graduation

package
v0.182.4 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: Apache-2.0 Imports: 20 Imported by: 0

Documentation

Overview

Package graduation composes independently produced WB and deployment evidence into one strict, reviewable graduation receipt. It never turns a hand-written status field into a green release decision.

Index

Constants

View Source
const (
	RemoteTargetProducer = "wb.verify.receipt.remote-target.v1"
	DeploymentProducer   = "external.deployment-receipt.v1"
)
View Source
const SchemaVersion = 1

Variables

This section is empty.

Functions

func Digest

func Digest(raw []byte) string

func ValidateRemoteURL added in v0.62.2

func ValidateRemoteURL(repository, raw string) error

ValidateRemoteURL binds the recorded remote URL to the repository the receipt claims to graduate. Without it remote_url is an unchecked free-text field: any string satisfies a non-blank test, so a receipt can name one repository while citing a remote that publishes another. The check is host-neutral by construction — gitremote.Parse already rejects embedded credentials, query strings, fragments, encoded paths, and option-like arguments on every supported host, so WB does not need to know which forge served the remote in order to prove its identity.

Types

type CIWaitReceipt

type CIWaitReceipt struct {
	SchemaVersion int       `json:"schema_version"`
	ObservedAt    time.Time `json:"observed_at"`
	githubchecks.PullRequestWaitResult
}

CIWaitReceipt is exactly the JSON envelope emitted by `wb ci wait --json`.

func DecodeCIWaitReceipt

func DecodeCIWaitReceipt(raw []byte) (CIWaitReceipt, error)

type Component

type Component[T any] struct {
	SHA256     string    `json:"sha256"`
	ObservedAt time.Time `json:"observed_at"`
	Evidence   T         `json:"evidence"`
}

type DeployedRevisionEvidence

type DeployedRevisionEvidence struct {
	SchemaVersion       int       `json:"schema_version"`
	Producer            string    `json:"producer"`
	Provider            string    `json:"provider"`
	Repository          string    `json:"repository"`
	RunURL              string    `json:"run_url"`
	Revision            string    `json:"revision"`
	RevisionJSONPointer string    `json:"revision_json_pointer"`
	ObservedAt          time.Time `json:"observed_at"`
	PayloadJSON         string    `json:"payload_json"`
	PayloadSHA256       string    `json:"payload_sha256"`
}

DeployedRevisionEvidence is a provider-neutral immutable deployment receipt. A deployment adapter must retain its exact structured provider payload and content digest; free-form “passed” prose is intentionally not representable here.

func DecodeDeployedRevision

func DecodeDeployedRevision(raw []byte) (DeployedRevisionEvidence, error)

type EvidencePaths

type EvidencePaths struct{ LocalCheck, CIWait, RemoteTarget, DeployedRevision, TerminalCleanup, Output string }

EvidencePaths names independently produced evidence and an optional exclusive output.

type Inputs

type Inputs struct {
	LocalCheck             VerificationIndex
	LocalCheckSHA256       string
	LocalCheckObservedAt   time.Time
	CIWait                 CIWaitReceipt
	CIWaitSHA256           string
	CIWaitObservedAt       time.Time
	RemoteTarget           RemoteTargetEvidence
	RemoteTargetSHA256     string
	RemoteTargetObservedAt time.Time
	DeployedRevision       DeployedRevisionEvidence
	DeployedSHA256         string
	DeployedObservedAt     time.Time
	TerminalCleanup        TerminalCleanupEvidence
	CleanupSHA256          string
	CleanupObservedAt      time.Time
}

type LocalCIComponent

type LocalCIComponent struct {
	LocalCheck Component[VerificationIndex] `json:"local_check"`
	CIWait     Component[CIWaitReceipt]     `json:"ci_wait"`
}

type Observer

type Observer struct {
	Now    func() time.Time
	RunGit func(context.Context, string, ...string) ([]byte, error)
	// contains filtered or unexported fields
}

Observer executes evidence composition and authoritative Git observation without CLI dependencies.

func DefaultObserver

func DefaultObserver() Observer

func (Observer) ComposeFiles

func (service Observer) ComposeFiles(paths EvidencePaths) ([]byte, error)

func (Observer) ObserveRemoteTarget

func (service Observer) ObserveRemoteTarget(ctx context.Context, request RemoteTargetRequest) ([]byte, error)

type Receipt

type Receipt struct {
	SchemaVersion    int                                 `json:"schema_version"`
	Repository       string                              `json:"repository"`
	Revision         string                              `json:"revision"`
	CreatedAt        time.Time                           `json:"created_at"`
	LocalCI          LocalCIComponent                    `json:"local_ci"`
	RemoteTarget     Component[RemoteTargetEvidence]     `json:"remote_target"`
	DeployedRevision Component[DeployedRevisionEvidence] `json:"deployed_revision"`
	TerminalCleanup  Component[TerminalCleanupEvidence]  `json:"terminal_cleanup"`
}

Receipt retains the immutable source digest and observation time for every supplied producer document, so review can independently retrieve and hash each component.

func Compose

func Compose(inputs Inputs, now time.Time) (Receipt, error)

type RemoteTargetEvidence

type RemoteTargetEvidence struct {
	SchemaVersion        int       `json:"schema_version"`
	Producer             string    `json:"producer"`
	Repository           string    `json:"repository"`
	Remote               string    `json:"remote"`
	RemoteURL            string    `json:"remote_url"`
	TargetRef            string    `json:"target_ref"`
	Revision             string    `json:"revision"`
	ObservedAt           time.Time `json:"observed_at"`
	ObservedOutput       string    `json:"observed_output"`
	ObservedOutputSHA256 string    `json:"observed_output_sha256"`
}

RemoteTargetEvidence can only be emitted by `wb verify receipt remote-target`. The captured git-ls-remote payload and digest make the observed remote ref independently inspectable rather than an assertion.

func DecodeRemoteTarget

func DecodeRemoteTarget(raw []byte) (RemoteTargetEvidence, error)

type RemoteTargetRequest

type RemoteTargetRequest struct{ Repository, RepositoryPath, Remote, Target, Output string }

RemoteTargetRequest binds an observation to one configured remote and exact branch.

type TerminalCleanupEvidence

type TerminalCleanupEvidence struct {
	GeneratedAt  time.Time                          `json:"generated_at"`
	Phase        string                             `json:"phase"`
	Task         string                             `json:"task,omitempty"`
	Filter       string                             `json:"filter,omitempty"`
	AllMerged    bool                               `json:"all_merged"`
	Apply        bool                               `json:"apply"`
	DeleteRemote bool                               `json:"delete_remote"`
	OlderThan    string                             `json:"older_than"`
	Results      []worktrees.CleanupResult          `json:"results"`
	Diagnostics  []worktrees.ListDiagnostic         `json:"diagnostics,omitempty"`
	Artifacts    []worktrees.LifecycleArtifact      `json:"artifacts,omitempty"`
	Recovery     *worktrees.InterruptedLockRecovery `json:"recovery,omitempty"`
}

TerminalCleanupEvidence is the persistent JSON report written by `wb worktree cleanup <task> --apply --remote`. It names only feature/integration worktrees; a canonical target checkout is intentionally not deleted.

func DecodeTerminalCleanup

func DecodeTerminalCleanup(raw []byte) (TerminalCleanupEvidence, error)

type VerificationIndex

type VerificationIndex struct {
	SchemaVersion int                          `json:"schema_version"`
	GeneratedAt   time.Time                    `json:"generated_at"`
	Profile       string                       `json:"profile,omitempty"`
	Checks        []quality.Check              `json:"checks"`
	Repositories  []quality.VerificationReport `json:"repositories"`
}

VerificationIndex is exactly the JSON envelope emitted by `wb check --profile ci --format json`, copied here because the command package owns its renderer. It deliberately preserves the public quality report types.

func DecodeVerificationIndex

func DecodeVerificationIndex(raw []byte) (VerificationIndex, error)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL