hyf

Context-aware query service for Radroots
git clone https://radroots.dev/git/hyf.git
Log | Files | Refs | README | LICENSE

check_architecture.sh (2471B)


      1 #!/usr/bin/env sh
      2 # Lightweight repo-owned architecture boundary check for the Hyf capsule.
      3 #
      4 # Enforced rules:
      5 #   1. Domain purity: files under src/hyf_core must not import the provider,
      6 #      runtime or stdio layers, or network/OS I/O (flare, std.os, std.net).
      7 #      (The current src/hyf_stdio -> hyf_provider coupling is a tracked
      8 #      deviation resolved by step S065, not part of this rule.)
      9 #   2. No source references a capsule-local .github/.act workflow path or the
     10 #      out-of-tree secrets.txt file.
     11 #
     12 # Usage: sh tools/check_architecture.sh [root]   (default: .)
     13 #        sh tools/check_architecture.sh --self-test
     14 set -eu
     15 
     16 check_root() {
     17   root="$1"
     18   violations=0
     19 
     20   if [ -d "$root/src/hyf_core" ]; then
     21     for file in $(find "$root/src/hyf_core" -name '*.mojo' 2>/dev/null); do
     22       if grep -nE '^[[:space:]]*(from|import)[[:space:]]+(hyf_provider|hyf_runtime|hyf_stdio)(\.|[[:space:]])' "$file" >/dev/null 2>&1 ||
     23          grep -nE '^[[:space:]]*(from|import)[[:space:]]+(flare|std\.os|std\.net)(\.|[[:space:]])' "$file" >/dev/null 2>&1; then
     24         echo "domain boundary violation: $file"
     25         violations=1
     26       fi
     27     done
     28   fi
     29 
     30   if [ -d "$root/src" ]; then
     31     for file in $(find "$root/src" -name '*.mojo' 2>/dev/null); do
     32       if grep -nE '\.github/|\.act/|secrets\.txt' "$file" >/dev/null 2>&1; then
     33         echo "prohibited workflow/secret path: $file"
     34         violations=1
     35       fi
     36     done
     37   fi
     38 
     39   return "$violations"
     40 }
     41 
     42 self_test() {
     43   tmp="$(mktemp -d)"
     44   trap 'rm -rf "$tmp"' EXIT
     45   # Clean tree must pass.
     46   mkdir -p "$tmp/clean/src/hyf_core"
     47   printf 'from std.collections import List\n' > "$tmp/clean/src/hyf_core/a.mojo"
     48   if ! check_root "$tmp/clean"; then
     49     echo "self-test failed: clean tree rejected"
     50     return 1
     51   fi
     52   # Domain-layer I/O import must fail.
     53   mkdir -p "$tmp/bad/src/hyf_core"
     54   printf 'from hyf_provider.client import get\n' > "$tmp/bad/src/hyf_core/b.mojo"
     55   if check_root "$tmp/bad"; then
     56     echo "self-test failed: provider import not detected"
     57     return 1
     58   fi
     59   rm -rf "$tmp/bad"
     60   mkdir -p "$tmp/bad2/src"
     61   printf 'const P = ".github/workflows/ci.yml"\n' > "$tmp/bad2/src/x.mojo"
     62   if check_root "$tmp/bad2"; then
     63     echo "self-test failed: prohibited path not detected"
     64     return 1
     65   fi
     66   echo "architecture self-test: ok"
     67 }
     68 
     69 if [ "${1:-}" = "--self-test" ]; then
     70   self_test
     71   check_root "."
     72   echo "architecture check: ok"
     73   exit 0
     74 fi
     75 
     76 check_root "${1:-.}"
     77 echo "architecture check: ok"