| Safe Haskell | None |
|---|---|
| Language | GHC2021 |
Ecluse.Core.Package
Description
The ecosystem-neutral package model used by admission and rules. Artifact entry keys retain source coordinates while adapters keep ownership of wire formats.
Synopsis
- data Scope
- mkScope :: Text -> Scope
- unScope :: Scope -> Text
- renderScope :: Scope -> Text
- data PackageName
- mkPackageName :: Ecosystem -> Maybe Scope -> Text -> PackageName
- pkgEcosystem :: PackageName -> Ecosystem
- pkgNamespace :: PackageName -> Maybe Scope
- pkgCanonical :: PackageName -> ShortText
- pkgBaseName :: PackageName -> ShortText
- renderPackageName :: PackageName -> Text
- unscopedName :: PackageName -> Text
- isAsciiNameComponent :: Text -> Bool
- canonicalise :: Ecosystem -> Text -> Text
- data CodeExecSignal
- data Availability
- data Artifact = Artifact {}
- data Hash
- hashAlg :: Hash -> HashAlg
- hashValue :: Hash -> Text
- mkHash :: HashAlg -> Text -> Either Text Hash
- mkSriHashes :: Text -> Either Text (NonEmpty Hash)
- data HashAlg
- renderHashAlg :: HashAlg -> Text
- parseHashAlg :: Text -> Either Text HashAlg
- sriPrefix :: Text -> Text
- sriBody :: Text -> Text
- sriAlgorithm :: Text -> Maybe HashAlg
- computeDigest :: HashAlg -> Maybe (LByteString -> ByteString)
- isComputable :: HashAlg -> Bool
- data PackageDetails = PackageDetails {}
- data PackageInfo = PackageInfo {}
- data InvalidEntry
- mkInvalidEntry :: InvalidEntryKind -> Text -> Value -> Text -> InvalidEntry
- data InvalidEntryKind
- renderInvalidEntryKind :: InvalidEntryKind -> Text
- dropCountsByKind :: [InvalidEntry] -> Map Text Int
Scopes
An npm scope, stored without its leading '@' (the scope of @myorg/pkg is
"myorg"). mkScope normalises away a leading '@', so equality does not depend on
how the scope was written.
renderScope :: Scope -> Text Source #
Render a scope in npm wire form, with the leading '@'.
Package identity
data PackageName Source #
A package identity, decoupled from any registry's wire format and built with
mkPackageName. Equality and ordering read ( only, so pkgEcosystem, pkgNamespace,
pkgCanonical)Flask and flask are one PyPI package and two npm ones.
Instances
| Show PackageName Source # | |
Defined in Ecluse.Core.Package Methods showsPrec :: Int -> PackageName -> ShowS # show :: PackageName -> String # showList :: [PackageName] -> ShowS # | |
| Eq PackageName Source # | |
Defined in Ecluse.Core.Package | |
| Ord PackageName Source # | |
Defined in Ecluse.Core.Package Methods compare :: PackageName -> PackageName -> Ordering # (<) :: PackageName -> PackageName -> Bool # (<=) :: PackageName -> PackageName -> Bool # (>) :: PackageName -> PackageName -> Bool # (>=) :: PackageName -> PackageName -> Bool # max :: PackageName -> PackageName -> PackageName # min :: PackageName -> PackageName -> PackageName # | |
mkPackageName :: Ecosystem -> Maybe Scope -> Text -> PackageName Source #
Build a PackageName, normalising the canonical key for the ecosystem: PEP 503 for
PyPI, verbatim for npm and RubyGems.
pkgEcosystem :: PackageName -> Ecosystem Source #
The ecosystem this name belongs to.
pkgNamespace :: PackageName -> Maybe Scope Source #
The scope, if scoped (npm @scope/name). Nothing for PyPI/RubyGems.
pkgCanonical :: PackageName -> ShortText Source #
The normalised matching key: PEP 503 for PyPI, verbatim for npm and RubyGems.
pkgBaseName :: PackageName -> ShortText Source #
The base name with any @scope/ prefix dropped. It is not part of identity. Read it
back through unscopedName.
renderPackageName :: PackageName -> Text Source #
Render a package name in its native wire form (the display name).
unscopedName :: PackageName -> Text Source #
The unscoped (base) name as Text: @babel/code-frame reads back as code-frame.
The name charset boundary
isAsciiNameComponent :: Text -> Bool Source #
Whether one component of a package name is ASCII with no control character: the boundary every ecosystem's grammar rests on, because an invisible codepoint renders two names as one.
Canonical keys
canonicalise :: Ecosystem -> Text -> Text Source #
Normalise a display name into its canonical matching key for an ecosystem. An ecosystem with a normalisation grammar keeps it in its own module.
Normalised signals
data CodeExecSignal Source #
Whether installing a version executes code (the cross-ecosystem unification of npm install scripts, PyPI sdist builds, and RubyGems native extensions).
Constructors
| NoCodeOnInstall | Determined: installation runs no code. |
| RunsCodeOnInstall Text | Determined: installation runs code. The text says how, for the audit trail. |
| CodeExecUnknown | Not yet determined (e.g. nothing has fetched the RubyGems gemspec yet). Pure rules abstain, and the effectful tier may resolve it. |
Instances
| Show CodeExecSignal Source # | |
Defined in Ecluse.Core.Package Methods showsPrec :: Int -> CodeExecSignal -> ShowS # show :: CodeExecSignal -> String # showList :: [CodeExecSignal] -> ShowS # | |
| Eq CodeExecSignal Source # | |
Defined in Ecluse.Core.Package Methods (==) :: CodeExecSignal -> CodeExecSignal -> Bool # (/=) :: CodeExecSignal -> CodeExecSignal -> Bool # | |
data Availability Source #
Whether a version is offered, advisory-deprecated, or withdrawn.
Constructors
| Available | Offered normally. |
| Deprecated Text | Advisory deprecation (npm), still resolvable. Carries the message. |
| Yanked (Maybe Text) | Withdrawn from resolution (PyPI yank keeps the file, RubyGems yank removes it). Carries the reason, if given. |
Instances
| Show Availability Source # | |
Defined in Ecluse.Core.Package Methods showsPrec :: Int -> Availability -> ShowS # show :: Availability -> String # showList :: [Availability] -> ShowS # | |
| Eq Availability Source # | |
Defined in Ecluse.Core.Package | |
Artifacts
One distribution file for a version. A version owns a NonEmpty list of
these: npm has exactly one, PyPI has an sdist plus many wheels, RubyGems has one
per platform.
Constructors
| Artifact | |
Fields
| |
Instances
An artifact digest validated by mkHash. Record updates must preserve its encoding and length.
hashValue :: Hash -> Text Source #
The digest itself, in the algorithm's wire encoding (e.g. hex, or the
single sha512-… component for SRI).
mkHash :: HashAlg -> Text -> Either Text Hash Source #
Validate encoding and digest length, preserving the wire spelling. Strength is a separate admission decision.
mkSriHashes :: Text -> Either Text (NonEmpty Hash) Source #
Split SRI components, rejecting the whole string when empty or when any component is malformed.
A hash algorithm an integrity digest is computed with. The Ord instance is integrity
authority, not constructor order: SRI < MD5 < SHA1 < SHA256 < SHA384 < Blake2b < SHA512.
Constructors
| SHA1 | |
| SHA256 | |
| SHA384 | |
| SHA512 | |
| MD5 | |
| Blake2b | |
| SRI | One Subresource-Integrity component. |
Instances
Algorithm vocabulary
renderHashAlg :: HashAlg -> Text Source #
The canonical lowercase name, also used in configuration and error text.
parseHashAlg :: Text -> Either Text HashAlg Source #
Parse canonical names and single-dash aliases, ignoring case and surrounding whitespace. SRI is not selectable.
sriPrefix :: Text -> Text Source #
The token before the first dash. Without a dash, the entire string is the prefix.
sriAlgorithm :: Text -> Maybe HashAlg Source #
Resolve an SRI prefix. An unsupported prefix asserts no algorithm and clears no integrity floor.
Digest computation
computeDigest :: HashAlg -> Maybe (LByteString -> ByteString) Source #
Digest computation for verifiable algorithms. MD5 cannot prove integrity, and SRI must first resolve its algorithm.
isComputable :: HashAlg -> Bool Source #
Whether the worker can compute and verify the algorithm.
Per-version details
data PackageDetails Source #
The ecosystem-agnostic snapshot of one package version: the signals a rule sees and the artifact facts that merge, admission, serving and the mirror read. Adapters project into it.
Constructors
| PackageDetails | |
Fields
| |
Instances
| Show PackageDetails Source # | |
Defined in Ecluse.Core.Package Methods showsPrec :: Int -> PackageDetails -> ShowS # show :: PackageDetails -> String # showList :: [PackageDetails] -> ShowS # | |
| Eq PackageDetails Source # | |
Defined in Ecluse.Core.Package Methods (==) :: PackageDetails -> PackageDetails -> Bool # (/=) :: PackageDetails -> PackageDetails -> Bool # | |
Packument-level view
data PackageInfo Source #
The packument-level view of a package (PackageDetails is the per-version snapshot
embedded within it). A registry adapter projects its packument into this type, so the proxy
core never sees the wire format.
Constructors
| PackageInfo | |
Fields
| |
Instances
| Show PackageInfo Source # | |
Defined in Ecluse.Core.Package Methods showsPrec :: Int -> PackageInfo -> ShowS # show :: PackageInfo -> String # showList :: [PackageInfo] -> ShowS # | |
| Eq PackageInfo Source # | |
Defined in Ecluse.Core.Package | |
Dropped entries
data InvalidEntry Source #
A single registry-document entry a projection dropped as malformed rather than failing the whole document, kept so an operator can see that an upstream served one, and which.
Instances
| Show InvalidEntry Source # | |
Defined in Ecluse.Core.Package.InvalidEntry Methods showsPrec :: Int -> InvalidEntry -> ShowS # show :: InvalidEntry -> String # showList :: [InvalidEntry] -> ShowS # | |
| Eq InvalidEntry Source # | |
Defined in Ecluse.Core.Package.InvalidEntry | |
mkInvalidEntry :: InvalidEntryKind -> Text -> Value -> Text -> InvalidEntry Source #
Record a dropped entry, reducing every URL in the key and the value to its authority: an upstream-supplied artifact location can carry a credential, and this record reaches a log line.
data InvalidEntryKind Source #
Which kind of registry-document entry a dropped InvalidEntry came from. A dropped manifest
or index file loses a serve candidate, a dropped tag, time or listing only its own datum.
Constructors
| InvalidVersionManifest | A |
| InvalidDistTag | A |
| InvalidPublishTime | A |
| InvalidIndexFile | A Simple-index file entry that did not project (no name or location, an unusable digest). |
| InvalidVersionListing | A versions-listing entry that was not a usable version string. |
Instances
| Show InvalidEntryKind Source # | |
Defined in Ecluse.Core.Package.InvalidEntry Methods showsPrec :: Int -> InvalidEntryKind -> ShowS # show :: InvalidEntryKind -> String # showList :: [InvalidEntryKind] -> ShowS # | |
| Eq InvalidEntryKind Source # | |
Defined in Ecluse.Core.Package.InvalidEntry Methods (==) :: InvalidEntryKind -> InvalidEntryKind -> Bool # (/=) :: InvalidEntryKind -> InvalidEntryKind -> Bool # | |
| Ord InvalidEntryKind Source # | |
Defined in Ecluse.Core.Package.InvalidEntry Methods compare :: InvalidEntryKind -> InvalidEntryKind -> Ordering # (<) :: InvalidEntryKind -> InvalidEntryKind -> Bool # (<=) :: InvalidEntryKind -> InvalidEntryKind -> Bool # (>) :: InvalidEntryKind -> InvalidEntryKind -> Bool # (>=) :: InvalidEntryKind -> InvalidEntryKind -> Bool # max :: InvalidEntryKind -> InvalidEntryKind -> InvalidEntryKind # min :: InvalidEntryKind -> InvalidEntryKind -> InvalidEntryKind # | |
renderInvalidEntryKind :: InvalidEntryKind -> Text Source #
The operator-facing label for a drop kind. It is the bucket key an operator filters on, so it is held stable as this text rather than the constructor name.
dropCountsByKind :: [InvalidEntry] -> Map Text Int Source #
How many entries dropped under each kind's label. Only the kinds actually seen appear, so a document's drop profile carries no bucket its ecosystem has no entries for.