Files
server-deploy/internal/debian/README.md
T

34 lines
2.0 KiB
Markdown

# Read-only relevant dpkg inventory
`Inventory(fs.FS) Snapshot` reads fixed `var/lib/dpkg/status` (regular file,
nonempty, at most 16 MiB) and checks the fixed `var/lib/dpkg/updates` directory
is empty before and after reading. It invokes no package tools and writes nothing.
The filesystem must provide metadata via `fs.StatFS`; unsupported, inaccessible,
malformed, oversized, changing or journal-busy input returns `state=unknown`, an
empty digest and empty packages array. Missing status is not a clean machine.
It validates stanza structure/identity/status before filtering. Field names are
case-insensitive; duplicate keys, malformed scalar continuations and duplicate
package/architecture records are rejected. Descriptions/other values are never
returned. Distinct multiarch records are retained; ambiguous all/unspecified
architecture duplicates fail closed. Bare not-installed selections are permitted
and still returned when relevant, so a caller cannot mistake them for no record.
An observed snapshot contains the SHA-256 of the complete status file bytes and
deterministically ordered name/version/architecture/status records for:
docker-ce, docker-ce-cli, containerd.io, docker-buildx-plugin,
docker-compose-plugin, docker.io, docker-compose, docker-compose-v2, docker-doc,
docker-buildx, podman-docker, containerd and runc.
The `Installed` type means a database record exists, not that it is fully
installed. Callers must conservatively review **every** returned record, including
hold, partial installation, residual config and not-installed selections.
OS paths/ancestors and filesystem implementation are trusted. Metadata/journal
rechecks detect ordinary changes but do not lock dpkg or produce an atomic
transaction against concurrent writes. The digest is not a host identity or
approval. This does not scan custom package databases, rootless/manual runtimes,
APT sources, package dependencies, or unrelated packages' operational health.
Format reference: [Debian control files](https://www.debian.org/doc/debian-policy/ch-controlfields.html).