localio

package
v1.0.59-beta.4 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 20, 2026 License: Apache-2.0 Imports: 14 Imported by: 0

Documentation

Overview

Package localio owns safe local artifact publication shared by product shortcuts. Remote names and URLs are always treated as untrusted input.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func ReadTextInput added in v1.0.58

func ReadTextInput(spec string, stdin io.Reader, maxBytes int64) (string, error)

ReadTextInput resolves a literal, "-" stdin, or @workspace-relative file. File symlinks must resolve inside the current working directory and all input forms are bounded to prevent accidental unbounded memory use.

func ResolveOutputPath

func ResolveOutputPath(baseDir, output, rawURL, preferredName string) (string, string, error)

func SafeFilename

func SafeFilename(preferredName, rawURL string) string

SafeFilename selects a portable basename from a preferred server name or URL.

func ValidateDownloadURL

func ValidateDownloadURL(rawURL string) (*url.URL, error)

ValidateDownloadURL accepts only public DingTalk and Aliyun OSS HTTPS hosts.

func ValidateOutput

func ValidateOutput(output string) error

ValidateOutput rejects absolute paths and portable `..` escapes.

Types

type DownloadOptions

type DownloadOptions struct {
	BaseDir       string
	Output        string
	PreferredName string
	Headers       map[string]string
}

DownloadOptions controls safe, atomic publication beneath BaseDir.

type DownloadResult

type DownloadResult struct {
	AbsolutePath string
	RelativePath string
	SizeBytes    int64
}

DownloadResult describes the published local artifact.

func Download

func Download(ctx context.Context, rawURL string, opts DownloadOptions) (DownloadResult, error)

Download validates a platform-owned HTTPS URL, resolves a workspace-relative output path without following symlink escapes, streams into a sibling temp file, fsyncs it, and atomically publishes the completed file.

func PublishBytes added in v1.0.58

func PublishBytes(payload []byte, opts PublishBytesOptions) (DownloadResult, error)

PublishBytes writes an in-memory artifact through the same symlink-safe, fsync and atomic no-clobber path used by remote downloads.

type PublishBytesOptions added in v1.0.58

type PublishBytesOptions struct {
	BaseDir       string
	Output        string
	PreferredName string
	MaxBytes      int64
}

PublishBytesOptions controls safe no-clobber publication beneath BaseDir.

type UploadResult added in v1.0.58

type UploadResult struct {
	SizeBytes int64
	Attempts  int
}

UploadResult records only non-sensitive transfer facts. The signed URL is deliberately never returned.

func PutFile added in v1.0.58

func PutFile(ctx context.Context, rawURL, path string, maxBytes int64) (UploadResult, error)

PutFile uploads a regular local file to an exact trusted pre-signed HTTPS endpoint. Redirects are rejected so file bytes and credentials cannot move to a second origin. Transient failures reuse the same verified open file so a path replacement cannot change the bytes sent by a later attempt.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL