Documentation
¶
Index ¶
- type ActivationPreflighter
- type ActivationVerifierClassifier
- type ActiveNativeProjector
- type AutomaticActivationClassifier
- type ClientActivator
- type ClientDetector
- type CommandRunner
- type DataPathPreflighter
- type DeliveryPlanner
- type DeliveryTargetResolver
- type DuplexCapabilityRunner
- type DuplexCommandRunner
- type LegacyLifecycle
- type LegacyRemovalPlan
- type ManagedStdioPreflighter
- type MutationLock
- type NativeTransitionActivationFence
- type NativeTransitionRecovery
- type NativeTransitionState
- type OpenCodeHostPreparer
- type OpenCodeTransitionRecorder
- type PackageLoader
- type PackageSecurityEvaluator
- type PackageStager
- type PathPolicy
- type PhysicalProfileAuthority
- type PluginDataAwareStager
- type SchemaRegistry
- type TargetedVersionProbingClientDetector
- type TreeCommandRunner
- type UnlockFunc
- type VerificationError
- type VerificationKind
- type VersionProbingClientDetector
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type ActivationPreflighter ¶
type ActivationPreflighter interface {
PreflightActivation(domain.ActivationRequest) error
}
ActivationPreflighter lets an activator reject a request before any client or managed file is touched.
type ActivationVerifierClassifier ¶
type ActivationVerifierClassifier interface {
VerifierAvailable(client domain.DetectedClient, plan domain.DeliveryPlan, backendExecutable string) bool
}
ActivationVerifierClassifier reports whether an exact client-side verifier can observe this plan, which decides if prior activation evidence may be retained instead of re-derived.
type ActiveNativeProjector ¶
type ActiveNativeProjector interface {
ProjectActiveNative(context.Context, domain.PackageEnvelope, domain.DeliveryPlan, string, string) ([]domain.NativeObjectOwnership, error)
}
ActiveNativeProjector computes native delivery from a digest-verified active package. It must not write to the package or inspect external client state.
type AutomaticActivationClassifier ¶
type AutomaticActivationClassifier interface {
AutomaticallyActivates(domain.ActivationRequest) bool
}
AutomaticActivationClassifier reports that activation completes without a user step, so no manual follow-up action is recorded.
type ClientActivator ¶
type ClientActivator interface {
Activate(context.Context, domain.ActivationRequest) (domain.ActivationOutcome, error)
Deactivate(context.Context, domain.DeactivationRequest) (domain.DeactivationOutcome, error)
}
type ClientDetector ¶
type ClientDetector interface {
Detect(context.Context) ([]domain.DetectedClient, error)
}
type CommandRunner ¶
type CommandRunner interface {
Run(context.Context, legacyports.Command) (legacyports.CommandResult, error)
}
CommandRunner executes one client command. Command and CommandResult stay in install/integrationctl/ports: they are plain data with no behavior, and duplicating them into domain would create a second source of truth and a conversion on every call. See docs/ARCHITECTURE.md.
type DataPathPreflighter ¶
DataPathPreflighter reports the effective plugin data path for a component and whether it is available on this host.
type DeliveryPlanner ¶
type DeliveryPlanner interface {
Plan(context.Context, domain.PlanRequest) (domain.DeliveryPlan, error)
}
DeliveryPlanner resolves one request into a plan with its install intent already applied. The use case never applies intent itself.
type DeliveryTargetResolver ¶
type DeliveryTargetResolver interface {
ResolveTarget(context.Context, domain.DetectedClient, domain.InstallScope, string) (domain.DeliveryTarget, error)
}
type DuplexCapabilityRunner ¶
type DuplexCapabilityRunner interface {
DuplexCommandRunner
DuplexCapability() error
}
DuplexCapabilityRunner reports whether duplex execution is actually available on this platform before an observation is attempted.
type DuplexCommandRunner ¶
type DuplexCommandRunner interface {
RunDuplexWithPlannedShutdown(context.Context, legacyports.Command, func(io.Writer, io.Reader) error) error
}
DuplexCommandRunner is an opt-in capability for protocols that must write to stdin and read stdout of the same live process, then shut it down by plan.
type LegacyLifecycle ¶
type LegacyLifecycle interface {
Exists(context.Context, string) (bool, error)
PlanRemove(context.Context, string) (LegacyRemovalPlan, error)
Remove(context.Context, string) (LegacyRemovalPlan, error)
}
LegacyLifecycle keeps migrated plugin.yaml installations removable through their original engine. It never parses or converts plugin.yaml as a standard Agent Plugin.
type LegacyRemovalPlan ¶
type ManagedStdioPreflighter ¶
ManagedStdioPreflighter resolves a declared stdio helper against the managed runtime before the plan promises to deliver it.
type MutationLock ¶
type MutationLock interface {
Acquire(context.Context) (UnlockFunc, error)
}
MutationLock serializes every state and managed-directory mutation across processes. Read-only planning deliberately does not acquire it.
type NativeTransitionActivationFence ¶
type NativeTransitionActivationFence interface {
HoldsActivation(installationID, bindingID string) (bool, error)
}
NativeTransitionActivationFence keeps generic lifecycle publication from changing the exact snapshot governed by a retained native record.
type NativeTransitionState ¶
type NativeTransitionState interface {
Load() (domain.StateFileV2, error)
PersistStateDecisionWithDisposition(domain.StateFileV2, domain.StateFileV2) (domain.StateDecisionDisposition, error)
}
type OpenCodeHostPreparer ¶
type OpenCodeHostPreparer interface {
PrepareOpenCodeHost(context.Context, domain.DetectedClient, domain.PackageEnvelope) (domain.DetectedClient, error)
RevalidateOpenCodeHost(context.Context, domain.DetectedClient) error
}
OpenCodeHostPreparer is trusted composition authority. Preparation may probe only an explicit desired-native target; revalidation fences authoritative effects. Dry-run and stored inspect/remove/recovery never call this port.
type OpenCodeTransitionRecorder ¶
type OpenCodeTransitionRecorder interface {
PersistPrepared(context.Context, domain.NativeAttemptIdentity, string, domain.OpenCodeTransitionPrepared, []domain.NativeObjectOwnership, []domain.NativeObjectOwnership) error
Reconcile(context.Context, string) (domain.NativeEffectState, error)
}
type PackageLoader ¶
type PackageSecurityEvaluator ¶
type PackageSecurityEvaluator interface {
Evaluate(context.Context, domain.SecurityEvaluationInput) (domain.SecurityAssessment, error)
}
PackageSecurityEvaluator inspects the already acquired immutable snapshot. It must complete before any client or managed package file is changed.
type PackageStager ¶
type PackageStager interface {
Stage(context.Context, domain.PackageEnvelope, domain.DeliveryPlan, string, domain.CompatibilityHints) (domain.StagedDelivery, error)
Discard(context.Context, domain.StagedDelivery) error
Verify(context.Context, string, string) error
}
type PathPolicy ¶
type PathPolicy interface {
// ValidateLeafID rejects an identifier that is not one portable, relative
// filesystem path component.
ValidateLeafID(value string) error
// RequireContainedChild rejects a candidate that is not a strict lexical
// child of base, or whose existing ancestry contains a symlink.
RequireContainedChild(base, candidate string) error
// RequireExactPath rejects a candidate that is not the exact expected
// managed path, and then applies RequireContainedChild to it.
RequireExactPath(expected, candidate string) error
}
PathPolicy is the containment contract every destructive or path-trusting decision goes through. The only implementation is adapters/pathpolicy.Policy; a permissive stand-in would silently disable symlink and escape rejection, so internal/archtest fails the build on a second implementation and ports/contracttest is the mandatory harness for any candidate.
type PhysicalProfileAuthority ¶
type PhysicalProfileAuthority interface {
CaptureProfileAuthority(context.Context, domain.DetectedClient) (domain.ProfileAuthority, error)
RevalidateProfileAuthority(context.Context, domain.ClientID, domain.ProfileAuthority) error
}
PhysicalProfileAuthority is explicitly implemented only by opted-in adapters. Capture is for a new owner; revalidation never discovers or recaptures a root.
type PluginDataAwareStager ¶
type PluginDataAwareStager interface {
StageWithPluginData(context.Context, domain.PackageEnvelope, domain.DeliveryPlan, string, domain.CompatibilityHints, string) (domain.StagedDelivery, error)
}
PluginDataAwareStager stages a package that also owns a plugin data directory, so staging and data provisioning commit as one unit.
type SchemaRegistry ¶
type TargetedVersionProbingClientDetector ¶
type TargetedVersionProbingClientDetector interface {
DetectTargetsWithVersionProbe(context.Context, []domain.ClientID) ([]domain.DetectedClient, error)
}
TargetedVersionProbingClientDetector observes versions only for explicitly selected clients while retaining read-only surface detection for all clients.
type TreeCommandRunner ¶
type TreeCommandRunner interface {
RunWithTreeExitGrace(context.Context, legacyports.Command, time.Duration) (legacyports.CommandResult, error)
}
TreeCommandRunner is an opt-in capability: the runner contains the whole process tree and reports the exit only after descendants are gone, so an observation is never based on descendant sampling.
type UnlockFunc ¶
type UnlockFunc func() error
type VerificationError ¶
type VerificationError struct {
Kind VerificationKind
ActualDigest string
Err error
}
VerificationError classifies integrity failures without converting an infrastructure error into evidence that a managed directory drifted.
func (*VerificationError) Error ¶
func (err *VerificationError) Error() string
func (*VerificationError) Unwrap ¶
func (err *VerificationError) Unwrap() error
type VerificationKind ¶
type VerificationKind string
const ( VerificationAbsent VerificationKind = "absent" VerificationDigestMismatch VerificationKind = "digest_mismatch" VerificationIndeterminate VerificationKind = "indeterminate" VerificationExcludedMarker VerificationKind = "excluded_ownership_marker" )
type VersionProbingClientDetector ¶
type VersionProbingClientDetector interface {
DetectWithVersionProbe(context.Context) ([]domain.DetectedClient, error)
}
VersionProbingClientDetector is an opt-in capability for mutating lifecycle resolution that must bind signed evidence to an exact installed version.
Source Files
¶
Directories
¶
| Path | Synopsis |
|---|---|
|
Package contracttest holds the executable contracts a port implementation has to satisfy.
|
Package contracttest holds the executable contracts a port implementation has to satisfy. |