Documentation
¶
Overview ¶
Package behaviorfalsify runs explicitly approved, bounded falsification controls for one exact browser-behavior criterion.
Index ¶
- Constants
- func Decode(data []byte, value any) error
- func Encode(value any) ([]byte, error)
- func EncodeEvidence(r EvidenceReceipt) ([]byte, error)
- func VerifyReceipt(r EvidenceReceipt, expectedPlan, expectedTool string) error
- type Approval
- type Artifact
- type AttemptResult
- type Command
- type ControlKind
- type ControlResult
- type ControlSpec
- type CriterionObservation
- type EvidenceReceipt
- type HookReceipt
- type InfrastructureFailure
- type Invocation
- type MutationScore
- type Plan
- type PlannedControl
- type ProcessEvidence
- type RawAttempt
- type Report
- type RepositoryRoots
- type Request
- type RunnerIdentity
- type SetupObservation
- type Status
- type TargetIdentity
- type ToolIdentity
Constants ¶
View Source
const ( PlanSchema = "corvint-browser-behavior-falsification-plan/0" InvocationSchema = "corvint-browser-behavior-control-invocation/0" HookSchema = "corvint-browser-behavior-control-run/0" ReportSchema = "corvint-browser-behavior-falsification-report/0" MarkerName = ".corvint-disposable-browser-fixture" )
View Source
const ApprovalSchema = "corvint-browser-behavior-approval/1"
View Source
const ReceiptSchema = "corvint-browser-behavior-evidence/1"
Variables ¶
This section is empty.
Functions ¶
func EncodeEvidence ¶
func EncodeEvidence(r EvidenceReceipt) ([]byte, error)
func VerifyReceipt ¶
func VerifyReceipt(r EvidenceReceipt, expectedPlan, expectedTool string) error
VerifyReceipt checks retained bytes against caller-pinned identities without accessing a workspace or running hooks. It validates observations; it does not authenticate their author.
Types ¶
type AttemptResult ¶
type AttemptResult struct {
Attempt int `json:"attempt"`
Status Status `json:"status"`
Reasons []string `json:"reasons"`
Receipt *HookReceipt `json:"receipt,omitempty"`
HookProcess ProcessEvidence `json:"hook_process"`
CleanupProcess ProcessEvidence `json:"cleanup_process"`
WorkspaceBefore string `json:"workspace_before"`
WorkspaceAfter string `json:"workspace_after"`
RetainedArtifacts []Artifact `json:"retained_artifacts"`
}
type ControlKind ¶
type ControlKind string
const ( WrongLocator ControlKind = "wrong-locator" WrongExpectedValue ControlKind = "wrong-expected-value" OmittedAssertion ControlKind = "omitted-assertion" OmittedEvent ControlKind = "omitted-event" ReorderedEvent ControlKind = "reordered-event" WrongProject ControlKind = "wrong-project" SuppressedPersistence ControlKind = "suppressed-persistence" OppositeBranch ControlKind = "opposite-branch" ChangedFixtureValue ControlKind = "changed-fixture-value" )
type ControlResult ¶
type ControlResult struct {
ID string `json:"id"`
Kind ControlKind `json:"kind"`
Ordinal int `json:"ordinal"`
Status Status `json:"status"`
Reasons []string `json:"reasons"`
Attempts []AttemptResult `json:"attempts"`
}
type ControlSpec ¶
type CriterionObservation ¶
type EvidenceReceipt ¶
type EvidenceReceipt struct {
Schema string `json:"schema"`
PlanPreimage []byte `json:"plan_preimage"`
Approval Approval `json:"approval"`
Tool ToolIdentity `json:"tool"`
RawAttempts []RawAttempt `json:"raw_attempts"`
Report Report `json:"report"`
Unsupported []string `json:"unsupported"`
Digest string `json:"digest"`
}
func ExecuteReceipt ¶
func ExecuteReceipt(ctx context.Context, plan Plan, approved string, tool ToolIdentity) (EvidenceReceipt, error)
ExecuteReceipt runs the same approved executor and retains an offline-verifiable observation. A native report must be declared as a hook artifact before cleanup removes it.
type HookReceipt ¶
type HookReceipt struct {
Schema string `json:"schema"`
PlanDigest string `json:"plan_digest"`
PerturbationSHA256 string `json:"perturbation_sha256"`
Target TargetIdentity `json:"target"`
Runner RunnerIdentity `json:"runner"`
Attempt int `json:"attempt"`
Retry int `json:"retry"`
NativeReceiptSHA256 string `json:"native_receipt_sha256"`
TestOutcome string `json:"test_outcome"`
TargetObservation CriterionObservation `json:"target_observation"`
Setup []SetupObservation `json:"setup"`
Infrastructure *InfrastructureFailure `json:"infrastructure,omitempty"`
Artifacts []Artifact `json:"artifacts"`
}
type InfrastructureFailure ¶
type Invocation ¶
type Invocation struct {
Schema string `json:"schema"`
PlanDigest string `json:"plan_digest"`
Attempt int `json:"attempt"`
Target TargetIdentity `json:"target"`
Runner RunnerIdentity `json:"runner"`
Control PlannedControl `json:"control"`
}
type MutationScore ¶
type Plan ¶
type Plan struct {
Schema string `json:"schema"`
Request Request `json:"request"`
Controls []PlannedControl `json:"planned_controls"`
WorkspaceSHA256 string `json:"workspace_sha256"`
Digest string `json:"digest"`
}
type PlannedControl ¶
type PlannedControl struct {
ControlSpec
Ordinal int `json:"ordinal"`
PerturbationSHA256 string `json:"perturbation_sha256"`
}
type ProcessEvidence ¶
type ProcessEvidence struct {
Exit int `json:"exit"`
Started bool `json:"started"`
Completed bool `json:"completed"`
Cancelled bool `json:"cancelled"`
TimedOut bool `json:"timed_out"`
Overflow bool `json:"overflow"`
OwnedCleanup bool `json:"owned_cleanup"`
DescendantsGone bool `json:"descendants_gone"`
StdoutSHA256 string `json:"stdout_sha256"`
StderrSHA256 string `json:"stderr_sha256"`
Error string `json:"error,omitempty"`
}
type RawAttempt ¶
type RawAttempt struct {
ControlID string `json:"control_id"`
Ordinal int `json:"ordinal"`
Attempt int `json:"attempt"`
HookBytes []byte `json:"hook_bytes"`
HookSHA256 string `json:"hook_sha256"`
NativeBytes []byte `json:"native_bytes"`
NativeSHA256 string `json:"native_sha256"`
Omissions []string `json:"omissions"`
}
RawAttempt retains exact bytes, encoded as base64 in JSON; no reserialization is hashed.
type Report ¶
type Report struct {
Schema string `json:"schema"`
PlanDigest string `json:"plan_digest"`
Results []ControlResult `json:"results"`
Counts map[Status]int `json:"counts"`
Requested int `json:"requested"`
Supported int `json:"supported"`
Executed int `json:"executed"`
CompleteVocabulary bool `json:"complete_vocabulary"`
MutationScore MutationScore `json:"mutation_score"`
CoverageGaps []string `json:"coverage_gaps"`
Fallback string `json:"fallback"`
Limitations []string `json:"limitations"`
Digest string `json:"digest"`
}
type RepositoryRoots ¶
type Request ¶
type Request struct {
Target TargetIdentity `json:"target"`
Runner RunnerIdentity `json:"runner"`
Controls []ControlSpec `json:"controls"`
Cleanup Command `json:"cleanup"`
DisposableRoot string `json:"disposable_root"`
Repositories RepositoryRoots `json:"repositories"`
MarkerSHA256 string `json:"marker_sha256"`
DeclaredEnvKeys []string `json:"declared_env_keys"`
Attempts int `json:"attempts"`
TimeoutSeconds int `json:"timeout_seconds"`
WallClockSeconds int `json:"wall_clock_seconds"`
ExternalState string `json:"external_state"`
}
type RunnerIdentity ¶
type RunnerIdentity struct {
Runner string `json:"runner"`
RunnerVersion string `json:"runner_version"`
Browser string `json:"browser"`
BrowserVersion string `json:"browser_version"`
ConfigFile string `json:"config_file"`
ConfigSHA256 string `json:"config_sha256"`
EnvironmentSHA256 string `json:"environment_sha256"`
}
type SetupObservation ¶
type TargetIdentity ¶
type TargetIdentity struct {
ContractID string `json:"contract_id"`
ContractSHA256 string `json:"contract_sha256"`
CriterionID string `json:"criterion_id"`
AssertionID string `json:"assertion_id"`
ApplicationRevision string `json:"application_revision"`
TestRevision string `json:"test_revision"`
DocumentationRevision string `json:"documentation_revision"`
ContractFile string `json:"contract_file"`
TestID string `json:"test_id"`
TestFile string `json:"test_file"`
TestLine int `json:"test_line"`
TestTitle string `json:"test_title"`
Project string `json:"project"`
}
type ToolIdentity ¶
type ToolIdentity struct {
Name string `json:"name"`
Version string `json:"version"`
Revision string `json:"revision"`
Executable string `json:"executable_sha256"`
SourceDirty bool `json:"source_dirty"`
}
ToolIdentity identifies the executable that observed execution, not an authenticated signer.
Click to show internal directories.
Click to hide internal directories.