criterionexperiment

package
v1.0.0-rc.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 29 Imported by: 0

Documentation

Overview

Package criterionexperiment implements the experimental, caller-reported criterion experiment companion. Its receipts are not execution attestations.

Index

Constants

View Source
const MaxDocument = 4 << 20
View Source
const Profile = "cem-criterion-experiments/0"

Variables

This section is empty.

Functions

func CanonicalDigest

func CanonicalDigest(v any) string

func Classify

func Classify(raw []byte, exit int, complete bool, test, assertion, expectedPackage string) string

Classify is deliberately conservative: only a complete named test run and one package terminal event can yield pass or expected-failure.

func Decode

func Decode(b []byte, out any) error

Decode uses the existing strict CEM JSON foundation, then exact field-name matching before Go decoding (encoding/json alone accepts case variants).

func Digest

func Digest(b []byte) string

func Encode

func Encode(v any) []byte

func Read

func Read(path string) ([]byte, error)

Types

type Authority

type Authority struct {
	Reviewer     string `json:"reviewer"`
	AnchorCommit string `json:"anchorCommit"`
	AnchorPath   string `json:"anchorPath"`
	AnchorSha256 string `json:"anchorSha256"`
	Independent  bool   `json:"independent"`
}

type Binding

type Binding struct {
	Ticket             string `json:"ticket"`
	AcceptanceRevision string `json:"acceptanceRevision"`
	AcceptanceSha256   string `json:"acceptanceSha256"`
	Attempt            string `json:"attempt"`
	Generation         string `json:"generation"`
	PolicySha256       string `json:"policySha256"`
	ConfigSha256       string `json:"configSha256"`
	CandidateTree      string `json:"candidateTree"`
}

type Captures

type Captures struct {
	Capture      tw.CriterionCapture
	Verification tw.CriterionVerification
}

type Criterion

type Criterion struct {
	Index            int       `json:"index"`
	AcceptanceSha256 string    `json:"acceptanceSha256"`
	Relation         string    `json:"relation"`
	Test             string    `json:"test"`
	Package          string    `json:"package"`
	Assertion        string    `json:"assertion"`
	Hunks            []string  `json:"hunks"`
	Oracle           Selector  `json:"oracle"`
	Authority        Authority `json:"authority"`
	Controls         []string  `json:"controls"`
}

type Plan

type Plan struct {
	Schema         string               `json:"schema"`
	Request        Request              `json:"request"`
	Binding        Binding              `json:"binding"`
	CEMSha256      string               `json:"cemSha256"`
	CapturesSha256 string               `json:"capturesSha256"`
	TasksVerifier  tw.CriterionIdentity `json:"tasksVerifier"`
}

func PlanExperiment

func PlanExperiment(ctx context.Context, repoPath string, r Request, out string, tasks TasksVerifierConfig) (Plan, error)

type Receipt

type Receipt struct {
	Schema          string     `json:"schema"`
	PlanSha256      string     `json:"planSha256"`
	Assurance       string     `json:"assurance"`
	OracleAssurance string     `json:"oracleAssurance"`
	Scenarios       []Scenario `json:"scenarios"`
}

func Run

func Run(ctx context.Context, repoPath, planPath, approval, out string, experimental, trusted bool, tasks TasksVerifierConfig) (Receipt, error)

type Request

type Request struct {
	Schema         string      `json:"schema"`
	Base           string      `json:"base"`
	Target         string      `json:"target"`
	CEM            string      `json:"cem"`
	Ticket         string      `json:"ticket"`
	Attempt        string      `json:"attempt"`
	Module         string      `json:"module"`
	GoBinary       string      `json:"goBinary"`
	GoSha256       string      `json:"goSha256"`
	TimeoutSeconds int         `json:"timeoutSeconds"`
	Criteria       []Criterion `json:"criteria"`
}

type Scenario

type Scenario struct {
	Criterion      int    `json:"criterion"`
	Role           string `json:"role"`
	Commit         string `json:"commit"`
	SnapshotSha256 string `json:"snapshotSha256"`
	StdoutSha256   string `json:"stdoutSha256"`
	StderrSha256   string `json:"stderrSha256"`
	ExitCode       int    `json:"exitCode"`
	Complete       bool   `json:"complete"`
	Classification string `json:"classification"`
}

type Selector

type Selector struct {
	Commit string `json:"commit"`
	Path   string `json:"path"`
}

type Summary

type Summary struct {
	Schema                 string   `json:"schema"`
	State                  string   `json:"state"`
	PlanSha256             string   `json:"planSha256"`
	ReceiptSha256          string   `json:"receiptSha256"`
	CEMSha256              string   `json:"cemSha256"`
	AcceptanceSha256       string   `json:"acceptanceSha256"`
	ArtifactManifestSha256 string   `json:"artifactManifestSha256"`
	Binding                Binding  `json:"binding"`
	Criteria               int      `json:"criteria"`
	RegisteredControls     int      `json:"registeredControls"`
	ApplicableControls     int      `json:"applicableControls"`
	ExecutedControls       int      `json:"executedControls"`
	KilledControls         int      `json:"killedControls"`
	Unknowns               []string `json:"unknowns"`
}

func Verify

func Verify(ctx context.Context, repoPath, planPath, receiptPath string, live bool, tasks TasksVerifierConfig) (Summary, error)

type TasksVerifierConfig

type TasksVerifierConfig struct{ Executable, SHA256 string }

TasksVerifierConfig comes from the operator, never from a saved plan.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL