feat: add deployment foundation and cross-device handoff

This commit is contained in:
2026-09-25 08:49:19 +08:00
parent 8ccb8b7c15
commit e965b0943d
77 changed files with 8018 additions and 0 deletions
+34
View File
@@ -0,0 +1,34 @@
// Package aptrepo authenticates staged Docker APT metadata, never installs it.
package aptrepo
import (
"server-deploy/internal/installplan"
"time"
)
type Result struct {
ProtocolVersion int `json:"protocolVersion"`
RepositoryAuthenticated bool `json:"repositoryAuthenticated"`
PackageBytesVerified bool `json:"packageBytesVerified"`
Executable bool `json:"executable"`
VerifiedAt time.Time `json:"verifiedAt"`
PrimaryFingerprint string `json:"primaryFingerprint"`
Lock installplan.Lock `json:"lock"`
}
// Verify requires a trusted staging directory and trusted ancestors, with no
// concurrent writers. Returned JSON is evidence, not an execution capability.
func Verify(directory, suite, arch string, versions map[string]string, now time.Time) (Result, error) {
files, err := readStaging(directory)
if err != nil {
return Result{}, err
}
if err := authenticate(files, now); err != nil {
return Result{}, err
}
lock, err := Resolve(files["Release"], files["Packages"], suite, arch, versions, now)
if err != nil {
return Result{}, err
}
return Result{ProtocolVersion: 1, RepositoryAuthenticated: true, VerifiedAt: now.UTC().Truncate(time.Second), PrimaryFingerprint: dockerFingerprint, Lock: lock}, nil
}