httk.workflow.manifests¶
Deterministic signed project manifests.
Attributes¶
Classes¶
Record the holder of one workspace maintenance lock. |
Functions¶
|
Return the deterministic records of one job payload, minus runner scratch. |
|
Describe the workspace maintenance lock, or |
|
Remove a stale, or with force any, maintenance lock and report it. |
|
Fence manager launches while a project snapshot is inspected. |
|
Verify a legacy manifest without modifying its project tree. |
|
Auto-detect a v2 or legacy manifest and verify it against its trust anchors. |
Module Contents¶
- httk.workflow.manifests.payload_file_records(root)[source]¶
Return the deterministic records of one job payload, minus runner scratch.
A payload’s runner-private entries — attempt control, logs, and job state — are excluded from every seal record exactly as they are from a payload digest, so publishing an outcome never changes a sealed payload’s records.
- class httk.workflow.manifests.MaintenanceLock[source]¶
Record the holder of one workspace maintenance lock.
- Parameters:
path – Locate the lock file.
pid – Record the holder process identifier, when readable.
hostname – Record the holder host, when readable.
created – Record the holder creation timestamp, when readable.
readable – Mark whether the lock contents could be read.
- path: pathlib.Path[source]¶
- property age_seconds: float | None[source]¶
Age of the lock, or
Nonewhen its timestamp is unusable.
- httk.workflow.manifests.read_maintenance_lock(workspace)[source]¶
Describe the workspace maintenance lock, or
Nonewhen it is absent.- Parameters:
workspace (httk.workflow.workspace.Workspace) – Locate the workspace whose lock to inspect.
- Returns:
The recorded lock, or
Nonewhen no lock exists.- Return type:
MaintenanceLock | None
- httk.workflow.manifests.release_maintenance_lock(workspace, *, force=False)[source]¶
Remove a stale, or with force any, maintenance lock and report it.
- Parameters:
workspace (httk.workflow.workspace.Workspace) – Locate the workspace whose lock to remove.
force (bool) – Permit removal of a lock that does not appear stale.
- Returns:
A human-readable removal result.
- Raises:
ValueError – If a live lock is protected by the default policy.
- Return type:
- httk.workflow.manifests.workspace_maintenance_guard(workspace)[source]¶
Fence manager launches while a project snapshot is inspected.
- Parameters:
workspace (httk.workflow.workspace.Workspace) – Lock and inspect this workspace around the guarded work.
- Returns:
A context manager that holds the maintenance lock.
- Raises:
ValueError – If the workspace is already maintained or not quiescent.
- Return type:
collections.abc.Iterator[None]
- httk.workflow.manifests.verify_legacy_manifest(root, path)[source]¶
Verify a legacy manifest without modifying its project tree.
- Parameters:
root (pathlib.Path) – Locate the tree the manifest should describe.
path (pathlib.Path) – Locate the legacy manifest to verify.
- Returns:
Whether the legacy tree records and signature verify.
- Return type:
- httk.workflow.manifests.verify_manifest(project=None, *, manifest=None, trusted_keys=None)[source]¶
Auto-detect a v2 or legacy manifest and verify it against its trust anchors.
The trust anchor is the key pinned in
project.json— never the key the manifest being verified names in its own header — plus any key passed in trusted_keys, as a recorded value or as the path of a*.pubfile.- Parameters:
project (str | os.PathLike[str] | None) – Locate the project to discover and verify.
manifest (str | os.PathLike[str] | None) – Select a manifest path instead of the project default.
trusted_keys (collections.abc.Sequence[str | os.PathLike[str]] | None) – Add explicit trust anchors to the project keys.
- Returns:
The detailed verification verdict.
- Raises:
ValueError – If no project or usable manifest exists.
- Return type: