apple_kit

Apple-native services for Radroots iOS and macOS apps
git clone https://radroots.dev/git/apple_kit.git
Log | Files | Refs | README | LICENSE

verify-boundaries.sh (2491B)


      1 #!/usr/bin/env bash
      2 set -euo pipefail
      3 
      4 repo_root="$(git rev-parse --show-toplevel)"
      5 cd "$repo_root"
      6 
      7 for forbidden_root in docs .github .act; do
      8   test ! -e "$forbidden_root"
      9   test ! -L "$forbidden_root"
     10 done
     11 
     12 if git ls-files | grep -E -i '(^|/)(\.env|id_rsa|id_ed25519|credentials|[^/]+\.(pem|key|p12|pfx|jks|keystore))$' >/dev/null; then
     13   echo "boundary_invalid: sensitive credential path is tracked" >&2
     14   exit 1
     15 fi
     16 if git grep -I -n -E -e '-----BEGIN ([A-Z0-9 ]+ )?PRIVATE KEY-----|AKIA[0-9A-Z]{16}|gh[pousr]_[A-Za-z0-9_]{36,}|nsec1[023456789acdefghjklmnpqrstuvwxyz]{40,}' -- Sources >/dev/null; then
     17   echo "boundary_invalid: production source contains credential material" >&2
     18   exit 1
     19 fi
     20 if git grep -I -n -E \
     21   -e 'localizedDescription' \
     22   -e 'public let errorMessage: String' \
     23   -e 'case rejected\(code: String\)' \
     24   -e 'case (invalidRequest|unavailable|permissionDenied|userCancelled|transientFailure|permanentFailure|transferFailure|persistenceFailure|notFound|blockedByPolicy|timeout|cancelled|schedulerFailure|preparationFailure|keychainStatus)\([^)]*String' \
     25   -- Sources >/dev/null; then
     26   echo "boundary_invalid: public error surface accepts arbitrary diagnostic text" >&2
     27   exit 1
     28 fi
     29 
     30 bash tools/swift-package.sh build
     31 bin_path="$(bash tools/swift-package.sh build --show-bin-path)"
     32 arch="$(swift -print-target-info | sed -n 's/.*"arch": "\([^"]*\)".*/\1/p')"
     33 test -n "$arch"
     34 sdk_path="$(xcrun --show-sdk-path --sdk macosx)"
     35 module_map="$bin_path/libsecp256k1.build/module.modulemap"
     36 dependency_include="${SWIFTPM_SCRATCH:-$repo_root/.build}/checkouts/swift-secp256k1/Sources/libsecp256k1/include"
     37 test -f "$module_map"
     38 test -d "$dependency_include"
     39 
     40 temporary_dir="$(mktemp -d)"
     41 temporary_api="$temporary_dir/apple_kit.txt"
     42 trap 'rm -rf "$temporary_dir"' EXIT
     43 
     44 for module in RadrootsKit RadrootsKitTesting; do
     45   xcrun swift-symbolgraph-extract \
     46     -module-name "$module" \
     47     -target "$arch-apple-macosx15.0" \
     48     -sdk "$sdk_path" \
     49     -I "$bin_path/Modules" \
     50     -Xcc "-fmodule-map-file=$module_map" \
     51     -Xcc -I \
     52     -Xcc "$dependency_include" \
     53     -minimum-access-level public \
     54     -skip-synthesized-members \
     55     -skip-inherited-docs \
     56     -omit-extension-block-symbols \
     57     -pretty-print \
     58     -output-dir "$temporary_dir"
     59 done
     60 
     61 swift tools/normalize-public-api.swift "$temporary_dir"/*.symbols.json >"$temporary_api"
     62 cmp "$temporary_api" contracts/api_baselines/apple_kit.txt
     63 
     64 echo "boundary ok: exact Swift API, no forbidden or credential surface"