sessionauthority

package
v0.144.4 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 18, 2026 License: Apache-2.0 Imports: 5 Imported by: 0

Documentation

Overview

Package sessionauthority defines the transport-neutral authority consumed by the shared pinned-worktree and successor-launch primitives. Protocol packages adapt their exact admitted aggregates to this narrow capability; a caller- supplied path or decoded projection is never sufficient authority.

Index

Constants

View Source
const (
	ContinuationEnvironment = "WB_SESSION_CONTINUATION_FILE"
	// ContinuationTracked is a repository-relative file authenticated by an
	// immutable Git commit, as used by the existing session-move protocol.
	ContinuationTracked ContinuationKind = "tracked"
	// ContinuationPrivate is a 0600 regular file outside the target worktree,
	// retained below the admitted aggregate directory.
	ContinuationPrivate     ContinuationKind = "private"
	LaunchRootPinnedClean   LaunchRootMode   = "pinned_clean"
	LaunchRootParkedLocal   LaunchRootMode   = "parked_local"
	LaunchRootParkedNeutral LaunchRootMode   = "parked_neutral"
)

Variables

This section is empty.

Functions

func ValidID

func ValidID(value string) bool

func ValidateMemberKey

func ValidateMemberKey(value string) error

Types

type ContinuationKind

type ContinuationKind string

type Fence

type Fence interface {
	HeldForSession(expectedRoot, aggregateID, digest string) bool
	RetainSessionDir(expectedRoot, aggregateID, digest string) (*os.File, error)
}

Fence is the descriptor-retaining execution authority common to admitted session protocols. RetainSessionDir returns a duplicate of the already- validated aggregate directory; implementations must not reopen an arbitrary caller path and treat a matching digest as equivalent authority.

type Launch

type Launch struct {
	AggregateID            string
	AggregateDigest        string
	AggregateFile          string
	SuccessorWBSessionID   string
	PredecessorWBSessionID string
	TargetMachine          string
	SourceRuntime          string
	SourceModel            string
	RequestedHarness       string
	RequestedModel         string
	PinnedCommit           string
	PinnedBranch           string
	ContinuationKind       ContinuationKind
	ContinuationPath       string
	ContinuationDigest     string
	// RootMode is immutable launch authority. Empty is accepted only as read
	// compatibility for legacy pinned-clean launch artifacts.
	RootMode LaunchRootMode
}

Launch is the immutable identity used by the one hardened tmux launcher. AggregateFile is authenticated inside the retained aggregate directory.

func (Launch) Validate

func (launch Launch) Validate() error

type LaunchRootMode

type LaunchRootMode string

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL