5 Distribution and Secure Updates
| (require rivet/distribution) | package: rivet |
The updater treats HTTPS as transport protection, not as its root of trust. Manifests are independently signed with Ed25519 and bind the application ID, version, channel, rollout, rollback policy, artifact byte size, SHA-256 digest, platform, and architecture.
struct
(struct update-artifact ( platform architecture url sha256 size installer arguments)) platform : symbol? architecture : symbol? url : string? sha256 : string? size : exact-nonnegative-integer? installer : symbol? arguments : (listof string?)
struct
(struct update-manifest ( application-id version build channel published-at minimum-version previous-version rollback-allowed? rollout artifacts)) application-id : string? version : string? build : exact-positive-integer? channel : symbol? published-at : string? minimum-version : string? previous-version : (or/c #f string?) rollback-allowed? : boolean? rollout : exact-nonnegative-integer? artifacts : (listof update-artifact?)
struct
(struct updater-config ( application-id current-version channel platform architecture public-key expected-key-id rollout-bucket maximum-download-bytes)) application-id : string? current-version : string? channel : symbol? platform : symbol? architecture : symbol? public-key : any/c expected-key-id : (or/c #f string?) rollout-bucket : exact-nonnegative-integer? maximum-download-bytes : exact-positive-integer?
struct
(struct update-candidate (manifest artifact))
manifest : update-manifest? artifact : update-artifact?
struct
(struct install-plan ( candidate downloaded-path backup-path install restart rollback)) candidate : update-candidate? downloaded-path : path-string? backup-path : (or/c #f path-string?) install : procedure? restart : procedure? rollback : procedure?
5.1 Versions and Channels
procedure
(version-compare left right) → (or/c -1 0 1)
left : string? right : string?
procedure
(valid-channel? value) → boolean?
value : any/c
procedure
(channel-accepts-version? channel version) → boolean?
channel : symbol? version : string?
5.2 Signed Manifests
update-artifact values describe one platform artifact using the fields platform, architecture, url, sha256, size, installer, and arguments. update-manifest values contain the signed application and release policy plus a list of artifacts.
procedure
(write-signed-manifest manifest private-key key-id [ out]) → void? manifest : update-manifest? private-key : any/c key-id : string? out : output-port? = (current-output-port)
procedure
(verify-signed-manifest input public-key [ #:key-id expected-key-id]) → update-manifest? input : input-port? public-key : any/c expected-key-id : (or/c #f string?) = #f
5.3 Selecting and Installing an Update
An updater-config records the application ID, current version, channel, platform, architecture, public key, expected key ID, deterministic rollout bucket, and maximum download size.
procedure
(fetch-update-manifest manifest-url public-key [ #:key-id key-id #:maximum-bytes maximum-bytes]) → update-manifest? manifest-url : string? public-key : any/c key-id : (or/c #f string?) = #f maximum-bytes : exact-positive-integer? = (* 1024 1024)
procedure
(select-update config manifest) → (or/c #f update-candidate?)
config : updater-config? manifest : update-manifest?
procedure
(download-update config candidate destination) → path? config : updater-config? candidate : update-candidate? destination : path-string?
procedure
(execute-install-plan! plan) → any/c
plan : install-plan?