Documentation
¶
Overview ¶
Package stepverify observes a quiescent, host-confined authoring step. Local digests and host assertions confer no execution authority or authentication.
Index ¶
- Constants
- Variables
- func BoundedEncode(value any) ([]byte, error)
- func DeclarationDigest(d Declaration) string
- func Encode(value any) []byte
- func ReadBoundInput(ctx context.Context, path string, d Declaration, h Host, before State) ([]byte, error)
- func ReadInput(ctx context.Context, path string, d *Declaration) ([]byte, error)
- type Checkout
- type CheckoutState
- type Declaration
- type Entry
- type EnvironmentKey
- type EnvironmentReceipt
- type Finding
- type Host
- type Receipt
- type State
Constants ¶
View Source
const MaxDepth = 64
View Source
const MaxEntries = 20_000
View Source
const MaxFileBytes = 32 << 20
View Source
const MaxRecordBytes = 32 << 20
View Source
const MaxTotalBytes = 128 << 20
Variables ¶
View Source
var ErrDrift = errors.New("STEP_DRIFT")
View Source
var ErrInput = errors.New("STEP_INPUT")
View Source
var ErrUnsupported = errors.New("STEP_UNSUPPORTED")
Functions ¶
func BoundedEncode ¶
BoundedEncode refuses oversized records rather than silently dropping evidence.
func DeclarationDigest ¶
func DeclarationDigest(d Declaration) string
func ReadBoundInput ¶
func ReadBoundInput(ctx context.Context, path string, d Declaration, h Host, before State) ([]byte, error)
ReadBoundInput retains the trusted complete before-state authority boundary when post-step metadata is unavailable. Current discoverable boundaries are also excluded. This permits content findings without executing unadmitted Git.
Types ¶
type CheckoutState ¶
type CheckoutState struct {
ID string `json:"id"`
Root string `json:"root"`
GitDir string `json:"git_dir"`
CommonDir string `json:"common_dir"`
Commit string `json:"commit"`
Tree string `json:"tree"`
IndexDigest string `json:"index_sha256"`
ContentDigest string `json:"content_sha256"`
AdminDigest string `json:"admin_sha256"`
ContentComplete bool `json:"content_complete"`
Complete bool `json:"complete"`
Entries []Entry `json:"entries"`
AdminEntries []Entry `json:"admin_entries"`
Unknowns []string `json:"unknowns"`
}
type Declaration ¶
type Declaration struct {
Profile string `json:"profile"`
SessionID string `json:"session_id"`
CapabilityID string `json:"capability_id"`
Author Checkout `json:"author"`
ReadOnly []Checkout `json:"read_only"`
WritePaths []string `json:"write_paths"`
GuardPaths []string `json:"guard_paths"`
Environment []EnvironmentKey `json:"environment"`
}
func DecodeDeclaration ¶
func DecodeDeclaration(data []byte) (Declaration, error)
type EnvironmentKey ¶
type EnvironmentReceipt ¶
type EnvironmentReceipt struct {
Profile string `json:"profile"`
DeclarationDigest string `json:"declaration_sha256"`
HostDigest string `json:"host_sha256"`
Verdict string `json:"environment_verdict"`
Findings []Finding `json:"findings"`
Unknowns []string `json:"unknowns"`
Digest string `json:"sha256"`
}
EnvironmentReceipt records host-supplied key classifications, never values.
func Preflight ¶
func Preflight(d Declaration, h Host) (EnvironmentReceipt, int, error)
type Finding ¶
type Finding struct {
Code string `json:"code"`
Checkout string `json:"checkout"`
Path string `json:"path"`
}
func Environment ¶
func Environment(d Declaration, h Host) (string, []Finding)
type Host ¶
type Host struct {
Profile string `json:"profile"`
ObserverID string `json:"observer_id"`
SessionID string `json:"session_id"`
CapabilityID string `json:"capability_id"`
DeclarationDigest string `json:"declaration_sha256"`
MetadataProtected bool `json:"metadata_protected"`
FilesystemConfined bool `json:"filesystem_confined"`
GitBinary string `json:"git_binary"`
GitBinaryDigest string `json:"git_binary_sha256"`
Environment *[]EnvironmentKey `json:"environment"`
}
func DecodeHost ¶
func DecodeHost(data []byte, d Declaration) (Host, error)
type Receipt ¶
type Receipt struct {
Profile string `json:"profile"`
DeclarationDigest string `json:"declaration_sha256"`
HostDigest string `json:"host_sha256"`
BeforeDigest string `json:"before_state_sha256"`
AfterDigest *string `json:"post_state_sha256"`
Before []CheckoutState `json:"before"`
After []CheckoutState `json:"after"`
WriteScopeVerdict string `json:"write_scope_verdict"`
EnvironmentVerdict string `json:"environment_verdict"`
Findings []Finding `json:"findings"`
Unknowns []string `json:"unknowns"`
Digest string `json:"sha256"`
}
type State ¶
type State struct {
Profile string `json:"profile"`
DeclarationDigest string `json:"declaration_sha256"`
HostDigest string `json:"host_sha256"`
SessionID string `json:"session_id"`
CapabilityID string `json:"capability_id"`
Checkouts []CheckoutState `json:"checkouts"`
Complete bool `json:"complete"`
Digest string `json:"sha256"`
}
func DecodeState ¶
func DecodeState(data []byte, d Declaration, h Host) (State, error)
Source Files
¶
Directories
¶
| Path | Synopsis |
|---|---|
|
SPDX-License-Identifier: AGPL-3.0-or-later Derived from internal/tasks/safeopen/at_linux.go at 25971bda1ca1664d8a546d751cb2bb9bbd454daf.
|
SPDX-License-Identifier: AGPL-3.0-or-later Derived from internal/tasks/safeopen/at_linux.go at 25971bda1ca1664d8a546d751cb2bb9bbd454daf. |
Click to show internal directories.
Click to hide internal directories.