pub struct MemorySource { /* private fields */ }Expand description
In-memory source — the test double, and the reference for how little a source is trusted to do.
Implementations§
Source§impl MemorySource
impl MemorySource
pub fn new() -> Self
pub fn with_manifest(self, bytes: &[u8]) -> Self
pub fn with_blob(self, digest: &str, bytes: &[u8]) -> Self
Sourcepub fn with_line_index(self, envelope: &[u8]) -> Self
pub fn with_line_index(self, envelope: &[u8]) -> Self
Attach a baseline line-status envelope the source carries beside the layer (REQ-STATUS-DIST-001). Carry a signed line index (REQ-INDEXAUTH-001).
Sourcepub fn serving(self, layers: &[&str]) -> Self
pub fn serving(self, layers: &[&str]) -> Self
What this source admits to serving. Setting it makes the source enumerable, which is what lets omission be detected — a source that never sets it cannot be accused of hiding.
pub fn with_line_status(self, envelope: &[u8]) -> Self
Sourcepub fn with_attestation(self, statement: &[u8], attested_bytes: &[u8]) -> Self
pub fn with_attestation(self, statement: &[u8], attested_bytes: &[u8]) -> Self
Carry an attestation beside the layer (REQ-ATTEST-002). The statement’s digest is derived from the bytes handed over, not declared: a source that could name its own content addresses would be trusted about something, and it is trusted about nothing.
Trait Implementations§
Source§impl Debug for MemorySource
impl Debug for MemorySource
Source§impl Default for MemorySource
impl Default for MemorySource
Source§fn default() -> MemorySource
fn default() -> MemorySource
Returns the “default value” for a type. Read more
Source§impl LayerSource for MemorySource
impl LayerSource for MemorySource
Source§fn fetch_manifest(&self, layer: &LayerRef) -> Result<Vec<u8>, SourceError>
fn fetch_manifest(&self, layer: &LayerRef) -> Result<Vec<u8>, SourceError>
Fetch the manifest bytes for a layer reference.
Source§fn fetch_blob(&self, digest: &str) -> Result<Vec<u8>, SourceError>
fn fetch_blob(&self, digest: &str) -> Result<Vec<u8>, SourceError>
Fetch a blob (a tool binary) by its digest (
sha256:<hex>).Source§fn fetch_line_index(&self, _line: &str) -> Result<Option<Vec<u8>>, SourceError>
fn fetch_line_index(&self, _line: &str) -> Result<Option<Vec<u8>>, SourceError>
Fetch the realm’s signed line-index envelope for this line, if the
source carries one (REQ-INDEXAUTH-001). Same contract as
fetch_line_status: opaque bytes, re-verified by the caller against
the trust root. The source is never trusted to have checked it — it is
precisely the party this document exists to constrain.Source§fn served_layers(&self, _line: &str) -> Result<Option<Vec<String>>, SourceError>
fn served_layers(&self, _line: &str) -> Result<Option<Vec<String>>, SourceError>
The layer ids this source is willing to serve for a line. Used to
detect OMISSION against the signed index. A source that cannot
enumerate returns
Ok(None) — distinct from Ok(Some(vec![])), which
means “I enumerate, and I have nothing”, and would flag every indexed
layer as hidden.Source§fn fetch_line_status(
&self,
_layer: &LayerRef,
) -> Result<Option<Vec<u8>>, SourceError>
fn fetch_line_status( &self, _layer: &LayerRef, ) -> Result<Option<Vec<u8>>, SourceError>
Fetch the baseline line-status DSSE envelope this source carries
beside the layer, if any (REQ-STATUS-DIST-001). Returns the opaque
envelope bytes — the source is not trusted to have verified them;
the caller re-verifies against the trust root before caching. A
source that carries no baseline returns
Ok(None), which is not an
error: line-status is updatable evidence, absent on some layers.Source§fn fetch_attestations(
&self,
_layer: &LayerRef,
) -> Result<Vec<CarriedAttestation>, SourceError>
fn fetch_attestations( &self, _layer: &LayerRef, ) -> Result<Vec<CarriedAttestation>, SourceError>
Fetch the attestations this source carries beside the layer as
referrer artifacts (REQ-ATTEST-002). Same contract as
fetch_line_status: OPAQUE, UNTRUSTED bytes. The source is never
trusted to have verified a statement — it is the party that would
benefit from a forged one — so the caller persists them verbatim and
varve verify re-checks each against the trust root. Read moreAuto Trait Implementations§
impl Freeze for MemorySource
impl RefUnwindSafe for MemorySource
impl Send for MemorySource
impl Sync for MemorySource
impl Unpin for MemorySource
impl UnsafeUnpin for MemorySource
impl UnwindSafe for MemorySource
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more