37 lines
1.9 KiB
Markdown
37 lines
1.9 KiB
Markdown
# Local package verifier
|
|
|
|
`Verify(directory, expectedDigest)` accepts an absolute staging directory and a
|
|
canonical `sha256:` digest of its exact `manifest.json` bytes. It returns the
|
|
validated manifest, matching payload bytes keyed by relative path, and manifest
|
|
digest. On failure it returns a zero `Verified` and fixed diagnostic text without
|
|
embedding file contents, decoder errors, or filesystem paths.
|
|
|
|
The manifest is limited to 1 MiB, each payload to 4 MiB, and all payloads together
|
|
to 16 MiB. Metadata checks precede opening regular files; actual reads also have
|
|
a limit plus one overflow-detection byte and must match the observed size.
|
|
The manifest digest is checked before shared `wire.Decode` parses it.
|
|
|
|
Inventory is derived from at most 128 declared files and their parent directories.
|
|
Each directory is enumerated one entry at a time; an unexpected entry fails
|
|
immediately. Symlinks, special files, empty/unnecessary directories, and unlisted
|
|
files are rejected. Lowercase portable paths prevent case collisions. Files and
|
|
subdirectories are opened relative to `os.Root`, with identity checks around open.
|
|
|
|
The caller must select a trusted staging directory with trusted ancestors and
|
|
prevent concurrent mutation. These checks do not provide a transactional snapshot
|
|
or complete protection against hostile concurrent filesystem changes. Consumers
|
|
should use the returned bytes rather than reopen package files.
|
|
|
|
This authenticates bytes against a caller-provided trust anchor. It does not
|
|
authenticate a publisher, validate Compose semantics, or authorize execution.
|
|
Signature trust stores and executable policy are outside this package.
|
|
|
|
Tests use local temporary directories. Symlink cases skip only Windows error 1314
|
|
(missing symlink privilege). Linux-specific FIFO cases verify rejection without
|
|
opening the FIFO; run tests with a timeout, for example:
|
|
|
|
```text
|
|
go test ./internal/appbundle -count=1 -timeout=30s
|
|
go vet ./internal/appbundle
|
|
```
|