commit c0a2f91bc8d299ef11a2ad0c1107f7fa73e9a953
parent 22a473b1ec787685a4e79156e9520b578146a18a
Author: triesap <tyson@radroots.org>
Date: Fri, 2 Oct 2026 01:27:19 +0000
test: admit only the required shared event dependencies
- Pin every shared Radroots dependency to published Lib revision 189c49b7.
- Select focused event and codec features without third-party version changes.
- Align source locks, strict Rust/Kotlin guards, and native provenance inputs.
- Verify Rust, Gradle, native freshness, API, SQLite, and license/source lanes.
Diffstat:
11 files changed, 57 insertions(+), 42 deletions(-)
diff --git a/app/desktop/src/test/kotlin/org/harvestcircle/architecture/MachineProvenanceTest.kt b/app/desktop/src/test/kotlin/org/harvestcircle/architecture/MachineProvenanceTest.kt
@@ -26,7 +26,7 @@ class MachineProvenanceTest {
)
assertTrue(
provenance.contains(
- "canonical_radroots_revision = \"ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb\"",
+ "canonical_radroots_revision = \"189c49b74b4bafc142b00b76b296477931139e72\"",
),
)
assertEquals(8, Regex("(?m)^\\[\\[import]]$").findAll(provenance).count())
diff --git a/build-logic/contracts/src/main/kotlin/org/harvestcircle/buildlogic/contracts/RadrootsLibSourceLock.kt b/build-logic/contracts/src/main/kotlin/org/harvestcircle/buildlogic/contracts/RadrootsLibSourceLock.kt
@@ -34,11 +34,11 @@ public class RadrootsLibSourceLock private constructor(
mapOf(
"schema" to "radroots.lib.source-lock.v1",
"repository" to "https://github.com/radrootslabs/lib",
- "revision" to "ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb",
+ "revision" to "189c49b74b4bafc142b00b76b296477931139e72",
"architecture" to "radroots.crates.release.v2",
- "workspace_catalog_sha256" to "deca0c080deae187ff8186c0708903e42f41ea57f77c5f91581e23aa561164a4",
+ "workspace_catalog_sha256" to "ee295f2352e2577a4052d980624415aec9871197d4fc9910a4c21c83a9179200",
"version" to "0.1.0-alpha",
- "source_archive_sha256" to "2cf12c24ed649c3c8dd48cebcb8583996646e116fc2472539a55748c803584db",
+ "source_archive_sha256" to "c648a3ab993d10253b9073e7e86db7b8970863bdf1d394d9fc30d66825695240",
)
public fun load(
diff --git a/build-logic/contracts/src/test/kotlin/org/harvestcircle/buildlogic/contracts/BuildContractsTest.kt b/build-logic/contracts/src/test/kotlin/org/harvestcircle/buildlogic/contracts/BuildContractsTest.kt
@@ -346,11 +346,11 @@ class BuildContractsTest {
"""
schema = "radroots.lib.source-lock.v1"
repository = "https://github.com/radrootslabs/lib"
- revision = "ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb"
+ revision = "189c49b74b4bafc142b00b76b296477931139e72"
architecture = "radroots.crates.release.v2"
- workspace_catalog_sha256 = "deca0c080deae187ff8186c0708903e42f41ea57f77c5f91581e23aa561164a4"
+ workspace_catalog_sha256 = "ee295f2352e2577a4052d980624415aec9871197d4fc9910a4c21c83a9179200"
version = "0.1.0-alpha"
- source_archive_sha256 = "2cf12c24ed649c3c8dd48cebcb8583996646e116fc2472539a55748c803584db"
+ source_archive_sha256 = "c648a3ab993d10253b9073e7e86db7b8970863bdf1d394d9fc30d66825695240"
lockfile = "core/Cargo.lock"
lockfile_sha256 = "$lockfileSha256"
""".trimIndent() + "\n"
diff --git a/core/Cargo.lock b/core/Cargo.lock
@@ -1029,6 +1029,8 @@ dependencies = [
"nostr 0.44.1",
"nostr-relay-builder",
"nostr-sdk 0.44.0",
+ "radroots_event",
+ "radroots_event_codec",
"radroots_identity",
"radroots_transport",
"radroots_transport_nostr",
@@ -1931,7 +1933,7 @@ checksum = "f8dcc9c7d52a811697d2151c701e0d08956f92b0e24136cf4cf27b57a6a0d9bf"
[[package]]
name = "radroots_blossom"
version = "0.1.0-alpha"
-source = "git+https://github.com/radrootslabs/lib?rev=ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb#ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb"
+source = "git+https://github.com/radrootslabs/lib?rev=189c49b74b4bafc142b00b76b296477931139e72#189c49b74b4bafc142b00b76b296477931139e72"
dependencies = [
"mediatype",
"serde",
@@ -1943,7 +1945,7 @@ dependencies = [
[[package]]
name = "radroots_core"
version = "0.1.0-alpha"
-source = "git+https://github.com/radrootslabs/lib?rev=ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb#ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb"
+source = "git+https://github.com/radrootslabs/lib?rev=189c49b74b4bafc142b00b76b296477931139e72#189c49b74b4bafc142b00b76b296477931139e72"
dependencies = [
"rust_decimal",
"serde",
@@ -1952,7 +1954,7 @@ dependencies = [
[[package]]
name = "radroots_event"
version = "0.1.0-alpha"
-source = "git+https://github.com/radrootslabs/lib?rev=ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb#ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb"
+source = "git+https://github.com/radrootslabs/lib?rev=189c49b74b4bafc142b00b76b296477931139e72#189c49b74b4bafc142b00b76b296477931139e72"
dependencies = [
"hex",
"jiff-tzdb",
@@ -1970,7 +1972,7 @@ dependencies = [
[[package]]
name = "radroots_event_codec"
version = "0.1.0-alpha"
-source = "git+https://github.com/radrootslabs/lib?rev=ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb#ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb"
+source = "git+https://github.com/radrootslabs/lib?rev=189c49b74b4bafc142b00b76b296477931139e72#189c49b74b4bafc142b00b76b296477931139e72"
dependencies = [
"hex",
"radroots_blossom",
@@ -1987,7 +1989,7 @@ dependencies = [
[[package]]
name = "radroots_identity"
version = "0.1.0-alpha"
-source = "git+https://github.com/radrootslabs/lib?rev=ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb#ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb"
+source = "git+https://github.com/radrootslabs/lib?rev=189c49b74b4bafc142b00b76b296477931139e72#189c49b74b4bafc142b00b76b296477931139e72"
dependencies = [
"k256",
"serde",
@@ -1997,7 +1999,7 @@ dependencies = [
[[package]]
name = "radroots_nostr"
version = "0.1.0-alpha"
-source = "git+https://github.com/radrootslabs/lib?rev=ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb#ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb"
+source = "git+https://github.com/radrootslabs/lib?rev=189c49b74b4bafc142b00b76b296477931139e72#189c49b74b4bafc142b00b76b296477931139e72"
dependencies = [
"nostr 0.44.8",
"radroots_event",
@@ -2011,7 +2013,7 @@ dependencies = [
[[package]]
name = "radroots_protocol"
version = "0.1.0-alpha"
-source = "git+https://github.com/radrootslabs/lib?rev=ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb#ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb"
+source = "git+https://github.com/radrootslabs/lib?rev=189c49b74b4bafc142b00b76b296477931139e72#189c49b74b4bafc142b00b76b296477931139e72"
dependencies = [
"serde",
]
@@ -2019,7 +2021,7 @@ dependencies = [
[[package]]
name = "radroots_runtime_paths"
version = "0.1.0-alpha"
-source = "git+https://github.com/radrootslabs/lib?rev=ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb#ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb"
+source = "git+https://github.com/radrootslabs/lib?rev=189c49b74b4bafc142b00b76b296477931139e72#189c49b74b4bafc142b00b76b296477931139e72"
dependencies = [
"rustix",
"serde",
@@ -2029,7 +2031,7 @@ dependencies = [
[[package]]
name = "radroots_service_sqlite"
version = "0.1.0-alpha"
-source = "git+https://github.com/radrootslabs/lib?rev=ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb#ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb"
+source = "git+https://github.com/radrootslabs/lib?rev=189c49b74b4bafc142b00b76b296477931139e72#189c49b74b4bafc142b00b76b296477931139e72"
dependencies = [
"fs2",
"futures",
@@ -2047,7 +2049,7 @@ dependencies = [
[[package]]
name = "radroots_storage"
version = "0.1.0-alpha"
-source = "git+https://github.com/radrootslabs/lib?rev=ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb#ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb"
+source = "git+https://github.com/radrootslabs/lib?rev=189c49b74b4bafc142b00b76b296477931139e72#189c49b74b4bafc142b00b76b296477931139e72"
dependencies = [
"radroots_event",
"radroots_event_codec",
@@ -2060,7 +2062,7 @@ dependencies = [
[[package]]
name = "radroots_trade"
version = "0.1.0-alpha"
-source = "git+https://github.com/radrootslabs/lib?rev=ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb#ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb"
+source = "git+https://github.com/radrootslabs/lib?rev=189c49b74b4bafc142b00b76b296477931139e72#189c49b74b4bafc142b00b76b296477931139e72"
dependencies = [
"radroots_core",
"radroots_event",
@@ -2070,7 +2072,7 @@ dependencies = [
[[package]]
name = "radroots_transport"
version = "0.1.0-alpha"
-source = "git+https://github.com/radrootslabs/lib?rev=ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb#ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb"
+source = "git+https://github.com/radrootslabs/lib?rev=189c49b74b4bafc142b00b76b296477931139e72#189c49b74b4bafc142b00b76b296477931139e72"
dependencies = [
"radroots_event",
"radroots_identity",
@@ -2081,7 +2083,7 @@ dependencies = [
[[package]]
name = "radroots_transport_nostr"
version = "0.1.0-alpha"
-source = "git+https://github.com/radrootslabs/lib?rev=ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb#ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb"
+source = "git+https://github.com/radrootslabs/lib?rev=189c49b74b4bafc142b00b76b296477931139e72#189c49b74b4bafc142b00b76b296477931139e72"
dependencies = [
"async-wsocket",
"futures",
@@ -2091,11 +2093,14 @@ dependencies = [
"radroots_nostr",
"radroots_protocol",
"radroots_transport",
+ "rustls",
"serde_json",
"sha2",
"tokio",
+ "tokio-rustls",
"tokio-tungstenite",
"url",
+ "webpki-roots 0.26.11",
]
[[package]]
diff --git a/core/Cargo.toml b/core/Cargo.toml
@@ -43,12 +43,14 @@ harvestcircle_runtime = { path = "crates/harvestcircle_runtime", version = "=0.1
harvestcircle_storage = { path = "crates/harvestcircle_storage", version = "=0.1.0-alpha" }
harvestcircle_test_bridge = { path = "crates/harvestcircle_test_bridge", version = "=0.1.0-alpha" }
harvestcircle_uniffi_bindgen = { path = "crates/harvestcircle_uniffi_bindgen", version = "=0.1.0-alpha" }
-radroots_identity = { git = "https://github.com/radrootslabs/lib", rev = "ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb", version = "=0.1.0-alpha", default-features = false }
-radroots_runtime_paths = { git = "https://github.com/radrootslabs/lib", rev = "ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb", version = "=0.1.0-alpha", default-features = false }
-radroots_service_sqlite = { git = "https://github.com/radrootslabs/lib", rev = "ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb", version = "=0.1.0-alpha", default-features = false }
-radroots_storage = { git = "https://github.com/radrootslabs/lib", rev = "ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb", version = "=0.1.0-alpha", default-features = false }
-radroots_transport = { git = "https://github.com/radrootslabs/lib", rev = "ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb", version = "=0.1.0-alpha", default-features = false }
-radroots_transport_nostr = { git = "https://github.com/radrootslabs/lib", rev = "ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb", version = "=0.1.0-alpha", default-features = false }
+radroots_event = { git = "https://github.com/radrootslabs/lib", rev = "189c49b74b4bafc142b00b76b296477931139e72", version = "=0.1.0-alpha", default-features = false }
+radroots_event_codec = { git = "https://github.com/radrootslabs/lib", rev = "189c49b74b4bafc142b00b76b296477931139e72", version = "=0.1.0-alpha", default-features = false }
+radroots_identity = { git = "https://github.com/radrootslabs/lib", rev = "189c49b74b4bafc142b00b76b296477931139e72", version = "=0.1.0-alpha", default-features = false }
+radroots_runtime_paths = { git = "https://github.com/radrootslabs/lib", rev = "189c49b74b4bafc142b00b76b296477931139e72", version = "=0.1.0-alpha", default-features = false }
+radroots_service_sqlite = { git = "https://github.com/radrootslabs/lib", rev = "189c49b74b4bafc142b00b76b296477931139e72", version = "=0.1.0-alpha", default-features = false }
+radroots_storage = { git = "https://github.com/radrootslabs/lib", rev = "189c49b74b4bafc142b00b76b296477931139e72", version = "=0.1.0-alpha", default-features = false }
+radroots_transport = { git = "https://github.com/radrootslabs/lib", rev = "189c49b74b4bafc142b00b76b296477931139e72", version = "=0.1.0-alpha", default-features = false }
+radroots_transport_nostr = { git = "https://github.com/radrootslabs/lib", rev = "189c49b74b4bafc142b00b76b296477931139e72", version = "=0.1.0-alpha", default-features = false }
getrandom = { version = "0.2", default-features = false }
quote = { version = "1" }
sha2 = { version = "0.10", default-features = false }
diff --git a/core/compatibility/harvestcircle-ffi-v4.properties b/core/compatibility/harvestcircle-ffi-v4.properties
@@ -9,5 +9,5 @@ storage.schema.minimum=1
storage.schema.current=2
product.version=0.1.0-alpha
package.version=1.0.0
-source.provenance_digest=40b9eccd486026128f92de8d55d002a9030f235a35f9b754c98c0b0d387bd8c0
+source.provenance_digest=6cc524ffa028e7958dabc7d721302b967b7895fb2531f2e1cb6a7efca47bbe3b
source.foundation_baseline=c08d18ea569351dddeef70d4c1410708daf067b6
diff --git a/core/crates/harvestcircle_nostr/Cargo.toml b/core/crates/harvestcircle_nostr/Cargo.toml
@@ -15,6 +15,8 @@ include = ["src/**", "Cargo.toml"]
nostr = { git = "https://github.com/rust-nostr/nostr.git", rev = "5bba5163eb77107f82c4a8262cf29d7f33a73219", package = "nostr" }
harvestcircle_application.workspace = true
harvestcircle_domain.workspace = true
+radroots_event = { workspace = true, features = ["std"] }
+radroots_event_codec = { workspace = true, features = ["std", "json"] }
radroots_identity.workspace = true
radroots_transport.workspace = true
radroots_transport_nostr.workspace = true
diff --git a/core/crates/harvestcircle_product/src/lib.rs b/core/crates/harvestcircle_product/src/lib.rs
@@ -140,7 +140,7 @@ mod tests {
let expected = provenance::digest(&source).expect("canonical provenance digest");
assert_eq!(
expected,
- "40b9eccd486026128f92de8d55d002a9030f235a35f9b754c98c0b0d387bd8c0"
+ "6cc524ffa028e7958dabc7d721302b967b7895fb2531f2e1cb6a7efca47bbe3b"
);
assert_eq!(
provenance::digest(&source.replace('\n', "\r\n")).unwrap(),
diff --git a/core/provenance/harvestcircle-v1.toml b/core/provenance/harvestcircle-v1.toml
@@ -3,7 +3,7 @@ source_product = "HarvestCircle"
source_repository = "https://github.com/radrootslabs/harvestcircle"
foundation_baseline = "c08d18ea569351dddeef70d4c1410708daf067b6"
canonical_radroots_repository = "https://github.com/radrootslabs/lib"
-canonical_radroots_revision = "ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb"
+canonical_radroots_revision = "189c49b74b4bafc142b00b76b296477931139e72"
[[import]]
component = "domain"
diff --git a/radroots.lib.source-lock.v1.toml b/radroots.lib.source-lock.v1.toml
@@ -1,9 +1,9 @@
schema = "radroots.lib.source-lock.v1"
repository = "https://github.com/radrootslabs/lib"
-revision = "ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb"
+revision = "189c49b74b4bafc142b00b76b296477931139e72"
architecture = "radroots.crates.release.v2"
-workspace_catalog_sha256 = "deca0c080deae187ff8186c0708903e42f41ea57f77c5f91581e23aa561164a4"
+workspace_catalog_sha256 = "ee295f2352e2577a4052d980624415aec9871197d4fc9910a4c21c83a9179200"
version = "0.1.0-alpha"
-source_archive_sha256 = "2cf12c24ed649c3c8dd48cebcb8583996646e116fc2472539a55748c803584db"
+source_archive_sha256 = "c648a3ab993d10253b9073e7e86db7b8970863bdf1d394d9fc30d66825695240"
lockfile = "core/Cargo.lock"
-lockfile_sha256 = "d4454a053e5f5d1810170fe9987e0f2a1d365de7de3eb9c71599029e46a03fc3"
+lockfile_sha256 = "648040384ae6978d255be3794f3a69bb37287fd929bb4b9bb8c1cb15e8f34976"
diff --git a/tools/xtask/src/lib.rs b/tools/xtask/src/lib.rs
@@ -1036,7 +1036,7 @@ fn development_integration_policy(root: &Path, findings: &mut Vec<String>) {
}
fn provenance_check(root: &Path, inventory: &Inventory, findings: &mut Vec<String>) {
- const LIB_REVISION: &str = "ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb";
+ const LIB_REVISION: &str = "189c49b74b4bafc142b00b76b296477931139e72";
const PROVENANCE_PATH: &str = "core/provenance/harvestcircle-v1.toml";
const SOURCE_LOCK_PATH: &str = "radroots.lib.source-lock.v1.toml";
const MAX_SOURCE_LOCK_BYTES: u64 = 1024 * 1024;
@@ -1045,6 +1045,12 @@ fn provenance_check(root: &Path, inventory: &Inventory, findings: &mut Vec<Strin
for authority in [
"repository = \"https://github.com/radrootslabs/harvestcircle\"".to_owned(),
format!(
+ "radroots_event = {{ git = \"https://github.com/radrootslabs/lib\", rev = \"{LIB_REVISION}\", version = \"=0.1.0-alpha\", default-features = false }}"
+ ),
+ format!(
+ "radroots_event_codec = {{ git = \"https://github.com/radrootslabs/lib\", rev = \"{LIB_REVISION}\", version = \"=0.1.0-alpha\", default-features = false }}"
+ ),
+ format!(
"radroots_identity = {{ git = \"https://github.com/radrootslabs/lib\", rev = \"{LIB_REVISION}\", version = \"=0.1.0-alpha\", default-features = false }}"
),
format!(
@@ -1089,13 +1095,13 @@ fn provenance_check(root: &Path, inventory: &Inventory, findings: &mut Vec<Strin
let expected_source_lock = concat!(
"schema = \"radroots.lib.source-lock.v1\"\n",
"repository = \"https://github.com/radrootslabs/lib\"\n",
- "revision = \"ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb\"\n",
+ "revision = \"189c49b74b4bafc142b00b76b296477931139e72\"\n",
"architecture = \"radroots.crates.release.v2\"\n",
- "workspace_catalog_sha256 = \"deca0c080deae187ff8186c0708903e42f41ea57f77c5f91581e23aa561164a4\"\n",
+ "workspace_catalog_sha256 = \"ee295f2352e2577a4052d980624415aec9871197d4fc9910a4c21c83a9179200\"\n",
"version = \"0.1.0-alpha\"\n",
- "source_archive_sha256 = \"2cf12c24ed649c3c8dd48cebcb8583996646e116fc2472539a55748c803584db\"\n",
+ "source_archive_sha256 = \"c648a3ab993d10253b9073e7e86db7b8970863bdf1d394d9fc30d66825695240\"\n",
"lockfile = \"core/Cargo.lock\"\n",
- "lockfile_sha256 = \"d4454a053e5f5d1810170fe9987e0f2a1d365de7de3eb9c71599029e46a03fc3\"\n",
+ "lockfile_sha256 = \"648040384ae6978d255be3794f3a69bb37287fd929bb4b9bb8c1cb15e8f34976\"\n",
);
let source_lock_bytes =
match bounded_no_follow_bytes(root, Path::new(SOURCE_LOCK_PATH), MAX_SOURCE_LOCK_BYTES) {
@@ -2363,13 +2369,13 @@ mod tests {
concat!(
"schema = \"radroots.lib.source-lock.v1\"\n",
"repository = \"https://github.com/radrootslabs/lib\"\n",
- "revision = \"ad17b7d3455a7147cfa303d976fc5c70c3a4c0cb\"\n",
+ "revision = \"189c49b74b4bafc142b00b76b296477931139e72\"\n",
"architecture = \"radroots.crates.release.v2\"\n",
- "workspace_catalog_sha256 = \"deca0c080deae187ff8186c0708903e42f41ea57f77c5f91581e23aa561164a4\"\n",
+ "workspace_catalog_sha256 = \"ee295f2352e2577a4052d980624415aec9871197d4fc9910a4c21c83a9179200\"\n",
"version = \"0.1.0-alpha\"\n",
- "source_archive_sha256 = \"2cf12c24ed649c3c8dd48cebcb8583996646e116fc2472539a55748c803584db\"\n",
+ "source_archive_sha256 = \"c648a3ab993d10253b9073e7e86db7b8970863bdf1d394d9fc30d66825695240\"\n",
"lockfile = \"core/Cargo.lock\"\n",
- "lockfile_sha256 = \"d4454a053e5f5d1810170fe9987e0f2a1d365de7de3eb9c71599029e46a03fc3\"\n",
+ "lockfile_sha256 = \"648040384ae6978d255be3794f3a69bb37287fd929bb4b9bb8c1cb15e8f34976\"\n",
),
);
write(&root, "core/Cargo.toml", "");