Documentation
¶
Overview ¶
Package intake admits closed-vocabulary reader claims before an author sees them. It does not interpret raw prose or grant authority to a reader claim.
Index ¶
Constants ¶
View Source
const ( Profile = "corvint-intake/0" MaxBytes = 1 << 20 MaxItems = 1024 )
Variables ¶
View Source
var ( ErrSchema = errors.New("INTAKE_SCHEMA") ErrRepository = errors.New("INTAKE_REPOSITORY") ErrPath = errors.New("INTAKE_PATH") ErrBoundary = errors.New("INTAKE_READER_BOUNDARY") )
Errors crossing the author boundary carry fixed codes, never rejected values.
Functions ¶
func BuildAuthorInput ¶
func BuildAuthorInput(ctx context.Context, root, base, head string, candidate []byte) ([]byte, error)
BuildAuthorInput is the sole production author-input builder. Repository identity is supplied by the trusted host, not taken from the reader's claimed pins.
func PreflightReader ¶
func PreflightReader(ctx context.Context, b ReaderBoundary) error
Types ¶
type ReaderBoundary ¶
type ReaderBoundary struct {
AuthorRoot string `json:"author_root"`
RawInput string `json:"raw_input"`
IntakeOutput string `json:"intake_output"`
}
ReaderBoundary is a preflight observation only. The host must enforce read-only raw/repository mounts, no network/credentials, and one exclusively writable output. The candidate is still untrusted until BuildAuthorInput validates it.
type Record ¶
type Record struct {
Profile string `json:"profile"`
Base string `json:"base"`
Head string `json:"head"`
Intent string `json:"intent"`
Behaviours []Behaviour `json:"claimed_behaviours"`
Flags []string `json:"flags"`
Migrations int64 `json:"migrations_claimed"`
Tests []string `json:"tests_claimed"`
Comparison string `json:"description_vs_diff"`
Concerns []string `json:"concerns"`
WorkItems []WorkItem `json:"work_items"`
}
Click to show internal directories.
Click to hide internal directories.