commit 2db097f9cbddac08fba681521dc552002052f8c2
parent 2a78c41a2c0ebbf1d10253fb0d58361fa84f1a69
Author: triesap <tyson@radroots.org>
Date: Tue, 28 Jul 2026 06:17:17 +0000
contract: govern event store production identity
- inventory every hand-written event-store production AST digest.
- accept test-only additions while retaining mixed-config production items.
- keep generated and vector predecessor artifacts exact-byte pinned.
- verify mutation tests, full xtask, strict Clippy, and formatting.
Diffstat:
5 files changed, 296 insertions(+), 1 deletion(-)
diff --git a/contracts/event_store_production_sources.toml b/contracts/event_store_production_sources.toml
@@ -0,0 +1,114 @@
+schema_version = 1
+hash_algorithm = "rust_production_ast_sha256_v1"
+
+[[sources]]
+path = "crates/event_store/src/error.rs"
+sha256 = "e218754814e195a76fcdfa99c4c4abeaa3b045b4c799b56685ed8acfe5edb90b"
+
+[[sources]]
+path = "crates/event_store/src/lib.rs"
+sha256 = "7d588cd181f42b6c8731d84f71e5a778cd6605add07dc9b7d0b8144b51a44a9f"
+
+[[sources]]
+path = "crates/event_store/src/migrations.rs"
+sha256 = "5244eaf726eaa1f81973c98ded096e78b4874dedcd869f6ab6b844962efb51d6"
+
+[[sources]]
+path = "crates/event_store/src/model.rs"
+sha256 = "14a98fe4361baa90e74c499ca96cd47822531041dfd874281b1758796b8fd22e"
+
+[[sources]]
+path = "crates/event_store/src/model/addressable_transition_feed_v1.rs"
+sha256 = "da82c889de4c131b33f40c88aced0a381b7f213b297d125327334714ab4c2511"
+
+[[sources]]
+path = "crates/event_store/src/model/current_visibility_v1.rs"
+sha256 = "f7ac71596075fe1bff6556d0eb0b63cc0fc0a20a8aca567f77fb05796f0c3d1c"
+
+[[sources]]
+path = "crates/event_store/src/model/food_availability_projection_v1.rs"
+sha256 = "ad6e31eb32bec50b61ac1810f6a62d9f693e2673e372ae12268160c2e59c6e6e"
+
+[[sources]]
+path = "crates/event_store/src/model/ingest_reconciliation_v1.rs"
+sha256 = "94e9d94f72ee9205cf8ea4af3f46aa6c6c94464032f95c555246d258ef6a3ea4"
+
+[[sources]]
+path = "crates/event_store/src/model/raw_source_rebuild_v1.rs"
+sha256 = "c5f39614b2d1d7b108fc8215675b0c1ebd121b878651890ed35ea0a6efadb9f5"
+
+[[sources]]
+path = "crates/event_store/src/model/reconciliation_v1.rs"
+sha256 = "e0f86be7735eec65d563fb5f608dcfe5cb90099510c8297c800f0ec5f2369f14"
+
+[[sources]]
+path = "crates/event_store/src/nip09.rs"
+sha256 = "fbd8a3b36d7f36e7b0d301aee0847d42c3908659f066cafcae3e247d67a75845"
+
+[[sources]]
+path = "crates/event_store/src/nip09/reconciliation_v1.rs"
+sha256 = "e532a0e1224896f94efe40aa1e6bc187853d0a919a8427b6a776d32733994e82"
+
+[[sources]]
+path = "crates/event_store/src/nip09/reconciliation_v1/raw_source_rebuild.rs"
+sha256 = "30a465f5df9a37654d15df2a92ee445037ef41c6f5a5b31e216879f4903b3d6c"
+
+[[sources]]
+path = "crates/event_store/src/nip09/reconciliation_v1/visibility_oracle_v1.rs"
+sha256 = "b85b11baf75cc9d838c996c728d35141b7cd9d0134f5d5baae2159b7d93fa38b"
+
+[[sources]]
+path = "crates/event_store/src/schema.rs"
+sha256 = "0527f9cc7d8d0bf1a4481327f8bd9549eba1bd6bbcce87d57f8bc5fbdb990bb7"
+
+[[sources]]
+path = "crates/event_store/src/source_maintenance_v1.rs"
+sha256 = "181576a5de365cf664b8a87091c30b0389ce0be90e7d1cc16fd7170342f6c2bc"
+
+[[sources]]
+path = "crates/event_store/src/store.rs"
+sha256 = "ef277328d99ef75a978f2907dc654cbf391436b9db693c3be69655dccbe74f89"
+
+[[sources]]
+path = "crates/event_store/src/store/addressable_transition_feed_v1.rs"
+sha256 = "4d1d9b09bacbfc1bcbedcfc641a50679b6b4b51e39786ab9e321a6d78c04f744"
+
+[[sources]]
+path = "crates/event_store/src/store/current_visibility_v1.rs"
+sha256 = "56a21d2ec6a408a2dd5131db0e3c7343c67e60efc67a9c8b2f97fbb90d2d5788"
+
+[[sources]]
+path = "crates/event_store/src/store/food_availability_projection_v1.rs"
+sha256 = "72d28049b8e28b48bb268318c458928e254369d23502b934bcc98bd38bbea390"
+
+[[sources]]
+path = "crates/event_store/src/store/post_core_extension_capabilities.rs"
+sha256 = "875d622e446c2ba31d032236848315cfc7830a4d744847c5e0d5dc5859ce3057"
+
+[[sources]]
+path = "crates/event_store/src/store/post_core_extension_dispatcher.rs"
+sha256 = "1a5569a1a29849db3eeebc92316aeea26db4b2dc58b7b7f297349fcb89b0ca34"
+
+[[sources]]
+path = "crates/event_store/src/store/post_core_extensions_v1.rs"
+sha256 = "4b12d5257e425ed1e15e20dec3558d1b02455f86b95342900db7d10286d6da00"
+
+[[sources]]
+path = "crates/event_store/src/store/post_core_extensions_v2.rs"
+sha256 = "9a1e1e576c5e82a87b26a20cc95a18ee57dda200d50a7e7c51150465e28815b4"
+
+[[sources]]
+path = "crates/event_store/src/store/post_core_storage_v1.rs"
+sha256 = "3febcfc52c52e027764c29c11ab38b148328f829525b6c8cb37cd1ca5c173811"
+
+[[sources]]
+path = "crates/event_store/src/store/post_core_storage_v2.rs"
+sha256 = "5ebd237e8f475184480938472e472ff8f4a7ea7b9f46f9d6100520d1c2d643c4"
+
+[[sources]]
+path = "crates/event_store/src/store/protocol_reconciliation_v1.rs"
+sha256 = "f9d6e28251c8ecaa60ec6ea1b4c2ab2bc0b9d125e67ea4849d35e09324a20108"
+
+[[sources]]
+path = "crates/event_store/src/store/protocol_storage_v1.rs"
+sha256 = "00378eb3b038e549fc4fa1da6797d99333be6baca2bce294be4b16a2c2bfa98e"
diff --git a/contracts/semantic_validator_inventory.toml b/contracts/semantic_validator_inventory.toml
@@ -26,6 +26,7 @@ implementation_paths = [
]
governed_inputs = [
"contracts/conformance/vectors/event_store",
+ "contracts/event_store_production_sources.toml",
"crates/event_store/Cargo.toml",
"crates/event_store/contracts",
"crates/event_store/migrations",
diff --git a/tools/xtask/src/contract/nip09_reconciliation.rs b/tools/xtask/src/contract/nip09_reconciliation.rs
@@ -2855,6 +2855,13 @@ fn canonical_rust_ast(
Ok(canonical)
}
+pub(super) fn canonical_production_rust_bytes(
+ relative: &str,
+ bytes: &[u8],
+) -> Result<Vec<u8>, String> {
+ canonical_rust_ast(relative, bytes, RustAstProfile::Production)
+}
+
fn parse_canonical_production_rust(relative: &str, bytes: &[u8]) -> Result<syn::File, String> {
let canonical = canonical_rust_ast(relative, bytes, RustAstProfile::Production)?;
let canonical = std::str::from_utf8(&canonical)
diff --git a/tools/xtask/src/contract/raw_source_rebuild.rs b/tools/xtask/src/contract/raw_source_rebuild.rs
@@ -1,7 +1,8 @@
use super::artifact_bundle::{GeneratedArtifact, read_regular_file};
use super::food_availability_projection::validate_food_availability_projection_predecessor_production_sources_under_lock;
use super::nip09_reconciliation::{
- governed_regular_file_inventory, validate_current_event_store_successor_authority,
+ canonical_production_rust_bytes, governed_regular_file_inventory,
+ validate_current_event_store_successor_authority,
validate_raw_source_rebuild_successor_compiler_inputs,
};
use super::source_maintenance::validate_source_maintenance_manifest_under_lock;
@@ -55,7 +56,10 @@ const EVENT_STORE_SUCCESSOR_COMPILER_TABLES_SHA256: &str =
const SCOPED_INTEGRITY_MODE: &str = "event_store_owned_tables_and_indices_v1";
const SQLITE_SEQUENCE_SCOPE: &str = "target_first_after_single_shared_sequence_scan_v1";
const HASH_ALGORITHM: &str = "sha256_bytes_v1";
+const PRODUCTION_AST_HASH_ALGORITHM: &str = "rust_production_ast_sha256_v1";
const WRITE_COMMAND: &str = "cargo xtask contract raw-source-rebuild-manifest --write";
+const EVENT_STORE_PRODUCTION_SOURCES_RELATIVE: &str =
+ "contracts/event_store_production_sources.toml";
const MANIFEST_RELATIVE: &str = "crates/event_store/contracts/raw_source_rebuild_v1.manifest.json";
const MANIFEST_SCHEMA_RELATIVE: &str =
@@ -75,6 +79,8 @@ const RESULT_VECTOR_EXECUTOR_ID: &str =
const RESULT_VECTOR_EXECUTOR_TEST: &str = "raw_source_rebuild_v1_result_vector";
const REBUILD_RUNTIME_SOURCE_RELATIVE: &str =
"crates/event_store/src/nip09/reconciliation_v1/raw_source_rebuild.rs";
+const RECONCILIATION_RESULT_VECTOR_EXECUTOR_SOURCE_RELATIVE: &str =
+ "crates/event_store/src/nip09/reconciliation_v1/result_vector_executor.rs";
const REBUILD_FAILPOINT_TEST_SOURCE_RELATIVE: &str =
"crates/event_store/src/store/raw_source_rebuild_v1_tests.rs";
const REBUILD_FAILPOINT_TEST: &str = "raw_source_rebuild_failpoints_roll_back_every_stage_v1";
@@ -1036,6 +1042,21 @@ struct SourceFileDescriptor {
hash_algorithm: String,
}
+#[derive(Clone, Debug, Deserialize, Eq, PartialEq)]
+#[serde(deny_unknown_fields)]
+struct EventStoreProductionSourceInventory {
+ schema_version: u32,
+ hash_algorithm: String,
+ sources: Vec<EventStoreProductionSourceBaseline>,
+}
+
+#[derive(Clone, Debug, Deserialize, Eq, Ord, PartialEq, PartialOrd)]
+#[serde(deny_unknown_fields)]
+struct EventStoreProductionSourceBaseline {
+ path: String,
+ sha256: String,
+}
+
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
#[serde(deny_unknown_fields)]
struct PublicApiDescriptor {
@@ -1116,6 +1137,16 @@ pub(crate) fn validate_raw_source_rebuild_manifest(workspace_root: &Path) -> Res
super::blossom_publication_readiness::validate_blossom_publication_readiness(workspace_root)
}
+pub(super) fn validate_event_store_production_source_authority(
+ workspace_root: &Path,
+) -> Result<(), String> {
+ let manifest_bytes = read_regular_file(workspace_root, MANIFEST_RELATIVE)?;
+ let manifest: RawSourceRebuildManifest = serde_json::from_slice(&manifest_bytes)
+ .map_err(|error| format!("parse {MANIFEST_RELATIVE}: {error}"))?;
+ validate_manifest_shape(&manifest)?;
+ validate_event_store_production_source_inventory(workspace_root, &manifest).map(|_| ())
+}
+
pub(super) fn validate_raw_source_rebuild_predecessor_production_sources_under_lock(
workspace_root: &Path,
raw_superseded_paths: &[&str],
@@ -1125,6 +1156,8 @@ pub(super) fn validate_raw_source_rebuild_predecessor_production_sources_under_l
let manifest: RawSourceRebuildManifest = serde_json::from_slice(&manifest_bytes)
.map_err(|error| format!("parse {MANIFEST_RELATIVE}: {error}"))?;
validate_manifest_shape(&manifest)?;
+ let semantic_sources =
+ validate_event_store_production_source_inventory(workspace_root, &manifest)?;
let superseded = raw_superseded_paths
.iter()
@@ -1151,6 +1184,9 @@ pub(super) fn validate_raw_source_rebuild_predecessor_production_sources_under_l
if superseded.contains(source.path.as_str()) {
continue;
}
+ if semantic_sources.contains(source.path.as_str()) {
+ continue;
+ }
let current = read_regular_file(workspace_root, &source.path)?;
if current.len() as u64 != source.byte_length || sha256_hex(¤t) != source.sha256 {
return Err(format!(
@@ -1173,6 +1209,72 @@ pub(super) fn validate_raw_source_rebuild_predecessor_production_sources_under_l
)
}
+fn validate_event_store_production_source_inventory(
+ workspace_root: &Path,
+ manifest: &RawSourceRebuildManifest,
+) -> Result<BTreeSet<String>, String> {
+ let source_bytes = read_regular_file(workspace_root, EVENT_STORE_PRODUCTION_SOURCES_RELATIVE)?;
+ let source = std::str::from_utf8(&source_bytes).map_err(|error| {
+ format!("{EVENT_STORE_PRODUCTION_SOURCES_RELATIVE} must be UTF-8 TOML: {error}")
+ })?;
+ let inventory: EventStoreProductionSourceInventory = toml::from_str(&source)
+ .map_err(|error| format!("parse {EVENT_STORE_PRODUCTION_SOURCES_RELATIVE}: {error}"))?;
+ if inventory.schema_version != 1 || inventory.hash_algorithm != PRODUCTION_AST_HASH_ALGORITHM {
+ return Err(format!(
+ "{EVENT_STORE_PRODUCTION_SOURCES_RELATIVE} has unsupported identity"
+ ));
+ }
+ if inventory
+ .sources
+ .windows(2)
+ .any(|pair| pair[0].path >= pair[1].path)
+ {
+ return Err(format!(
+ "{EVENT_STORE_PRODUCTION_SOURCES_RELATIVE} source paths must be strictly sorted and unique"
+ ));
+ }
+
+ let expected_paths = manifest
+ .source_files
+ .iter()
+ .filter(|source| is_semantic_event_store_production_source(&source.path))
+ .map(|source| source.path.clone())
+ .collect::<BTreeSet<_>>();
+ let actual_paths = inventory
+ .sources
+ .iter()
+ .map(|source| source.path.clone())
+ .collect::<BTreeSet<_>>();
+ if actual_paths != expected_paths {
+ return Err(format!(
+ "{EVENT_STORE_PRODUCTION_SOURCES_RELATIVE} source inventory drifted; expected {expected_paths:?}, found {actual_paths:?}"
+ ));
+ }
+
+ for baseline in &inventory.sources {
+ validate_sha256("event-store production source baseline", &baseline.sha256)?;
+ let bytes = read_regular_file(workspace_root, &baseline.path)?;
+ let canonical = canonical_production_rust_bytes(&baseline.path, &bytes)?;
+ let actual_sha256 = sha256_hex(&canonical);
+ if actual_sha256 != baseline.sha256 {
+ return Err(format!(
+ "{} production Rust authority drifted: expected {}, found {actual_sha256}",
+ baseline.path, baseline.sha256
+ ));
+ }
+ }
+ Ok(actual_paths)
+}
+
+fn is_semantic_event_store_production_source(path: &str) -> bool {
+ path.starts_with("crates/event_store/src/")
+ && path.ends_with(".rs")
+ && path != "crates/event_store/src/generated.rs"
+ && !path.starts_with("crates/event_store/src/generated/")
+ && path != RECONCILIATION_RESULT_VECTOR_EXECUTOR_SOURCE_RELATIVE
+ && path != REBUILD_FAILPOINT_TEST_SOURCE_RELATIVE
+}
+
fn validate_raw_source_rebuild_manifest_under_lock(workspace_root: &Path) -> Result<(), String> {
validate_source_maintenance_manifest_under_lock(workspace_root)?;
for artifact in expected_artifacts(workspace_root)? {
@@ -6598,6 +6700,76 @@ mod tests {
}
#[test]
+ fn event_store_production_source_inventory_is_test_neutral_and_fail_closed() {
+ let root = workspace_root();
+ let workspace = tempfile::tempdir().expect("production source workspace");
+ let manifest: RawSourceRebuildManifest =
+ serde_json::from_slice(&read_regular_file(&root, MANIFEST_RELATIVE).expect("manifest"))
+ .expect("typed manifest");
+ for relative in std::iter::once(MANIFEST_RELATIVE)
+ .chain(std::iter::once(EVENT_STORE_PRODUCTION_SOURCES_RELATIVE))
+ .chain(
+ manifest
+ .source_files
+ .iter()
+ .map(|source| source.path.as_str())
+ .filter(|path| is_semantic_event_store_production_source(path)),
+ )
+ {
+ let destination = workspace.path().join(relative);
+ fs::create_dir_all(destination.parent().expect("source parent"))
+ .expect("create source parent");
+ fs::copy(root.join(relative), destination).expect("copy production source authority");
+ }
+ validate_event_store_production_source_authority(workspace.path())
+ .expect("current production source authority");
+
+ let error_relative = "crates/event_store/src/error.rs";
+ let error_path = workspace.path().join(error_relative);
+ let original = fs::read_to_string(&error_path).expect("read error source");
+ fs::write(
+ &error_path,
+ format!("{original}\n#[cfg(test)]\nfn coverage_probe() {{}}\n"),
+ )
+ .expect("write test-only source addition");
+ validate_event_store_production_source_authority(workspace.path())
+ .expect("test-only source addition must preserve production identity");
+
+ fs::write(
+ &error_path,
+ format!("{original}\nfn production_authority_drift() {{}}\n"),
+ )
+ .expect("write production source drift");
+ let error = validate_event_store_production_source_authority(workspace.path())
+ .expect_err("production source drift must fail closed");
+ assert!(
+ error.contains("production Rust authority drifted"),
+ "{error}"
+ );
+
+ fs::write(&error_path, original).expect("restore error source");
+ let inventory_path = workspace
+ .path()
+ .join(EVENT_STORE_PRODUCTION_SOURCES_RELATIVE);
+ let inventory = fs::read_to_string(&inventory_path).expect("read production inventory");
+ fs::write(
+ &inventory_path,
+ inventory.replacen(
+ "sha256 = \"e218754814e195a76fcdfa99c4c4abeaa3b045b4c799b56685ed8acfe5edb90b\"",
+ "sha256 = \"0000000000000000000000000000000000000000000000000000000000000000\"",
+ 1,
+ ),
+ )
+ .expect("write production baseline drift");
+ let error = validate_event_store_production_source_authority(workspace.path())
+ .expect_err("production baseline drift must fail closed");
+ assert!(
+ error.contains("production Rust authority drifted"),
+ "{error}"
+ );
+ }
+
+ #[test]
fn delegated_compiler_sources_and_xtask_targets_fail_closed() {
let root = workspace_root();
let pinned_workspace = tempfile::tempdir().expect("compiler pin workspace");
diff --git a/tools/xtask/src/contract/validator_inventory.rs b/tools/xtask/src/contract/validator_inventory.rs
@@ -146,6 +146,7 @@ pub(super) fn validate_semantic_validator_inventory(workspace_root: &Path) -> Re
"{INVENTORY_RELATIVE} implementation inventory drifted; missing {missing:?}, unexpected {unexpected:?}"
));
}
+ super::raw_source_rebuild::validate_event_store_production_source_authority(workspace_root)?;
Ok(())
}