localcompletion

package
v1.0.0-rc.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 31 Imported by: 0

Documentation

Overview

Package localcompletion coordinates a caller-owned local workflow. Its receipts are observations, never harness attestation or semantic authority.

Index

Constants

View Source
const (
	MaxPlanBytes = 64 << 10
)
View Source
const TransportAdaptedQualification = "TRANSPORT_ADAPTED_HISTORICAL"

TransportAdaptedQualification names the changed verifier identity claim. It never satisfies a pristine historical-binary requirement.

View Source
const TransportAdaptedRecoveryProfile = "corvint-transport-adapted-held-recovery/0"

TransportAdaptedRecoveryProfile is the closed request profile of the recovery-only aggregate finish that substitutes explicitly admitted, transport-adapted historical BASE and TREE verifiers (ALO-V0-023..026).

Variables

This section is empty.

Functions

func ConfigureAggregateCheck

func ConfigureAggregateCheck(options dogfoodflow.CheckOptions, allowPending bool) dogfoodflow.CheckOptions

ConfigureAggregateCheck supplies native owner/state authority rather than accepting identities from the report. Public callers require COMMITTED; only explicit enrolled Finish enables its already-published pending report.

func FinishAggregateRecovery

func FinishAggregateRecovery(ctx context.Context, root, key string, request []byte, command PublicCommand) (Evaluation, *TransportRecoveryProvenance, error)

FinishAggregateRecovery is the recovery-only aggregate finish. It is the ordinary aggregate finish transaction except that its strict check runs the request's admitted, independent BASE and TREE verifiers instead of the running binary. Finish and FinishWithAggregateProfile are unchanged.

func HashSession

func HashSession(raw string) string

func ReadPlan

func ReadPlan(name string) ([]byte, error)

ReadPlan reads one bounded regular caller-owned input. Errors contain no rejected plan body or filesystem path.

func ReadTransportRecoveryRequest

func ReadTransportRecoveryRequest(name string) ([]byte, error)

ReadTransportRecoveryRequest reads one bounded regular request file.

func SessionKey

func SessionKey(explicit string) (string, error)

Types

type Check

type Check struct {
	ID                       string   `json:"id"`
	Argv                     []string `json:"argv"`
	TimeoutSeconds           int      `json:"timeoutSeconds"`
	AllowCemSidecarOnlyReuse bool     `json:"allowCemSidecarOnlyReuse"`
}

type CheckObservation

type CheckObservation struct {
	ID             string   `json:"id"`
	Qualified      bool     `json:"qualified"`
	Argv           []string `json:"argv"`
	TestedCommit   string   `json:"testedCommit,omitempty"`
	CurrentTarget  string   `json:"currentTarget"`
	Exit           int      `json:"exit"`
	TimedOut       bool     `json:"timedOut"`
	Cancelled      bool     `json:"cancelled"`
	SecretScreened bool     `json:"secretScreened"`
	Stdout         string   `json:"stdout,omitempty"`
	Stderr         string   `json:"stderr,omitempty"`
}

type Evaluation

type Evaluation struct {
	Lifecycle       string             `json:"lifecycle"`
	Owner           string             `json:"owner,omitempty"`
	Satisfied       bool               `json:"satisfied"`
	Unmet           []string           `json:"unmet"`
	Base            string             `json:"base,omitempty"`
	Target          string             `json:"target,omitempty"`
	PlanDigest      string             `json:"planDigest,omitempty"`
	Intents         []string           `json:"intents"`
	IntentPointers  []IntentPointer    `json:"intentPointers"`
	ReportSetDigest string             `json:"reportSetDigest,omitempty"`
	Reports         []string           `json:"reports,omitempty"`
	NextActions     [][]string         `json:"nextActions,omitempty"`
	Checks          []CheckObservation `json:"checks,omitempty"`
	Plan            *Plan              `json:"plan,omitempty"`
	Evidence        []EvidenceWorklist `json:"evidence,omitempty"`
}

func Begin

func Begin(ctx context.Context, root, key string, raw []byte) (Evaluation, error)

func Cancel

func Cancel(ctx context.Context, root, key string) (Evaluation, error)

func Evaluate

func Evaluate(ctx context.Context, root, key string) (Evaluation, error)

func Finish

func Finish(ctx context.Context, root, key string, command PublicCommand) (Evaluation, error)

func FinishWithAggregateProfile

func FinishWithAggregateProfile(ctx context.Context, root, key, profile string, command PublicCommand) (Evaluation, error)

func Review

func Review(ctx context.Context, root, key, reportDigest string) (Evaluation, error)

func Verify

func Verify(ctx context.Context, root, key, checkID string) (Evaluation, error)

type EvidenceWorklist

type EvidenceWorklist struct {
	Tool     string `json:"tool"`
	Map      string `json:"map"`
	Code     string `json:"code,omitempty"`
	Worklist []any  `json:"worklist"`
	Omitted  int    `json:"omitted"`
}

type IntentPointer

type IntentPointer struct {
	Path     string `json:"path"`
	Revision string `json:"revision"`
	BlobHash string `json:"blob_hash"`
}

type Plan

type Plan struct {
	Base    string   `json:"base"`
	Intents []string `json:"intents"`
	Checks  []Check  `json:"checks"`
}

type PublicCommand

type PublicCommand func(context.Context, string, []string, io.Writer, io.Writer) int

PublicCommand invokes the existing CEM/OCM entrypoints, without a shell or reinterpretation of their evidence semantics.

type TransportRecoveryProvenance

type TransportRecoveryProvenance struct {
	Qualification string `json:"qualification"`
	RequestSHA256 string `json:"requestSha256"`
	BaseSHA256    string `json:"baseVerifierSha256"`
	TreeSHA256    string `json:"treeVerifierSha256"`
}

TransportRecoveryProvenance is returned with the recovery evaluation so the caller can retain the changed qualification beside the published report.

type TransportRecoveryRequest

type TransportRecoveryRequest struct {
	Base          TransportRecoveryVerifier `json:"base"`
	PlanDigest    string                    `json:"planDigest"`
	Profile       string                    `json:"profile"`
	Qualification string                    `json:"qualification"`
	Session       string                    `json:"session"`
	Tree          TransportRecoveryVerifier `json:"tree"`
}

TransportRecoveryRequest is the closed canonical request. It names no store, root or key other than the enrollment the caller already selected.

type TransportRecoveryVerifier

type TransportRecoveryVerifier struct {
	AdapterPatchSHA256 string `json:"adapterPatchSha256"`
	HistoricalRevision string `json:"historicalRevision"`
	HistoricalTree     string `json:"historicalTree"`
	Path               string `json:"path"`
	SHA256             string `json:"sha256"`
}

TransportRecoveryVerifier is one role's executable identity and the provenance it claims: an exact historical revision and tree plus the digest of the only adapter patch applied to that source.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL