schemacache

package
v1.0.63 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 3, 2026 License: Apache-2.0 Imports: 20 Imported by: 0

Documentation

Index

Constants

View Source
const (
	HeaderSize             = 208
	EnvelopeVersion        = uint16(1)
	DTOFormatVersion       = uint32(2)
	SerializerProtobuf     = uint8(2)
	CodecRaw               = uint8(0)
	MaxMetaFileSize        = uint64(4 << 20)
	MaxRegistryFileSize    = uint64(64 << 20)
	MaxProductRangeSize    = uint64(8 << 20)
	MaxRegistryPayloadSize = MaxRegistryFileSize - HeaderSize
)

Variables

View Source
var (
	ErrDisabled         = errors.New("schema cache disabled on this platform")
	ErrNotFound         = errors.New("schema cache artifact not found")
	ErrInvalidArtifact  = errors.New("invalid schema cache artifact")
	ErrIdentityMismatch = errors.New("schema cache identity mismatch")
	ErrUnsafePath       = errors.New("unsafe schema cache path")
	ErrLockTimeout      = errors.New("schema cache lock timeout")
	ErrClosed           = errors.New("schema cache handle closed")
)

Functions

func EditionSHA256

func EditionSHA256(edition string) ([32]byte, error)

func MarshalEnvelope

func MarshalEnvelope(e Envelope) ([]byte, error)

func PersistentBackendEnabled

func PersistentBackendEnabled(goos, goarch string) bool

PersistentBackendEnabled is the reviewed v1 disk-cache surface: darwin, linux, and windows on amd64/arm64. Each machine generates identity locally, so the backend is not limited to the old compile-time proof pair. Other targets stay live-only.

func UseMemoryOpenForTest

func UseMemoryOpenForTest(t *testing.T)

UseMemoryOpenForTest swaps Open onto a portable file backend under t.TempDir so targets without the unix backend (Windows coverage) can Publish and Read the same artifacts. Production must not call this; the ForTest suffix is the boundary. The swap is inlined (not testseam) so schemacache stays out of the thin Schema dependency closure.

func UseUserCacheDirErrorForTest

func UseUserCacheDirErrorForTest(t *testing.T)

UseUserCacheDirErrorForTest makes the per-user cache base lookup fail for the test (covers the fallback's user-cache-unavailable error leg).

func UseUserCacheDirForTest

func UseUserCacheDirForTest(t *testing.T, dir string)

UseUserCacheDirForTest points the per-user cache base at dir for the test. Production must not call this; the ForTest suffix is the boundary.

Types

type Artifact

type Artifact struct {
	Expectation ArtifactExpectation
	Payload     []byte
}

Artifact pairs a trusted expectation with the exact payload to publish.

type ArtifactExpectation

type ArtifactExpectation struct {
	Kind          ArtifactKind
	Serializer    uint8
	Codec         uint8
	FormatVersion uint32
	EncodedLength uint64
	DecodedLength uint64
	EncodedSHA256 [32]byte
}

ArtifactExpectation is the binary-pinned identity of one exact artifact.

type ArtifactKind

type ArtifactKind uint8
const (
	KindMeta     ArtifactKind = 1
	KindRegistry ArtifactKind = 2
	KindPayloads ArtifactKind = 3
)

type Cache

type Cache struct {
	// contains filtered or unexported fields
}

Cache is a securely opened edition-specific cache directory.

func Open

func Open(edition string, options ...Option) (*Cache, error)

func (*Cache) AcquireLock

func (c *Cache) AcquireLock(ctx context.Context, timeout time.Duration) (*Lock, error)

func (*Cache) Close

func (c *Cache) Close() error

func (*Cache) Directory

func (c *Cache) Directory() string

func (*Cache) OpenPayloads

func (c *Cache) OpenPayloads(identity ExpectedIdentity, expected ArtifactExpectation) (*Registry, error)

OpenPayloads opens the command payload file for bounded ReadRange calls. It is deliberately independent of the registry so a corrupted registry cannot affect payload reads.

func (*Cache) OpenRegistry

func (c *Cache) OpenRegistry(identity ExpectedIdentity, expected ArtifactExpectation) (*Registry, error)

OpenRegistry authenticates the header and binary-pinned total identity. It deliberately does not hash Registry payload bytes on this leaf path.

func (*Cache) Publish

func (c *Cache) Publish(identity ExpectedIdentity, registry, meta Artifact, extra ...Artifact) error

Publish commits Registry first and Meta last. Meta is the generation commit marker.

func (*Cache) ReadMeta

func (c *Cache) ReadMeta(identity ExpectedIdentity, expected ArtifactExpectation) ([]byte, error)

ReadMeta authenticates the exact complete Meta payload before returning it.

func (*Cache) WriteArtifact

func (c *Cache) WriteArtifact(identity ExpectedIdentity, artifact Artifact) error

WriteArtifact atomically replaces one artifact. Publish should be used when committing a Registry and Meta pair.

type Counters

type Counters struct {
	// contains filtered or unexported fields
}

func (*Counters) Snapshot

func (c *Counters) Snapshot() IOSnapshot

type Envelope

type Envelope struct {
	Kind                   ArtifactKind
	Serializer             uint8
	Codec                  uint8
	Flags                  uint8
	FormatVersion          uint32
	CatalogSnapshotVersion uint32
	EncodedLength          uint64
	DecodedLength          uint64
	EditionSHA256          [32]byte
	SourceSHA256           [32]byte
	SurfaceSHA256          [32]byte
	BuildID                [32]byte
	EncodedSHA256          [32]byte
}

Envelope is the fixed, allocation-free portion of a cache artifact.

func ParseEnvelope

func ParseEnvelope(b []byte) (Envelope, error)

func (Envelope) MarshalBinary

func (e Envelope) MarshalBinary() ([]byte, error)

type ExpectedIdentity

type ExpectedIdentity struct {
	CatalogSnapshotVersion uint32
	EditionSHA256          [32]byte
	SourceSHA256           [32]byte
	SurfaceSHA256          [32]byte
	BuildID                [32]byte
}

ExpectedIdentity contains only values pinned by the running binary. Header values are compared with this identity and are never accepted on their own.

func (ExpectedIdentity) Authenticate

func (i ExpectedIdentity) Authenticate(e Envelope, a ArtifactExpectation) error

Authenticate compares every envelope identity field with binary-pinned trusted values. It does not authenticate payload bytes by itself.

type IOSnapshot

type IOSnapshot struct {
	RootOpenOps          uint64
	MkdirOps             uint64
	FileOpenOps          uint64
	StatOps              uint64
	HeaderReadOps        uint64
	MetaPayloadReadOps   uint64
	MetaPayloadReadBytes uint64
	RegistryReadOps      uint64
	RegistryReadBytes    uint64
	PayloadReadOps       uint64
	PayloadReadBytes     uint64
	WriteOps             uint64
	WriteBytes           uint64
	FileSyncOps          uint64
	CloseOps             uint64
	RenameOps            uint64
	RemoveOps            uint64
	DirectorySyncOps     uint64
	LockAttempts         uint64
}

IOSnapshot exposes cache-only operations without coupling callers to payload parsing.

type Lock

type Lock struct {
	// contains filtered or unexported fields
}

Lock is a process-local and cross-process rebuild lock.

func (*Lock) Release

func (l *Lock) Release() error

type Option

type Option func(*openOptions)

func WithCounters

func WithCounters(c *Counters) Option

func WithNoCreate

func WithNoCreate() Option

WithNoCreate turns a missing cache ancestry into ErrNotFound instead of creating it. Speculative readers must never mutate the filesystem.

func WithUserOnly

func WithUserOnly() Option

WithUserOnly bypasses the DWS_SCHEMA_CACHE_DIR / shared / system bases and opens the per-user cache directly. The repair path uses it to persist and reuse a repair when the preferred shared cache exists but cannot be locked (typically root-owned read-only with corrupted artifacts).

type RangeDescriptor

type RangeDescriptor struct {
	Offset uint64
	Length uint64
	SHA256 [32]byte
}

RangeDescriptor must come from an already authenticated Meta payload. Offset is relative to the Registry payload, after its fixed header.

type Registry

type Registry struct {
	// contains filtered or unexported fields
}

Registry keeps one authenticated regular file open for bounded ReadRange calls.

func (*Registry) Close

func (r *Registry) Close() error

func (*Registry) ReadRange

func (r *Registry) ReadRange(descriptor RangeDescriptor) ([]byte, error)

func (*Registry) ValidateAggregate

func (r *Registry) ValidateAggregate() error

ValidateAggregate hashes the complete Registry payload for repair or full audit. ReadRange does not call it.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL