Documentation
¶
Overview ¶
Package releasecandidate closes the already-qualified core and companion artifacts into one immutable, versioned local publication candidate.
Index ¶
- func InstallCore(ctx context.Context, candidateDirectory, store string) (string, error)
- func ReadReadinessEvidence(path string) (map[string]ReadinessEvidence, error)
- type Asset
- type Manifest
- type Options
- type Qualification
- type QualificationRow
- type ReadinessCore
- type ReadinessEvidence
- type ReadinessIdentity
- type ReadinessOptions
- type ReadinessRecord
- func BuildReadinessRecord(ctx context.Context, options ReadinessOptions) (*ReadinessRecord, []byte, error)
- func VerifyReadinessFile(ctx context.Context, path, candidateDirectory string, ...) (*ReadinessRecord, error)
- func VerifyReadinessRecord(ctx context.Context, raw []byte, candidateDirectory string, ...) (*ReadinessRecord, error)
- func WriteReadinessRecord(ctx context.Context, options ReadinessOptions, output string) (*ReadinessRecord, error)
- type ReadinessRow
- type ReadinessStoreRelease
- type ReadinessVulnerability
- type Result
- type SourceIdentity
- type VerifiedCandidate
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func InstallCore ¶
InstallCore extracts the host core archive into a new version/platform path. It never writes or changes a current/latest selector, so coexistence and rollback are explicit selection of an already-verified immutable path.
func ReadReadinessEvidence ¶
func ReadReadinessEvidence(path string) (map[string]ReadinessEvidence, error)
ReadReadinessEvidence parses the operator evidence file (SRR-V1-012): one row per line, ROW<TAB>STATUS<TAB>PATH<TAB>DECISION<TAB>REASON, with absent values left empty. A relative PATH is appended to the file's directory as spelled, not cleaned, so the kernel resolves a ".." after the symlinks before it, as opening the path would. A CRLF line ending is read as LF.
Types ¶
type Manifest ¶
type Manifest struct {
Profile string `json:"profile"`
Version string `json:"version"`
BuildNumber string `json:"buildNumber"`
CorvintVersion string `json:"corvintVersion"`
GoVersion string `json:"goVersion"`
GitVersion string `json:"gitVersion"`
Sources []SourceIdentity `json:"sources"`
Assets []Asset `json:"assets"`
}
type Qualification ¶
type Qualification struct {
Profile string `json:"profile"`
Rows []QualificationRow `json:"rows"`
}
type QualificationRow ¶
type ReadinessCore ¶
type ReadinessEvidence ¶
ReadinessEvidence is one operator-supplied row: a status, the evidence file whose digest is recorded, and the accepting decision or reason.
type ReadinessIdentity ¶
type ReadinessOptions ¶
type ReadinessRecord ¶
type ReadinessRecord struct {
Profile string `json:"profile"`
Identity ReadinessIdentity `json:"identity"`
Core ReadinessCore `json:"core"`
StoreRelease *ReadinessStoreRelease `json:"storeRelease"`
Vulnerability ReadinessVulnerability `json:"vulnerability"`
Rows []ReadinessRow `json:"rows"`
}
func BuildReadinessRecord ¶
func BuildReadinessRecord(ctx context.Context, options ReadinessOptions) (*ReadinessRecord, []byte, error)
BuildReadinessRecord assembles the canonical record from one verified candidate, the source root and operator evidence. It runs no gate and writes nothing; the caller owns the output path.
func VerifyReadinessFile ¶
func VerifyReadinessFile(ctx context.Context, path, candidateDirectory string, evidence map[string]ReadinessEvidence) (*ReadinessRecord, error)
VerifyReadinessFile verifies the record at path, then refuses rows that differ from the rows the evidence file builds, so a record cannot relabel its evidence (a FAIL log as PASS, say) and still verify (SRR-V1-012).
func VerifyReadinessRecord ¶
func VerifyReadinessRecord(ctx context.Context, raw []byte, candidateDirectory string, evidence map[string]string) (*ReadinessRecord, error)
VerifyReadinessRecord refuses a malformed or non-canonical record, re-binds it to the verified candidate and recomputes every evidence digest from the operator-named files (row id to path).
func WriteReadinessRecord ¶
func WriteReadinessRecord(ctx context.Context, options ReadinessOptions, output string) (*ReadinessRecord, error)
WriteReadinessRecord builds the record and publishes it at output. An existing output is refused, never replaced, and so is an output inside the candidate or the source root, which build must not write (SRR-V1-011, SRR-V1-012). A file name the record cannot be published under is refused before the build. The output's directory is resolved and opened once before the guard, and the write goes through that handle, so a path component replaced during the build cannot redirect it. After the open the directory is resolved again, that settled path must still be the handle's, and the guard walks it, so an ancestor swapped for a link before the open is walked through the link's target.
type ReadinessRow ¶
type ReadinessStoreRelease ¶
type ReadinessVulnerability ¶
type Result ¶
type Result struct {
Directory string
Manifest Manifest
Qualification Qualification
}
type SourceIdentity ¶
type VerifiedCandidate ¶
type VerifiedCandidate struct {
Directory string
Manifest Manifest
Qualification Qualification
// contains filtered or unexported fields
}
func Verify ¶
func Verify(directory string) (*VerifiedCandidate, error)
Verify admits a closed candidate only when its checksum, manifest asset inventory, and qualification rows agree with every retained regular file.
func VerifyContext ¶
func VerifyContext(ctx context.Context, directory string) (*VerifiedCandidate, error)
VerifyContext is Verify with caller cancellation propagated to the only executed child: the exact host core version probe.