releasecandidate

package
v1.0.0-rc.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 31 Imported by: 0

Documentation

Overview

Package releasecandidate closes the already-qualified core and companion artifacts into one immutable, versioned local publication candidate.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func InstallCore

func InstallCore(ctx context.Context, candidateDirectory, store string) (string, error)

InstallCore extracts the host core archive into a new version/platform path. It never writes or changes a current/latest selector, so coexistence and rollback are explicit selection of an already-verified immutable path.

func ReadReadinessEvidence

func ReadReadinessEvidence(path string) (map[string]ReadinessEvidence, error)

ReadReadinessEvidence parses the operator evidence file (SRR-V1-012): one row per line, ROW<TAB>STATUS<TAB>PATH<TAB>DECISION<TAB>REASON, with absent values left empty. A relative PATH is appended to the file's directory as spelled, not cleaned, so the kernel resolves a ".." after the symlinks before it, as opening the path would. A CRLF line ending is read as LF.

Types

type Asset

type Asset struct {
	Path      string `json:"path"`
	Role      string `json:"role"`
	SHA256    string `json:"sha256"`
	SizeBytes int64  `json:"sizeBytes"`
}

type Manifest

type Manifest struct {
	Profile        string           `json:"profile"`
	Version        string           `json:"version"`
	BuildNumber    string           `json:"buildNumber"`
	CorvintVersion string           `json:"corvintVersion"`
	GoVersion      string           `json:"goVersion"`
	GitVersion     string           `json:"gitVersion"`
	Sources        []SourceIdentity `json:"sources"`
	Assets         []Asset          `json:"assets"`
}

type Options

type Options struct {
	CoreDirectory      string
	CompanionDirectory string
	SourceRoot         string
	Scratch            string
	OutputParent       string
	Version            string
}

type Qualification

type Qualification struct {
	Profile string             `json:"profile"`
	Rows    []QualificationRow `json:"rows"`
}

type QualificationRow

type QualificationRow struct {
	Platform string `json:"platform"`
	Workflow string `json:"workflow"`
	Status   string `json:"status"`
	Evidence string `json:"evidence"`
}

type ReadinessCore

type ReadinessCore struct {
	CandidateProfile string  `json:"candidateProfile"`
	ChecksumsSHA256  string  `json:"checksumsSha256"`
	Archives         []Asset `json:"archives"`
	Reproducibility  string  `json:"reproducibility"`
}

type ReadinessEvidence

type ReadinessEvidence struct {
	Status   string
	Path     string
	Decision string
	Reason   string
}

ReadinessEvidence is one operator-supplied row: a status, the evidence file whose digest is recorded, and the accepting decision or reason.

type ReadinessIdentity

type ReadinessIdentity struct {
	Version     string `json:"version"`
	Tag         string `json:"tag"`
	BuildNumber string `json:"buildNumber"`
	GoVersion   string `json:"goVersion"`
	Commit      string `json:"commit"`
	Tree        string `json:"tree"`
}

type ReadinessOptions

type ReadinessOptions struct {
	CandidateDirectory   string
	SourceRoot           string
	StoreReleaseID       string
	StoreCandidateSHA256 string
	Evidence             map[string]ReadinessEvidence
}

type ReadinessRecord

type ReadinessRecord struct {
	Profile       string                 `json:"profile"`
	Identity      ReadinessIdentity      `json:"identity"`
	Core          ReadinessCore          `json:"core"`
	StoreRelease  *ReadinessStoreRelease `json:"storeRelease"`
	Vulnerability ReadinessVulnerability `json:"vulnerability"`
	Rows          []ReadinessRow         `json:"rows"`
}

func BuildReadinessRecord

func BuildReadinessRecord(ctx context.Context, options ReadinessOptions) (*ReadinessRecord, []byte, error)

BuildReadinessRecord assembles the canonical record from one verified candidate, the source root and operator evidence. It runs no gate and writes nothing; the caller owns the output path.

func VerifyReadinessFile

func VerifyReadinessFile(ctx context.Context, path, candidateDirectory string, evidence map[string]ReadinessEvidence) (*ReadinessRecord, error)

VerifyReadinessFile verifies the record at path, then refuses rows that differ from the rows the evidence file builds, so a record cannot relabel its evidence (a FAIL log as PASS, say) and still verify (SRR-V1-012).

func VerifyReadinessRecord

func VerifyReadinessRecord(ctx context.Context, raw []byte, candidateDirectory string, evidence map[string]string) (*ReadinessRecord, error)

VerifyReadinessRecord refuses a malformed or non-canonical record, re-binds it to the verified candidate and recomputes every evidence digest from the operator-named files (row id to path).

func WriteReadinessRecord

func WriteReadinessRecord(ctx context.Context, options ReadinessOptions, output string) (*ReadinessRecord, error)

WriteReadinessRecord builds the record and publishes it at output. An existing output is refused, never replaced, and so is an output inside the candidate or the source root, which build must not write (SRR-V1-011, SRR-V1-012). A file name the record cannot be published under is refused before the build. The output's directory is resolved and opened once before the guard, and the write goes through that handle, so a path component replaced during the build cannot redirect it. After the open the directory is resolved again, that settled path must still be the handle's, and the guard walks it, so an ancestor swapped for a link before the open is walked through the link's target.

type ReadinessRow

type ReadinessRow struct {
	ID       string `json:"id"`
	Status   string `json:"status"`
	SHA256   string `json:"sha256"`
	Decision string `json:"decision"`
	Reason   string `json:"reason"`
}

type ReadinessStoreRelease

type ReadinessStoreRelease struct {
	ReleaseID       string `json:"releaseId"`
	CandidateSHA256 string `json:"candidateSha256"`
}

type ReadinessVulnerability

type ReadinessVulnerability struct {
	Decision          string `json:"decision"`
	RequireDirectives int    `json:"requireDirectives"`
	Toolchain         string `json:"toolchain"`
	Status            string `json:"status"`
}

type Result

type Result struct {
	Directory     string
	Manifest      Manifest
	Qualification Qualification
}

func Assemble

func Assemble(ctx context.Context, options Options) (_ *Result, err error)

type SourceIdentity

type SourceIdentity struct {
	Name   string `json:"name"`
	Commit string `json:"commit"`
	Tree   string `json:"tree"`
}

type VerifiedCandidate

type VerifiedCandidate struct {
	Directory     string
	Manifest      Manifest
	Qualification Qualification
	// contains filtered or unexported fields
}

func Verify

func Verify(directory string) (*VerifiedCandidate, error)

Verify admits a closed candidate only when its checksum, manifest asset inventory, and qualification rows agree with every retained regular file.

func VerifyContext

func VerifyContext(ctx context.Context, directory string) (*VerifiedCandidate, error)

VerifyContext is Verify with caller cancellation propagated to the only executed child: the exact host core version probe.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL