ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Package.Admission

Description

The single public-version admission gate: the rules engine decides the version, the requested Filename selects the artifact, and the integrity floor decides whether that artifact's digests are strong enough to gate.

The serve path's tarball gate and the worker's ingest re-evaluation both call the one admitArtifact, so a version the worker would freeze into the rule-exempt mirror is exactly a version the serve gate would admit. Neither decides for itself whether a retry could change a refusal, which is admissionTransience, read by both.

Synopsis

Documentation

data ArtifactAdmission Source #

The admission verdict for one requested artifact. An inability to decide is no refusal: serve renders 503/500, and the worker redelivers or drops per admissionTransience.

Constructors

AdmissionAdmit Filename Artifact (NonEmpty Hash)

Admitted, with digests clearing the integrity floor. Carries the Filename the gate matched against current metadata, and the floor-checked digest set.

AdmissionDenied Decision

A rule, or deny-by-default, blocked the version. Carries the Decision so each consumer renders the deciding rule and reason on its own surface.

AdmissionUndecidable Decision

A fail-closed rule could not vet the version. Carries the Undecidable Decision, whose transience admissionTransience reads out for both consumers.

AdmissionFileAbsent

Admitted, but no artifact carries the requested filename: a forwarded miss on serve, a withdrawn-file drop at the worker, never a fabricated location.

AdmissionIntegrityMissing

The selected artifact carries no digest at all, so nothing ties its bytes to a fingerprint. Kept apart from AdmissionBelowFloor so the refusal can say which.

AdmissionBelowFloor

The selected artifact carries digests, but none meets the configured public-integrity floor (a legacy SHA-1 shasum only, under a SHA-256 floor).

admissionTransience :: ArtifactAdmission -> Maybe Transience Source #

The transience of a verdict no rule could decide, and Nothing for a settled one. The serve gate renders it as a 503 or a 500, and the mirror worker redelivers or drops on it.

admitArtifact Source #

Arguments

:: EvalContext 
-> [PreparedRule] 
-> MinIntegrity 
-> Filename

The requested artifact filename (the client's, or the mirror job's).

-> PackageDetails 
-> IO ArtifactAdmission 

Decide one requested artifact under current policy: the rules, then the filename, then the integrity floor. Serve and worker pass the same inputs, so re-evaluation can only narrow.

admitArtifactWithEvidence :: EvalContext -> [PreparedRule] -> MinIntegrity -> Filename -> PackageDetails -> IO (ArtifactAdmission, [SkippedCheck]) Source #

admitArtifact beside the skipped-check evidence its decision carried, empty unless the version was admitted, for the audit line the gate emits once.