string `json:"planId"`
PlanPreimageBase64 string `json:"planPreimageBase64"`
RequestedPackagePatterns []string `json:"requestedPackagePatterns"`
RequestedRunnerPackages []string `json:"requestedRunnerPackages"`
ToolchainID string `json:"toolchainId"`
VerifierExecutableSHA256 string `json:"verifierExecutableSha256"`
}
type DecoderStatus ¶
type DecoderStatus string
const ( DecoderComplete DecoderStatus = "COMPLETE" DecoderRejected DecoderStatus = "REJECTED" DecoderTruncated DecoderStatus = "TRUNCATED" )
type DiscoveryRequest ¶
type DiscoveryRequest struct {
GoExecutable string
WorkingDirectory string
Environment []gorunner.EnvironmentVariable
PackagePatterns []string
RunRoot string
}
DiscoveryRequest freezes the exact environment and writable run root shared by listing and execution. Discover must directly run the pinned Go executable with godiscovery.ClosedFields, no -e and no shell, then return a verified closed document. Non-zero exit, any stderr, decode error, or drift is an error.
type DiscoveryResult ¶
type DiscoveryResult struct {
ExitCode int
Commitments godiscovery.Commitments
}
type ExecutionAuthority ¶
type ExecutionAuthority interface {
Acquire(ctx context.Context, request AuthorityRequest) (ExecutionLease, error)
}
ExecutionAuthority is supplied by the parent source, discovery, toolchain, and dependency-verification layer. Acquire must fail unless it can bind all four identities. The lease keeps them stable until Release. In particular, ModuleCacheDirectory is a separately verified, complete, read-only offline dependency materialization; it is not created or deleted by this provider.
type ExecutionLease ¶
type ExecutionLease interface {
Binding() AuthorityBinding
Discover(ctx context.Context, request DiscoveryRequest, stdout, stderr io.Writer) (DiscoveryResult, error)
Revalidate(ctx context.Context) error
Release(ctx context.Context) error
}
ExecutionLease represents caller-verified, pinned execution inputs. Revalidate is the mandatory complete verifier boundary: it must revalidate every admitted source, workspace/vendor/local-replacement, dependency, and toolchain entry, honor ctx, and return only after its bounded verification subprocesses and I/O have quiesced. It runs immediately before launch and after descendant cleanup. Provider-local pathname checks are defense in depth and do not replace or claim this semantic completeness.
type ModuleMode ¶
type ModuleMode string
const ( ModuleReadonly ModuleMode = "MODULE_READONLY" ModuleWorkspace ModuleMode = "WORKSPACE" ModuleVendor ModuleMode = "VENDOR" )
type Receipt ¶
Receipt is a caller-owned, non-persistent canonical transcript. Event and Run members include their terminal LF; Transcript is their exact concatenation.
func ComposeReceipt ¶
func ComposeReceipt(input ReceiptInput) (Receipt, error)
ComposeReceipt binds normalized Go facts to the final WEI, emits consecutive evidence events, and closes them with exactly one terminal run document.
type ReceiptIdentityLease ¶
type ReceiptIdentityLease interface {
ObserveReceiptIdentities(ctx context.Context) (ReceiptIdentityObservation, error)
BindCanonical(ctx context.Context, request CanonicalBindingRequest) (CanonicalBinding, error)
}
ReceiptIdentityLease is the optional canonical-receipt extension. The observations are independently recomputable bare digests, not asserted IDs. A canonical request fails before launch when its authority lacks this seam.
type ReceiptInput ¶
type ReceiptInput struct {
ActualEnvironmentSHA256 string
CapabilityID string
PlanID string
Nonce string
Discovery godiscovery.Document
DiscoveryCanonical []byte
Events []gotest.Event
Observation gotest.Observation
Runner gorunner.Result
Decoder DecoderStatus
SourcePreSHA256 string
SourcePostSHA256 string
ToolchainPreSHA256 string
ToolchainPostSHA256 string
EphemeralDeletionComplete bool
ProviderFailure bool
}
ReceiptInput contains only facts available after execution, post-identity observation, and provider-owned state deletion. It contains no raw output or environment values. Empty post identities mean that axis is UNKNOWN.
type Transcript ¶
type Transcript struct {
Qualification string
Scope string
Coverage string
Persistence string
LPCVQualified bool
CanonicalTerminalSupported bool
Execution Execution
Authority AuthorityBinding
Discovery godiscovery.Document
DiscoveryCanonical []byte
ConformanceContext ConformanceContext
Runner gorunner.Result
Observation gotest.Observation
RunnerError error
DecodeError error
AuthorityError error
CleanupError error
EphemeralDeletionComplete bool
Receipt Receipt
}
func Execute ¶
func Execute(ctx context.Context, config Config) (transcript Transcript, returnErr error)
Execute runs a trusted repository's explicit package selection with a minimal child environment. Returned runner bytes, normalized observations, and canonical receipt are caller-owned transient values.