feat: client sync core — config, pull, inventory, manifest, OpenCode target

- admin-protected client config (flag > AGENT_LIB_CONFIG > platform default),
  token used for basic auth only, redacted from all errors and files
- work-repo pull via go-git (bare cache clone + fetch, remote re-pointed on
  config change), clean failure keeps previous state
- inventory: own items + external areas from lockfile; MCP inventoried but
  never deployed
- manifest v1 records name/type/origin/revision/content-hash per item,
  deterministic bytes; folder hashes over sorted relpath+filehash lines so
  tree and disk hashes agree
- shared deploy package (atomic temp+rename, exec-bit preserving) now backs
  both curator materialization and client deployment
- sync validates and hashes everything before the first mutation; second run
  is a byte-level no-op
This commit is contained in:
2026-08-23 10:31:00 +02:00
parent a755d138da
commit 49dbcf469e
17 changed files with 1211 additions and 52 deletions
+15
View File
@@ -98,6 +98,21 @@ func New() *Lockfile {
return &Lockfile{Version: Version, Sources: map[string]*Source{}}
}
// ParseBytes unmarshals and validates lockfile JSON content.
func ParseBytes(data []byte) (*Lockfile, error) {
var l Lockfile
if err := json.Unmarshal(data, &l); err != nil {
return nil, fmt.Errorf("lockfile is not valid JSON: %w", err)
}
if l.Version != Version {
return nil, fmt.Errorf("lockfile has schema version %d, want %d", l.Version, Version)
}
if l.Sources == nil {
l.Sources = map[string]*Source{}
}
return &l, nil
}
// Load reads the lockfile at path. A missing file yields ErrNotExist.
func Load(path string) (*Lockfile, error) {
data, err := os.ReadFile(path)