Expand description
Which platform an agent binary targets, read from its own bytes — the
single source of truth for the agent_releases Object Store key scheme.
Key scheme (backward compatible):
- Windows releases stay at the bare
<version>key — agents in the field fetch exactly that today, so any change would be a migration. (Windows aarch64 also maps to the bare key: the fleet is x86_64 in practice, and distinguishing it is a future problem.) - Linux releases live at
<version>-linux-<arch>(x86_64/aarch64), macOS releases at<version>-macos-<arch>. Semver prerelease dashes are fine because consumers always match the suffix (-linux-x86_64/-macos-aarch64/ …), never a dash mid-version.
Detection is by magic bytes, not filename: MZ → PE (arch from the
COFF header’s Machine field), \x7fELF → ELF (arch from e_machine),
thin 64-bit Mach-O → macOS (arch from cputype). Universal (fat)
Mach-O and 32-bit Mach-O are clear errors: a release key names exactly
one arch, so the operator publishes one thin binary per arch. Pure byte
inspection, no parsing library — the PE path only needs e_lfanew +
the COFF Machine field, which pelite (used for VERSIONINFO in
exe_version.rs) doesn’t surface as a bare number without dragging in
its full header model.
Enums§
- Agent
Platform - The platform an uploaded agent binary runs on.
Constants§
- LINUX_
SUFFIXES - Both Linux suffixes, for “any Linux key” scans (rollout checks).
- LINUX_
SUFFIX_ AARC H64 - Object Store key suffix for Linux aarch64 releases.
- LINUX_
SUFFIX_ X86_ 64 - Object Store key suffix for Linux x86_64 releases.
- MACOS_
SUFFIXES - Both macOS suffixes, for “any macOS key” scans.
- MACOS_
SUFFIX_ AARC H64 - Object Store key suffix for macOS aarch64 (Apple silicon) releases.
- MACOS_
SUFFIX_ X86_ 64 - Object Store key suffix for macOS x86_64 (Intel) releases.
- PLATFORM_
SUFFIXES - Every platform key suffix (all non-Windows platforms), in the order rollout existence checks probe them after the bare Windows key.
Functions§
- base_
version_ of_ key - The rollout-visible version for a store key: the key with any platform
suffix (linux / macos) stripped. A scope’s
target_versionalways names the BASE version (0.46.0, never0.46.0-linux-x86_64) — the agent’s own platform decides which suffixed binary it fetches — so guards that compare a key againsttarget_versionmust go through this. - candidate_
keys - Every store key a rollout’s existence check should accept for
version: the bare (Windows) key plus each linux and macOS platform key. A version is rollable-out when ANY of these exists — a Linux-only or macOS-only publish never writes the bare key. - check_
release_ key - The charset every
agent_releaseskey must fit: the key reaches a quotedContent-Dispositionfilename, generated PowerShell / batch / shell install scripts, and NATS subjects — restrict the charset (semver-ish) rather than escaping four different formats. Shared by the backend publish endpoint, the CLI publish, and the installer endpoint (which used to carry its own copy). - platform_
of_ key - The platform label for an existing store key, derived from its suffix:
"linux-x86_64"/"linux-aarch64"/"macos-x86_64"/"macos-aarch64"for suffixed keys,"windows"for anything else (bare keys are Windows by definition of the key scheme). Used by the releases listing, which only has keys to look at.