Files
server-deploy/internal/aptrepo/verify.go
T

35 lines
1.3 KiB
Go

// Package aptrepo authenticates staged Docker APT metadata, never installs it.
package aptrepo
import (
"server-deploy/internal/installplan"
"time"
)
type Result struct {
ProtocolVersion int `json:"protocolVersion"`
RepositoryAuthenticated bool `json:"repositoryAuthenticated"`
PackageBytesVerified bool `json:"packageBytesVerified"`
Executable bool `json:"executable"`
VerifiedAt time.Time `json:"verifiedAt"`
PrimaryFingerprint string `json:"primaryFingerprint"`
Lock installplan.Lock `json:"lock"`
}
// Verify requires a trusted staging directory and trusted ancestors, with no
// concurrent writers. Returned JSON is evidence, not an execution capability.
func Verify(directory, suite, arch string, versions map[string]string, now time.Time) (Result, error) {
files, err := readStaging(directory)
if err != nil {
return Result{}, err
}
if err := authenticate(files, now); err != nil {
return Result{}, err
}
lock, err := Resolve(files["Release"], files["Packages"], suite, arch, versions, now)
if err != nil {
return Result{}, err
}
return Result{ProtocolVersion: 1, RepositoryAuthenticated: true, VerifiedAt: now.UTC().Truncate(time.Second), PrimaryFingerprint: dockerFingerprint, Lock: lock}, nil
}