Serve documentation from the operator UI

This commit is contained in:
Emil
2026-08-02 15:50:07 +03:00
parent 284aef5d6f
commit f20cc7fe00
72 changed files with 3509 additions and 698 deletions
+44 -16
View File
@@ -4,6 +4,7 @@ from __future__ import annotations
import hashlib
import importlib.util
import os
from importlib import metadata
from pathlib import Path
@@ -22,11 +23,17 @@ def installed_distribution_digest(
files are excluded because they are neither stable wheel payloads nor used
by the registry's cache-isolated discovery import.
"""
installed = metadata.distribution(distribution) if isinstance(distribution, str) else distribution
installed = (
metadata.distribution(distribution)
if isinstance(distribution, str)
else distribution
)
raw_top_level = installed.read_text("top_level.txt")
if raw_top_level is None:
raise ValueError("installed distribution does not declare top-level packages")
declared_top_levels = [line.strip() for line in raw_top_level.splitlines() if line.strip()]
declared_top_levels = [
line.strip() for line in raw_top_level.splitlines() if line.strip()
]
if any(not value.isidentifier() for value in declared_top_levels):
raise ValueError("installed distribution declares an invalid top-level package")
top_levels = set(declared_top_levels)
@@ -34,55 +41,74 @@ def installed_distribution_digest(
raise ValueError("installed distribution has no measurable top-level package")
declared_files = tuple(installed.files or ())
editable_bootstrap = any(
Path(str(item)).name.startswith("__editable__") and Path(str(item)).suffix == ".pth"
Path(str(item)).name.startswith("__editable__")
and Path(str(item)).suffix == ".pth"
for item in declared_files
)
if editable_bootstrap and not allow_editable:
raise ValueError("editable workload installations are not accepted for secure discovery")
raise ValueError(
"editable workload installations are not accepted for secure discovery"
)
for item in declared_files:
relative = Path(str(item))
suffix = relative.suffix.lower()
if suffix == ".pth" and not allow_editable:
raise ValueError("installed workload distribution declares a .pth bootstrap")
raise ValueError(
"installed workload distribution declares a .pth bootstrap"
)
if suffix in {".pyc", ".pyo"} and "__pycache__" not in relative.parts:
raise ValueError("installed workload distribution declares sourceless bytecode")
raise ValueError(
"installed workload distribution declares sourceless bytecode"
)
selected: list[tuple[str, Path]] = []
for top_level in sorted(top_levels):
root = Path(installed.locate_file(top_level))
root = Path(str(installed.locate_file(top_level)))
if not root.exists():
# PEP 660 editable distributions may expose source packages through
# a meta-path finder rather than a physical site-packages path.
spec = importlib.util.find_spec(top_level)
locations = tuple(spec.submodule_search_locations or ()) if spec is not None else ()
locations = (
tuple(spec.submodule_search_locations or ()) if spec is not None else ()
)
if len(locations) > 1:
raise ValueError("shared namespace packages are not supported for workload integrity")
raise ValueError(
"shared namespace packages are not supported for workload integrity"
)
if locations:
root = Path(locations[0])
if root.is_symlink():
raise ValueError("installed workload package root must not be a symbolic link")
raise ValueError(
"installed workload package root must not be a symbolic link"
)
if root.is_dir():
candidates = root.rglob("*")
for path in candidates:
if path.is_symlink():
raise ValueError("installed workload package contains a symbolic-link payload")
raise ValueError(
"installed workload package contains a symbolic-link payload"
)
if not path.is_file():
continue
relative_parts = path.relative_to(root).parts
if "__pycache__" in relative_parts:
continue
if path.suffix.lower() in {".pyc", ".pyo"}:
raise ValueError("installed workload package contains sourceless bytecode")
raise ValueError(
"installed workload package contains sourceless bytecode"
)
relative = f"{top_level}/{path.relative_to(root).as_posix()}"
selected.append((relative, path))
continue
module = Path(installed.locate_file(top_level + ".py"))
module = Path(str(installed.locate_file(top_level + ".py")))
if not module.exists():
spec = importlib.util.find_spec(top_level)
if spec is not None and spec.origin is not None:
module = Path(spec.origin)
if module.is_symlink() or not module.is_file():
raise ValueError("installed workload package contains a missing top-level payload")
raise ValueError(
"installed workload package contains a missing top-level payload"
)
selected.append((top_level + ".py", module))
# Include declared package data outside top-level import trees. Generated
# console wrappers and installer metadata are excluded; executable .pth and
@@ -106,9 +132,11 @@ def installed_distribution_digest(
or "__pycache__" in relative.parts
):
continue
path = Path(installed.locate_file(item))
path = Path(str(installed.locate_file(item)))
if path.is_symlink():
raise ValueError("installed workload distribution contains a symbolic-link payload")
raise ValueError(
"installed workload distribution contains a symbolic-link payload"
)
if not path.is_file() or text in selected_names:
continue
selected.append((text, path))