feat: add deployment foundation and cross-device handoff
This commit is contained in:
@@ -0,0 +1,36 @@
|
||||
# Local package verifier
|
||||
|
||||
`Verify(directory, expectedDigest)` accepts an absolute staging directory and a
|
||||
canonical `sha256:` digest of its exact `manifest.json` bytes. It returns the
|
||||
validated manifest, matching payload bytes keyed by relative path, and manifest
|
||||
digest. On failure it returns a zero `Verified` and fixed diagnostic text without
|
||||
embedding file contents, decoder errors, or filesystem paths.
|
||||
|
||||
The manifest is limited to 1 MiB, each payload to 4 MiB, and all payloads together
|
||||
to 16 MiB. Metadata checks precede opening regular files; actual reads also have
|
||||
a limit plus one overflow-detection byte and must match the observed size.
|
||||
The manifest digest is checked before shared `wire.Decode` parses it.
|
||||
|
||||
Inventory is derived from at most 128 declared files and their parent directories.
|
||||
Each directory is enumerated one entry at a time; an unexpected entry fails
|
||||
immediately. Symlinks, special files, empty/unnecessary directories, and unlisted
|
||||
files are rejected. Lowercase portable paths prevent case collisions. Files and
|
||||
subdirectories are opened relative to `os.Root`, with identity checks around open.
|
||||
|
||||
The caller must select a trusted staging directory with trusted ancestors and
|
||||
prevent concurrent mutation. These checks do not provide a transactional snapshot
|
||||
or complete protection against hostile concurrent filesystem changes. Consumers
|
||||
should use the returned bytes rather than reopen package files.
|
||||
|
||||
This authenticates bytes against a caller-provided trust anchor. It does not
|
||||
authenticate a publisher, validate Compose semantics, or authorize execution.
|
||||
Signature trust stores and executable policy are outside this package.
|
||||
|
||||
Tests use local temporary directories. Symlink cases skip only Windows error 1314
|
||||
(missing symlink privilege). Linux-specific FIFO cases verify rejection without
|
||||
opening the FIFO; run tests with a timeout, for example:
|
||||
|
||||
```text
|
||||
go test ./internal/appbundle -count=1 -timeout=30s
|
||||
go vet ./internal/appbundle
|
||||
```
|
||||
Reference in New Issue
Block a user