Files

37 lines
1.9 KiB
Markdown

# Local package verifier
`Verify(directory, expectedDigest)` accepts an absolute staging directory and a
canonical `sha256:` digest of its exact `manifest.json` bytes. It returns the
validated manifest, matching payload bytes keyed by relative path, and manifest
digest. On failure it returns a zero `Verified` and fixed diagnostic text without
embedding file contents, decoder errors, or filesystem paths.
The manifest is limited to 1 MiB, each payload to 4 MiB, and all payloads together
to 16 MiB. Metadata checks precede opening regular files; actual reads also have
a limit plus one overflow-detection byte and must match the observed size.
The manifest digest is checked before shared `wire.Decode` parses it.
Inventory is derived from at most 128 declared files and their parent directories.
Each directory is enumerated one entry at a time; an unexpected entry fails
immediately. Symlinks, special files, empty/unnecessary directories, and unlisted
files are rejected. Lowercase portable paths prevent case collisions. Files and
subdirectories are opened relative to `os.Root`, with identity checks around open.
The caller must select a trusted staging directory with trusted ancestors and
prevent concurrent mutation. These checks do not provide a transactional snapshot
or complete protection against hostile concurrent filesystem changes. Consumers
should use the returned bytes rather than reopen package files.
This authenticates bytes against a caller-provided trust anchor. It does not
authenticate a publisher, validate Compose semantics, or authorize execution.
Signature trust stores and executable policy are outside this package.
Tests use local temporary directories. Symlink cases skip only Windows error 1314
(missing symlink privilege). Linux-specific FIFO cases verify rejection without
opening the FIFO; run tests with a timeout, for example:
```text
go test ./internal/appbundle -count=1 -timeout=30s
go vet ./internal/appbundle
```