cemcandidate

package
v1.0.0-rc.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 18 Imported by: 0

Documentation

Overview

Package cemcandidate joins explicit reference evidence without promoting native Tasks authority, historical execution or criterion adequacy.

Index

Constants

View Source
const MaxDocument = 4 << 20
View Source
const Profile = "cem-candidate-assembly/0"
View Source
const StableAssemblyProfile = "cem-stable-assembly/1"

Variables

This section is empty.

Functions

func Decode

func Decode(raw []byte, out any) error

Decode requires all non-optional fields and exact scalar kinds before Go's decoder can coerce null into a zero-valued string or integer. Native nullable slices/maps and optional pointers remain nullable, preserving their ABI.

func Read

func Read(name string) ([]byte, error)

Read uses the existing bounded no-follow CEM reader. Parent components are checked against a publication root; the selected filename cannot be Git metadata.

Types

type FileRef

type FileRef struct {
	Path   string `json:"path"`
	Sha256 string `json:"sha256"`
}
type Link struct {
	CriterionIndex int      `json:"criterionIndex"`
	HunkIDs        []string `json:"hunkIds"`
	EvidenceIDs    []string `json:"evidenceIds"`
}

type Request

type Request struct {
	Profile       string  `json:"profile"`
	Repository    string  `json:"repository"`
	ExpectedBase  string  `json:"expectedBase"`
	Target        string  `json:"target"`
	TicketID      string  `json:"ticketId"`
	AttemptID     string  `json:"attemptId"`
	SourcePrefix  string  `json:"sourcePrefix"`
	SourceMap     FileRef `json:"sourceMap"`
	Capture       FileRef `json:"capture"`
	Verification  FileRef `json:"verification"`
	RunnerPlan    FileRef `json:"runnerPlan"`
	RunnerReceipt FileRef `json:"runnerReceipt"`
	Links         []Link  `json:"links"`
}

type Result

type Result struct {
	Profile                           string                 `json:"profile"`
	CandidatePath                     string                 `json:"candidatePath"`
	CandidateSha256                   string                 `json:"candidateSha256"`
	Verification                      verify.CandidateResult `json:"verification"`
	DeclaredInputGitBinding           string                 `json:"declaredInputGitBinding"`
	TargetRevision                    string                 `json:"targetRevision"`
	InputInventorySha256              string                 `json:"inputInventorySha256"`
	NativeCaptureSemanticVerification string                 `json:"nativeCaptureSemanticVerification"`
	ExecutionAtCommit                 string                 `json:"executionAtCommit"`
}

func Assemble

func Assemble(ctx context.Context, r Request, out string) (Result, error)

Assemble writes a new candidate bundle only. Runtime records are decoded for reference coherence, never accepted as native authority or execution attestation.

type StableAssemblyResult

type StableAssemblyResult struct {
	Profile                           string              `json:"profile"`
	StablePath                        string              `json:"stablePath"`
	StableSha256                      string              `json:"stableSha256"`
	Verification                      verify.StableResult `json:"verification"`
	TargetRevision                    string              `json:"targetRevision"`
	DeclaredInputGitBinding           string              `json:"declaredInputGitBinding"`
	InputInventorySha256              string              `json:"inputInventorySha256"`
	NativeCaptureSemanticVerification string              `json:"nativeCaptureSemanticVerification"`
	ReceiptAuthority                  string              `json:"receiptAuthority"`
	SourceInventoryCompleteness       string              `json:"sourceInventoryCompleteness"`
	ExecutionAtCommit                 string              `json:"executionAtCommit"`
}

func AssembleStable

func AssembleStable(ctx context.Context, r StableRequest, out string) (StableAssemblyResult, error)

AssembleStable constructs a new typed stable document from a canonically verified source. Native semantic reads belong to the independently pinned operator harness; decoding retained artifacts here establishes coherence only.

type StableRequest

type StableRequest struct {
	Profile              string  `json:"profile"`
	Repository           string  `json:"repository"`
	ExpectedBase         string  `json:"expectedBase"`
	Target               string  `json:"target"`
	TicketID             string  `json:"ticketId"`
	AttemptID            string  `json:"attemptId"`
	SourcePrefix         string  `json:"sourcePrefix"`
	SourceMap            FileRef `json:"sourceMap"`
	Capture              FileRef `json:"capture"`
	Verification         FileRef `json:"verification"`
	SnapshotHeadArtifact FileRef `json:"snapshotHeadArtifact"`
	RunnerPlan           FileRef `json:"runnerPlan"`
	RunnerReceipt        FileRef `json:"runnerReceipt"`
	Links                []Link  `json:"links"`
}

StableRequest is distinct from the experimental candidate request. The snapshot artifact is an independently pinned file; its bytes are not a native identity.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL