34 lines
2.0 KiB
Markdown
34 lines
2.0 KiB
Markdown
# Read-only relevant dpkg inventory
|
|
|
|
`Inventory(fs.FS) Snapshot` reads fixed `var/lib/dpkg/status` (regular file,
|
|
nonempty, at most 16 MiB) and checks the fixed `var/lib/dpkg/updates` directory
|
|
is empty before and after reading. It invokes no package tools and writes nothing.
|
|
The filesystem must provide metadata via `fs.StatFS`; unsupported, inaccessible,
|
|
malformed, oversized, changing or journal-busy input returns `state=unknown`, an
|
|
empty digest and empty packages array. Missing status is not a clean machine.
|
|
|
|
It validates stanza structure/identity/status before filtering. Field names are
|
|
case-insensitive; duplicate keys, malformed scalar continuations and duplicate
|
|
package/architecture records are rejected. Descriptions/other values are never
|
|
returned. Distinct multiarch records are retained; ambiguous all/unspecified
|
|
architecture duplicates fail closed. Bare not-installed selections are permitted
|
|
and still returned when relevant, so a caller cannot mistake them for no record.
|
|
|
|
An observed snapshot contains the SHA-256 of the complete status file bytes and
|
|
deterministically ordered name/version/architecture/status records for:
|
|
docker-ce, docker-ce-cli, containerd.io, docker-buildx-plugin,
|
|
docker-compose-plugin, docker.io, docker-compose, docker-compose-v2, docker-doc,
|
|
docker-buildx, podman-docker, containerd and runc.
|
|
|
|
The `Installed` type means a database record exists, not that it is fully
|
|
installed. Callers must conservatively review **every** returned record, including
|
|
hold, partial installation, residual config and not-installed selections.
|
|
|
|
OS paths/ancestors and filesystem implementation are trusted. Metadata/journal
|
|
rechecks detect ordinary changes but do not lock dpkg or produce an atomic
|
|
transaction against concurrent writes. The digest is not a host identity or
|
|
approval. This does not scan custom package databases, rootless/manual runtimes,
|
|
APT sources, package dependencies, or unrelated packages' operational health.
|
|
|
|
Format reference: [Debian control files](https://www.debian.org/doc/debian-policy/ch-controlfields.html).
|