check_architecture.sh (2471B)
1 #!/usr/bin/env sh 2 # Lightweight repo-owned architecture boundary check for the Hyf capsule. 3 # 4 # Enforced rules: 5 # 1. Domain purity: files under src/hyf_core must not import the provider, 6 # runtime or stdio layers, or network/OS I/O (flare, std.os, std.net). 7 # (The current src/hyf_stdio -> hyf_provider coupling is a tracked 8 # deviation resolved by step S065, not part of this rule.) 9 # 2. No source references a capsule-local .github/.act workflow path or the 10 # out-of-tree secrets.txt file. 11 # 12 # Usage: sh tools/check_architecture.sh [root] (default: .) 13 # sh tools/check_architecture.sh --self-test 14 set -eu 15 16 check_root() { 17 root="$1" 18 violations=0 19 20 if [ -d "$root/src/hyf_core" ]; then 21 for file in $(find "$root/src/hyf_core" -name '*.mojo' 2>/dev/null); do 22 if grep -nE '^[[:space:]]*(from|import)[[:space:]]+(hyf_provider|hyf_runtime|hyf_stdio)(\.|[[:space:]])' "$file" >/dev/null 2>&1 || 23 grep -nE '^[[:space:]]*(from|import)[[:space:]]+(flare|std\.os|std\.net)(\.|[[:space:]])' "$file" >/dev/null 2>&1; then 24 echo "domain boundary violation: $file" 25 violations=1 26 fi 27 done 28 fi 29 30 if [ -d "$root/src" ]; then 31 for file in $(find "$root/src" -name '*.mojo' 2>/dev/null); do 32 if grep -nE '\.github/|\.act/|secrets\.txt' "$file" >/dev/null 2>&1; then 33 echo "prohibited workflow/secret path: $file" 34 violations=1 35 fi 36 done 37 fi 38 39 return "$violations" 40 } 41 42 self_test() { 43 tmp="$(mktemp -d)" 44 trap 'rm -rf "$tmp"' EXIT 45 # Clean tree must pass. 46 mkdir -p "$tmp/clean/src/hyf_core" 47 printf 'from std.collections import List\n' > "$tmp/clean/src/hyf_core/a.mojo" 48 if ! check_root "$tmp/clean"; then 49 echo "self-test failed: clean tree rejected" 50 return 1 51 fi 52 # Domain-layer I/O import must fail. 53 mkdir -p "$tmp/bad/src/hyf_core" 54 printf 'from hyf_provider.client import get\n' > "$tmp/bad/src/hyf_core/b.mojo" 55 if check_root "$tmp/bad"; then 56 echo "self-test failed: provider import not detected" 57 return 1 58 fi 59 rm -rf "$tmp/bad" 60 mkdir -p "$tmp/bad2/src" 61 printf 'const P = ".github/workflows/ci.yml"\n' > "$tmp/bad2/src/x.mojo" 62 if check_root "$tmp/bad2"; then 63 echo "self-test failed: prohibited path not detected" 64 return 1 65 fi 66 echo "architecture self-test: ok" 67 } 68 69 if [ "${1:-}" = "--self-test" ]; then 70 self_test 71 check_root "." 72 echo "architecture check: ok" 73 exit 0 74 fi 75 76 check_root "${1:-.}" 77 echo "architecture check: ok"