feat(evidence): add filesystem and HTTP sources
This commit is contained in:
@@ -0,0 +1,36 @@
|
||||
# Evidence Task 2 Report
|
||||
|
||||
## Status
|
||||
|
||||
Implemented filesystem and explicit-manifest HTTP Evidence source adapters, typed source
|
||||
configuration with legacy compatibility, and factory construction.
|
||||
|
||||
## Delivered behavior
|
||||
|
||||
- Filesystem discovery is deterministic and rooted at a strict canonical directory.
|
||||
- Symlink/path escapes are rejected before content is exposed.
|
||||
- Discovery hashing and acquisition reads enforce a configurable byte limit.
|
||||
- Filesystem fingerprints are content SHA-256 values; stable IDs derive from relative paths.
|
||||
- HTTP accepts only explicit `http`/`https` manifest entries and keeps transport URLs private.
|
||||
- HTTP provenance strips query strings/fragments, while config and adapter representations hide
|
||||
signed or secret-bearing transport URLs.
|
||||
- HTTP acquisition uses separate connect/read timeouts, streaming byte limits, bounded redirects,
|
||||
private redirect rejection, and safe transient/permanent error classification.
|
||||
- HTTP fingerprints prefer a deterministic ETag digest, then Last-Modified, then content SHA-256.
|
||||
- `build_evidence_sources(cfg)` supports both typed `evidence.sources` entries and the legacy
|
||||
`source_root` plus `evidence_dir` filesystem configuration.
|
||||
|
||||
## TDD and verification
|
||||
|
||||
- RED: focused tests initially failed during collection because the adapter package did not exist.
|
||||
- GREEN: `15 passed` for filesystem, HTTP, and resource-config tests.
|
||||
- Full harness: `548 passed, 5 deselected`.
|
||||
- Changed-file Ruff: clean.
|
||||
- Repository-wide Ruff remains non-clean due to 34 pre-existing findings in unrelated test files;
|
||||
no unrelated lint files were modified.
|
||||
|
||||
## Notes
|
||||
|
||||
The approved `SourceObject` namespace grammar does not permit raw quoted ETags such as
|
||||
`etag:"abc"`. The adapter therefore uses `etag:<sha256-of-opaque-etag>`: it preserves ETag-based
|
||||
change identity without weakening the canonical contract or exposing validator contents.
|
||||
Reference in New Issue
Block a user