apple_kit

Apple-native services for Radroots iOS and macOS apps
git clone https://radroots.dev/git/apple_kit.git
Log | Files | Refs | README | LICENSE

commit c254f3740126527e95340c41f6d2650770893e9c
parent 35aedb6b54ff645b663fecff26082b3e91fcb232
Author: triesap <tyson@radroots.org>
Date:   Sun, 13 Sep 2026 04:16:03 +0000

media: supply exact Blossom upload request headers

- Bind the hash header to revalidated staged image bytes
- Request bounded JSON responses with identity encoding
- Route SwiftPM verification through governed output paths
- Verify package and hosted simulator suites with unchanged API

Diffstat:
MREADME | 8++++++--
MSources/RadrootsKit/RadrootsAppleMediaPreparation.swift | 6+++++-
MTests/RadrootsKitTests/RadrootsAppleMediaPreparationTests.swift | 3+++
Atools/swift-package.sh | 27+++++++++++++++++++++++++++
Mtools/verify-boundaries.sh | 6+++---
5 files changed, 44 insertions(+), 6 deletions(-)

diff --git a/README b/README @@ -5,8 +5,12 @@ Swift package for native Rad Roots Apple-platform application services. ## Verification -Run `tools/verify-boundaries.sh`, `tools/verify-supply-chain.sh`, `swift build`, -and `swift test` from a standalone clone. The boundary command byte-compares +Run `tools/verify-boundaries.sh`, `tools/verify-supply-chain.sh`, +`bash tools/swift-package.sh build`, and `bash tools/swift-package.sh test` +from a standalone clone. The package launcher runs SwiftPM with the exact +resolved dependency and uses `SWIFTPM_SCRATCH` and `SWIFTPM_CACHE` when supplied. +An ordinary clone uses its local `.build` scratch directory. +The boundary command byte-compares the normalized public symbol inventory against its reviewed API baseline and rejects forbidden repository roots or credential material. In an extbuild-enabled checkout, first run diff --git a/Sources/RadrootsKit/RadrootsAppleMediaPreparation.swift b/Sources/RadrootsKit/RadrootsAppleMediaPreparation.swift @@ -209,7 +209,11 @@ public actor RadrootsAppleMediaPreparer { return try RadrootsBackgroundTransferRequest( identifier: identifier, remoteURL: remoteURL, method: .put, operation: .upload(source: .stagedBlob(preparedImage.file)), - headers: ["Authorization": authorization, "Content-Type": "image/png"], + headers: [ + "Authorization": authorization, "Content-Type": "image/png", + "X-SHA-256": preparedImage.sha256, + "Accept": "application/json", "Accept-Encoding": "identity", + ], metadata: ["purpose": "blossom_upload", "sha256": preparedImage.sha256], networkPolicy: networkPolicy, responsePolicy: .boundedJSON(), expectedSourceSHA256: preparedImage.sha256 diff --git a/Tests/RadrootsKitTests/RadrootsAppleMediaPreparationTests.swift b/Tests/RadrootsKitTests/RadrootsAppleMediaPreparationTests.swift @@ -52,6 +52,9 @@ import UniformTypeIdentifiers #expect(request.operation == .upload(source: .stagedBlob(prepared.file))) #expect(request.headers["Authorization"] == "Nostr signed-event") #expect(request.headers["Content-Type"] == "image/png") + #expect(request.headers["X-SHA-256"] == prepared.sha256) + #expect(request.headers["Accept"] == "application/json") + #expect(request.headers["Accept-Encoding"] == "identity") #expect(request.metadata["sha256"] == prepared.sha256) #expect(try request.responsePolicy == .boundedJSON()) #expect(request.expectedSourceSHA256 == prepared.sha256) diff --git a/tools/swift-package.sh b/tools/swift-package.sh @@ -0,0 +1,27 @@ +#!/usr/bin/env bash +set -euo pipefail + +repo_root="$(git rev-parse --show-toplevel)" +cd "$repo_root" + +command=${1:-} +case "$command" in + build|test) shift ;; + *) echo "usage: $0 {build|test} [SwiftPM arguments...]" >&2; exit 64 ;; +esac + +scratch_path=${SWIFTPM_SCRATCH:-"$repo_root/.build"} +case "$scratch_path" in + /*) ;; + *) echo "error: SWIFTPM_SCRATCH must be an absolute path" >&2; exit 64 ;; +esac +output_args=(--scratch-path "$scratch_path") +if [[ -n "${SWIFTPM_CACHE:-}" ]]; then + case "$SWIFTPM_CACHE" in + /*) ;; + *) echo "error: SWIFTPM_CACHE must be an absolute path" >&2; exit 64 ;; + esac + output_args+=(--cache-path "$SWIFTPM_CACHE") +fi + +exec swift "$command" "${output_args[@]}" --disable-automatic-resolution "$@" diff --git a/tools/verify-boundaries.sh b/tools/verify-boundaries.sh @@ -27,13 +27,13 @@ if git grep -I -n -E \ exit 1 fi -swift build -bin_path="$(swift build --show-bin-path)" +bash tools/swift-package.sh build +bin_path="$(bash tools/swift-package.sh build --show-bin-path)" arch="$(swift -print-target-info | sed -n 's/.*"arch": "\([^"]*\)".*/\1/p')" test -n "$arch" sdk_path="$(xcrun --show-sdk-path --sdk macosx)" module_map="$bin_path/libsecp256k1.build/module.modulemap" -dependency_include="$repo_root/.build/checkouts/swift-secp256k1/Sources/libsecp256k1/include" +dependency_include="${SWIFTPM_SCRATCH:-$repo_root/.build}/checkouts/swift-secp256k1/Sources/libsecp256k1/include" test -f "$module_map" test -d "$dependency_include"