Documentation
¶
Overview ¶
Package localcompletion coordinates a caller-owned local workflow. Its receipts are observations, never harness attestation or semantic authority.
Index ¶
- Constants
- func ConfigureAggregateCheck(options dogfoodflow.CheckOptions, allowPending bool) dogfoodflow.CheckOptions
- func FinishAggregateRecovery(ctx context.Context, root, key string, request []byte, command PublicCommand) (Evaluation, *TransportRecoveryProvenance, error)
- func HashSession(raw string) string
- func ReadPlan(name string) ([]byte, error)
- func ReadTransportRecoveryRequest(name string) ([]byte, error)
- func SessionKey(explicit string) (string, error)
- type Check
- type CheckObservation
- type Evaluation
- func Begin(ctx context.Context, root, key string, raw []byte) (Evaluation, error)
- func Cancel(ctx context.Context, root, key string) (Evaluation, error)
- func Evaluate(ctx context.Context, root, key string) (Evaluation, error)
- func Finish(ctx context.Context, root, key string, command PublicCommand) (Evaluation, error)
- func FinishWithAggregateProfile(ctx context.Context, root, key, profile string, command PublicCommand) (Evaluation, error)
- func Review(ctx context.Context, root, key, reportDigest string) (Evaluation, error)
- func Verify(ctx context.Context, root, key, checkID string) (Evaluation, error)
- type EvidenceWorklist
- type IntentPointer
- type Plan
- type PublicCommand
- type TransportRecoveryProvenance
- type TransportRecoveryRequest
- type TransportRecoveryVerifier
Constants ¶
const (
MaxPlanBytes = 64 << 10
)
const TransportAdaptedQualification = "TRANSPORT_ADAPTED_HISTORICAL"
TransportAdaptedQualification names the changed verifier identity claim. It never satisfies a pristine historical-binary requirement.
const TransportAdaptedRecoveryProfile = "corvint-transport-adapted-held-recovery/0"
TransportAdaptedRecoveryProfile is the closed request profile of the recovery-only aggregate finish that substitutes explicitly admitted, transport-adapted historical BASE and TREE verifiers (ALO-V0-023..026).
Variables ¶
This section is empty.
Functions ¶
func ConfigureAggregateCheck ¶
func ConfigureAggregateCheck(options dogfoodflow.CheckOptions, allowPending bool) dogfoodflow.CheckOptions
ConfigureAggregateCheck supplies native owner/state authority rather than accepting identities from the report. Public callers require COMMITTED; only explicit enrolled Finish enables its already-published pending report.
func FinishAggregateRecovery ¶
func FinishAggregateRecovery(ctx context.Context, root, key string, request []byte, command PublicCommand) (Evaluation, *TransportRecoveryProvenance, error)
FinishAggregateRecovery is the recovery-only aggregate finish. It is the ordinary aggregate finish transaction except that its strict check runs the request's admitted, independent BASE and TREE verifiers instead of the running binary. Finish and FinishWithAggregateProfile are unchanged.
func HashSession ¶
func ReadPlan ¶
ReadPlan reads one bounded regular caller-owned input. Errors contain no rejected plan body or filesystem path.
func ReadTransportRecoveryRequest ¶
ReadTransportRecoveryRequest reads one bounded regular request file.
func SessionKey ¶
Types ¶
type CheckObservation ¶
type CheckObservation struct {
ID string `json:"id"`
Qualified bool `json:"qualified"`
Argv []string `json:"argv"`
TestedCommit string `json:"testedCommit,omitempty"`
CurrentTarget string `json:"currentTarget"`
Exit int `json:"exit"`
TimedOut bool `json:"timedOut"`
Cancelled bool `json:"cancelled"`
SecretScreened bool `json:"secretScreened"`
Stdout string `json:"stdout,omitempty"`
Stderr string `json:"stderr,omitempty"`
}
type Evaluation ¶
type Evaluation struct {
Lifecycle string `json:"lifecycle"`
Owner string `json:"owner,omitempty"`
Satisfied bool `json:"satisfied"`
Unmet []string `json:"unmet"`
Base string `json:"base,omitempty"`
Target string `json:"target,omitempty"`
PlanDigest string `json:"planDigest,omitempty"`
Intents []string `json:"intents"`
IntentPointers []IntentPointer `json:"intentPointers"`
ReportSetDigest string `json:"reportSetDigest,omitempty"`
Reports []string `json:"reports,omitempty"`
NextActions [][]string `json:"nextActions,omitempty"`
Checks []CheckObservation `json:"checks,omitempty"`
Plan *Plan `json:"plan,omitempty"`
Evidence []EvidenceWorklist `json:"evidence,omitempty"`
}
func Finish ¶
func Finish(ctx context.Context, root, key string, command PublicCommand) (Evaluation, error)
func FinishWithAggregateProfile ¶
func FinishWithAggregateProfile(ctx context.Context, root, key, profile string, command PublicCommand) (Evaluation, error)
type EvidenceWorklist ¶
type IntentPointer ¶
type PublicCommand ¶
PublicCommand invokes the existing CEM/OCM entrypoints, without a shell or reinterpretation of their evidence semantics.
type TransportRecoveryProvenance ¶
type TransportRecoveryProvenance struct {
Qualification string `json:"qualification"`
RequestSHA256 string `json:"requestSha256"`
BaseSHA256 string `json:"baseVerifierSha256"`
TreeSHA256 string `json:"treeVerifierSha256"`
}
TransportRecoveryProvenance is returned with the recovery evaluation so the caller can retain the changed qualification beside the published report.
type TransportRecoveryRequest ¶
type TransportRecoveryRequest struct {
Base TransportRecoveryVerifier `json:"base"`
PlanDigest string `json:"planDigest"`
Profile string `json:"profile"`
Qualification string `json:"qualification"`
Session string `json:"session"`
Tree TransportRecoveryVerifier `json:"tree"`
}
TransportRecoveryRequest is the closed canonical request. It names no store, root or key other than the enrollment the caller already selected.
type TransportRecoveryVerifier ¶
type TransportRecoveryVerifier struct {
AdapterPatchSHA256 string `json:"adapterPatchSha256"`
HistoricalRevision string `json:"historicalRevision"`
HistoricalTree string `json:"historicalTree"`
Path string `json:"path"`
SHA256 string `json:"sha256"`
}
TransportRecoveryVerifier is one role's executable identity and the provenance it claims: an exact historical revision and tree plus the digest of the only adapter patch applied to that source.