Documentation
¶
Overview ¶
SPDX-License-Identifier: AGPL-3.0-or-later Derived from internal/tasks/safeopen/at_linux.go at 29a6db884ed795f7694c316433896d190e1ab508; kept private for decision 0397.
SPDX-License-Identifier: AGPL-3.0-or-later Derived from internal/tasks/safeopen/open_unix.go at 29a6db884ed795f7694c316433896d190e1ab508; kept private for decision 0397. Native replay owns this narrow no-follow boundary (decision 0397). Every directory component is opened atomically with O_DIRECTORY|O_NOFOLLOW.
Package postmergeworkflow implements an experimental credential-free replay harness. Adapter observations are evidence to compare, not workflow authority.
Index ¶
- Constants
- func Decode(b []byte, v any) error
- func FixtureProfile(name string) string
- func SHA256(b []byte) string
- type Approval
- type ArtifactRef
- type Expected
- type Fixture
- type Implementation
- type Label
- type Mismatch
- type NativeManifest
- type NativePolicy
- type NativeReport
- type NativeStage
- type Policy
- type Registry
- type Report
- type Request
- type Result
- type Stage
Constants ¶
const MaxBytes = 4 << 20
const NativeManifestProfile = "postmerge-runtime-manifest/1"
const NativeProfile = "postmerge-replay/1"
NativeProfile is the experimental intake/refusal route, not whole-workflow qualification.
const Profile = "postmerge-replay/0"
Variables ¶
This section is empty.
Functions ¶
func Decode ¶
Decode rejects duplicate keys as well as unknown fields. Duplicate keys are otherwise silently overwritten by encoding/json, including policy bindings.
func FixtureProfile ¶
FixtureProfile is only a bounded dispatch hint. Each route still performs its full strict decode; malformed hints fall through to the unchanged /0 refusal.
Types ¶
type ArtifactRef ¶
type ArtifactRef struct {
Path string `json:"path"`
SHA256 string `json:"sha256"`
Bytes int64 `json:"bytes"`
}
ArtifactRef describes exact private bytes; it does not attest native execution.
type Implementation ¶
type NativeManifest ¶
type NativeManifest struct {
Profile string `json:"profile"`
Mode string `json:"mode"`
Implementation Implementation `json:"implementation"`
Product struct {
Base string `json:"base"`
Merge string `json:"merge"`
Tree string `json:"tree"`
} `json:"product"`
FixtureSHA256 string `json:"fixture_sha256"`
ReaderCandidate struct {
Path string `json:"path"`
SHA256 string `json:"sha256"`
} `json:"reader_candidate"`
RetainedOutputRoot string `json:"retained_output_root"`
}
type NativePolicy ¶
type NativeReport ¶
type NativeReport struct {
Profile string `json:"profile"`
Binding connector.Binding `json:"binding"`
FixtureSHA256 string `json:"fixture_sha256"`
PolicySHA256 string `json:"policy_sha256"`
ManifestSHA256 string `json:"manifest_sha256"`
Implementation Implementation `json:"implementation"`
Status string `json:"status"`
Reasons []string `json:"reasons"`
Stages []NativeStage `json:"stages"`
ComparisonStatus string `json:"comparison_status"`
GeneratedMismatches []Mismatch `json:"generated_mismatches"`
HumanVerifiedMismatches []Mismatch `json:"human_verified_mismatches"`
WorkflowQualification string `json:"workflow_qualification"`
}
func ReplayNative ¶
func ReplayNative(ctx context.Context, root, fixtureFile, policyFile, change string) (NativeReport, error)
ReplayNative observes the real connector, intake and delta only. Expected labels never enter author input; a failed delta forbids every downstream operation, and the unintegrated follow-up stage blocks the rest.
type NativeStage ¶
type NativeStage struct {
Name string `json:"name"`
Disposition string `json:"disposition"`
NativeProfile string `json:"native_profile"`
Inputs []ArtifactRef `json:"inputs"`
Output *ArtifactRef `json:"output"`
Reasons []string `json:"reasons"`
}
type Policy ¶
type Policy struct {
Profile string `json:"profile"`
Connector connector.Policy `json:"connector"`
Executable string `json:"executable"`
ExecutableSHA256 string `json:"executable_sha256"`
Args []string `json:"args"`
RuntimeSHA256 string `json:"runtime_sha256"`
Registry string `json:"registry"`
RegistrySHA256 string `json:"registry_sha256"`
}
Policy is a separate host-owned input. The fixture cannot choose an executable, arguments, connector binding, runtime configuration or human label registry.
type Report ¶
type Report struct {
Profile string `json:"profile"`
Binding connector.Binding `json:"binding"`
FixtureSHA256 string `json:"fixture_sha256"`
PolicySHA256 string `json:"policy_sha256"`
Status string `json:"status"` // MATCH | MISMATCH | BLOCKED
Reasons []string `json:"reasons"`
// Mismatches are reported separately by the basis of the expectation
// they contradict; a generated expectation never counts as human-verified.
HumanVerifiedMismatches []Mismatch `json:"human_verified_mismatches"`
GeneratedMismatches []Mismatch `json:"generated_mismatches"`
DeferredStages []string `json:"deferred_stages"`
RecordingSHA256 string `json:"recording_sha256"`
Recording string `json:"recording_jsonl"`
WorkflowQualification string `json:"workflow_qualification"`
Limits []string `json:"limits"`
}