commit c254f3740126527e95340c41f6d2650770893e9c
parent 35aedb6b54ff645b663fecff26082b3e91fcb232
Author: triesap <tyson@radroots.org>
Date: Sun, 13 Sep 2026 04:16:03 +0000
media: supply exact Blossom upload request headers
- Bind the hash header to revalidated staged image bytes
- Request bounded JSON responses with identity encoding
- Route SwiftPM verification through governed output paths
- Verify package and hosted simulator suites with unchanged API
Diffstat:
5 files changed, 44 insertions(+), 6 deletions(-)
diff --git a/README b/README
@@ -5,8 +5,12 @@ Swift package for native Rad Roots Apple-platform application services.
## Verification
-Run `tools/verify-boundaries.sh`, `tools/verify-supply-chain.sh`, `swift build`,
-and `swift test` from a standalone clone. The boundary command byte-compares
+Run `tools/verify-boundaries.sh`, `tools/verify-supply-chain.sh`,
+`bash tools/swift-package.sh build`, and `bash tools/swift-package.sh test`
+from a standalone clone. The package launcher runs SwiftPM with the exact
+resolved dependency and uses `SWIFTPM_SCRATCH` and `SWIFTPM_CACHE` when supplied.
+An ordinary clone uses its local `.build` scratch directory.
+The boundary command byte-compares
the normalized public symbol inventory against its reviewed API baseline and
rejects forbidden repository roots or credential material. In an
extbuild-enabled checkout, first run
diff --git a/Sources/RadrootsKit/RadrootsAppleMediaPreparation.swift b/Sources/RadrootsKit/RadrootsAppleMediaPreparation.swift
@@ -209,7 +209,11 @@ public actor RadrootsAppleMediaPreparer {
return try RadrootsBackgroundTransferRequest(
identifier: identifier, remoteURL: remoteURL, method: .put,
operation: .upload(source: .stagedBlob(preparedImage.file)),
- headers: ["Authorization": authorization, "Content-Type": "image/png"],
+ headers: [
+ "Authorization": authorization, "Content-Type": "image/png",
+ "X-SHA-256": preparedImage.sha256,
+ "Accept": "application/json", "Accept-Encoding": "identity",
+ ],
metadata: ["purpose": "blossom_upload", "sha256": preparedImage.sha256],
networkPolicy: networkPolicy,
responsePolicy: .boundedJSON(), expectedSourceSHA256: preparedImage.sha256
diff --git a/Tests/RadrootsKitTests/RadrootsAppleMediaPreparationTests.swift b/Tests/RadrootsKitTests/RadrootsAppleMediaPreparationTests.swift
@@ -52,6 +52,9 @@ import UniformTypeIdentifiers
#expect(request.operation == .upload(source: .stagedBlob(prepared.file)))
#expect(request.headers["Authorization"] == "Nostr signed-event")
#expect(request.headers["Content-Type"] == "image/png")
+ #expect(request.headers["X-SHA-256"] == prepared.sha256)
+ #expect(request.headers["Accept"] == "application/json")
+ #expect(request.headers["Accept-Encoding"] == "identity")
#expect(request.metadata["sha256"] == prepared.sha256)
#expect(try request.responsePolicy == .boundedJSON())
#expect(request.expectedSourceSHA256 == prepared.sha256)
diff --git a/tools/swift-package.sh b/tools/swift-package.sh
@@ -0,0 +1,27 @@
+#!/usr/bin/env bash
+set -euo pipefail
+
+repo_root="$(git rev-parse --show-toplevel)"
+cd "$repo_root"
+
+command=${1:-}
+case "$command" in
+ build|test) shift ;;
+ *) echo "usage: $0 {build|test} [SwiftPM arguments...]" >&2; exit 64 ;;
+esac
+
+scratch_path=${SWIFTPM_SCRATCH:-"$repo_root/.build"}
+case "$scratch_path" in
+ /*) ;;
+ *) echo "error: SWIFTPM_SCRATCH must be an absolute path" >&2; exit 64 ;;
+esac
+output_args=(--scratch-path "$scratch_path")
+if [[ -n "${SWIFTPM_CACHE:-}" ]]; then
+ case "$SWIFTPM_CACHE" in
+ /*) ;;
+ *) echo "error: SWIFTPM_CACHE must be an absolute path" >&2; exit 64 ;;
+ esac
+ output_args+=(--cache-path "$SWIFTPM_CACHE")
+fi
+
+exec swift "$command" "${output_args[@]}" --disable-automatic-resolution "$@"
diff --git a/tools/verify-boundaries.sh b/tools/verify-boundaries.sh
@@ -27,13 +27,13 @@ if git grep -I -n -E \
exit 1
fi
-swift build
-bin_path="$(swift build --show-bin-path)"
+bash tools/swift-package.sh build
+bin_path="$(bash tools/swift-package.sh build --show-bin-path)"
arch="$(swift -print-target-info | sed -n 's/.*"arch": "\([^"]*\)".*/\1/p')"
test -n "$arch"
sdk_path="$(xcrun --show-sdk-path --sdk macosx)"
module_map="$bin_path/libsecp256k1.build/module.modulemap"
-dependency_include="$repo_root/.build/checkouts/swift-secp256k1/Sources/libsecp256k1/include"
+dependency_include="${SWIFTPM_SCRATCH:-$repo_root/.build}/checkouts/swift-secp256k1/Sources/libsecp256k1/include"
test -f "$module_map"
test -d "$dependency_include"