feat: add deployment foundation and cross-device handoff

This commit is contained in:
2026-09-25 08:49:19 +08:00
parent 8ccb8b7c15
commit e965b0943d
77 changed files with 8018 additions and 0 deletions
+70
View File
@@ -0,0 +1,70 @@
// Package inspect reports local prerequisite observations without executing
// commands, connecting to Docker or altering configuration.
package inspect
import (
"errors"
"io/fs"
"os"
"runtime"
)
type Report struct {
ProtocolVersion int `json:"protocolVersion"`
OS string `json:"os"`
Architecture string `json:"architecture"`
SupportedPlatform bool `json:"supportedPlatform"`
SystemdRuntime string `json:"systemdRuntime"`
DockerClient string `json:"dockerClient"`
DockerDaemon string `json:"dockerDaemon"`
Compose string `json:"compose"`
Unchecked []string `json:"unchecked"`
DeploymentReady bool `json:"deploymentReady"`
}
func Collect() Report { return Probe(runtime.GOOS, runtime.GOARCH, os.DirFS("/")) }
// Probe observes filesystem metadata only. "present" is not an assertion that
// systemd is responsive or the Docker executable is authentic or operational.
func Probe(goos, arch string, files fs.FS) Report {
r := Report{ProtocolVersion: 1, OS: goos, Architecture: arch, SupportedPlatform: goos == "linux" && (arch == "amd64" || arch == "arm64"), SystemdRuntime: "not_checked", DockerClient: "not_checked", DockerDaemon: "not_checked", Compose: "not_checked", Unchecked: []string{"docker_daemon", "compose_version", "host_identity", "distribution_support", "permissions", "disk_space", "ports", "dns", "firewall", "gateway"}}
if goos != "linux" {
return r
}
r.SystemdRuntime = observe(files, "run/systemd/system", true)
r.DockerClient = observe(files, "usr/bin/docker", false)
if r.DockerClient != "present" {
alternate := observe(files, "usr/local/bin/docker", false)
// Either known executable establishes presence. Otherwise retain any
// uncertainty instead of reporting absence from an incomplete check.
switch {
case alternate == "present":
r.DockerClient = "present"
case r.DockerClient == "unknown" || alternate == "unknown":
r.DockerClient = "unknown"
case r.DockerClient == "invalid" || alternate == "invalid":
r.DockerClient = "invalid"
}
}
return r
}
func observe(files fs.FS, path string, directory bool) string {
info, err := fs.Stat(files, path)
if errors.Is(err, fs.ErrNotExist) {
return "missing"
}
if err != nil {
return "unknown"
}
if directory {
if info.IsDir() {
return "present"
}
return "invalid"
}
if !info.Mode().IsRegular() || info.Mode().Perm()&0111 == 0 {
return "invalid"
}
return "present"
}
+110
View File
@@ -0,0 +1,110 @@
package inspect
import (
"io/fs"
"os"
"path/filepath"
"testing"
"testing/fstest"
)
func TestReportsFactsWithoutClaimingDeploymentReadiness(t *testing.T) {
files := fstest.MapFS{
"run/systemd/system": &fstest.MapFile{Mode: os.ModeDir | 0755},
"usr/bin/docker": &fstest.MapFile{Mode: 0755, Data: []byte("not executed")},
}
r := Probe("linux", "amd64", files)
if !r.SupportedPlatform || r.SystemdRuntime != "present" || r.DockerClient != "present" || r.DeploymentReady {
t.Fatalf("incorrect report: %+v", r)
}
if r.DockerDaemon != "not_checked" || r.Compose != "not_checked" {
t.Fatal("claimed unperformed checks")
}
}
func TestMissingAndUnsupportedEnvironment(t *testing.T) {
r := Probe("linux", "amd64", fstest.MapFS{})
if r.DockerClient != "missing" || r.SystemdRuntime != "missing" {
t.Fatalf("missing prerequisites masked: %+v", r)
}
r = Probe("windows", "amd64", fstest.MapFS{})
if r.SupportedPlatform || r.DeploymentReady || r.DockerClient != "not_checked" {
t.Fatal("Windows accepted as deployment target")
}
r = Probe("linux", "386", fstest.MapFS{})
if r.SupportedPlatform {
t.Fatal("unsupported architecture accepted")
}
}
func TestWrongFileKindsAndPermissions(t *testing.T) {
r := Probe("linux", "amd64", fstest.MapFS{
"run/systemd/system": &fstest.MapFile{Mode: 0644},
"usr/bin/docker": &fstest.MapFile{Mode: 0644},
})
if r.SystemdRuntime != "invalid" || r.DockerClient != "invalid" {
t.Fatalf("wrong file kinds accepted: %+v", r)
}
}
func TestRealDirectoryProbeDoesNotWrite(t *testing.T) {
dir := t.TempDir()
if err := os.MkdirAll(filepath.Join(dir, "run/systemd/system"), 0700); err != nil {
t.Fatal(err)
}
r := Probe("linux", "arm64", os.DirFS(dir))
if r.SystemdRuntime != "present" || r.DockerClient != "missing" {
t.Fatalf("bad real probe: %+v", r)
}
items, err := os.ReadDir(dir)
if err != nil || len(items) != 1 || items[0].Name() != "run" {
t.Fatal("probe changed filesystem")
}
}
type deniedFS struct{}
func (deniedFS) Open(string) (fs.File, error) { return nil, fs.ErrPermission }
func TestPermissionErrorsAreUnknownNotMissing(t *testing.T) {
r := Probe("linux", "amd64", deniedFS{})
if r.DockerClient != "unknown" || r.SystemdRuntime != "unknown" {
t.Fatalf("hid inspection failure: %+v", r)
}
}
func TestDockerAlternatePath(t *testing.T) {
r := Probe("linux", "amd64", fstest.MapFS{"usr/local/bin/docker": &fstest.MapFile{Mode: 0755}})
if r.DockerClient != "present" {
t.Fatal("alternate installation not found")
}
}
type pathDeniedFS struct{ fs.FS }
func (f pathDeniedFS) Open(name string) (fs.File, error) {
if name == "usr/bin/docker" {
return nil, fs.ErrPermission
}
return f.FS.Open(name)
}
func TestAlternateDockerAfterInvalidOrUnknownPrimary(t *testing.T) {
for _, mode := range []fs.FileMode{0644, fs.ModeDir | 0755} {
files := fstest.MapFS{
"usr/bin/docker": &fstest.MapFile{Mode: mode},
"usr/local/bin/docker": &fstest.MapFile{Mode: 0755},
}
if r := Probe("linux", "amd64", files); r.DockerClient != "present" {
t.Errorf("valid alternate overlooked after invalid primary: %+v", r)
}
}
files := pathDeniedFS{fstest.MapFS{"usr/local/bin/docker": &fstest.MapFile{Mode: 0755}}}
if r := Probe("linux", "amd64", files); r.DockerClient != "present" {
t.Errorf("valid alternate overlooked after inaccessible primary: %+v", r)
}
if r := Probe("linux", "amd64", pathDeniedFS{fstest.MapFS{}}); r.DockerClient != "unknown" {
t.Errorf("missing alternate masked inaccessible primary: %+v", r)
}
}