apple_kit

Apple-native services for Radroots iOS and macOS apps
git clone https://radroots.dev/git/apple_kit.git
Log | Files | Refs | README | LICENSE

README (2380B)


      1 # apple_kit
      2 
      3 This is the README for `apple_kit` which contains `RadrootsKit`, the shared
      4 Swift package for native Rad Roots Apple-platform application services.
      5 
      6 ## Verification
      7 
      8 Run `tools/verify-boundaries.sh`, `tools/verify-supply-chain.sh`,
      9 `bash tools/swift-package.sh build`, and `bash tools/swift-package.sh test`
     10 from a standalone clone. The package launcher runs SwiftPM with the exact
     11 resolved dependency and uses `SWIFTPM_SCRATCH` and `SWIFTPM_CACHE` when supplied.
     12 An ordinary clone uses its local `.build` scratch directory.
     13 The boundary command byte-compares
     14 the normalized public symbol inventory against its reviewed API baseline and
     15 rejects forbidden repository roots or credential material. In an
     16 extbuild-enabled checkout, first run
     17 `cargo extbuild doctor` and route those commands through
     18 `cargo extbuild run --`.
     19 
     20 ## Storage capacity
     21 
     22 File, capture and transfer adapters report typed capacity failures without raw
     23 filesystem details. The atomic file writer checks original-byte capacity on its
     24 held directory descriptor before creating pending bytes. This local check does
     25 not reserve space, export capacity values, or replace actual write/quota error
     26 handling. A failed write may already have installed bytes; retain the
     27 original identity and reconcile before retrying. The transfer receipt envelope
     28 has a separate bounded-capacity error. Neither error authorizes deletion of
     29 unresolved receipts, staged media or leases, or automatic network retry.
     30 
     31 ## Identity custody
     32 
     33 User-presence cancellation and timeout invalidate the active authentication
     34 context. Cancellation before evaluation prevents its launch. Legacy identity
     35 migration removes the legacy secret only after reading and validating the
     36 retained active key against the same public identity. An unavailable or invalid
     37 active key preserves legacy custody for explicit recovery.
     38 Hosts with retained public metadata can supply its expected public key to the
     39 guarded migration overload; a mismatch fails before import or legacy deletion.
     40 Cancelled custody requests cannot use a later successful presence callback to
     41 authorize another effect. Cancellation does not roll back an already committed key.
     42 
     43 ## Copyright
     44 
     45 Except as otherwise noted, all files in the `apple_kit` distribution are
     46 
     47     Copyright (c) 2026 Tyson Lupul
     48 
     49 ## License
     50 
     51 This repository is licensed under GPL-3.0-or-later. See LICENSE.