hostprovision

package
v0.1.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: MIT Imports: 10 Imported by: 0

Documentation

Overview

Package hostprovision validates operator input and creates device enrollment.

Index

Constants

This section is empty.

Variables

View Source
var (
	ErrPending         = errors.New("host provisioning: recovery=1 unresolved .pending exists; retain both enrollment files, reopen USB and inspect; do not retry mutation")
	ErrStaging         = errors.New("host provisioning: recovery=2 staging failed; active enrollment preserved; inspect and retain any .pending before retry")
	ErrAcknowledgement = errors.New("host provisioning: recovery=3 ACK does not confirm candidate; retain active and .pending, reopen USB and inspect; do not retry mutation")
	ErrPromotion       = errors.New("host provisioning: recovery=4 promotion failed; retain active and .pending, reopen USB and inspect; do not retry mutation")
	ErrDurability      = errors.New("host provisioning: recovery=5 active candidate installed but directory sync failed; retain active, verify storage and reopen USB to inspect; do not retry mutation")
)
View Source
var ErrInput = errors.New("host provisioning: invalid input")
View Source
var ErrRegistry = errors.New("host provisioning: registry write failed")

Functions

func ReadPrivateFile

func ReadPrivateFile(path string, maximum int) ([]byte, error)

ReadPrivateFile reads an existing regular mode-0600 file, without following a final symlink. Its actual read is bounded even if the file grows after stat.

func SaveEnrollment

func SaveEnrollment(path string, enrollment Enrollment) error

Types

type Enrollment

type Enrollment struct {
	DeviceID  [16]byte `json:"device_id"`
	DeviceKey [32]byte `json:"device_key"`
	Timezone  string   `json:"timezone"`
}

func Create

func Create(input Input, identity *[16]byte, random io.Reader) (provision.Config, Enrollment, error)

func CreateFor

func CreateFor(codec provision.Codec, input Input, identity *[16]byte, random io.Reader) (provision.Config, Enrollment, error)

func DecodeEnrollment

func DecodeEnrollment(data []byte) (Enrollment, error)

DecodeEnrollment requires the exact private enrollment schema and rejects duplicate fields, abbreviated identity arrays, unknown fields and trailing JSON.

func LoadEnrollment

func LoadEnrollment(path string) (Enrollment, error)

type Input

type Input struct {
	SSID       string `json:"ssid"`
	Passphrase string `json:"passphrase"`
	Manager    string `json:"manager"`
	Timezone   string `json:"timezone,omitempty"`
}

func DecodeInput

func DecodeInput(reader io.Reader) (Input, error)

type PendingEnrollment

type PendingEnrollment struct {
	// contains filtered or unexported fields
}

PendingEnrollment holds one exclusive candidate until a matching USB ACK. Close releases the directory handle; it never discards the candidate.

func StageEnrollment

func StageEnrollment(path string, enrollment Enrollment) (*PendingEnrollment, error)

func (*PendingEnrollment) Close

func (p *PendingEnrollment) Close() error

func (*PendingEnrollment) Confirm

func (p *PendingEnrollment) Confirm(request provision.Request, response provision.Response) error

Confirm promotes only the staged request after a canonical successful ACK. Public inspect metadata alone is insufficient to recover an ambiguous write.

func (*PendingEnrollment) ConfirmFor

func (p *PendingEnrollment) ConfirmFor(codec provision.Codec, request provision.Request, response provision.Response) error

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL