Documentation
¶
Overview ¶
Package preflight performs read-only readiness checks for Relayer. Reports deliberately contain no configuration path, command arguments, environment values, agent identifiers, names or raw dependency errors.
Every check is passive with one deliberate exception: when tmux is the effective backend, Options.TmuxProbe runs tmux inside a private socket to establish that it can actually serve a session. Nothing belonging to the user - configuration, audit journal, tmux server, agent process - is created, read or mutated.
Index ¶
- Constants
- Variables
- func ValidateReport(report Report) error
- type AgentInfo
- type AgentSource
- type AuditInfo
- type AuditLocation
- type CheckResult
- type CheckStatus
- type CommandKind
- type ConfigurationInfo
- type FailureKind
- type Input
- type LstatFunc
- type Options
- type OverallStatus
- type OwnerCheckFunc
- type OwnerStatus
- type PlatformInfo
- type ReadDirFunc
- type Report
- type ResolveAuditPathFunc
- type Scope
- type TmuxProbeFunc
- type ToolInfo
Constants ¶
const CurrentSchemaVersion = 1
Variables ¶
var ErrInvalidReport = errors.New("invalid preflight report")
ErrInvalidReport is deliberately static. A rejected report may contain caller-controlled paths, commands, environment values or raw errors, so the validation error must never echo the field which caused the rejection.
var ErrNilContext = errors.New("preflight context is nil")
Functions ¶
func ValidateReport ¶
ValidateReport verifies the complete display contract before a report may be rendered or cross a native/UI boundary. It accepts only reports produced by Check or FailureReport: every identifier, enum and displayed sentence belongs to a finite package-owned vocabulary.
Types ¶
type AgentInfo ¶
type AgentInfo struct {
Ordinal int `json:"ordinal"`
Source AgentSource `json:"source"`
Command CommandKind `json:"command"`
Installation toolcatalog.InstallStatus `json:"installation"`
Adapter string `json:"adapter,omitempty"`
AdapterMaturity adapters.Status `json:"adapter_maturity,omitempty"`
Backend string `json:"backend,omitempty"`
}
AgentInfo uses a one-based ordinal in place of the configured agent ID or name. Executable names and resolved filesystem paths are also omitted.
type AgentSource ¶
type AgentSource string
const ( AgentConfigured AgentSource = "configured" AgentDemo AgentSource = "demo" )
type AuditLocation ¶
type AuditLocation string
const ( AuditLocationDisabled AuditLocation = "disabled" AuditLocationDefault AuditLocation = "default" AuditLocationCustom AuditLocation = "custom" )
type CheckResult ¶
type CheckResult struct {
ID string `json:"id"`
Scope Scope `json:"scope"`
Status CheckStatus `json:"status"`
Summary string `json:"summary"`
Remediation string `json:"remediation,omitempty"`
}
CheckResult contains only finite, static display text selected by the package.
type CheckStatus ¶
type CheckStatus string
CheckStatus is deliberately closed so presentation layers never need raw error strings to explain readiness.
const ( CheckPass CheckStatus = "pass" CheckWarning CheckStatus = "warning" CheckBlock CheckStatus = "block" )
type CommandKind ¶
type CommandKind string
const ( CommandDirect CommandKind = "direct" CommandShell CommandKind = "shell" )
type ConfigurationInfo ¶
type FailureKind ¶
type FailureKind string
FailureKind is a closed classification used by the application facade when it cannot construct an effective Input. The underlying error is never put into the report.
const ( FailureConfigMissing FailureKind = "config_missing" FailureConfigInvalid FailureKind = "config_invalid" FailureConfigUnreadable FailureKind = "config_unreadable" FailureWorkingDirectory FailureKind = "working_directory" FailureAgentResolution FailureKind = "agent_resolution" FailurePolicyResolution FailureKind = "policy_resolution" FailureAdapterResolution FailureKind = "adapter_resolution" FailurePreflightInternal FailureKind = "preflight_internal" )
type Input ¶
Input contains an already effective, validated runtime plan. Application facades remain responsible for applying the empty-agent demo fallback before calling Check.
type Options ¶
type Options struct {
Detector toolcatalog.Detector
// TmuxProbe is the one check in this package that executes a program.
// Discovering the tmux binary is not evidence that it can serve Relayer's
// machine-readable protocol, and a report that cannot observe that failure
// tells the operator the backend is healthy right before startup fails with
// an opaque identity error.
//
// The probe is bounded and self-contained: one short-lived session on a
// private socket inside a 0700 temporary directory, removed by name. It
// never reads, attaches to, or mutates the user's tmux server, and never
// calls kill-server. A nil probe uses tmuxbackend.Probe.
TmuxProbe TmuxProbeFunc
GOOS string
GOARCH string
Lstat LstatFunc
ReadDir ReadDirFunc
ResolveAuditPath ResolveAuditPathFunc
OwnerCheck OwnerCheckFunc
}
Options contains passive dependencies, plus the single deliberate exception described on TmuxProbe. Empty platform fields use the current runtime; a nil detector uses toolcatalog.DefaultDetector.
type OverallStatus ¶
type OverallStatus string
OverallStatus summarizes the strongest check status in a report.
const ( StatusReady OverallStatus = "ready" StatusWarning OverallStatus = "warning" StatusBlocked OverallStatus = "blocked" )
type OwnerCheckFunc ¶
type OwnerCheckFunc func(fs.FileInfo) OwnerStatus
type OwnerStatus ¶
type OwnerStatus string
const ( OwnerCurrent OwnerStatus = "current" OwnerOther OwnerStatus = "other" OwnerUnknown OwnerStatus = "unknown" )
type PlatformInfo ¶
type Report ¶
type Report struct {
SchemaVersion int `json:"schema_version"`
Status OverallStatus `json:"status"`
Platform PlatformInfo `json:"platform"`
Configuration ConfigurationInfo `json:"configuration"`
Audit AuditInfo `json:"audit"`
Tools []ToolInfo `json:"tools"`
Agents []AgentInfo `json:"agents"`
Checks []CheckResult `json:"checks"`
}
Report is a versioned, display-safe snapshot shared by CLI and GUI.
func Check ¶
Check passively validates one effective plan. It never opens an audit sink, constructs a terminal backend, starts a process or invokes an executable.
func FailureReport ¶
func FailureReport(kind FailureKind, options Options) Report
FailureReport builds a static, blocked report for facade failures that occur before an effective Input exists. Unknown kinds collapse to an internal failure and never become caller-controlled display text.
func (Report) HasBlockers ¶
HasBlockers reports whether at least one check prevents safe startup.
type ResolveAuditPathFunc ¶
type TmuxProbeFunc ¶
TmuxProbeFunc reports whether a discovered tmux can actually run a session.
type ToolInfo ¶
type ToolInfo struct {
ProfileID toolcatalog.ProfileID `json:"profile_id"`
Installation toolcatalog.InstallStatus `json:"installation"`
}