use core::fmt;
use crate::release_quarantine::{
ORDERED_CONTEXTS, ORDERED_SINKS, QuarantineWorkflowInventory, Sha256Digest, WorkflowIdentity,
rel_quar_00_a_ambient_authority_inventory, sha256_bounded,
};
use crate::release_quarantine_reachability::{
MutationReachabilityRecord, Rel02ReceiptState, rel_quar_00_b_reachability_denial,
};
pub const CANONICAL_DIGEST_DOMAIN: &[u8] = b"fastmcp-rel-quar-00-integration-v1\0";
pub const CANONICAL_INPUT_LIMIT_BYTES: usize = 65_536;
pub const PUBLIC_ENTRYPOINT_IDENTITY: &str = "quarantine_release_surface";
pub const INTEGRATION_REVISION: &str = "rel-quar-00-integration-v1";
pub const REQUIRED_WORKFLOW_IDENTITIES: usize = 2;
#[derive(Debug, Clone, PartialEq, Eq)]
pub struct ClosureDiagnostic {
pub code: &'static str,
pub field: String,
}
impl fmt::Display for ClosureDiagnostic {
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
write!(f, "{}: {}", self.code, self.field)
}
}
fn reject(code: &'static str, field: impl Into<String>) -> ClosureDiagnostic {
ClosureDiagnostic {
code,
field: field.into(),
}
}
#[derive(Debug, Clone, PartialEq, Eq)]
pub struct QuarantineClosureReceipt {
pub workflow_identities: usize,
pub contexts: usize,
pub sinks: usize,
pub externally_inert_cells: usize,
pub unresolved_provider_observations: usize,
pub rel_02_receipt: Rel02ReceiptState,
pub a_digest: Sha256Digest,
pub b_digest: Sha256Digest,
pub canonical_digest: Sha256Digest,
}
fn append_usize(buffer: &mut Vec<u8>, value: usize) {
buffer.extend_from_slice(&(value as u64).to_be_bytes());
}
fn append_bytes(buffer: &mut Vec<u8>, bytes: &[u8]) {
append_usize(buffer, bytes.len());
buffer.extend_from_slice(bytes);
}
fn append_str(buffer: &mut Vec<u8>, value: &str) {
append_bytes(buffer, value.as_bytes());
}
fn append_identity(buffer: &mut Vec<u8>, identity: &WorkflowIdentity) {
append_str(buffer, identity.workflow_name);
append_str(buffer, identity.path);
append_str(buffer, identity.revision);
append_str(buffer, identity.definition_sha256_hex);
append_usize(buffer, identity.actions.len());
for action in identity.actions {
append_str(buffer, action.name);
append_str(buffer, action.commit_sha);
}
append_str(buffer, identity.provider_disablement.tag());
}
#[must_use]
pub fn canonical_closure_bytes(
inventory: &QuarantineWorkflowInventory,
record: &MutationReachabilityRecord,
a_digest: &Sha256Digest,
b_digest: &Sha256Digest,
) -> Vec<u8> {
let mut buffer = Vec::with_capacity(16_384);
buffer.extend_from_slice(CANONICAL_DIGEST_DOMAIN);
append_bytes(&mut buffer, a_digest.as_bytes());
append_bytes(&mut buffer, b_digest.as_bytes());
append_usize(&mut buffer, REQUIRED_WORKFLOW_IDENTITIES);
append_identity(&mut buffer, &inventory.historical);
append_identity(&mut buffer, &inventory.quarantine);
append_usize(&mut buffer, record.cells.len());
for cell in &record.cells {
append_bytes(&mut buffer, cell.state_digest.as_bytes());
}
append_str(&mut buffer, record.provider_disabled.tag());
append_usize(&mut buffer, record.unresolved_historical_runs);
append_usize(
&mut buffer,
inventory.unresolved_provider_observations.len(),
);
append_usize(&mut buffer, record.counters.ambient_publish_triggers);
append_usize(&mut buffer, record.counters.mutation_permissions);
append_usize(&mut buffer, record.counters.secret_access);
append_usize(&mut buffer, record.counters.publication_processes);
append_usize(&mut buffer, record.counters.registry_requests);
append_usize(&mut buffer, record.counters.release_tag_asset_mutations);
append_usize(&mut buffer, record.counters.provider_grants);
append_str(&mut buffer, PUBLIC_ENTRYPOINT_IDENTITY);
append_str(&mut buffer, INTEGRATION_REVISION);
buffer
}
fn is_immutable_pin(sha: &str) -> bool {
sha.len() == 40
&& sha
.bytes()
.all(|b| b.is_ascii_digit() || (b'a'..=b'f').contains(&b))
}
pub fn rel_quar_00_integration_quarantine_closure(
inventory: &QuarantineWorkflowInventory,
record: &MutationReachabilityRecord,
) -> Result<QuarantineClosureReceipt, ClosureDiagnostic> {
let a_receipt = rel_quar_00_a_ambient_authority_inventory(inventory)
.map_err(|diagnostic| reject("E_A_SLICE", diagnostic.code))?;
let b_receipt = rel_quar_00_b_reachability_denial(record)
.map_err(|diagnostic| reject("E_B_SLICE", diagnostic.code))?;
if record.a_digest != a_receipt.canonical_digest {
return Err(reject("E_SLICE_BINDING", "record.a_digest"));
}
if inventory.ordered_contexts.len() != ORDERED_CONTEXTS.len() {
return Err(reject("E_CONTEXT_COUNT", "inventory.ordered_contexts"));
}
if inventory.ordered_sinks.len() != ORDERED_SINKS.len() {
return Err(reject("E_SINK_COUNT", "inventory.ordered_sinks"));
}
let expected_cells = ORDERED_CONTEXTS.len() * ORDERED_SINKS.len();
if a_receipt.reachability_cells != expected_cells {
return Err(reject("E_CELL_COUNT", "a_receipt.reachability_cells"));
}
if b_receipt.denial_cells != expected_cells {
return Err(reject("E_CELL_COUNT", "b_receipt.denial_cells"));
}
for identity in [&inventory.historical, &inventory.quarantine] {
for action in identity.actions {
if !is_immutable_pin(action.commit_sha) {
return Err(reject(
"E_ACTION_PIN",
format!("{}:{}", identity.path, action.name),
));
}
}
}
if let Some(field) = record.counters.first_non_zero() {
return Err(reject("E_COUNTER_NON_ZERO", field));
}
if record.provider_disabled != inventory.quarantine.provider_disablement {
return Err(reject("E_PROVIDER_STATE", "record.provider_disabled"));
}
if a_receipt.unresolved_provider_observations == 0 {
return Err(reject(
"E_UNRESOLVED_CLEARED",
"a_receipt.unresolved_provider_observations",
));
}
if record.rel_02_receipt != Rel02ReceiptState::Absent {
return Err(reject("E_REL_02_PRESENT", "record.rel_02_receipt"));
}
let bytes = canonical_closure_bytes(
inventory,
record,
&a_receipt.canonical_digest,
&b_receipt.canonical_digest,
);
let canonical_digest = sha256_bounded(&bytes, CANONICAL_INPUT_LIMIT_BYTES)
.map_err(|_| reject("E_CANONICAL_INPUT", "canonical_closure_bytes"))?;
Ok(QuarantineClosureReceipt {
workflow_identities: REQUIRED_WORKFLOW_IDENTITIES,
contexts: ORDERED_CONTEXTS.len(),
sinks: ORDERED_SINKS.len(),
externally_inert_cells: expected_cells,
unresolved_provider_observations: a_receipt.unresolved_provider_observations,
rel_02_receipt: record.rel_02_receipt,
a_digest: a_receipt.canonical_digest,
b_digest: b_receipt.canonical_digest,
canonical_digest,
})
}
pub fn quarantine_release_surface(
inventory: &QuarantineWorkflowInventory,
record: &MutationReachabilityRecord,
) -> Result<QuarantineClosureReceipt, ClosureDiagnostic> {
rel_quar_00_integration_quarantine_closure(inventory, record)
}