Documentation
¶
Overview ¶
Package archive runs a bootstrap archive: it verifies a version 1 archive, extracts it into a cache keyed by its payload digest, and runs the entrypoint it carries. It is the reader side of services/bootstrap's emitter, so a csf binary of this release runs a newer archive — the boot sector the brief freezes.
The format is frozen at version 1. A later format adds members or manifest fields; it never changes a field this reader reads, so a reader built today runs an archive built later.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Archive ¶
Archive is a verified version 1 bootstrap archive: its frozen manifest and the payload members the manifest's digest covers, in the order the archive carried them. The manifest itself is not a payload member.
func Read ¶
Read verifies the archive at path and returns it. It refuses an archive whose first member is not the version 1 manifest, whose format version this reader does not know, whose payload digest is not the manifest's, or whose platform this host cannot run — all before any byte is extracted.
type Member ¶
Member is one archive member after reading: its slash name, whether it is a directory, its permission bits and its content (a directory's is empty).
type Runner ¶
type Runner struct {
// contains filtered or unexported fields
}
Runner verifies, extracts and runs bootstrap archives.
func NewRunner ¶
NewRunner returns a runner that runs entrypoints through launcher and extracts archives under cache.
func (*Runner) Extract ¶
Extract writes the archive's members under the runner's cache, in a directory named by the payload digest, and returns that directory. Extracting the same archive twice is one directory: a second call reuses the first. The tree is built under a temporary sibling and renamed into place, so a reader never sees a half-extracted archive, and an archive that escapes its root — a name that is absolute or climbs out with ".." — is refused rather than written.
func (*Runner) Run ¶
func (r *Runner) Run(ctx context.Context, path string, args []string, stdin io.Reader, stdout, stderr io.Writer) (int, error)
Run verifies the archive at path, extracts it into the cache and runs its entrypoint with args, wiring the caller's streams through, and returns the entrypoint's exit code. The archive is verified before anything is extracted, so a tampered archive runs nothing.