cli

Command-line interface for Radroots
git clone https://radroots.dev/git/cli.git
Log | Files | Refs | README | LICENSE

commit c96c4805d0577b12c3cb5056d730627759204090
parent 17a42017217a3e47790ba3963ae871a055edb4c3
Author: triesap <tyson@radroots.org>
Date:   Tue, 25 Aug 2026 07:17:28 +0000

security: enforce standalone supply-chain policy

Diffstat:
MAGENTS.md | 32+++++++++++++++++++-------------
MREADME | 19++++++++++++-------
Adeny.toml | 60++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Ascripts/verify-supply-chain.sh | 11+++++++++++
Asupply-chain/audits.toml | 4++++
Asupply-chain/config.toml | 713+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Asupply-chain/imports.lock | 2++
7 files changed, 821 insertions(+), 20 deletions(-)

diff --git a/AGENTS.md b/AGENTS.md @@ -23,10 +23,12 @@ paths, or an enclosing monorepo layout. ## Authority and published-source boundary Repository-local machine authority is limited to manifests and locks, -`radroots.lib.source-lock.v1.toml`, and explicit machine-readable contracts -added under `contracts/**`. Source and tests are implementation evidence, and -`flake.nix` owns the standalone command surfaces. The root `README` is concise -public routing material, not a substitute for a machine contract. +`radroots.lib.source-lock.v1.toml`, the checked-in dependency-policy store, and +explicit machine-readable contracts added under `contracts/**`. Source and +tests are implementation evidence. Native Cargo and repository scripts own +the standalone command surfaces; checked-in Nix material is deferred and +unclaimed through RCLD-RSHR-170. The root `README` is concise public routing +material, not a substitute for a machine contract. `.env.example` is non-authoritative pre-refactor evidence. It does not describe current runtime behavior and remains only until its owning later cleanup @@ -100,17 +102,21 @@ then route repository-owned commands through `cargo extbuild run -- ...`. Standalone public verification surfaces are: ```sh -nix run .#fmt -nix run .#check -nix run .#test -nix run .#release-acceptance +cargo fmt --all --check +cargo check --all-targets --locked +cargo test --all-targets --locked +cargo clippy --all-targets --locked -- -D warnings +RUSTDOCFLAGS="-D warnings" cargo doc --no-deps --locked +scripts/verify-supply-chain.sh +tools/verify-repository-boundary.sh ``` -Use the smallest relevant surface during development and the complete release -acceptance surface for a production candidate. Rust changes additionally -require the relevant locked `cargo fmt`, `cargo check`, `cargo test`, and -warnings-denied `cargo clippy` lanes. Run `git diff --check` and inspect the -final status and diff before every checkpoint. +Use the smallest relevant surface during development and the complete native +set for a production candidate. The supply-chain gate uses exact cargo-deny +0.19.8 and cargo-vet 0.10.2; its checked-in exemptions are visible accepted +review debt, not claims of independent source audits. Nix and OCI remain +deferred and unclaimed through RCLD-RSHR-170. Run `git diff --check` and +inspect the final status and diff before every checkpoint. Never claim a lane passed unless it ran successfully. Record unavailable or environment-blocked lanes exactly, and do not treat parent-only automation as a diff --git a/README b/README @@ -76,15 +76,20 @@ not a standalone build or release input. The forge-agnostic standalone checks are: ```sh -nix run .#fmt -nix run .#check -nix run .#test -nix run .#release-acceptance +cargo fmt --all --check +cargo check --all-targets --locked +cargo test --all-targets --locked +cargo clippy --all-targets --locked -- -D warnings +RUSTDOCFLAGS="-D warnings" cargo doc --no-deps --locked +scripts/verify-supply-chain.sh +tools/verify-repository-boundary.sh ``` -Each surface rejects forbidden capsule-local documentation and workflow roots -before running its Rust checks. An extbuild-enabled checkout routes these -commands through `cargo extbuild run -- ...`. +The supply-chain command validates the exact locked dependency graph, license +policy, approved registries and immutable Lib source, then rejects forbidden +capsule-local documentation and workflow roots. An extbuild-enabled checkout +routes these commands through `cargo extbuild run -- ...`. Nix and OCI are +deferred and unclaimed through RCLD-RSHR-170. ## Copyright and license diff --git a/deny.toml b/deny.toml @@ -0,0 +1,60 @@ +[graph] +targets = [ + "aarch64-apple-darwin", + "aarch64-unknown-linux-gnu", + "x86_64-pc-windows-gnu", + "x86_64-unknown-linux-gnu", +] +all-features = true + +[advisories] +ignore = [] + +[licenses] +allow = [ + "0BSD", + "Apache-2.0", + "Apache-2.0 WITH LLVM-exception", + "BSD-1-Clause", + "BSD-2-Clause", + "BSD-3-Clause", + "BSL-1.0", + "CC0-1.0", + "CDLA-Permissive-2.0", + "GPL-3.0-or-later", + "ISC", + "MIT", + "MIT-0", + "MPL-2.0", + "Unicode-3.0", + "Unlicense", + "Zlib", +] +confidence-threshold = 0.93 + +[licenses.private] +ignore = false +registries = [] + +[bans] +multiple-versions = "allow" +wildcards = "deny" +highlight = "all" +workspace-default-features = "allow" +external-default-features = "allow" +allow = [] +allow-workspace = true +deny = [] +skip = [] +skip-tree = [] + +[sources] +unknown-registry = "deny" +unknown-git = "deny" +allow-registry = ["https://github.com/rust-lang/crates.io-index"] +allow-git = ["https://github.com/radrootslabs/lib.git"] + +[sources.allow-org] +github = [] +gitlab = [] +bitbucket = [] diff --git a/scripts/verify-supply-chain.sh b/scripts/verify-supply-chain.sh @@ -0,0 +1,11 @@ +#!/usr/bin/env bash +set -euo pipefail + +repo_root="$(git rev-parse --show-toplevel)" +cd "$repo_root" + +test "$(cargo deny --version)" = "cargo-deny 0.19.8" +test "$(cargo vet --version)" = "cargo-vet 0.10.2" +cargo vet --locked +cargo deny -L error --all-features --locked check advisories bans licenses sources +tools/verify-repository-boundary.sh diff --git a/supply-chain/audits.toml b/supply-chain/audits.toml @@ -0,0 +1,4 @@ + +# cargo-vet audits file + +[audits] diff --git a/supply-chain/config.toml b/supply-chain/config.toml @@ -0,0 +1,713 @@ + +# cargo-vet config file + +[cargo-vet] +version = "0.10" + +[[exemptions.allocator-api2]] +version = "0.2.21" +criteria = "safe-to-deploy" + +[[exemptions.anstream]] +version = "1.0.0" +criteria = "safe-to-deploy" + +[[exemptions.anstyle]] +version = "1.0.14" +criteria = "safe-to-deploy" + +[[exemptions.anstyle-parse]] +version = "1.0.0" +criteria = "safe-to-deploy" + +[[exemptions.anstyle-query]] +version = "1.1.5" +criteria = "safe-to-deploy" + +[[exemptions.anstyle-wincon]] +version = "3.0.11" +criteria = "safe-to-deploy" + +[[exemptions.arrayvec]] +version = "0.7.8" +criteria = "safe-to-deploy" + +[[exemptions.assert_cmd]] +version = "2.2.2" +criteria = "safe-to-run" + +[[exemptions.atoi]] +version = "2.0.0" +criteria = "safe-to-deploy" + +[[exemptions.autocfg]] +version = "1.5.1" +criteria = "safe-to-deploy" + +[[exemptions.base16ct]] +version = "0.2.0" +criteria = "safe-to-deploy" + +[[exemptions.base64]] +version = "0.22.1" +criteria = "safe-to-deploy" + +[[exemptions.bitflags]] +version = "2.13.1" +criteria = "safe-to-deploy" + +[[exemptions.block-buffer]] +version = "0.10.4" +criteria = "safe-to-deploy" + +[[exemptions.bstr]] +version = "1.13.0" +criteria = "safe-to-run" + +[[exemptions.bumpalo]] +version = "3.20.3" +criteria = "safe-to-deploy" + +[[exemptions.bytes]] +version = "1.12.1" +criteria = "safe-to-deploy" + +[[exemptions.cc]] +version = "1.4.0" +criteria = "safe-to-deploy" + +[[exemptions.cfg-if]] +version = "1.0.4" +criteria = "safe-to-deploy" + +[[exemptions.clap]] +version = "4.6.5" +criteria = "safe-to-deploy" + +[[exemptions.clap_builder]] +version = "4.6.5" +criteria = "safe-to-deploy" + +[[exemptions.clap_derive]] +version = "4.6.4" +criteria = "safe-to-deploy" + +[[exemptions.clap_lex]] +version = "1.1.0" +criteria = "safe-to-deploy" + +[[exemptions.colorchoice]] +version = "1.0.5" +criteria = "safe-to-deploy" + +[[exemptions.const-oid]] +version = "0.9.6" +criteria = "safe-to-deploy" + +[[exemptions.cpufeatures]] +version = "0.2.17" +criteria = "safe-to-deploy" + +[[exemptions.crc]] +version = "3.4.0" +criteria = "safe-to-deploy" + +[[exemptions.crc-catalog]] +version = "2.5.0" +criteria = "safe-to-deploy" + +[[exemptions.crossbeam-queue]] +version = "0.3.13" +criteria = "safe-to-deploy" + +[[exemptions.crossbeam-utils]] +version = "0.8.22" +criteria = "safe-to-deploy" + +[[exemptions.crypto-bigint]] +version = "0.5.5" +criteria = "safe-to-deploy" + +[[exemptions.crypto-common]] +version = "0.1.6" +criteria = "safe-to-deploy" + +[[exemptions.der]] +version = "0.7.10" +criteria = "safe-to-deploy" + +[[exemptions.difflib]] +version = "0.4.0" +criteria = "safe-to-run" + +[[exemptions.digest]] +version = "0.10.7" +criteria = "safe-to-deploy" + +[[exemptions.displaydoc]] +version = "0.2.7" +criteria = "safe-to-deploy" + +[[exemptions.dotenvy]] +version = "0.15.7" +criteria = "safe-to-deploy" + +[[exemptions.either]] +version = "1.17.0" +criteria = "safe-to-deploy" + +[[exemptions.elliptic-curve]] +version = "0.13.8" +criteria = "safe-to-deploy" + +[[exemptions.equivalent]] +version = "1.0.2" +criteria = "safe-to-deploy" + +[[exemptions.errno]] +version = "0.3.14" +criteria = "safe-to-deploy" + +[[exemptions.event-listener]] +version = "5.4.2" +criteria = "safe-to-deploy" + +[[exemptions.fastrand]] +version = "2.5.0" +criteria = "safe-to-deploy" + +[[exemptions.ff]] +version = "0.13.1" +criteria = "safe-to-deploy" + +[[exemptions.find-msvc-tools]] +version = "0.1.9" +criteria = "safe-to-deploy" + +[[exemptions.flume]] +version = "0.12.0" +criteria = "safe-to-deploy" + +[[exemptions.foldhash]] +version = "0.2.0" +criteria = "safe-to-deploy" + +[[exemptions.form_urlencoded]] +version = "1.2.2" +criteria = "safe-to-deploy" + +[[exemptions.fs2]] +version = "0.4.3" +criteria = "safe-to-deploy" + +[[exemptions.futures]] +version = "0.3.34" +criteria = "safe-to-deploy" + +[[exemptions.futures-channel]] +version = "0.3.34" +criteria = "safe-to-deploy" + +[[exemptions.futures-core]] +version = "0.3.34" +criteria = "safe-to-deploy" + +[[exemptions.futures-executor]] +version = "0.3.34" +criteria = "safe-to-deploy" + +[[exemptions.futures-intrusive]] +version = "0.5.0" +criteria = "safe-to-deploy" + +[[exemptions.futures-io]] +version = "0.3.34" +criteria = "safe-to-deploy" + +[[exemptions.futures-macro]] +version = "0.3.34" +criteria = "safe-to-deploy" + +[[exemptions.futures-sink]] +version = "0.3.34" +criteria = "safe-to-deploy" + +[[exemptions.futures-task]] +version = "0.3.34" +criteria = "safe-to-deploy" + +[[exemptions.futures-util]] +version = "0.3.34" +criteria = "safe-to-deploy" + +[[exemptions.generic-array]] +version = "0.14.9" +criteria = "safe-to-deploy" + +[[exemptions.getrandom]] +version = "0.4.3" +criteria = "safe-to-deploy" + +[[exemptions.group]] +version = "0.13.0" +criteria = "safe-to-deploy" + +[[exemptions.hashbrown]] +version = "0.16.1" +criteria = "safe-to-deploy" + +[[exemptions.hashbrown]] +version = "0.17.1" +criteria = "safe-to-deploy" + +[[exemptions.hashlink]] +version = "0.11.1" +criteria = "safe-to-deploy" + +[[exemptions.heck]] +version = "0.5.0" +criteria = "safe-to-deploy" + +[[exemptions.hex]] +version = "0.4.3" +criteria = "safe-to-deploy" + +[[exemptions.icu_collections]] +version = "2.2.0" +criteria = "safe-to-deploy" + +[[exemptions.icu_locale_core]] +version = "2.2.0" +criteria = "safe-to-deploy" + +[[exemptions.icu_normalizer]] +version = "2.2.0" +criteria = "safe-to-deploy" + +[[exemptions.icu_normalizer_data]] +version = "2.2.0" +criteria = "safe-to-deploy" + +[[exemptions.icu_properties]] +version = "2.2.0" +criteria = "safe-to-deploy" + +[[exemptions.icu_properties_data]] +version = "2.2.0" +criteria = "safe-to-deploy" + +[[exemptions.icu_provider]] +version = "2.2.0" +criteria = "safe-to-deploy" + +[[exemptions.idna]] +version = "1.1.0" +criteria = "safe-to-deploy" + +[[exemptions.idna_adapter]] +version = "1.2.2" +criteria = "safe-to-deploy" + +[[exemptions.indexmap]] +version = "2.14.0" +criteria = "safe-to-deploy" + +[[exemptions.is_terminal_polyfill]] +version = "1.70.2" +criteria = "safe-to-deploy" + +[[exemptions.itoa]] +version = "1.0.18" +criteria = "safe-to-deploy" + +[[exemptions.jiff-tzdb]] +version = "0.1.8" +criteria = "safe-to-deploy" + +[[exemptions.k256]] +version = "0.13.4" +criteria = "safe-to-deploy" + +[[exemptions.libc]] +version = "0.2.189" +criteria = "safe-to-deploy" + +[[exemptions.libsqlite3-sys]] +version = "0.37.0" +criteria = "safe-to-deploy" + +[[exemptions.linux-raw-sys]] +version = "0.12.1" +criteria = "safe-to-deploy" + +[[exemptions.litemap]] +version = "0.8.2" +criteria = "safe-to-deploy" + +[[exemptions.lock_api]] +version = "0.4.14" +criteria = "safe-to-deploy" + +[[exemptions.log]] +version = "0.4.33" +criteria = "safe-to-deploy" + +[[exemptions.mediatype]] +version = "0.21.0" +criteria = "safe-to-deploy" + +[[exemptions.memchr]] +version = "2.8.3" +criteria = "safe-to-deploy" + +[[exemptions.mio]] +version = "1.2.2" +criteria = "safe-to-deploy" + +[[exemptions.num-traits]] +version = "0.2.19" +criteria = "safe-to-deploy" + +[[exemptions.once_cell]] +version = "1.21.4" +criteria = "safe-to-deploy" + +[[exemptions.once_cell_polyfill]] +version = "1.70.2" +criteria = "safe-to-deploy" + +[[exemptions.parking]] +version = "2.2.1" +criteria = "safe-to-deploy" + +[[exemptions.parking_lot]] +version = "0.12.5" +criteria = "safe-to-deploy" + +[[exemptions.parking_lot_core]] +version = "0.9.12" +criteria = "safe-to-deploy" + +[[exemptions.percent-encoding]] +version = "2.3.2" +criteria = "safe-to-deploy" + +[[exemptions.pin-project-lite]] +version = "0.2.17" +criteria = "safe-to-deploy" + +[[exemptions.pkg-config]] +version = "0.3.33" +criteria = "safe-to-deploy" + +[[exemptions.potential_utf]] +version = "0.1.5" +criteria = "safe-to-deploy" + +[[exemptions.predicates]] +version = "3.1.4" +criteria = "safe-to-run" + +[[exemptions.predicates-core]] +version = "1.0.10" +criteria = "safe-to-run" + +[[exemptions.predicates-tree]] +version = "1.0.13" +criteria = "safe-to-run" + +[[exemptions.proc-macro2]] +version = "1.0.107" +criteria = "safe-to-deploy" + +[[exemptions.quote]] +version = "1.0.47" +criteria = "safe-to-deploy" + +[[exemptions.r-efi]] +version = "6.0.0" +criteria = "safe-to-deploy" + +[[exemptions.rand_core]] +version = "0.6.4" +criteria = "safe-to-deploy" + +[[exemptions.redox_syscall]] +version = "0.5.18" +criteria = "safe-to-deploy" + +[[exemptions.regex-automata]] +version = "0.4.18" +criteria = "safe-to-run" + +[[exemptions.rust_decimal]] +version = "1.42.1" +criteria = "safe-to-deploy" + +[[exemptions.rustix]] +version = "1.1.4" +criteria = "safe-to-deploy" + +[[exemptions.rustversion]] +version = "1.0.23" +criteria = "safe-to-deploy" + +[[exemptions.scopeguard]] +version = "1.2.0" +criteria = "safe-to-deploy" + +[[exemptions.sec1]] +version = "0.7.3" +criteria = "safe-to-deploy" + +[[exemptions.secp256k1]] +version = "0.29.1" +criteria = "safe-to-deploy" + +[[exemptions.secp256k1-sys]] +version = "0.10.1" +criteria = "safe-to-deploy" + +[[exemptions.serde]] +version = "1.0.229" +criteria = "safe-to-deploy" + +[[exemptions.serde_core]] +version = "1.0.229" +criteria = "safe-to-deploy" + +[[exemptions.serde_derive]] +version = "1.0.229" +criteria = "safe-to-deploy" + +[[exemptions.serde_json]] +version = "1.0.151" +criteria = "safe-to-deploy" + +[[exemptions.sha2]] +version = "0.10.9" +criteria = "safe-to-deploy" + +[[exemptions.shlex]] +version = "2.0.1" +criteria = "safe-to-deploy" + +[[exemptions.slab]] +version = "0.4.12" +criteria = "safe-to-deploy" + +[[exemptions.smallvec]] +version = "1.15.2" +criteria = "safe-to-deploy" + +[[exemptions.socket2]] +version = "0.6.5" +criteria = "safe-to-deploy" + +[[exemptions.spin]] +version = "0.9.9" +criteria = "safe-to-deploy" + +[[exemptions.sqlx]] +version = "0.9.0" +criteria = "safe-to-deploy" + +[[exemptions.sqlx-core]] +version = "0.9.0" +criteria = "safe-to-deploy" + +[[exemptions.sqlx-macros]] +version = "0.9.0" +criteria = "safe-to-deploy" + +[[exemptions.sqlx-macros-core]] +version = "0.9.0" +criteria = "safe-to-deploy" + +[[exemptions.sqlx-sqlite]] +version = "0.9.0" +criteria = "safe-to-deploy" + +[[exemptions.stable_deref_trait]] +version = "1.2.1" +criteria = "safe-to-deploy" + +[[exemptions.strsim]] +version = "0.11.1" +criteria = "safe-to-deploy" + +[[exemptions.subtle]] +version = "2.6.1" +criteria = "safe-to-deploy" + +[[exemptions.syn]] +version = "2.0.119" +criteria = "safe-to-deploy" + +[[exemptions.syn]] +version = "3.0.3" +criteria = "safe-to-deploy" + +[[exemptions.synstructure]] +version = "0.13.2" +criteria = "safe-to-deploy" + +[[exemptions.tempfile]] +version = "3.27.0" +criteria = "safe-to-deploy" + +[[exemptions.termtree]] +version = "0.5.1" +criteria = "safe-to-run" + +[[exemptions.thiserror]] +version = "2.0.19" +criteria = "safe-to-deploy" + +[[exemptions.thiserror-impl]] +version = "2.0.19" +criteria = "safe-to-deploy" + +[[exemptions.tinystr]] +version = "0.8.3" +criteria = "safe-to-deploy" + +[[exemptions.tokio]] +version = "1.53.1" +criteria = "safe-to-deploy" + +[[exemptions.tokio-macros]] +version = "2.7.2" +criteria = "safe-to-deploy" + +[[exemptions.tokio-stream]] +version = "0.1.19" +criteria = "safe-to-deploy" + +[[exemptions.tracing]] +version = "0.1.44" +criteria = "safe-to-deploy" + +[[exemptions.tracing-attributes]] +version = "0.1.31" +criteria = "safe-to-deploy" + +[[exemptions.tracing-core]] +version = "0.1.36" +criteria = "safe-to-deploy" + +[[exemptions.typenum]] +version = "1.20.1" +criteria = "safe-to-deploy" + +[[exemptions.unicode-general-category]] +version = "1.1.0" +criteria = "safe-to-deploy" + +[[exemptions.unicode-ident]] +version = "1.0.24" +criteria = "safe-to-deploy" + +[[exemptions.url]] +version = "2.5.8" +criteria = "safe-to-deploy" + +[[exemptions.utf8_iter]] +version = "1.0.4" +criteria = "safe-to-deploy" + +[[exemptions.utf8parse]] +version = "0.2.2" +criteria = "safe-to-deploy" + +[[exemptions.vcpkg]] +version = "0.2.15" +criteria = "safe-to-deploy" + +[[exemptions.version_check]] +version = "0.9.5" +criteria = "safe-to-deploy" + +[[exemptions.wait-timeout]] +version = "0.2.1" +criteria = "safe-to-run" + +[[exemptions.wasi]] +version = "0.11.1+wasi-snapshot-preview1" +criteria = "safe-to-deploy" + +[[exemptions.wasm-bindgen]] +version = "0.2.126" +criteria = "safe-to-deploy" + +[[exemptions.wasm-bindgen-macro]] +version = "0.2.126" +criteria = "safe-to-deploy" + +[[exemptions.wasm-bindgen-macro-support]] +version = "0.2.126" +criteria = "safe-to-deploy" + +[[exemptions.wasm-bindgen-shared]] +version = "0.2.126" +criteria = "safe-to-deploy" + +[[exemptions.winapi]] +version = "0.3.9" +criteria = "safe-to-deploy" + +[[exemptions.winapi-i686-pc-windows-gnu]] +version = "0.4.0" +criteria = "safe-to-deploy" + +[[exemptions.winapi-x86_64-pc-windows-gnu]] +version = "0.4.0" +criteria = "safe-to-deploy" + +[[exemptions.windows-link]] +version = "0.2.1" +criteria = "safe-to-deploy" + +[[exemptions.windows-sys]] +version = "0.61.2" +criteria = "safe-to-deploy" + +[[exemptions.writeable]] +version = "0.6.3" +criteria = "safe-to-deploy" + +[[exemptions.yoke]] +version = "0.8.3" +criteria = "safe-to-deploy" + +[[exemptions.yoke-derive]] +version = "0.8.2" +criteria = "safe-to-deploy" + +[[exemptions.zerofrom]] +version = "0.1.8" +criteria = "safe-to-deploy" + +[[exemptions.zerofrom-derive]] +version = "0.1.7" +criteria = "safe-to-deploy" + +[[exemptions.zeroize]] +version = "1.9.0" +criteria = "safe-to-deploy" + +[[exemptions.zerotrie]] +version = "0.2.4" +criteria = "safe-to-deploy" + +[[exemptions.zerovec]] +version = "0.11.6" +criteria = "safe-to-deploy" + +[[exemptions.zerovec-derive]] +version = "0.11.3" +criteria = "safe-to-deploy" + +[[exemptions.zmij]] +version = "1.0.23" +criteria = "safe-to-deploy" diff --git a/supply-chain/imports.lock b/supply-chain/imports.lock @@ -0,0 +1,2 @@ + +# cargo-vet imports lock