Documentation
¶
Overview ¶
Package hostprovision validates operator input and creates device enrollment.
Index ¶
- Variables
- func ReadPrivateFile(path string, maximum int) ([]byte, error)
- func SaveEnrollment(path string, enrollment Enrollment) error
- type Enrollment
- func Create(input Input, identity *[16]byte, random io.Reader) (provision.Config, Enrollment, error)
- func CreateFor(codec provision.Codec, input Input, identity *[16]byte, random io.Reader) (provision.Config, Enrollment, error)
- func DecodeEnrollment(data []byte) (Enrollment, error)
- func LoadEnrollment(path string) (Enrollment, error)
- type Input
- type PendingEnrollment
Constants ¶
This section is empty.
Variables ¶
var ( ErrPending = errors.New("host provisioning: recovery=1 unresolved .pending exists; retain both enrollment files, reopen USB and inspect; do not retry mutation") ErrStaging = errors.New("host provisioning: recovery=2 staging failed; active enrollment preserved; inspect and retain any .pending before retry") ErrAcknowledgement = errors.New("host provisioning: recovery=3 ACK does not confirm candidate; retain active and .pending, reopen USB and inspect; do not retry mutation") ErrPromotion = errors.New("host provisioning: recovery=4 promotion failed; retain active and .pending, reopen USB and inspect; do not retry mutation") ErrDurability = errors.New("host provisioning: recovery=5 active candidate installed but directory sync failed; retain active, verify storage and reopen USB to inspect; do not retry mutation") )
var ErrInput = errors.New("host provisioning: invalid input")
var ErrRegistry = errors.New("host provisioning: registry write failed")
Functions ¶
func ReadPrivateFile ¶
ReadPrivateFile reads an existing regular mode-0600 file, without following a final symlink. Its actual read is bounded even if the file grows after stat.
func SaveEnrollment ¶
func SaveEnrollment(path string, enrollment Enrollment) error
Types ¶
type Enrollment ¶
type Enrollment struct {
DeviceID [16]byte `json:"device_id"`
DeviceKey [32]byte `json:"device_key"`
Timezone string `json:"timezone"`
}
func DecodeEnrollment ¶
func DecodeEnrollment(data []byte) (Enrollment, error)
DecodeEnrollment requires the exact private enrollment schema and rejects duplicate fields, abbreviated identity arrays, unknown fields and trailing JSON.
func LoadEnrollment ¶
func LoadEnrollment(path string) (Enrollment, error)
type Input ¶
type PendingEnrollment ¶
type PendingEnrollment struct {
// contains filtered or unexported fields
}
PendingEnrollment holds one exclusive candidate until a matching USB ACK. Close releases the directory handle; it never discards the candidate.
func StageEnrollment ¶
func StageEnrollment(path string, enrollment Enrollment) (*PendingEnrollment, error)
func (*PendingEnrollment) Close ¶
func (p *PendingEnrollment) Close() error
func (*PendingEnrollment) Confirm ¶
Confirm promotes only the staged request after a canonical successful ACK. Public inspect metadata alone is insufficient to recover an ambiguous write.